Redhat

Enterprise Linux

1709 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 17.09.2019 16:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:27

A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descript...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 13.09.2019 13:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:54

In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transaction (via the hardware transa...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 13.09.2019 13:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:54

In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instr...

  • EPSS 0.04%
  • Veröffentlicht 11.09.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:30:19

drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.

  • EPSS 0.09%
  • Veröffentlicht 11.09.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:30:20

drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.

  • EPSS 0.03%
  • Veröffentlicht 11.09.2019 16:15:10
  • Zuletzt bearbeitet 21.11.2024 04:30:19

drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: The security community disputes this issues as not being serious enough to be deservin...

  • EPSS 0.76%
  • Veröffentlicht 06.09.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:52:26

LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Script...

  • EPSS 8.45%
  • Veröffentlicht 06.09.2019 14:15:15
  • Zuletzt bearbeitet 21.11.2024 04:27:24

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable se...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 04.09.2019 12:15:11
  • Zuletzt bearbeitet 21.11.2024 04:29:19

In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivile...

  • EPSS 0.09%
  • Veröffentlicht 29.08.2019 18:15:12
  • Zuletzt bearbeitet 21.11.2024 04:29:30

In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c when SAS expander discovery fails. This will cause a BUG and denial of service.