<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Red Hat Enterprise Linux</title>
  <link>https://cvedaily.com/pages/tags/rhel.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/rhel.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Red Hat Enterprise Linux</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-43298 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43298</guid>
    <pubDate>Fri, 08 May 2026 14:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43298</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: Skip vcn poison irq release on VF  VF doesn't enable VCN poison irq in VCNv2.5. Skip releasing it and avoid call trace during deinitialization.  [   71.913601] [drm] clean up the vf2pf work item [   71.915088] ------------[ cut here ]------------ [   71.915092] WARNING: CPU: 3 PID: 1079 at /tmp/amd.aFkFvSQl/amd/amdgp…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-65105 – Apptainer is an open source container platform. In Apptainer versions less than ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65105</guid>
    <pubDate>Tue, 02 Dec 2025 18:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-65105</strong></p>
  <p>Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms of the little used --security option, in particular the forms --security=apparmor:<profile> and --security=selinux:<label> which otherwise put restrictions on operations that containers can do. The --security option has always been mentioned in Apptainer documentation as…</p>
  <p><strong>CVSS:</strong> 4.5 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-53629 – In the Linux kernel, the following vulnerability has been resolved:

fs: dlm: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53629</guid>
    <pubDate>Tue, 07 Oct 2025 16:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-53629</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fs: dlm: fix use after free in midcomms commit  While working on processing dlm message in softirq context I experienced the following KASAN use-after-free warning:  [  151.760477] ================================================================== [  151.761803] BUG: KASAN: use-after-free in dlm_midcomms_commit_mhandle+0x19d/0x4…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-50516 – In the Linux kernel, the following vulnerability has been resolved:

fs: dlm: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50516</guid>
    <pubDate>Tue, 07 Oct 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-50516</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fs: dlm: fix invalid derefence of sb_lvbptr  I experience issues when putting a lkbsb on the stack and have sb_lvbptr field to a dangled pointer while not using DLM_LKF_VALBLK. It will crash with the following kernel message, the dangled pointer is here 0xdeadbeef as example:  [  102.749317] BUG: unable to handle page fault for…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-50401 – In the Linux kernel, the following vulnerability has been resolved:

nfsd: under...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50401</guid>
    <pubDate>Thu, 18 Sep 2025 16:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-50401</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  nfsd: under NFSv4.1, fix double svc_xprt_put on rpc_create failure  On error situation `clp->cl_cb_conn.cb_xprt` should not be given a reference to the xprt otherwise both client cleanup and the error handling path of the caller call to put it. Better to delay handing over the reference to a later branch.  [   72.530665] refcoun…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-50373 – In the Linux kernel, the following vulnerability has been resolved:

fs: dlm: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50373</guid>
    <pubDate>Wed, 17 Sep 2025 15:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-50373</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fs: dlm: fix race in lowcomms  This patch fixes a race between queue_work() in _dlm_lowcomms_commit_msg() and srcu_read_unlock(). The queue_work() can take the final reference of a dlm_msg and so msg->idx can contain garbage which is signaled by the following warning:  [  676.237050] ------------[ cut here ]------------ [  676.2…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-38241 – In the Linux kernel, the following vulnerability has been resolved:

mm/shmem, s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38241</guid>
    <pubDate>Wed, 09 Jul 2025 11:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-38241</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mm/shmem, swap: fix softlockup with mTHP swapin  Following softlockup can be easily reproduced on my test machine with:  echo always > /sys/kernel/mm/transparent_hugepage/hugepages-64kB/enabled swapon /dev/zram0 # zram0 is a 48G swap device mkdir -p /sys/fs/cgroup/memory/test echo 1G > /sys/fs/cgroup/test/memory.max echo $BASHPI…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-53082 – In the Linux kernel, the following vulnerability has been resolved:

vp_vdpa: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53082</guid>
    <pubDate>Fri, 02 May 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-53082</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  vp_vdpa: fix the crash in hot unplug with vp_vdpa  While unplugging the vp_vdpa device, it triggers a kernel panic The root cause is: vdpa_mgmtdev_unregister() will accesses modern devices which will cause a use after free. So need to change the sequence in vp_vdpa_remove  [  195.003359] BUG: unable to handle page fault for addr…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22013 – In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22013</guid>
    <pubDate>Tue, 08 Apr 2025 09:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22013</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  KVM: arm64: Unconditionally save+flush host FPSIMD/SVE/SME state  There are several problems with the way hyp code lazily saves the host's FPSIMD/SVE state, including:  * Host SVE being discarded unexpectedly due to inconsistent   configuration of TIF_SVE and CPACR_ELx.ZEN. This has been seen to   result in QEMU crashes where SV…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-56658 – In the Linux kernel, the following vulnerability has been resolved:

net: defer ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56658</guid>
    <pubDate>Fri, 27 Dec 2024 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-56658</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: defer final 'struct net' free in netns dismantle  Ilya reported a slab-use-after-free in dst_destroy [1]  Issue is in xfrm6_net_init() and xfrm4_net_init() :  They copy xfrm[46]_dst_ops_template into net->xfrm.xfrm[46]_dst_ops.  But net structure might be freed before all the dst callbacks are called. So when dst_destroy()…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-6238 – pgAdmin &lt;= 8.8 has an installation Directory permission issue. Because of this i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6238</guid>
