Redhat
Redhat Enterprise Linux AUS: vulnerabilidades y CVE
Redhat Enterprise Linux AUS tiene 48 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 3 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE48
Últimos 12 meses3
Críticas3
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-31431 | Alta (7.8) | 3.4% | ⚠ Explotación activa | 22 abr 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
| CVE-2025-31277 | Alta (8.8) | 1.6% | ⚠ Explotación activa | 30 jul 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content… |
| CVE-2016-5195 | Alta (7) | 84% | ⚠ Explotación activa | 10 nov 2016 | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping,… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-31431 | Alta (7.8) | 3.4% | ⚠ Explotación activa | 22 abr 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
| CVE-2025-62230 | Alta (7.3) | 0.28% | — | 30 oct 2025 | A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a… |
| CVE-2025-62231 | Alta (7.3) | 0.30% | — | 30 oct 2025 | A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted… |
| CVE-2025-31277 | Alta (8.8) | 1.6% | ⚠ Explotación activa | 30 jul 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content… |
| CVE-2024-3183 | Alta (8.1) | 2.1% | — | 12 jun 2024 | A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the… |
| CVE-2024-0229 | Alta (7.8) | 1.2% | — | 9 feb 2024 | An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash,… |
| CVE-2023-47038 | Alta (7.8) | 0.81% | — | 18 dic 2023 | A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer. |
| CVE-2023-3972 | Alta (7.8) | 0.27% | — | 1 nov 2023 | A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the… |
| CVE-2023-0494 | Alta (7.8) | 0.90% | — | 27 mar 2023 | A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory.… |
| CVE-2021-3669 | Media (5.5) | 0.29% | — | 26 ago 2022 | A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. |
| CVE-2021-20316 | Media (6.8) | 0.98% | — | 23 ago 2022 | A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share. |
| CVE-2021-3609 | Alta (7) | 0.43% | — | 3 mar 2022 | .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in… |
| CVE-2021-3570 | Alta (8.8) | 3.0% | — | 9 jul 2021 | A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code… |
| CVE-2020-14355 | Media (6.6) | 2.7% | — | 7 oct 2020 | Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws.… |
| CVE-2020-1045 | Alta (7.5) | 5.9% | — | 11 sept 2020 | <p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker… |
| CVE-2020-10711 | Media (5.9) | 3.1% | — | 22 may 2020 | A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the… |
| CVE-2019-9506 | Alta (8.1) | 2.7% | — | 14 ago 2019 | The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical… |
| CVE-2019-11478 | Alta (7.5) | 95% | — | 19 jun 2019 | Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker… |
| CVE-2019-11477 | Alta (7.5) | 99% | — | 19 jun 2019 | Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to… |
| CVE-2019-10126 | Crítica (9.8) | 6.8% | — | 14 jun 2019 | A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences. |
| CVE-2019-11811 | Alta (7) | 0.45% | — | 7 may 2019 | An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/ioports after the ipmi_si module is removed, related to drivers/char/ipmi/ipmi_si_intf.c,… |
| CVE-2018-16878 | Media (5.5) | 0.42% | — | 18 abr 2019 | A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS |
| CVE-2018-14638 | Alta (7.5) | 2.6% | — | 14 sept 2018 | A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service. |
| CVE-2018-13405 | Alta (7.8) | 1.0% | — | 6 jul 2018 | The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is… |
| CVE-2017-7847 | Media (4.3) | 1.6% | — | 11 jun 2018 | Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2. |
| CVE-2017-7829 | Media (5.3) | 1.8% | — | 11 jun 2018 | It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This… |
| CVE-2017-7824 | Crítica (9.8) | 3.6% | — | 11 jun 2018 | A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a… |
| CVE-2016-9901 | Crítica (9.8) | 2.9% | — | 11 jun 2018 | HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API… |
| CVE-2018-1049 | Media (5.9) | 7.4% | — | 16 feb 2018 | In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes… |
| CVE-2017-10661 | Alta (7) | 13% | — | 19 ago 2017 | Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that… |
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 238Linux · 230