Redhat
Redhat Hardened Images: vulnerabilities and CVEs
Redhat Hardened Images has 49 published vulnerabilities, 49 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs49
Last 12 months49
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19617 | Medium (5.5) | 0.16% | — | Aug 14, 2026 | A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration… |
| CVE-2026-19548 | Medium (5.5) | 0.15% | — | Aug 12, 2026 | Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the… |
| CVE-2026-71227 | Medium (5.1) | 0.17% | — | Aug 5, 2026 | A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the… |
| CVE-2026-71226 | High (7.3) | 0.18% | — | Aug 5, 2026 | Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers. |
| CVE-2026-71225 | Medium (6.5) | 0.52% | — | Aug 5, 2026 | A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the… |
| CVE-2026-59851 | High (8.8) | 0.49% | — | Jul 21, 2026 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing… |
| CVE-2026-59850 | High (7.5) | 0.35% | — | Jul 21, 2026 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free… |
| CVE-2026-59848 | Medium (5.3) | 0.34% | — | Jul 21, 2026 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. |
| CVE-2026-59847 | High (7.5) | 0.33% | — | Jul 21, 2026 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without… |
| CVE-2026-59846 | Low (3.9) | 0.12% | — | Jul 21, 2026 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. |
| CVE-2026-59849 | High (7.5) | 0.44% | — | Jul 21, 2026 | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a… |
| CVE-2026-59845 | Medium (5.9) | 0.10% | — | Jul 21, 2026 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local… |
| CVE-2026-59844 | Medium (6.5) | 0.57% | — | Jul 21, 2026 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through… |
| CVE-2026-59843 | Medium (6.5) | 0.73% | — | Jul 21, 2026 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. |
| CVE-2026-59842 | Medium (5.3) | 0.49% | — | Jul 21, 2026 | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap… |
| CVE-2026-15370 | High (7.3) | 0.17% | — | Jul 21, 2026 | A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled… |
| CVE-2026-13757 | Medium (6.2) | 0.20% | — | Jun 29, 2026 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit… |
| CVE-2026-13595 | Medium (5.3) | 0.17% | — | Jun 29, 2026 | A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically… |
| CVE-2026-55653 | Medium (6.5) | 0.51% | — | Jun 23, 2026 | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards)… |
| CVE-2026-55654 | Low (3.7) | 0.65% | — | Jun 23, 2026 | A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is… |
| CVE-2026-42055 | Critical (9.2) | 6.5% | — | Jun 17, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to… |
| CVE-2026-48864 | High (7.8) | 0.26% | — | May 26, 2026 | A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a… |
| CVE-2026-9256 | Critical (9.2) | 2.7% | — | May 22, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular… |
| CVE-2026-9149 | Medium (6.5) | 0.57% | — | May 21, 2026 | A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an… |
| CVE-2026-9150 | Medium (6.5) | 0.58% | — | May 20, 2026 | A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by… |
| CVE-2026-42009 | High (7.5) | 1.1% | — | May 18, 2026 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence… |
| CVE-2026-42010 | Critical (9.8) | 0.94% | — | May 7, 2026 | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this… |
| CVE-2026-3833 | High (7.4) | 0.89% | — | Apr 30, 2026 | A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within… |
| CVE-2026-3832 | Low (3.7) | 0.85% | — | Apr 30, 2026 | A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how… |
| CVE-2026-6732 | High (7.5) | 0.94% | — | Apr 23, 2026 | A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.
Other products by Redhat
Enterprise Linux · 1,937Enterprise Linux Desktop · 1,928Enterprise Linux Server · 1,891Enterprise Linux Workstation · 1,845Enterprise Linux Server AUS · 1,059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 239Linux · 230