Search

Found 5,504 results in 703ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-23144 medium 5.5 FIX rhel sles rocky 2mo ago In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: cleanup attrs subdirs on context dir setup failure When a context DAMON sysfs directory setup is failed after set…
CVE-2025-38180 medium 5.5 FIX rocky rhel sles 2mo ago In the Linux kernel, the following vulnerability has been resolved: net: atm: fix /proc/net/atm/lec handling /proc/net/atm/lec must ensure safety against dev_lec[] changes. It appears it had dev_p…
CVE-2026-4948 medium 5.5 5.5 FIX debian debian sles rhel firewalld 2mo ago A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-au…
CVE-2026-2100 medium 5.3 5.3 FIX rhel slesdebian debian p11-kit_projectredhat 2mo ago A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters se…
CVE-2026-25749 medium 5.5 FIX rocky rhel sles 2mo ago Moderate: vim security update
CVE-2026-23893 medium 5.5 FIX rocky rhel sles 2mo ago RHSA-2026:5587: opencryptoki security update (Moderate)
CVE-2026-4426 medium 6.5 6.5 FIX debian debian sles rhel libarchiveredhat 3mo ago A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge exte…
CVE-2026-21964 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:6391: mysql:8.4 security update (Moderate)
CVE-2026-21948 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:6391: mysql:8.4 security update (Moderate)
CVE-2026-21941 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:6391: mysql:8.4 security update (Moderate)
CVE-2026-21937 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:6391: mysql:8.4 security update (Moderate)
CVE-2026-21936 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:6391: mysql:8.4 security update (Moderate)
CVE-2025-39818 medium 5.5 FIX rhel sles rocky 3mo ago In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-thc: Fix incorrect pointer arithmetic in I2C regs save Improper use of secondary pointer (&dev->i2c_sub…
CVE-2026-2376 medium 5.4 5.4 rhel redhat 3mo ago A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the applicat…
CVE-2026-1299 medium 5.5 FIX rocky rhel sles 3mo ago The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is seriali…
CVE-2025-9820 medium 4.0 4.0 FIX rocky rheldebian debian 3mo ago RHSA-2026:5585: gnutls security update (Moderate)
CVE-2025-15367 medium 5.5 FIX rocky rheldebian debian 3mo ago The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2025-15366 medium 5.5 FIX rocky rheldebian debian 3mo ago The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2025-14831 medium 5.3 5.3 FIX rocky rheldebian debian 3mo ago RHSA-2026:5585: gnutls security update (Moderate)
CVE-2026-23001 medium 5.5 FIX rocky rhel sles 3mo ago In the Linux kernel, the following vulnerability has been resolved: macvlan: fix possible UAF in macvlan_forward_source() Add RCU protection on (struct macvlan_source_entry)->vlan. Whenever macvla…
CVE-2025-38106 medium 5.5 FIX rhel slesdebian debian 3mo ago In the Linux kernel, the following vulnerability has been resolved: io_uring: fix use-after-free of sq->thread in __io_uring_show_fdinfo() syzbot reports: BUG: KASAN: slab-use-after-free in getrus…
CVE-2025-12801 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:3938: nfs-utils security update (Moderate)
CVE-2021-30952 medium 7.0 KEVFIX sles rockydebian debian 3mo ago Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code executio…
CVE-2026-1642 medium 5.5 FIX rocky rhel sles 3mo ago RHSA-2026:5581: nginx:1.24 security update (Moderate)
CVE-2026-23097 medium 5.5 FIX rocky rhel sles 3mo ago In the Linux kernel, the following vulnerability has been resolved: migrate: correct lock ordering for hugetlb file folios Syzbot has found a deadlock (analyzed by Lance Yang): 1) Task (5749): Hol…
CVE-2025-71085 medium 5.5 FIX rocky rhel sles 3mo ago In the Linux kernel, the following vulnerability has been resolved: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() There exists a kernel oops caused by a BUG_ON(nhead < 0) at…
CVE-2025-40168 medium 5.5 FIX rocky rhel sles 3mo ago In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). smc_clc_prfx_match() is called from smc_listen_work() and not …
CVE-2025-14905 medium 5.5 FIX debian debian rocky rhel 3mo ago RHSA-2026:5513: 389-ds:1.4 security update (Moderate)
CVE-2025-38206 medium 5.5 FIX rhel slesdebian debian 3mo ago In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double free could happen in the following path. exfat_create_upcase_table() e…
CVE-2026-0915 medium 5.5 FIX rocky rheldebian debian google 4mo ago RHSA-2026:4772: glibc security update (Moderate)