    <pubDate>Tue, 25 Jun 2024 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-6238</strong></p>
  <p>pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian or RHEL 8 platforms.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4438 – The etcd package distributed with the Red Hat OpenStack platform has an incomple...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4438</guid>
    <pubDate>Wed, 08 May 2024 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4438</strong></p>
  <p>The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487, known as Rapid Reset. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4437 – The etcd package distributed with the Red Hat OpenStack platform has an incomple...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4437</guid>
    <pubDate>Wed, 08 May 2024 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4437</strong></p>
  <p>The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4436 – The etcd package distributed with the Red Hat OpenStack platform has an incomple...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4436</guid>
    <pubDate>Wed, 08 May 2024 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4436</strong></p>
  <p>The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52587 – In the Linux kernel, the following vulnerability has been resolved:

IB/ipoib: F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52587</guid>
    <pubDate>Wed, 06 Mar 2024 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52587</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  IB/ipoib: Fix mcast list locking  Releasing the `priv->lock` while iterating the `priv->multicast_list` in `ipoib_mcast_join_task()` opens a window for `ipoib_mcast_dev_flush()` to remove the items while in the middle of iteration. If the mcast is removed while the lock was dropped, the for loop spins forever resulting in a hard…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2680 – This CVE exists because of an incomplete fix for CVE-2021-3750. More specificall...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2680</guid>
    <pubDate>Wed, 13 Sep 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2680</strong></p>
  <p>This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm that was actually missing the fix for CVE-2021-3750.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4042 – A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4042</guid>
    <pubDate>Wed, 23 Aug 2023 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4042</strong></p>
  <p>A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-2319 – It was discovered that an update for PCS package in RHBA-2023:2151 erratum relea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2319</guid>
    <pubDate>Wed, 17 May 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-2319</strong></p>
  <p>It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was assigned to that Red Hat specific security regression in Red Hat Enterprise Linu…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2295 – A vulnerability was found in the libreswan library. This security issue occurs w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2295</guid>
    <pubDate>Wed, 17 May 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2295</strong></p>
  <p>A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote c…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2491 – A flaw was found in the Emacs text editor. Processing a specially crafted org-mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2491</guid>
    <pubDate>Wed, 17 May 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2491</strong></p>
  <p>A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2203 – A flaw was found in the WebKitGTK package. An improper input validation issue ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2203</guid>
    <pubDate>Wed, 17 May 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2203</strong></p>
  <p>A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Re…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30549 – Apptainer is an open source container platform for Linux. There is an ext4 use-a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30549</guid>
    <pubDate>Tue, 25 Apr 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30549</strong></p>
  <p>Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that include apptainer-suid < 1.1.8 on older operating systems where that CVE has not been patched. That includes Red Hat Enterprise Linux 7, Debian 10 buster (unless the linux-5.10 package is installed), Ubuntu 18.04 bionic and…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-41352 – An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41352</guid>
    <pubDate>Mon, 26 Sep 2022 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-41352</strong></p>
  <p>An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red H…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-2739 – The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2739</guid>
    <pubDate>Thu, 01 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-2739</strong></p>
  <p>The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in environment variables.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2738 – The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2738</guid>
    <pubDate>Thu, 01 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2738</strong></p>
  <p>The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be used to crash or cause potential code execution in Go applications that use the Go GPGME wrapper library, under certain conditions, during GPG signa…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-4218 – A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4218</guid>
    <pubDate>Wed, 24 Aug 2022 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-4218</strong></p>
  <p>A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA counters. Reading the counter sysctl panics the system. This flaw allows a local attacker with local access to cause a denial of service while the system reboots. The issue is specific to CentOS/RHEL.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-28623 – Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28623</guid>
    <pubDate>Fri, 08 Jul 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-28623</strong></p>
  <p>Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL and HPE IceWall SSO version 10.0 certd library Patch 9 for HP-UX.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-1665 – A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Powe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1665</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1665</guid>
    <pubDate>Tue, 21 Jun 2022 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-1665</strong></p>
  <p>A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot validations, allowing the attacker to load another non-trusted code.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1291</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1665">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-20295 – It was discovered that the update for the virt:rhel module in the RHSA-2020:4676...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20295</guid>
