Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.0Red Hat

High [CVE-2024-6508] oauth2 insufficient state parameter entropy

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18.

CVE-2024-6508
Unclassified
Aug 21, 2024
High7.5Red Hat

High [CVE-2024-5971] response write hangs in case of java 17 tlsv1.3 newsessionticket

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource consumption, leaving the server side to a denial of service attack. This happens only with Java 17 TLSv1.3 scenarios. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9; Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7; Red Hat build of Apache Camel for Spring Boot 3; and 3 more. Affected products named by the advisory: Red Hat build of Apache Camel - HawtIO 4; Red Hat Fuse 7; Red Hat Integration Camel K 1.

CVE-2024-5971
Unclassified
Jul 8, 2024
High8.1Red Hat

High [CVE-2006-5051 +1] regresshion - race condition in ssh allows rce/dos

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Extended Update Support; Red Hat OpenShift Container Platform 4.13; and 3 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16.

CVE-2006-5051CVE-2024-6387
Red Hat Enterprise Linux
Jul 1, 2024
High8.3Red Hat

High [CVE-2024-3727] digest type does not guarantee valid type

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks. Affected products named by the advisory: OADP-1.3-RHEL-9; Red Hat Advanced Cluster Security 4.4; Red Hat Advanced Cluster Security 4.5; Red Hat Enterprise Linux 8; and 19 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Migration Toolkit for Containers 1.8; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; and 14 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; and 10 more.

CVE-2024-3727
Unclassified
May 9, 2024
High7.4Red Hat

High [CVE-2024-1249] unvalidated cross-origin messages in checkloginiframe leads to ddos

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages. Affected products named by the advisory: Red Hat build of Keycloak 22; Red Hat Single Sign-On 7.6 for RHEL 7; Red Hat Single Sign-On 7.6 for RHEL 8; Red Hat Single Sign-On 7.6 for RHEL 9; and 6 more. Affected products named by the advisory: RHEL-8 based Middleware Containers; RHOSS-1.33-RHEL-8; Red Hat build of Apicurio Registry 2; Red Hat Decision Manager 7; and 2 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat Process Automation 7.

CVE-2024-1249
Unclassified
Apr 17, 2024
High8.1Red Hat

High [CVE-2024-1132] path transversal in redirection validation

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL. Affected products named by the advisory: Migration Toolkit for Runtimes 1 on RHEL 8; MTA-6.2-RHEL-9; Red Hat build of Keycloak 22; Red Hat Single Sign-On 7.6 for RHEL 7; and 7 more. Affected products named by the advisory: Red Hat Single Sign-On 7.6 for RHEL 8; Red Hat Single Sign-On 7.6 for RHEL 9; RHEL-8 based Middleware Containers; Red Hat build of Apicurio Registry 2; and 3 more.

CVE-2024-1132
Unclassified
Apr 17, 2024
High7.0Red Hat

High [CVE-2024-2700] leak of local configuration properties into quarkus applications

A vulnerability was found in the quarkus-core component. Quarkus captures local environment variables from the Quarkus namespace during the application's build, therefore, running the resulting application inherits the values captured at build time. Some local environment variables may have been set by the developer or CI environment for testing purposes, such as dropping the database during application startup or trusting all TLS certificates to accept self-signed certificates. If these properties are configured using environment variables or the.env facility, they are captured into the built application, which can lead to dangerous behavior if the application does not override these values. This behavior only happens for configuration properties from the `quarkus.*` namespace. Affected products named by the advisory: Red Hat build of Quarkus 3.2.12.Final; Red Hat build of Quarkus 3.8.4.redhat; RHOSS-1.33-RHEL-8; Red Hat build of Apache Camel 4 for Quarkus 3; and 6 more. Affected products named by the advisory: Red Hat build of Apache Camel - HawtIO 4; Red Hat Build of Keycloak; Red Hat build of OptaPlanner 8; Red Hat Integration Camel K 1; and 1 more.

CVE-2024-2700
Unclassified
Apr 4, 2024
High7.5Red Hat

High [CVE-2024-1635] out-of-memory error after several closed connections with wildfly-http-client protocol

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits exhausted at some point, depending on the amount of memory available. At HTTP upgrade to remoting, the WriteTimeoutStreamSinkConduit leaks connections if RemotingConnection is closed by Remoting ServerConnectionOpenListener. Because the remoting connection originates in Undertow as part of the HTTP upgrade, there is an external layer to the remoting connection. This connection is unaware of the outermost layer when closing the connection during the connection opening procedure. Hence, the Undertow WriteTimeoutStreamSinkConduit is not notified of the closed connection in this scenario. Because WriteTimeoutStreamSinkConduit creates a timeout task, the whole dependency tree leaks via that task, which is added to XNIO WorkerThread. So, the workerThread points to the Undertow conduit, which contains the connections and causes the leak.

CVE-2024-1635
Unclassified
Feb 19, 2024
High8.0Red Hat

High [CVE-2024-1488] unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.2 Telecommunications Update Service; Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Telecommunications Update Service; Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.6 Extended Update Support; and 4 more.

