Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1678 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 37 critical, 637 high, 830 medium, 172 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

Medium5.4Red Hat

Medium [CVE-2024-11831] cross-site scripting (xss) in serialize-javascript

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-79. Affected products named by the advisory: Red Hat Advanced Cluster Security 4.4; Red Hat Advanced Cluster Security 4.5; Red Hat Ceph Storage 7.1; Red Hat Ceph Storage 8.1; and 39 more. Affected products named by the advisory: Red Hat Ceph Storage 9.0; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; RHODF-4.14-RHEL-9; and 35 more.

CVE-2024-11831
Red Hat Enterprise Linux
Feb 10, 2025
Medium6.1Red Hat

Medium [CVE-2024-12086] Rsync: rsync server leaks arbitrary client files

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client. This vulnerability marked as moderate rather than important because it requires the attacker to control the rsync server, which limits the scope of exploitation to scenarios where the client interacts with untrusted or compromised servers. Additionally, the attack is non-trivial, as it relies on the attacker sending specially crafted checksum values and deducing file contents byte-by-byte based on the client’s responses. This makes the exploit more complex and time-consuming compared to direct file access vulnerabilities. Furthermore, the impact is limited to file data enumeration, and it does not allow arbitrary code execution or privilege escalation on the client. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N). Weakness: CWE-390.

CVE-2024-12086
Red Hat Enterprise Linux
Jan 14, 2025
Medium5.4Red Hat

Medium [CVE-2024-9341] Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N). Weakness: CWE-59. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 10 as not affected. Red Hat fixing advisory: RHSA-2024:8846, RHSA-2024:8039, RHSA-2024:8112, RHSA-2024:9454, RHSA-2024:9459, RHSA-2024:8694, RHSA-2024:8690, RHSA-2024:8238, RHSA-2024:8428, RHSA-2024:8263, RHSA-2024:10147, RHSA-2024:7925, RHSA-2024:10818, RHSA-2024:6122. Affected products named by the advisory: Red Hat package: podman; Red Hat package: buildah.

CVE-2024-9341
Red Hat Enterprise Linux
Oct 1, 2024
Medium5.5Red Hat

Medium [CVE-2024-8775] Ansible-core: exposure of sensitive information in ansible vault files due to improper logging

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the playbook output or logs. This can lead to the unintentional disclosure of secrets like passwords or API keys, compromising security and potentially allowing unauthorized access or actions. This issue is classified as moderate rather than important because while it does expose sensitive information during playbook execution, the exposure is limited to logs and output generated during the run, which is typically accessible only to authorized users with sufficient privileges. The flaw does not result in an immediate or direct compromise of systems, as no remote exploitation vector is introduced. Additionally, the risk can be mitigated through proper configuration (`no_log: true`) and access control measures, reducing the likelihood of unauthorized access to the logged data. However, the unintentional disclosure of secrets like passwords or API keys still presents a potential risk for privilege escalation or lateral movement within an environment, justifying a moderate severity rating.

CVE-2024-8775
Red Hat Enterprise Linux
Sep 14, 2024
Medium6.5Red Hat

Medium [CVE-2023-39329] Openjpeg: resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.c

A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-400. Affected Red Hat products: Red Hat AI Inference Server 3.2; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:4128. Affected products named by the advisory: Red Hat package: openjpeg2.

CVE-2023-39329
Red Hat Enterprise Linux
Jul 13, 2024
Medium4.3Vendor: LowRed Hat

Medium [CVE-2023-39327] Openjpeg: malicious files can cause the program to enter a large loop

A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal. Red Hat severity: Low — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-400. Affected Red Hat products: Red Hat AI Inference Server 3.2; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2026:4128. Affected products named by the advisory: Red Hat package: openjpeg2.

CVE-2023-39327
Red Hat Enterprise Linux
Jul 13, 2024
Medium5.4Vendor: LowRed Hat

Medium [CVE-2023-6710] Mod_cluster/mod_proxy_cluster: stored cross site scripting

A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script on the alias parameter on the URL, it adds a new virtual host and adds the script to the cluster-manager page. The impact of this vulnerability is considered as Low, as the cluster_manager URL should not be exposed outside and is protected by user/password. Red Hat severity: Low — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-79. Affected Red Hat products: JBoss Core Services for RHEL 8; JBoss Core Services on RHEL 7; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2024:1316, RHSA-2024:2387. Affected products named by the advisory: Red Hat package: mod_proxy_cluster.

CVE-2023-6710
Red Hat Enterprise Linux
Dec 12, 2023
Medium5.3Vendor: LowRed Hat

Medium [CVE-2023-4693] out-of-bounds read at fs/ntfs.c

An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting a high Confidentiality risk. This vulnerability is considered as 'Low' severity by Red Hat as the NTFS module is not shipped as part of Red Hat's signed grub2 image. Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2024:3184, RHSA-2024:2456. Affected products named by the advisory: Red Hat package: grub2.

CVE-2023-4693
Red Hat Enterprise Linux
Oct 25, 2023
Medium5.9Red Hat

Medium [CVE-2023-4806] potential use-after-free in getaddrinfo

A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags. This issue is only exploitable with very specific conditions, as detailed in the description. However, all glibc versions shipped in Red Hat Enterprise Linux are vulnerable to this issue. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-416. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.6 Extended Update Support; Red Hat Enterprise Linux 9; Red Hat Virtualization 4 for Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2023:5455, RHSA-2023:7409, RHSA-2023:5453. Affected products named by the advisory: Red Hat package: glibc; Red Hat package: compat-glibc.

CVE-2023-4806
Red Hat Enterprise Linux
Sep 18, 2023
Medium6.5Red Hat

Medium [CVE-2023-4527] stack read overflow in getaddrinfo in no-aaaa mode

A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash. The no-aaaa stub resolver option was backported only to Red Hat Enterprise Linux versions 8.7 and 9.1. Therefore, previous versions are not affected. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H). Weakness: CWE-121. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2023:5455, RHSA-2023:5453. Affected products named by the advisory: Red Hat package: glibc.

CVE-2023-4527
Red Hat Enterprise Linux
Sep 18, 2023

← All Red Hat advisories