    <pubDate>Fri, 01 Apr 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-20295</strong></p>
  <p>It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released as part of Red Hat Enterprise Linux 8.3 failed to include the fix for the qemu-kvm component issue CVE-2020-10756, which was previously corrected in virt:rhel/qemu-kvm via erratum RHSA-2020:4059 (https://access.redhat.com/errata/RHSA-2020:4059). CVE-2…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-20269 – A flaw was found in the permissions of a log file created by kexec-tools. This f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20269</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20269</guid>
    <pubDate>Thu, 10 Mar 2022 17:41:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-20269</strong></p>
  <p>A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kernel internal information from a previous panic. The highest threat from this vulnerability is to confidentiality. This flaw affects kexec-tools shipped by Fedora versions prior to 2.0.21-8 and RHEL versions prior to 2.0.20-47.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20269">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-20325 – Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20325</guid>
    <pubDate>Fri, 18 Feb 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-20325</strong></p>
  <p>Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-20…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43816 – containerd is an open source container runtime. On installations using SELinux, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43816</guid>
    <pubDate>Wed, 05 Jan 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43816</strong></p>
  <p>containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved b…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-1702 – A malicious container image can consume an unbounded amount of memory when being...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1702</guid>
    <pubDate>Thu, 27 May 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-1702</strong></p>
  <p>A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container images, into crashing the process responsible for pulling the image. This flaw affects containers-image versions before 5…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-26582 – A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26582</guid>
    <pubDate>Thu, 15 Apr 2021 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-26582</strong></p>
  <p>A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS).</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-14391 – A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14391</guid>
    <pubDate>Mon, 08 Feb 2021 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-14391</strong></p>
  <p>A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-14312 – A flaw was found in the default configuration of dnsmasq, as shipped with Fedora...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14312</guid>
    <pubDate>Sat, 06 Feb 2021 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-14312</strong></p>
  <p>A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In particular, the option `local-service` is not enabled. Running dnsmasq in this manner may inadvertently make it an open resolver accessible from any a…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10772 – An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterpri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10772</guid>
    <pubDate>Fri, 27 Nov 2020 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10772</strong></p>
  <p>An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned erratum. This issue is about the incomplete fi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-406</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-10759 – A PGP signature bypass flaw was found in fwupd (all versions), which could lead ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10759</guid>
    <pubDate>Tue, 15 Sep 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-10759</strong></p>
  <p>A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-14344 – An integer overflow leading to a heap-buffer overflow was found in The X Input M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14344</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14344</guid>
    <pubDate>Wed, 05 Aug 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-14344</strong></p>
  <p>An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat Enterprise Linux.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14344">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4125 – Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4125</guid>
    <pubDate>Mon, 20 Jul 2020 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4125</strong></p>
  <p>Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-15719 – libldap in certain third-party OpenLDAP packages has a certificate-validation fl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15719</guid>
    <pubDate>Tue, 14 Jul 2020 14:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-15719</strong></p>
  <p>libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14300 – The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14300</guid>
    <pubDate>Mon, 13 Jul 2020 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14300</strong></p>
  <p>The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2016-9962, that was previously corrected in the docker packages in Re…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-273</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14298 – The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14298</guid>
    <pubDate>Mon, 13 Jul 2020 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14298</strong></p>
  <p>The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and other containers running on the same host. This issue only affects docker version…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-273</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-10730 – A NULL pointer dereference, or possible use-after-free flaw was found in Samba A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10730</guid>
    <pubDate>Tue, 07 Jul 2020 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-10730</strong></p>
  <p>A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise Linux do not support Samba in AD mode, the affected code is shipped with the libldb package. This flaw allows an authenticated user to possibly trigger a use-after-free or NULL po…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-19339 – It was found that the Red Hat Enterprise Linux 8 kpatch update did not include t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19339</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19339</guid>
    <pubDate>Fri, 17 Jan 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-19339</strong></p>