CVE-2026-0861 medium 5.5 FIX rheldebian debian sles google 4mo ago Moderate: glibc security update
CVE-2025-15281 medium 5.5 FIX rocky rheldebian debian google 4mo ago RHSA-2026:4772: glibc security update (Moderate)
CVE-2026-22998 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec Commit efa56305908b ("nvmet-tcp: Fix a kernel panic when hos…
CVE-2025-68811 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: svcrdma: use rc_pageoff for memcpy byte offset svc_rdma_copy_inline_range added rc_curpage (page index) to the page base instead …
CVE-2025-68349 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid Fixes a crash when layout is null during this call sta…
CVE-2025-40322 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: fbdev: bitblit: bound-check glyph index in bit_putcs* bit_putcs_aligned()/unaligned() derived the glyph pointer from the characte…
CVE-2025-40304 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds Add bounds checking to prevent writes past framebuffer bound…
CVE-2023-53034 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans There is a kernel API ntb_mw_clear_trans() would pass 0 t…
CVE-2025-40318 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once hci_cmd_sync_dequeue_once() does lookup and then cancel the entry unde…
CVE-2025-40271 medium 6.5 EXPFIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which m…
CVE-2025-40269 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential overflow of PCM transfer buffer The PCM stream data in USB-audio driver is transferred over USB UR…
CVE-2025-40170 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: net: use dst_dev_rcu() in sk_setup_caps() Use RCU to protect accesses to dst->dev from sk_setup_caps() and sk_dst_gso_max_size().…
CVE-2025-40158 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_output() Use RCU in ip6_output() in order to use dst_dev_rcu() to prevent possible UAF. We can remove rcu_r…
CVE-2025-40141 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix possible UAF on iso_conn_free This attempt to fix similar issue to sco_conn_free where if the conn->sk is not…
CVE-2025-40135 medium 5.5 FIX rocky rhel sles google 4mo ago In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_xmit() Use RCU in ip6_xmit() in order to use dst_dev_rcu() to prevent possible UAF.
CVE-2025-38730 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: io_uring/net: commit partial buffers on retry Ring provided buffers are potentially only valid within the single execution contex…
CVE-2025-38459 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix infinite recursive call of clip_push(). syzbot reported the splat below. [0] This happens if we call ioctl(ATMARP…
CVE-2025-38415 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: Squashfs: check return result of sb_min_blocksize Syzkaller reports an "UBSAN: shift-out-of-bounds in squashfs_bio_read" bug. Sy…
CVE-2025-38403 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: Clear the vmci transport packet properly when initializing it In vmci_transport_packet_init memset the vmci_transport…
CVE-2025-38024 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] d…
CVE-2025-38022 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem Call Trace: __dump_stack lib/dump_stack.c:94 [in…
CVE-2025-37819 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode() With ACPI in place, gicv2m_get_fwnode() is registered with the pci…
CVE-2025-37789 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix nested key length validation in the set() action It's not safe to access nla_len(ovs_key) if the data is sm…
CVE-2025-14104 medium 5.5 FIX rocky rhel sles 4mo ago A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-…
CVE-2025-40251 medium 5.5 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy The function devl_rate_nodes_destroy is documented to "Unset paren…
CVE-2025-38568 medium 5.5 FIX rhel sles rocky 4mo ago In the Linux kernel, the following vulnerability has been resolved: net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing TCA_MQPRIO_TC_ENTRY_INDEX is validated using NLA_POLICY_MAX(…
CVE-2024-26766 medium 5.5 FIX rocky slesdebian debian 4mo ago In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix sdma.h tx->num_descs off-by-one error Unfortunately the commit `fd8958efe877` introduced another error causing the `…
CVE-2025-54349 medium 5.5 FIX rocky rheldebian debian 4mo ago RHSA-2026:1592: iperf3 security update (Moderate)
