« Volver al listado

Redhat

Redhat Codeready Linux Builder: vulnerabilidades y CVE

Redhat Codeready Linux Builder tiene 42 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 4 figuran en el catálogo de explotación activa de CISA.

CVE42
Últimos 12 meses1
Críticas0
Explotadas activamente4

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-0492Alta (7.8)5.5%⚠ Explotación activa3 mar 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to…
CVE-2023-4911Alta (7.8)81%⚠ Explotación activa3 oct 2023
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES…
CVE-2019-8720Alta (8.8)1.6%⚠ Explotación activa6 mar 2023
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption…
CVE-2022-0847Alta (7.8)93%⚠ Explotación activa10 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-13601Alta (7.7)0.32%—26 nov 2025
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable…
CVE-2025-3155Alta (7.4)14%—3 abr 2025
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an…
CVE-2025-2784Media (6.5)0.84%—3 abr 2025
A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a…
CVE-2023-3758Alta (7.1)1.0%—18 abr 2024
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
CVE-2024-1488Alta (7.3)0.32%—15 feb 2024
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port…
CVE-2023-5455Media (6.5)0.57%—10 ene 2024
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as…
CVE-2024-0193Media (6.7)0.84%—2 ene 2024
A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a…
CVE-2023-4641Media (5.5)0.26%—27 dic 2023
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first…
CVE-2023-5633Alta (7.8)0.28%—23 oct 2023
The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running…
CVE-2023-4911Alta (7.8)81%⚠ Explotación activa3 oct 2023
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES…
CVE-2023-4732Media (4.7)0.18%—3 oct 2023
A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker with a local user privilege may cause a denial of service problem due to a BUG statement…
CVE-2023-4042Media (5.5)0.34%—23 ago 2023
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat…
CVE-2023-0179Alta (7.8)1.9%—27 mar 2023
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root…
CVE-2019-8720Alta (8.8)1.6%⚠ Explotación activa6 mar 2023
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption…
CVE-2021-3669Media (5.5)0.29%—26 ago 2022
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
CVE-2021-3975Media (6.5)1.5%—23 ago 2022
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be…
CVE-2021-31566Alta (7.8)0.39%—23 ago 2022
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a…
CVE-2021-23177Alta (7.8)0.39%—23 ago 2022
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger…
CVE-2021-3659Media (5.5)0.27%—22 ago 2022
A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The…
CVE-2021-3697Alta (7)0.46%—6 jul 2022
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap…
CVE-2021-3696Media (4.5)0.47%—6 jul 2022
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low…
CVE-2021-3695Media (4.5)0.46%—6 jul 2022
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure…
CVE-2022-0435Alta (8.8)68%—25 mar 2022
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw…
CVE-2022-0330Alta (7.8)0.38%—25 mar 2022
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their…
CVE-2022-1011Alta (7.8)1.2%—18 mar 2022
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in…
CVE-2021-20257Media (6.5)0.37%—16 mar 2022
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values.…
CVE-2022-0847Alta (7.8)93%⚠ Explotación activa10 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale…
CVE-2022-0516Alta (7.8)0.34%—10 mar 2022
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized…
CVE-2021-3733Media (6.5)4.7%—10 mar 2022
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service…
CVE-2021-3737Alta (7.5)12%—4 mar 2022
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation3
  2. T1059 Command and Scripting Interpreter1
  3. T1059.007 JavaScript1
  4. T1078 Valid Accounts1
  5. T1203 Exploitation for Client Execution1
  6. T1548.004 Elevated Execution with Prompt1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Redhat