📦 Enterprise Linux

by Redhat

🔍 What is Enterprise Linux?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-1709

CRITICAL CVSS 9.4 Feb 6, 2026

Keylime versions 7.12.0 and later have a critical authentication bypass vulnerability where the registrar fails to enforce client-side TLS certificate authentication. This allows unauthenticated netwo...

CVE-2025-32463

CRITICAL CVSS 9.3 Jun 30, 2025

This vulnerability in Sudo allows local users to escalate privileges to root by exploiting the --chroot option to load a malicious /etc/nsswitch.conf file from a user-controlled directory. It affects ...

CVE-2023-46846

CRITICAL CVSS 9.3 Nov 3, 2023

CVE-2023-46846 is an HTTP request smuggling vulnerability in Squid proxy due to lenient chunked decoder handling. It allows attackers to bypass security controls like firewalls and frontend systems by...

CVE-2023-34152

CRITICAL CVSS 9.8 May 30, 2023

CVE-2023-34152 is a critical remote code execution vulnerability in ImageMagick's OpenBlob function when compiled with --enable-pipes configuration. Attackers can exploit this by processing malicious ...

CVE-2022-30599

CRITICAL CVSS 9.8 May 18, 2022

CVE-2022-30599 is a critical SQL injection vulnerability in Moodle's badges functionality that allows attackers to execute arbitrary SQL commands. This affects all Moodle instances with badges enabled...

CVE-2022-1587

CRITICAL CVSS 9.1 May 16, 2022

An out-of-bounds read vulnerability in PCRE2 library's JIT compiler allows reading memory beyond allocated buffers during recursive regular expression processing. This affects any software using PCRE2...

CVE-2021-20325

CRITICAL CVSS 9.8 Feb 18, 2022

CVE-2021-20325 is a Red Hat-specific security regression where fixes for CVE-2021-40438 and CVE-2021-26691 were missing in httpd packages shipped with RHEL 8.5.0, making systems vulnerable to those CV...

CVE-2021-3657

CRITICAL CVSS 9.8 Feb 18, 2022

This vulnerability in mbsync allows remote attackers to execute arbitrary code by exploiting buffer overflows when processing extremely large IMAP literals. Affected users are those running mbsync ver...

CVE-2021-3773

CRITICAL CVSS 9.8 Feb 16, 2022

A netfilter flaw allows network-connected attackers to infer OpenVPN connection endpoint information by analyzing network traffic patterns. This affects Linux systems running OpenVPN with netfilter en...

CVE-2021-20314

CRITICAL CVSS 9.8 Aug 12, 2021

A stack buffer overflow vulnerability in libspf2 versions below 1.2.11 allows attackers to cause denial of service or potentially execute arbitrary code by sending malicious SPF explanation messages. ...

CVE-2021-20236

CRITICAL CVSS 9.8 May 28, 2021

A stack buffer overflow vulnerability in ZeroMQ servers before version 4.3.3 allows malicious clients to execute arbitrary code or crash the server by sending crafted topic subscription requests follo...

CVE-2018-25009

CRITICAL CVSS 9.1 May 21, 2021

A heap-based buffer overflow vulnerability in libwebp's GetLE16() function allows attackers to execute arbitrary code or cause denial of service. This affects any application that processes WebP image...

CVE-2018-25011

CRITICAL CVSS 9.8 May 21, 2021

A heap-based buffer overflow vulnerability in libwebp's PutLE16() function allows attackers to execute arbitrary code or cause denial of service. This affects any application that processes WebP image...

CVE-2018-25012

CRITICAL CVSS 9.1 May 21, 2021

A heap-based buffer overflow vulnerability in libwebp's GetLE24() function allows attackers to execute arbitrary code or cause denial of service by processing malicious WebP images. This affects any a...

CVE-2018-25014

CRITICAL CVSS 9.8 May 21, 2021

CVE-2018-25014 is a use-after-free vulnerability in libwebp's ReadSymbol() function that allows attackers to execute arbitrary code or cause denial of service. This affects any application using libwe...

CVE-2020-36329

CRITICAL CVSS 9.8 May 21, 2021

CVE-2020-36329 is a use-after-free vulnerability in libwebp that allows attackers to execute arbitrary code or cause denial of service. This affects any application using vulnerable versions of libweb...