  <p>It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A flaw was found in the way Intel CPUs handle inconsistency between, virtual to physical memory address translations in CPU's local cache and system software's Paging structure entries. A privileged guest user may use this flaw to induce a hardware Machine Check Error on the host pr…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19339">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-10214 – The containers/image library used by the container tools Podman, Buildah, and Sk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10214</guid>
    <pubDate>Mon, 25 Nov 2019 11:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-10214</strong></p>
  <p>The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-3278 – frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3278</guid>
    <pubDate>Thu, 07 Nov 2019 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-3278</strong></p>
  <p>frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the ELF header of multiple binaries in /usr/bin/f* (e.g. fcore, fcatch, fstack, fstep, ...) shipped in the package. A local attacker can exploit this vulnerability by running arbitrary code as another user.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-8181 – The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8181</guid>
    <pubDate>Wed, 06 Nov 2019 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-8181</strong></p>
  <p>The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10171 – It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10171</guid>
    <pubDate>Fri, 02 Aug 2019 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10171</strong></p>
  <p>It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-11989 – A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11989</guid>
    <pubDate>Fri, 19 Jul 2019 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-11989</strong></p>
  <p>A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for Apache 2.4 on RHEL 7, 10.0 for Apache 2.4 on HP-UX 11i v3, 10.0 for IIS on Windows, 11.0 for Apache 2.4 on RHEL 7, MFA Pr…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2019-3815 – A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3815</guid>
    <pubDate>Mon, 28 Jan 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2019-3815</strong></p>
  <p>A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Red Hat Enterprise since v219-62.2.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-16885 – A flaw was found in the Linux kernel that allows the userspace to call memcpy_fr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16885</guid>
    <pubDate>Thu, 03 Jan 2019 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-16885</strong></p>
  <p>A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault and a system halt by accessing invalid memory address. This issue only affects kernel version 3.10.x as shipped with Red Hat Enterprise Linux 7.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16863 – It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16863</guid>
    <pubDate>Mon, 03 Dec 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16863</strong></p>
  <p>It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8989 – A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8989</guid>
    <pubDate>Mon, 06 Aug 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8989</strong></p>
  <p>A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, and Windows could be exploited remotely to allow URL Redirection.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-8657 – It was discovered that EAP packages in certain versions of Red Hat Enterprise Li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8657</guid>
    <pubDate>Tue, 31 Jul 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-8657</strong></p>
  <p>It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the file is sourced by the jboss init script and its content executed with root privil…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-2623 – It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2623</guid>
    <pubDate>Fri, 27 Jul 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-2623</strong></p>
  <p>It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-12171 – A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12171</guid>
    <pubDate>Thu, 26 Jul 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-12171</strong></p>
  <p>A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a restricted HTTP resource.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-9604 – It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9604</guid>
    <pubDate>Wed, 11 Jul 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-9604</strong></p>
  <p>It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or '.builtin_trusted_keys' upstream, by joining it as its session keyring. This allows root to bypass module signature verification by adding a new public key of its own devising to the keyring.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-10872 – A flaw was found in the way the Linux kernel handled exceptions delivered after ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10872</guid>
    <pubDate>Tue, 10 Jul 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-10872</strong></p>
  <p>A flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, processor does not deliver interrupts and exceptions, they are delivered once the first instruction after the stack switch is executed. An unprivileged system user could use this flaw to crash the system kernel resulting in…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-1113 – setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1113</guid>
    <pubDate>Tue, 03 Jul 2018 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-1113</strong></p>
  <p>setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates security assumptions made by pam_shells and some daemons which allow access based on a user's shell being listed in /etc/shells. Under some circumstances, users which had their shell changed to /sbin/nologin could still access the system.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1132 – A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1132</guid>
    <pubDate>Wed, 20 Jun 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1132</strong></p>
  <p>A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the controller or SDNInterfaceapp. SDNInterface has been deprecated in OpenDayLight since it was last used in the final Carbon series release. In addition to the component not being included in OpenDayLight in newer releases, the SDNInterface component is…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1125 – procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1125</guid>
    <pubDate>Wed, 23 May 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1125</strong></p>
  <p>procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as on Red Hat Enterprise Linux and Fedora), the impact is limited to a crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1111 – DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1111</guid>
