Redhat
Redhat Enterprise Linux TUS: vulnerabilidades y CVE
Redhat Enterprise Linux TUS tiene 25 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses4
Críticas2
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-34486 | Alta (7.5) | 6.6% | ⚠ Explotación activa | 9 abr 2026 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are… |
| CVE-2026-31431 | Alta (7.8) | 3.4% | ⚠ Explotación activa | 22 abr 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
| CVE-2025-31277 | Alta (8.8) | 1.6% | ⚠ Explotación activa | 30 jul 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content… |
| CVE-2016-5195 | Alta (7) | 84% | ⚠ Explotación activa | 10 nov 2016 | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping,… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-31431 | Alta (7.8) | 3.4% | ⚠ Explotación activa | 22 abr 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is… |
| CVE-2026-34486 | Alta (7.5) | 6.6% | ⚠ Explotación activa | 9 abr 2026 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are… |
| CVE-2025-62230 | Alta (7.3) | 0.28% | — | 30 oct 2025 | A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a… |
| CVE-2025-62231 | Alta (7.3) | 0.30% | — | 30 oct 2025 | A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted… |
| CVE-2025-31277 | Alta (8.8) | 1.6% | ⚠ Explotación activa | 30 jul 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content… |
| CVE-2024-3183 | Alta (8.1) | 2.1% | — | 12 jun 2024 | A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the… |
| CVE-2024-0229 | Alta (7.8) | 1.2% | — | 9 feb 2024 | An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash,… |
| CVE-2023-4806 | Media (5.9) | 1.6% | — | 18 sept 2023 | A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module… |
| CVE-2023-4527 | Media (6.5) | 1.7% | — | 18 sept 2023 | A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can… |
| CVE-2021-20316 | Media (6.8) | 0.98% | — | 23 ago 2022 | A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share. |
| CVE-2020-25717 | Alta (8.1) | 1.6% | — | 18 feb 2022 | A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation. |
| CVE-2016-2124 | Media (5.9) | 1.8% | — | 18 feb 2022 | A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required. |
| CVE-2021-3672 | Media (5.6) | 2.8% | — | 23 nov 2021 | A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The… |
| CVE-2021-3570 | Alta (8.8) | 3.0% | — | 9 jul 2021 | A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code… |
| CVE-2020-14301 | Media (6.5) | 1.2% | — | 27 may 2021 | An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to… |
| CVE-2020-14355 | Media (6.6) | 2.7% | — | 7 oct 2020 | Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws.… |
| CVE-2020-1045 | Alta (7.5) | 5.9% | — | 11 sept 2020 | <p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker… |
| CVE-2020-2590 | Baja (3.7) | 3.2% | — | 15 ene 2020 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to… |
| CVE-2019-14816 | Alta (7.8) | 0.91% | — | 20 sept 2019 | There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute… |
| CVE-2019-9506 | Alta (8.1) | 2.7% | — | 14 ago 2019 | The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical… |
| CVE-2018-16878 | Media (5.5) | 0.42% | — | 18 abr 2019 | A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS |
| CVE-2019-9948 | Crítica (9.1) | 12% | — | 23 mar 2019 | urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a… |
| CVE-2017-15041 | Crítica (9.8) | 8.9% | — | 5 oct 2017 | Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it is possible to arrange things so that example.com/pkg1 points to a Subversion repository but… |
| CVE-2016-5195 | Alta (7) | 84% | ⚠ Explotación activa | 10 nov 2016 | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping,… |
| CVE-2014-4341 | Media (5) | 7.1% | — | 20 jul 2014 | MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session. |
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 238Linux · 230