CVE-2020-36330

CRITICAL CVSS 9.1 May 21, 2021

CVE-2020-36330 is an out-of-bounds read vulnerability in libwebp versions before 1.0.1, allowing attackers to read sensitive memory data or cause denial-of-service. It affects systems using libwebp fo...

CVE-2021-3466

CRITICAL CVSS 9.8 Mar 25, 2021

CVE-2021-3466 is a buffer overflow vulnerability in libmicrohttpd's post_process_urlencoded function due to missing bounds checking. This allows remote attackers to write arbitrary data to memory, pot...

CVE-2021-20231

CRITICAL CVSS 9.8 Mar 12, 2021

This CVE-2021-20231 is a critical use-after-free vulnerability in GnuTLS that occurs when a client sends a key_share extension, potentially leading to memory corruption. Attackers could exploit this t...

CVE-2020-27846

CRITICAL CVSS 9.8 Dec 21, 2020

CVE-2020-27846 is a signature verification vulnerability in the crewjam/saml library that allows attackers to bypass SAML authentication. This affects any application using vulnerable versions of this...

CVE-2026-26103

HIGH CVSS 7.1 Feb 25, 2026

A local privilege escalation vulnerability in udisks allows unprivileged users to trigger the root-owned daemon to overwrite LUKS encryption headers. This permanently destroys encryption keys, renderi...

CVE-2025-9784

HIGH CVSS 7.5 Sep 2, 2025

This vulnerability in Undertow allows malicious clients to send malformed requests that trigger server-side stream resets without incrementing abuse counters. This 'MadeYouReset' attack enables denial...

CVE-2025-7424

HIGH CVSS 7.5 Jul 10, 2025

A type confusion vulnerability in libxslt's psvi memory field allows attackers to crash applications or corrupt memory during XML transformations. This affects any software using vulnerable libxslt ve...

CVE-2025-5318

HIGH CVSS 8.1 Jun 24, 2025

This vulnerability in libssh allows an authenticated remote attacker to trigger an out-of-bounds read in the sftp_handle function, potentially exposing sensitive memory contents or affecting service b...

CVE-2025-6021

HIGH CVSS 7.5 Jun 12, 2025

This CVE describes an integer overflow vulnerability in libxml2's xmlBuildQName function that can cause stack-based buffer overflow when processing malicious XML input. This vulnerability affects any ...

CVE-2025-5914

HIGH CVSS 7.8 Jun 9, 2025

This CVE describes an integer overflow vulnerability in libarchive's RAR handling function that leads to a double-free condition. Attackers can exploit this to execute arbitrary code or cause denial-o...

CVE-2025-46397

HIGH CVSS 7.8 Apr 23, 2025

A buffer overflow vulnerability in xfig's bezier_spline function allows local attackers to execute arbitrary code by manipulating input. This affects systems running vulnerable versions of xfig, prima...

CVE-2025-3155

HIGH CVSS 7.4 Apr 3, 2025

CVE-2025-3155 is a vulnerability in Yelp (the GNOME help application) that allows malicious help documents to execute arbitrary scripts. This could enable attackers to exfiltrate user files to externa...

CVE-2025-2784

HIGH CVSS 7.0 Apr 3, 2025

CVE-2025-2784 is a heap buffer over-read vulnerability in libsoup's skip_insight_whitespace() function. When processing a malicious HTTP response, libsoup clients can read one byte beyond allocated me...

CVE-2025-0678

HIGH CVSS 7.8 Mar 3, 2025

A heap-based buffer overflow vulnerability in grub2's squash4 filesystem module allows attackers to execute arbitrary code by crafting malicious filesystems. This affects systems using grub2 with squa...

CVE-2024-45782

HIGH CVSS 7.8 Mar 3, 2025

This vulnerability in the HFS filesystem driver allows attackers to trigger a heap-based buffer overflow by providing a specially crafted volume name. This could lead to arbitrary code execution in GR...

CVE-2025-26600

HIGH CVSS 7.8 Feb 25, 2025

A use-after-free vulnerability in X.Org and Xwayland allows attackers to potentially execute arbitrary code or cause denial of service when a device is removed while frozen. This affects systems using...

CVE-2025-26601

HIGH CVSS 7.8 Feb 25, 2025

A use-after-free vulnerability in X.Org and Xwayland allows attackers to potentially execute arbitrary code or cause denial of service. This affects systems using X11 display servers or Wayland compos...

