Vulnerabilities
Summary — last 7 days
New vulnerabilities3,332▲ 359 vs. last week
Critical / high1,490▲ 132 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
3,731 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (4.7) | 0.14% | — | Redhat Enterprise Linux | 9/3/2026 | 9/22/2026 | A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when processing crafted GFS2 filesystem images. | |
| Analyzed | Medium (6.3) | 0.14% | — | Redhat Enterprise Linux | 9/3/2026 | 9/22/2026 | A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images. | |
| Analyzed | High (7) | 0.17% | — | Redhat Enterprise Linux | 9/3/2026 | 9/22/2026 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images. | |
| Analyzed | High (7) | 0.17% | — | Redhat Enterprise Linux | 9/3/2026 | 9/22/2026 | A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images. | |
| Analyzed | Medium (4.7) | 0.14% | — | Redhat Enterprise Linux | 9/3/2026 | 9/22/2026 | A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of… | |
| Analyzed | Medium (6.1) | 0.26% | — | GimpRedhat Enterprise Linux | 8/28/2026 | 9/1/2026 | A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read and a stack out-of-bounds access. This… | |
| Analyzed | Medium (6.1) | 0.26% | — | GimpRedhat Enterprise Linux | 8/28/2026 | 8/31/2026 | A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly perform memory bounds checking. This missing validation results in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service… | |
| Analyzed | Medium (6.1) | 0.26% | — | GimpRedhat Enterprise Linux | 8/28/2026 | 8/31/2026 | A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the used_clrs (palette count) parameter. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an… | |
| Analyzed | Medium (6.1) | 0.27% | — | GimpRedhat Enterprise Linux | 8/28/2026 | 8/31/2026 | A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate the HAM row size and improperly handles cases where the number of color planes (nPlanes) is zero. This causes a row size mismatch that bypasses memory bounds… | |
| Modified | Medium (4.4) | 0.23% | — | GimpRedhat Enterprise Linux | 8/25/2026 | 9/2/2026 | A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per-line parameters independently rather than ensuring their combined values are consistent with the allocated buffer size. This incorrect validation leads to improper… | |
| Analyzed | Medium (6.1) | 0.26% | — | GimpRedhat Enterprise Linux | 8/24/2026 | 9/1/2026 | A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service… | |
| Modified | High (7.5) | 0.43% | — | Redhat Enterprise LinuxFreeipa | 8/20/2026 | 9/28/2026 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS)… | |
| Modified | High (7.5) | 0.43% | — | Redhat Enterprise LinuxFreeipa | 8/20/2026 | 9/28/2026 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage,… | |
| Analyzed | Medium (6.5) | 0.43% | — | Redhat Enterprise LinuxFreeipa | 8/20/2026 | 8/24/2026 | A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service,… | |
| Modified | High (8.7) | 0.43% | — | Redhat Enterprise LinuxFreeipa | 8/20/2026 | 9/28/2026 | A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service… | |
| Modified | High (8.1) | 0.22% | — | FreeipaRedhat Enterprise Linux | 8/20/2026 | 9/28/2026 | A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS)… | |
| Analyzed | Medium (4.4) | 0.15% | — | Redhat Openshift Container PlatformRedhat Enterprise Linux | 8/14/2026 | 8/31/2026 | A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients. | |
| Analyzed | Medium (6.5) | 0.33% | — | SambaRedhat Enterprise Linux | 8/14/2026 | 9/23/2026 | A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A… | |
| Analyzed | Medium (5.5) | 0.14% | — | Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux | 8/14/2026 | 9/1/2026 | A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This… | |
| Analyzed | Medium (6.3) | 0.14% | — | Redhat Enterprise Linux | 8/13/2026 | 8/25/2026 | A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a… | |
| Analyzed | Medium (6.3) | 0.13% | — | Redhat Enterprise Linux | 8/13/2026 | 8/25/2026 | A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to… | |
| Analyzed | Medium (6.6) | 0.13% | — | Redhat Enterprise Linux | 8/13/2026 | 8/25/2026 | A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the… | |
| Analyzed | Medium (6.5) | 0.19% | — | Redhat Enterprise Linux | 8/13/2026 | 8/25/2026 | A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the… | |
| Analyzed | Medium (6.5) | 0.19% | — | Redhat Enterprise Linux | 8/12/2026 | 8/25/2026 | A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6 Advertise traffic with a short User Datagram Protocol (UDP) length can cause the DHCPv6… | |
| Analyzed | Medium (6.5) | 0.21% | — | Redhat Enterprise Linux | 8/12/2026 | 8/25/2026 | A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can… |