    <pubDate>Thu, 17 May 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1111</strong></p>
  <p>DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-1777 – rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Glus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1777</guid>
    <pubDate>Thu, 12 Apr 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-1777</strong></p>
  <p>rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attackers to prevent system registration via a man-in-the-middle attack.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-2628 – curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2628</guid>
    <pubDate>Mon, 12 Mar 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-2628</strong></p>
  <p>curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-15131 – It was found that system umask policy is not being honored when creating XDG use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15131</guid>
    <pubDate>Tue, 09 Jan 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-15131</strong></p>
  <p>It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-15121 – A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and cras...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15121</guid>
    <pubDate>Thu, 07 Dec 2017 02:29:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-15121</strong></p>
  <p>A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-15087 – It was discovered that the fix for CVE-2017-12163 was not properly shipped in er...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15087</guid>
    <pubDate>Wed, 08 Nov 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-15087</strong></p>
  <p>It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-15086 – It was discovered that the fix for CVE-2017-12151 was not properly shipped in er...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15086</guid>
    <pubDate>Wed, 08 Nov 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-15086</strong></p>
  <p>It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-300</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-15085 – It was discovered that the fix for CVE-2017-12150 was not properly shipped in er...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15085</guid>
    <pubDate>Wed, 08 Nov 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-15085</strong></p>
  <p>It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-300</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-7837 – The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterpri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7837</guid>
    <pubDate>Tue, 19 Sep 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-7837</strong></p>
  <p>The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-7553 – Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7553</guid>
    <pubDate>Thu, 14 Sep 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-7553</strong></p>
  <p>Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by creating netlink sockets.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-3149 – The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-3149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-3149</guid>
    <pubDate>Tue, 25 Jul 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-3149</strong></p>
  <p>The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6312 – The mod_dontdothat component of the mod_dav_svn Apache module in Subversion as p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6312</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6312</strong></p>
  <p>The mod_dontdothat component of the mod_dav_svn Apache module in Subversion as packaged in Red Hat Enterprise Linux 5.11 does not properly detect recursion during entity expansion, which allows remote authenticated users with access to the webdav repository to cause a denial of service (memory consumption and httpd crash).  NOTE: Exists as a regression to CVE-2009-1955.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-0764 – Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterpris...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0764</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-0764</strong></p>
  <p>Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by reading temporary files during ifcfg and keyfile changes.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-7050 – SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7050</guid>
    <pubDate>Thu, 08 Jun 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-7050</strong></p>
  <p>SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5416 – 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5416</guid>
    <pubDate>Thu, 08 Jun 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5416</strong></p>
  <p>389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to read the default Access Control Instructions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-5405 – 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5405</guid>
    <pubDate>Thu, 08 Jun 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-5405</strong></p>
  <p>389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-199</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-4992 – 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4992</guid>
    <pubDate>Thu, 08 Jun 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-4992</strong></p>
  <p>389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to infer the existence of RDN component objects.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3099 – mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3099</guid>
    <pubDate>Thu, 08 Jun 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3099</strong></p>
  <p>mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-7091 – sudo: It was discovered that the default sudo configuration on Red Hat Enterpris...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7091</guid>
    <pubDate>Thu, 22 Dec 2016 21:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-7091</strong></p>
  <p>sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges provided by sudo.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6325 – The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6325</guid>
    <pubDate>Thu, 13 Oct 2016 14:59:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6325</strong></p>
  <p>The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5425 – The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5425</guid>
    <pubDate>Thu, 13 Oct 2016 14:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5425</strong></p>
  <p>The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3699 – The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3699</guid>
    <pubDate>Fri, 07 Oct 2016 14:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3699</strong></p>
  <p>The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-5408 – Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5408</guid>
    <pubDate>Wed, 10 Aug 2016 14:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-5408</strong></p>