CVE-2025-26599

HIGH CVSS 7.8 Feb 25, 2025

This CVE describes an uninitialized pointer vulnerability in X.Org and Xwayland display servers. When compCheckRedirect() fails to allocate a backing pixmap, compRedirectWindow() returns a BadAlloc er...

CVE-2025-26594

HIGH CVSS 7.8 Feb 25, 2025

A use-after-free vulnerability in X.Org and Xwayland allows attackers to potentially crash the X server or execute arbitrary code by freeing the root cursor. This affects systems running X.Org Server ...

CVE-2025-26595

HIGH CVSS 7.8 Feb 25, 2025

A stack-based buffer overflow vulnerability in X.Org and Xwayland allows attackers to execute arbitrary code or cause denial of service. This affects systems using X Window System or Wayland with Xway...

CVE-2025-26596

HIGH CVSS 7.8 Feb 25, 2025

A heap buffer overflow vulnerability in X.Org and Xwayland allows attackers to write beyond allocated memory boundaries. This affects systems using X11 display servers or Xwayland for Wayland compatib...

CVE-2025-26597

HIGH CVSS 7.8 Feb 25, 2025

A buffer overflow vulnerability in X.Org and Xwayland allows attackers to execute arbitrary code or cause denial of service by exploiting improper memory handling in keyboard symbol table resizing. Th...

CVE-2025-26598

HIGH CVSS 7.8 Feb 25, 2025

This CVE describes an out-of-bounds write vulnerability in X.Org and Xwayland where the GetBarrierDevice() function incorrectly returns the last element of a device list instead of NULL when no matchi...

CVE-2024-12085

HIGH CVSS 7.5 Jan 14, 2025

This vulnerability in rsync allows attackers to leak uninitialized stack memory one byte at a time by manipulating checksum length during file comparison. It affects systems using vulnerable rsync ver...

CVE-2024-9675

HIGH CVSS 7.8 Oct 9, 2024

This vulnerability in Buildah allows attackers to bypass path validation in cache mounts, enabling arbitrary host directory access during container builds. Users running Buildah with untrusted Contain...

CVE-2024-44070

HIGH CVSS 7.5 Aug 19, 2024

A buffer overflow vulnerability exists in FRRouting (FRR) BGP daemon where bgp_attr_encap function fails to validate stream length before processing TLV values. This allows attackers to cause denial o...

CVE-2024-3056

HIGH CVSS 7.7 Aug 2, 2024

This vulnerability in Podman allows attackers to create malicious containers that exhaust system memory through IPC resource exhaustion. When containers share IPC namespaces, a malicious container can...

CVE-2024-6239

HIGH CVSS 7.5 Jun 21, 2024

A vulnerability in Poppler's Pdfinfo utility allows attackers to cause denial of service by crashing the application when using the -dests parameter with specially crafted PDF files. This affects syst...

CVE-2024-3183

HIGH CVSS 8.1 Jun 12, 2024

This FreeIPA vulnerability allows attackers who compromise a principal to obtain encrypted Kerberos tickets and salts, enabling offline brute-force attacks to recover passwords. It affects FreeIPA dep...

CVE-2023-3758

HIGH CVSS 7.1 Apr 18, 2024

A race condition in SSSD (System Security Services Daemon) causes inconsistent application of Group Policy Object (GPO) policies for authenticated users. This can lead to improper authorization decisi...

CVE-2024-2002

HIGH CVSS 7.5 Mar 18, 2024

A double-free vulnerability in libdwarf allows memory corruption when processing specially crafted DWARF debugging information files. This could lead to denial of service, arbitrary code execution, or...

CVE-2024-1488

HIGH CVSS 8.0 Feb 15, 2024

This CVE allows any local process to modify Unbound DNS resolver's runtime configuration via port 8953 due to incorrect default permissions. Attackers can alter DNS forwarders to intercept or disrupt ...

CVE-2023-50387

HIGH CVSS 7.5 Feb 14, 2024

CVE-2023-50387 (KeyTrap) is a DNSSEC protocol vulnerability that allows remote attackers to cause denial of service by exhausting CPU resources through specially crafted DNSSEC responses. The vulnerab...

