📦 Enterprise Linux For Ibm Z Systems

by Redhat

🔍 What is Enterprise Linux For Ibm Z Systems?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-1709

CRITICAL CVSS 9.4 Feb 6, 2026

Keylime versions 7.12.0 and later have a critical authentication bypass vulnerability where the registrar fails to enforce client-side TLS certificate authentication. This allows unauthenticated netwo...

CVE-2023-46846

CRITICAL CVSS 9.3 Nov 3, 2023

CVE-2023-46846 is an HTTP request smuggling vulnerability in Squid proxy due to lenient chunked decoder handling. It allows attackers to bypass security controls like firewalls and frontend systems by...

CVE-2025-13601

HIGH CVSS 7.7 Nov 26, 2025

A heap-based buffer overflow vulnerability in glib's g_escape_uri_string() function allows attackers to write beyond allocated memory boundaries when processing strings with many characters requiring ...

CVE-2025-6021

HIGH CVSS 7.5 Jun 12, 2025

This CVE describes an integer overflow vulnerability in libxml2's xmlBuildQName function that can cause stack-based buffer overflow when processing malicious XML input. This vulnerability affects any ...

CVE-2025-3155

HIGH CVSS 7.4 Apr 3, 2025

CVE-2025-3155 is a vulnerability in Yelp (the GNOME help application) that allows malicious help documents to execute arbitrary scripts. This could enable attackers to exfiltrate user files to externa...

CVE-2025-2784

HIGH CVSS 7.0 Apr 3, 2025

CVE-2025-2784 is a heap buffer over-read vulnerability in libsoup's skip_insight_whitespace() function. When processing a malicious HTTP response, libsoup clients can read one byte beyond allocated me...

CVE-2025-1755

HIGH CVSS 7.5 Feb 27, 2025

MongoDB Compass versions before 1.42.1 are vulnerable to local privilege escalation when a malicious file is placed in the C:\node_modules\ directory. This allows attackers with local access to execut...

CVE-2025-1756

HIGH CVSS 7.5 Feb 27, 2025

MongoDB Shell (mongosh) versions before 2.3.0 are vulnerable to local privilege escalation when a malicious file is placed in C:\node_modules\. This allows attackers with local access to execute arbit...

CVE-2024-12085

HIGH CVSS 7.5 Jan 14, 2025

This vulnerability in rsync allows attackers to leak uninitialized stack memory one byte at a time by manipulating checksum length during file comparison. It affects systems using vulnerable rsync ver...

CVE-2024-9675

HIGH CVSS 7.8 Oct 9, 2024

This vulnerability in Buildah allows attackers to bypass path validation in cache mounts, enabling arbitrary host directory access during container builds. Users running Buildah with untrusted Contain...

CVE-2023-3758

HIGH CVSS 7.1 Apr 18, 2024

A race condition in SSSD (System Security Services Daemon) causes inconsistent application of Group Policy Object (GPO) policies for authenticated users. This can lead to improper authorization decisi...

CVE-2024-1488

HIGH CVSS 8.0 Feb 15, 2024

This CVE allows any local process to modify Unbound DNS resolver's runtime configuration via port 8953 due to incorrect default permissions. Attackers can alter DNS forwarders to intercept or disrupt ...

CVE-2024-0409

HIGH CVSS 7.8 Jan 18, 2024

This vulnerability in X.Org server's cursor code allows memory corruption by using incorrect private types in Xephyr and Xwayland, potentially leading to privilege escalation or denial of service. It ...

CVE-2023-5869

HIGH CVSS 8.8 Dec 10, 2023

This CVE-2023-5869 vulnerability in PostgreSQL allows authenticated database users to execute arbitrary code on the server through an integer overflow when modifying SQL arrays. Attackers can write ar...

CVE-2023-3972

HIGH CVSS 7.8 Nov 1, 2023

This vulnerability allows unprivileged local users to escalate privileges to root by exploiting insecure temporary directory handling in insights-client. Attackers can create and control the /var/tmp/...

CVE-2023-5367

HIGH CVSS 7.8 Oct 25, 2023

This CVE-2023-5367 is an out-of-bounds write vulnerability in xorg-x11-server that allows attackers to write beyond allocated heap buffers. It could lead to privilege escalation or denial of service o...

CVE-2023-5633

HIGH CVSS 7.8 Oct 23, 2023

CVE-2023-5633 is a use-after-free vulnerability in VMware's 3D acceleration memory handling that allows local unprivileged users within a VMware guest virtual machine to escalate privileges. This affe...

CVE-2023-4911

HIGH CVSS 7.8 Oct 3, 2023

CVE-2023-4911 is a buffer overflow vulnerability in the GNU C Library's dynamic loader (ld.so) that allows local attackers to exploit SUID binaries. By crafting malicious GLIBC_TUNABLES environment va...

CVE-2023-5157

HIGH CVSS 7.5 Sep 27, 2023

A vulnerability in MariaDB allows remote attackers to cause denial of service via port scans on ports 3306 and 4567. This affects MariaDB servers with these ports exposed to untrusted networks. The vu...

CVE-2023-38200

HIGH CVSS 7.5 Jul 24, 2023

This vulnerability in Keylime's registrar component allows remote attackers to cause a denial of service by exhausting all available SSL connections due to their blocking nature. It affects systems ru...