  <p>Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-4051.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-4474 – The image build process for the overcloud images in Red Hat OpenStack Platform 8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4474</guid>
    <pubDate>Thu, 30 Jun 2016 16:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-4474</strong></p>
  <p>The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which allows attackers to gain access via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3707 – The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3707</guid>
    <pubDate>Mon, 27 Jun 2016 10:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3707</strong></p>
  <p>The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other products, allows remote attackers to execute SysRq commands via crafted ICMP Echo Request packets, as demonstrated by a brute-force attack to discover a cookie, or an attack that o…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-0774 – The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0774</guid>
    <pubDate>Wed, 27 Apr 2016 17:59:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-0774</strong></p>
  <p>The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux package before 3.2.73-2+deb7u3 on Debian wheezy and the kernel package before 3.10.0-229.26.2 on Red Hat Enterprise Linux (RHEL) 7.1 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a den…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5329 – The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterpri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5329</guid>
    <pubDate>Mon, 11 Apr 2016 21:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5329</strong></p>
  <p>The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obtain access to services in deployed overclouds by leveraging knowledge of the default credentials.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5229 – The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5229</guid>
    <pubDate>Fri, 08 Apr 2016 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5229</strong></p>
  <p>The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-17</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2015-5281 – The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5281</guid>
    <pubDate>Tue, 24 Nov 2015 20:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2015-5281</strong></p>
  <p>The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot me…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-7833 – The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7833</guid>
    <pubDate>Mon, 19 Oct 2015 10:59:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-7833</strong></p>
  <p>The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-17</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-3216 – Race condition in a certain Red Hat patch to the PRNG lock implementation in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-3216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-3216</guid>
    <pubDate>Tue, 07 Jul 2015 10:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-3216</strong></p>
  <p>Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 and other products, allows remote attackers to cause a denial of service (application crash) by establishing many TLS sessions to a multithreaded server, leading to use of a negative value for a certain…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2015-0267 – The Red Hat module-setup.sh script for kexec-tools, as distributed in the kexec-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0267</guid>
    <pubDate>Tue, 19 May 2015 18:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2015-0267</strong></p>
  <p>The Red Hat module-setup.sh script for kexec-tools, as distributed in the kexec-tools before 2.0.7-19 packages in Red Hat Enterprise Linux, allows local users to write to arbitrary files via a symlink attack on a temporary file.</p>
  <p><strong>CVSS:</strong> 3.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-8159 – The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8159</guid>
    <pubDate>Mon, 16 Mar 2015 10:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-8159</strong></p>
  <p>The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-9278 – The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when ru...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-9278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-9278</guid>
    <pubDate>Sat, 06 Dec 2014 15:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-9278</strong></p>
  <p>The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in the .k5users file of that user, which might bypass intended authentication requirements that would force a local login.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-9278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3632 – The default configuration in a sudoers file in the Red Hat openstack-neutron pac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3632</guid>
    <pubDate>Tue, 07 Oct 2014 14:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3632</strong></p>
  <p>The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stack Platform 5.0 for Red Hat Enterprise Linux 6, allows remote attackers to gain privileges via a crafted configuration file.  NOTE: this vulnerability exists because of a CVE-2013-6433 regression.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0186 – A certain tomcat7 package for Apache Tomcat 7 in Red Hat Enterprise Linux (RHEL)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0186</guid>
    <pubDate>Sat, 14 Jun 2014 11:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0186</strong></p>
  <p>A certain tomcat7 package for Apache Tomcat 7 in Red Hat Enterprise Linux (RHEL) 7 allows remote attackers to cause a denial of service (CPU consumption) via a crafted request.  NOTE: this vulnerability exists because of an unspecified regression.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0042 – OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux O...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0042</guid>
    <pubDate>Mon, 02 Jun 2014 15:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0042</strong></p>
  <p>OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, sets gpgcheck to 0 for certain templates, which disables GPG signature checking on downloaded packages and allows man-in-the-middle attackers to install arbitrary packages via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0041 – OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux O...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0041</guid>
    <pubDate>Mon, 02 Jun 2014 15:55:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0041</strong></p>
  <p>OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, sets sslverify to false for certain Yum repositories, which disables SSL protection and allows man-in-the-middle attackers to prevent updates via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0041">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