CVE-2024-1488
Red Hat Enterprise Linux
Feb 15, 2024
High8.0Red Hat

High [CVE-2024-1485] decompress can delete files outside scope via relative paths

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed. Red Hat Openshift has a "Low" rated impact due to the affected code being shipped, but unused. Red Hat severity: Important — CVSS 8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:H). Weakness: CWE-22. Affected Red Hat products: OpenShift Developer Tools and Services; Red Hat OpenShift Container Platform 4. Will not fix / out of support: OpenShift Developer Tools and Services. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2024-1485
Unclassified
Feb 13, 2024
High8.6Red Hat

High [CVE-2024-21626] runc container breakout through process.cwd trickery and leaked fds

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue. While a user performs `O_CLOEXEC` all file descriptors before executing the container code, the file descriptor is open when performing `setcwd(2)`, which means that the reference can be kept alive in the container by configuring the working directory to be a path resolved through the file descriptor. The non-dumpable bit is unset after `execve`, meaning there are multiple ways to attack this other than bad configurations. The only way to defend against it entirely is to close all unneeded file descriptors.

CVE-2024-21626
Unclassified
Jan 31, 2024
High8.2Red Hat

High [CVE-2023-6779] off-by-one heap-based buffer overflow in __vsyslog_internal

An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an incorrect calculation of the buffer size to store the message, resulting in an application crash. This issue affects glibc 2.37 and newer. The glibc package, as shipped with Red Hat products, is not affected by this vulnerability because this issue was introduced in glibc 2.37, this glibc version is not used by any Red Hat product. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H). Weakness: CWE-193. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2023-6779
Unclassified
Jan 31, 2024
High8.4Red Hat

High [CVE-2023-6246] heap-based buffer overflow in __vsyslog_internal

A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program name (the basename of argv[0]) is bigger than 1024 bytes, resulting in an application crash or local privilege escalation. This issue affects glibc 2.36 and newer. The glibc package, as shipped with Red Hat products, is not affected by this vulnerability because this issue was introduced in glibc 2.36, this glibc version is not used by any Red Hat product. Red Hat severity: Important — CVSS 8.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-122. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2023-6246
Unclassified
Jan 31, 2024
High7.5Red Hat

High [CVE-2023-52355] tiffrasterscanlinesize64 produce too-big size and could cause oom

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat AI Inference Server 3.2; Red Hat Discovery 2; and 1 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 10.0 Extended Update Support.

CVE-2023-52355
Red Hat Enterprise Linux
Jan 25, 2024
High7.0Red Hat

High [CVE-2023-6531] gc's deletion of an skb races with unix_stream_read_generic leading to uaf

A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() on the socket that the SKB is queued on. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2023-6531
Linux Kernel
Jan 21, 2024
High7.0Red Hat

High [CVE-2024-0646] ktls overwrites readonly memory pages when using function splice with a ktls socket as destination

An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate their privileges on the system. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.2 Telecommunications Update Service; Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions; and 10 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Telecommunications Update Service; Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.6 Extended Update Support; and 5 more.

CVE-2024-0646
Linux Kernel
Jan 17, 2024
High7.0Red Hat

High [CVE-2023-6546] gsm multiplexing race condition leads to privilege escalation

A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, and can lead to a use-after-free problem on a struct gsm_dlci while restarting the gsm mux. This could allow a local unprivileged user to escalate their privileges on the system. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Telecommunications Update Service; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.6 Extended Update Support; Red Hat Enterprise Linux 8.8 Extended Update Support; Red Hat Enterprise Linux 9.0 Extended Update Support; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.2 Extended Update Support; Red Hat Virtualization 4 for Red Hat Enterprise Linux 8; RHOL-5.7-RHEL-8.

CVE-2023-6546
Linux Kernel
Dec 21, 2023
High7.5Red Hat

High [CVE-2023-5379] ajp request closes connection exceeding maxrequestsize

A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when the TCP connection is closed from the backend after sending the AJP request without receiving an AJP response, and stops forwarding. This issue could allow a malicious user could to repeatedly send requests that exceed the max-header-size, causing a Denial of Service (DoS). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7.

CVE-2023-5379
Unclassified
Dec 12, 2023
High8.6Red Hat

High [CVE-2023-46847] denial of service in http digest authentication

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication. Affected products named by the advisory: Red Hat Enterprise Linux 6 Extended Lifecycle Support; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 7.6 Advanced Update Support; Red Hat Enterprise Linux 7.7 Advanced Update Support; and 11 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.2 Telecommunications Update Service; Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions; and 5 more.

CVE-2023-46847
Red Hat Enterprise Linux
Nov 3, 2023
High7.5Red Hat

High [CVE-2023-4692] out-of-bounds write at fs/ntfs.c may lead to unsigned code execution

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection bypass may be achieved. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2023-4692
Red Hat Enterprise Linux
Oct 25, 2023

← All vendors