CVE-2024-0229

HIGH CVSS 7.8 Feb 9, 2024

This vulnerability in the X.Org server allows out-of-bounds memory access when a frozen device is reattached to a different master device. It can lead to application crashes, local privilege escalatio...

CVE-2023-50781

HIGH CVSS 7.5 Feb 5, 2024

This vulnerability in m2crypto allows attackers to decrypt TLS communications that use RSA key exchanges, potentially exposing sensitive data transmitted over encrypted channels. It affects TLS server...

CVE-2023-6531

HIGH CVSS 7.0 Jan 21, 2024

A use-after-free vulnerability in the Linux kernel's Unix domain socket garbage collector allows local attackers to potentially escalate privileges or cause denial of service. The race condition occur...

CVE-2024-0409

HIGH CVSS 7.8 Jan 18, 2024

This vulnerability in X.Org server's cursor code allows memory corruption by using incorrect private types in Xephyr and Xwayland, potentially leading to privilege escalation or denial of service. It ...

CVE-2024-0646

HIGH CVSS 7.0 Jan 17, 2024

This CVE describes an out-of-bounds memory write vulnerability in the Linux kernel's TLS implementation when using splice() with ktls sockets. A local attacker can exploit this to crash the system or ...

CVE-2024-0562

HIGH CVSS 7.8 Jan 15, 2024

A use-after-free vulnerability in the Linux kernel's writeback subsystem allows attackers to potentially crash the system or execute arbitrary code with kernel privileges. This affects Linux systems w...

CVE-2024-0193

HIGH CVSS 7.8 Jan 2, 2024

A use-after-free vulnerability in the Linux kernel's netfilter subsystem allows local unprivileged users with CAP_NET_ADMIN capability to escalate privileges. This flaw occurs when the catchall elemen...

CVE-2023-51767

HIGH CVSS 7.0 Dec 24, 2023

This CVE describes a potential row hammer attack vulnerability in OpenSSH that could allow authentication bypass. An attacker with physical access to the same hardware could flip bits in memory to byp...

CVE-2023-6546

HIGH CVSS 7.0 Dec 21, 2023

This CVE describes a race condition vulnerability in the Linux kernel's GSM 0710 tty multiplexor. It allows a local unprivileged user to trigger a use-after-free condition, potentially leading to priv...

CVE-2023-47038

HIGH CVSS 7.0 Dec 18, 2023

This vulnerability in Perl allows an attacker to trigger a heap buffer overflow by providing a malicious regular expression. Systems running affected Perl versions (5.30.0 through 5.38.0) that process...

CVE-2023-5869

HIGH CVSS 8.8 Dec 10, 2023

This CVE-2023-5869 vulnerability in PostgreSQL allows authenticated database users to execute arbitrary code on the server through an integer overflow when modifying SQL arrays. Attackers can write ar...

CVE-2025-14512

MEDIUM CVSS 6.5 Dec 11, 2025

This vulnerability in GLib's GIO component allows heap buffer overflow and denial-of-service via integer overflow when processing malicious file attributes. Systems using GLib for file operations or r...

CVE-2025-14087

MEDIUM CVSS 5.6 Dec 10, 2025

A buffer-underflow vulnerability in GLib's GVariant parser allows remote attackers to cause heap corruption by sending maliciously crafted input strings. This can lead to denial of service or potentia...

CVE-2025-32990

MEDIUM CVSS 6.5 Jul 10, 2025

This CVE describes a heap-buffer-overflow vulnerability in GnuTLS's certtool utility when parsing template files. An attacker can trigger memory corruption leading to denial-of-service (system crash)....

CVE-2025-32989

MEDIUM CVSS 5.3 Jul 10, 2025

A heap-buffer-overread vulnerability in GnuTLS allows attackers to create malicious certificates with malformed Certificate Transparency extensions that leak sensitive information during certificate v...

CVE-2025-5372

MEDIUM CVSS 5.0 Jul 4, 2025

A vulnerability in libssh versions built with OpenSSL <3.0 causes the ssh_kdf() function to incorrectly report successful key derivation when it actually fails. This leads to uninitialized cryptograph...

CVE-2025-4598

MEDIUM CVSS 4.7 May 30, 2025

This vulnerability in systemd-coredump allows attackers to exploit a race condition to access privileged process coredumps. By forcing a SUID process to crash and replacing it before systemd-coredump ...