CVE-2026-22796 medium 5.3 5.3 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2026-22795 medium 5.5 5.5 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2025-69418 medium 4.0 4.0 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2025-68160 medium 4.7 4.7 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2025-14178 medium 5.5 FIX rockyalmalinux almalinux rhel 4mo ago RHSA-2026:2470: php:7.4 security update (Moderate)
CVE-2025-14177 medium 5.5 FIX rocky rhelalmalinux almalinux 4mo ago RHSA-2026:2470: php:7.4 security update (Moderate)
CVE-2025-12084 medium 5.5 FIX rocky rheldebian debian 4mo ago When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building ex…
CVE-2025-40258 medium 5.5 FIX rocky rhel sles 4mo ago In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() syzbot reported use-after-free in mptcp_schedule_work() [1] Issue here is tha…
CVE-2026-21933 medium 6.1 6.1 FIX rocky rhel sles oracle 4mo ago RHSA-2026:4832: java-1.8.0-ibm security update (Important)
CVE-2026-21925 medium 4.8 4.8 FIX rocky rhel sles oracle 4mo ago RHSA-2026:4832: java-1.8.0-ibm security update (Important)
CVE-2025-67726 medium 5.5 FIX rocky slesdebian debian 4mo ago RHSA-2026:0930: pcs security update (Moderate)
CVE-2025-67725 medium 5.5 FIX rocky slesdebian debian 4mo ago RHSA-2026:0930: pcs security update (Moderate)
CVE-2025-68285 medium 5.5 FIX rocky rhel sles 5mo ago In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop in __ceph_open_session() can race with the client r…
CVE-2025-46397 medium 5.5 FIX rocky rheldebian debian 5mo ago RHSA-2026:0756: transfig security update (Moderate)
CVE-2025-14242 medium 5.5 FIX rocky rhel sles 5mo ago RHSA-2026:0608: vsftpd security update (Moderate)
CVE-2025-12817 medium 5.5 FIX rocky rhel sles 5mo ago RHSA-2026:0524: postgresql:15 security update (Moderate)
CVE-2025-39883 medium 5.5 FIX rocky rhel sles 5mo ago In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory When I did memory failure tests, below panic occur…
CVE-2025-39840 medium 5.5 FIX rhel sles rocky 5mo ago In the Linux kernel, the following vulnerability has been resolved: audit: fix out-of-bounds read in audit_compare_dname_path() When a watch on dir=/ is combined with an fsnotify event for a single…
CVE-2025-12818 medium 5.5 FIX rocky rhel sles 5mo ago RHSA-2026:0695: libpq security update (Moderate)
CVE-2025-61915 medium 5.5 FIX rocky rheldebian debian 5mo ago RHSA-2026:0596: cups security update (Moderate)
CVE-2025-58436 medium 5.5 FIX rocky rheldebian debian 5mo ago RHSA-2026:0596: cups security update (Moderate)
CVE-2026-21968 medium 5.5 FIX rocky rhel sles 5mo ago RHSA-2026:6435: mariadb:10.11 security update (Moderate)
CVE-2023-52971 medium 5.5 FIX rocky rhel sles 5mo ago RHSA-2026:6435: mariadb:10.11 security update (Moderate)
CVE-2025-32365 medium 5.5 FIX rocky rhel sles 5mo ago Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
CVE-2025-45582 medium 5.5 rhel sles rocky 5mo ago Moderate: tar security update
CVE-2025-8291 medium 5.5 FIX rocky rhelalmalinux almalinux 6mo ago The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD re…
CVE-2025-6491 medium 5.5 FIX rockyalmalinux almalinux rhel 6mo ago RHSA-2026:2470: php:7.4 security update (Moderate)
CVE-2025-5987 medium 5.5 FIX rheldebian debian sles 6mo ago Moderate: libssh security update
CVE-2025-1735 medium 5.5 FIX rockyalmalinux almalinux rhel 6mo ago RHSA-2026:2470: php:7.4 security update (Moderate)
CVE-2025-1220 medium 5.5 FIX rocky rhelalmalinux almalinux 6mo ago RHSA-2026:2470: php:7.4 security update (Moderate)
CVE-2025-61985 medium 5.5 FIX rocky rhel sles 6mo ago ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
CVE-2025-61984 medium 5.5 FIX rocky rhel sles 6mo ago ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrus…
CVE-2025-38499 medium 5.5 5.5 FIX rhel sles rocky 6mo ago In the Linux kernel, the following vulnerability has been resolved: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns What we want is to verify there is that clone wo…
CVE-2025-14512 medium 6.5 6.5 FIX rheldebian debian sles gnomeredhat 6mo ago A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when pro…
CVE-2025-53069 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53062 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53054 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53053 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53045 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53044 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53042 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)
CVE-2025-53040 medium 5.5 FIX rocky rheldebian debian 6mo ago RHSA-2025:23137: mysql:8.4 security update (Moderate)