CVE-2023-0179

HIGH CVSS 7.8 Mar 27, 2023

A buffer overflow vulnerability in the Linux Kernel's Netfilter subsystem allows local attackers to leak memory addresses and potentially execute arbitrary code. This could lead to local privilege esc...

CVE-2023-0494

HIGH CVSS 7.8 Mar 27, 2023

This CVE-2023-0494 vulnerability in X.Org allows attackers to exploit a dangling pointer in DeepCopyPointerClasses via ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() functions. This can lead to loc...

CVE-2019-8720

HIGH CVSS 8.8 Mar 6, 2023

CVE-2019-8720 is a memory corruption vulnerability in WebKit that allows arbitrary code execution when processing malicious web content. This affects any application using WebKit for web rendering, in...

CVE-2022-1227

HIGH CVSS 8.8 Apr 29, 2022

CVE-2022-1227 is a privilege escalation vulnerability in Podman that allows attackers to gain host filesystem access when users run 'podman top' on malicious container images. This affects Podman user...

CVE-2022-27649

HIGH CVSS 7.5 Apr 4, 2022

This vulnerability in Podman and Moby (Docker Engine) allows containers to start with non-empty inheritable Linux process capabilities. An attacker with access to programs having inheritable file capa...

CVE-2022-0330

HIGH CVSS 7.8 Mar 25, 2022

A memory access vulnerability in the Linux kernel's i915 GPU driver allows local attackers to execute malicious GPU code, potentially causing system crashes or privilege escalation. This affects Linux...

CVE-2022-1011

HIGH CVSS 7.8 Mar 18, 2022

A use-after-free vulnerability in the Linux kernel's FUSE filesystem allows a local attacker to trigger write() operations that can lead to unauthorized data access and privilege escalation. This affe...

CVE-2022-0847

HIGH CVSS 7.8 Mar 10, 2022

CVE-2022-0847 (Dirty Pipe) is a Linux kernel vulnerability that allows unprivileged local users to write to read-only files in the page cache, enabling privilege escalation to root. This affects Linux...

CVE-2022-0516

HIGH CVSS 7.8 Mar 10, 2022

A local privilege escalation vulnerability in the KVM subsystem for s390 architecture in Linux kernel allows a local attacker with normal user privileges to gain unauthorized memory write access. This...

CVE-2021-3656

HIGH CVSS 8.8 Mar 4, 2022

This vulnerability in KVM's AMD SVM nested virtualization allows a malicious L1 guest to disable security intercepts for L2 guests, potentially enabling L2 guests to read/write host physical memory. T...

CVE-2021-23214

HIGH CVSS 8.1 Mar 4, 2022

CVE-2021-23214 is a SQL injection vulnerability in PostgreSQL that allows man-in-the-middle attackers to inject arbitrary SQL queries during initial connection establishment, even when SSL certificate...

CVE-2022-0492

HIGH CVSS 7.8 Mar 3, 2022

CVE-2022-0492 is a Linux kernel vulnerability in the cgroups v1 release_agent feature that allows local attackers to escalate privileges and escape container namespaces. This affects Linux systems usi...

CVE-2021-4091

HIGH CVSS 7.5 Feb 18, 2022

CVE-2021-4091 is a double-free vulnerability in 389 Directory Server's handling of virtual attributes during persistent searches. An attacker can send crafted search requests to cause the directory se...

CVE-2020-25717

HIGH CVSS 8.1 Feb 18, 2022

CVE-2020-25717 is a privilege escalation vulnerability in Samba's domain user mapping mechanism. Authenticated attackers can exploit this flaw to gain elevated privileges on Samba servers. This affect...

CVE-2020-25719

HIGH CVSS 7.2 Feb 18, 2022

This vulnerability in Samba's Active Directory Domain Controller allows attackers to bypass Kerberos authentication by exploiting confusion about user identity when Kerberos PAC (Privilege Attribute C...

CVE-2021-3551

HIGH CVSS 7.8 Feb 16, 2022

CVE-2021-3551 is a credential exposure vulnerability in Dogtag PKI-server where the spkispawn command, when run in debug mode, stores admin credentials in installation log files. This allows local att...

CVE-2021-4034

HIGH CVSS 7.8 Jan 28, 2022

CVE-2021-4034 (PwnKit) is a local privilege escalation vulnerability in polkit's pkexec utility that allows unprivileged local users to gain root privileges by exploiting improper argument handling. T...

CVE-2024-12088

MEDIUM CVSS 6.5 Jan 14, 2025

A path traversal vulnerability in rsync's --safe-links option allows attackers to write files outside intended directories when the client fails to properly verify nested symbolic links from the serve...

CVE-2024-9676

MEDIUM CVSS 6.5 Oct 15, 2024

A symlink traversal vulnerability in the containers/storage library used by Podman, Buildah, and CRI-O allows malicious container images to cause denial of service via OOM kill. Attackers can exploit ...

CVE-2024-3049

MEDIUM CVSS 5.9 Jun 6, 2024

This vulnerability in Booth cluster ticket manager allows an attacker to bypass HMAC validation by providing a specially-crafted hash to gcry_md_get_algo_dlen(). This could enable unauthorized access ...