CVE-2025-46399

MEDIUM CVSS 5.5 Apr 23, 2025

A NULL pointer dereference vulnerability exists in fig2dev's genge_itp_spline function, allowing local attackers to cause denial of service through input manipulation. This affects systems running vul...

CVE-2024-45778

MEDIUM CVSS 4.1 Mar 3, 2025

A stack overflow vulnerability in GRUB2's BFS filesystem parser allows an attacker to crash the bootloader by providing a specially crafted BFS filesystem. This affects systems using GRUB2 with BFS su...

CVE-2024-45777

MEDIUM CVSS 6.7 Feb 19, 2025

This vulnerability in grub2 allows attackers to trigger an out-of-bounds write when processing language files, potentially overwriting sensitive heap data. This could lead to bypassing secure boot pro...

CVE-2025-26465

MEDIUM CVSS 6.8 Feb 18, 2025

This OpenSSH vulnerability allows machine-in-the-middle attacks when VerifyHostKeyDNS is enabled. Attackers can impersonate legitimate servers by exploiting error code mishandling during host key veri...

CVE-2024-12086

MEDIUM CVSS 6.1 Jan 14, 2025

This rsync vulnerability allows a malicious server to read arbitrary files from a client's machine during file transfer operations. Attackers can reconstruct file contents byte-by-byte by sending spec...

CVE-2024-12088

MEDIUM CVSS 6.5 Jan 14, 2025

A path traversal vulnerability in rsync's --safe-links option allows attackers to write files outside intended directories when the client fails to properly verify nested symbolic links from the serve...

CVE-2024-49394

MEDIUM CVSS 5.3 Nov 12, 2024

This vulnerability in mutt and neomutt email clients allows attackers to reuse signed but unencrypted email messages by manipulating the In-Reply-To header, enabling sender impersonation. It affects u...

CVE-2024-9676

MEDIUM CVSS 6.5 Oct 15, 2024

A symlink traversal vulnerability in the containers/storage library used by Podman, Buildah, and CRI-O allows malicious container images to cause denial of service via OOM kill. Attackers can exploit ...

CVE-2024-9341

MEDIUM CVSS 5.4 Oct 1, 2024

This vulnerability in Go's containers/common library allows attackers to exploit symbolic links when FIPS mode is enabled, potentially mounting sensitive host directories inside containers. This bypas...

CVE-2024-8354

MEDIUM CVSS 5.5 Sep 19, 2024

A vulnerability in QEMU's USB endpoint handling allows unprivileged guest users to trigger an assertion failure, crashing the QEMU process on the host. This causes a denial of service affecting any ho...

CVE-2024-45619

MEDIUM CVSS 4.3 Sep 3, 2024

A buffer handling vulnerability in OpenSC and related components allows attackers to access uninitialized memory via crafted USB devices or smart cards. This could lead to information disclosure or sy...

CVE-2024-6237

MEDIUM CVSS 6.5 Jul 9, 2024

CVE-2024-6237 is a denial-of-service vulnerability in 389 Directory Server where an unauthenticated attacker can crash the server by sending a specific extended search request. This affects organizati...

CVE-2024-6505

MEDIUM CVSS 6.8 Jul 5, 2024

A heap overflow vulnerability in QEMU's virtio-net device allows privileged guest users to crash the host QEMU process by manipulating RSS indirections_table values. This affects virtualization enviro...

CVE-2024-5742

MEDIUM CVSS 6.7 Jun 12, 2024

This vulnerability in GNU Nano allows local privilege escalation through insecure temporary file handling. When Nano is killed during editing, it creates an emergency file with user permissions that a...

CVE-2024-3049

MEDIUM CVSS 5.9 Jun 6, 2024

This vulnerability in Booth cluster ticket manager allows an attacker to bypass HMAC validation by providing a specially-crafted hash to gcry_md_get_algo_dlen(). This could enable unauthorized access ...

CVE-2023-33951

MEDIUM CVSS 6.7 Jul 24, 2023

A race condition vulnerability in the Linux kernel's vmwgfx driver allows improper handling of GEM objects due to insufficient locking. This enables a local privileged user to leak kernel memory infor...

CVE-2023-1073

MEDIUM CVSS 6.6 Mar 27, 2023

A memory corruption vulnerability in the Linux kernel's HID subsystem allows local attackers to crash the system or potentially escalate privileges by inserting a malicious USB device. This affects Li...