CVE-2026-15816
- EPSS 0.26%
- Veröffentlicht 07.08.2026 10:33:33
- Zuletzt bearbeitet 20.08.2026 22:17:07
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option...
CVE-2026-19079
- EPSS 0.08%
- Veröffentlicht 07.08.2026 07:21:55
- Zuletzt bearbeitet 14.08.2026 19:07:46
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files un...
CVE-2026-49331
- EPSS 0.13%
- Veröffentlicht 05.08.2026 14:40:45
- Zuletzt bearbeitet 06.08.2026 15:37:22
A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application...
CVE-2026-58216
- EPSS 0.52%
- Veröffentlicht 30.07.2026 16:17:14
- Zuletzt bearbeitet 31.07.2026 23:17:25
An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the structure size and at...
CVE-2026-49332
- EPSS 0.28%
- Veröffentlicht 28.07.2026 12:18:26
- Zuletzt bearbeitet 20.08.2026 17:17:40
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks nor...
CVE-2026-16730
- EPSS 0.11%
- Veröffentlicht 24.07.2026 11:26:18
- Zuletzt bearbeitet 14.08.2026 08:17:37
A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connection...
CVE-2026-15813
- EPSS 0.27%
- Veröffentlicht 20.07.2026 10:36:03
- Zuletzt bearbeitet 21.07.2026 18:31:51
A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack...
CVE-2026-48914
- EPSS 0.16%
- Veröffentlicht 12.06.2026 09:42:36
- Zuletzt bearbeitet 15.07.2026 00:16:17
A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a ma...
CVE-2026-10843
- EPSS 0.33%
- Veröffentlicht 04.06.2026 12:04:49
- Zuletzt bearbeitet 22.07.2026 20:10:00
A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-s...
CVE-2026-7309
- EPSS 0.18%
- Veröffentlicht 28.04.2026 12:33:55
- Zuletzt bearbeitet 07.05.2026 02:16:00
A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantia...