« Back to list

Redhat

Redhat Hardened Images: vulnerabilities and CVEs

Redhat Hardened Images has 49 published vulnerabilities, 49 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs49
Last 12 months49
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-19617Medium (5.5)0.16%—Aug 14, 2026
A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration…
CVE-2026-19548Medium (5.5)0.15%—Aug 12, 2026
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the…
CVE-2026-71227Medium (5.1)0.17%—Aug 5, 2026
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the…
CVE-2026-71226High (7.3)0.18%—Aug 5, 2026
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
CVE-2026-71225Medium (6.5)0.52%—Aug 5, 2026
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the…
CVE-2026-59851High (8.8)0.49%—Jul 21, 2026
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing…
CVE-2026-59850High (7.5)0.35%—Jul 21, 2026
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free…
CVE-2026-59848Medium (5.3)0.34%—Jul 21, 2026
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.
CVE-2026-59847High (7.5)0.33%—Jul 21, 2026
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without…
CVE-2026-59846Low (3.9)0.12%—Jul 21, 2026
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
CVE-2026-59849High (7.5)0.44%—Jul 21, 2026
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a…
CVE-2026-59845Medium (5.9)0.10%—Jul 21, 2026
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local…
CVE-2026-59844Medium (6.5)0.57%—Jul 21, 2026
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through…
CVE-2026-59843Medium (6.5)0.73%—Jul 21, 2026
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
CVE-2026-59842Medium (5.3)0.49%—Jul 21, 2026
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap…
CVE-2026-15370High (7.3)0.17%—Jul 21, 2026
A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled…
CVE-2026-13757Medium (6.2)0.20%—Jun 29, 2026
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit…
CVE-2026-13595Medium (5.3)0.17%—Jun 29, 2026
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically…
CVE-2026-55653Medium (6.5)0.51%—Jun 23, 2026
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards)…
CVE-2026-55654Low (3.7)0.65%—Jun 23, 2026
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is…
CVE-2026-42055Critical (9.2)6.5%—Jun 17, 2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to…
CVE-2026-48864High (7.8)0.26%—May 26, 2026
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a…
CVE-2026-9256Critical (9.2)2.7%—May 22, 2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular…
CVE-2026-9149Medium (6.5)0.57%—May 21, 2026
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an…
CVE-2026-9150Medium (6.5)0.58%—May 20, 2026
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by…
CVE-2026-42009High (7.5)1.1%—May 18, 2026
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence…
CVE-2026-42010Critical (9.8)0.94%—May 7, 2026
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this…
CVE-2026-3833High (7.4)0.89%—Apr 30, 2026
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within…
CVE-2026-3832Low (3.7)0.85%—Apr 30, 2026
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how…
CVE-2026-6732High (7.5)0.94%—Apr 23, 2026
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application14
  2. T1059 Command and Scripting Interpreter7
  3. T1499.004 Application or System Exploitation7
  4. T1203 Exploitation for Client Execution4
  5. T1068 Exploitation for Privilege Escalation3
  6. T1005 Data from Local System1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Redhat