Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2024-5042] rbac permissions can allow for the spread of node compromises
A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster. Affected products named by the advisory: RHODF-4.16-RHEL-9; Red Hat Openshift Data Foundation 4.20; Red Hat Advanced Cluster Management for Kubernetes 2.
Medium [CVE-2024-1726] security checks for some inherited endpoints performed after serialization in resteasy reactive may trigger a denial of service
A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoints being performed after serialization, more processing resources are consumed while the HTTP request is checked. In certain configurations, if an attacker has knowledge of any POST, PUT, or PATCH request paths, they can potentially identify vulnerable endpoints and trigger excessive resource usage as the endpoints process the requests. This can result in a denial of service. Affected products named by the advisory: Red Hat build of Quarkus 3.2.11.Final; Red Hat build of Quarkus.
Medium [CVE-2024-1102] jberet-core logging database credentials
A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9; Red Hat JBoss Enterprise Application Platform 7.
Medium [CVE-2023-6717] xss via assertion consumer service url in saml post-binding flow
A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue may allow a malicious admin in one realm or a client with registration access to target users in different realms or applications, executing arbitrary JavaScript in their contexts upon form submission. This can enable unauthorized access and harmful actions, compromising the confidentiality, integrity, and availability of the complete KC instance. Affected products named by the advisory: Red Hat build of Keycloak 22; RHOSS-1.33-RHEL-8; Red Hat build of Apicurio Registry 2; Red Hat Data Grid 8; and 6 more. Affected products named by the advisory: Red Hat Decision Manager 7; Red Hat Fuse 7; Red Hat JBoss Data Grid 7; Red Hat OpenShift GitOps; and 2 more. Affected products named by the advisory: Red Hat Process Automation 7; Red Hat Single Sign-On 7.
Medium [CVE-2024-1300] Io.vertx:vertx-core: memory leak when a tcp server is configured with tls and sni support
A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server name map, leading to memory exhaustion. This flaw allows attackers to send TLS client hello messages with fake server names, triggering a JVM out-of-memory error. Affected products named by the advisory: Cryostat 2 on RHEL 8; Migration Toolkit for Runtimes 1 on RHEL 8; MTA-6.2-RHEL-9; Red Hat build of Quarkus 3.2.11.Final; and 8 more. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 3; Red Hat Build of Keycloak; Red Hat build of OptaPlanner 8; Red Hat Integration Camel K 1; and 3 more. Affected products named by the advisory: Red Hat Integration Camel Quarkus 2; Red Hat JBoss Data Grid 7; Red Hat Process Automation 7.
Medium [CVE-2024-1023] memory leak due to the use of netty fastthreadlocal data structures in vertx
A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak. Affected products named by the advisory: Cryostat 2 on RHEL 8; MTA-6.2-RHEL-9; Red Hat build of Quarkus 3.2.11.Final; Red Hat build of Apache Camel for Spring Boot 3; and 6 more. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat build of OptaPlanner 8; Red Hat Data Grid 8; Red Hat Integration Camel K 1; and 2 more. Affected products named by the advisory: Red Hat Integration Camel Quarkus 2; Red Hat JBoss Data Grid 7.
Medium [CVE-2024-1459] directory traversal vulnerability
A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9; Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8; and 2 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9; Red Hat Data Grid 8.
Medium [CVE-2023-6780] integer overflow in __vsyslog_internal
An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer. This issue can only result in a memory allocation failure when the syslog function is called with a very long message, preventing the output of the message. This is the only known impact of this issue and this CVE was assigned to track this possibility. The glibc package, as shipped with Red Hat products, is not affected by this vulnerability because this issue was introduced in glibc 2.37, this glibc version is not used by any Red Hat product. Red Hat severity: Low — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-190. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2024-0775] use-after-free while changing the mount option in __ext4_remount leading
A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while freeing the old quota file names before a potential failure, leading to a use-after-free. Red Hat severity: Moderate — CVSS 6.7 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-416. Affected Red Hat products: Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2024-0639] potential deadlock on &net->sctp.addr_wq_lock leading to dos
A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system. Affected products named by the advisory: Red Hat Enterprise Linux 9.
Medium [CVE-2024-0565] cifs filesystem decryption improper input validation remote code execution vulnerability in function receive_encrypted_standard of client
An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denial of service. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.6 Extended Update Support; Red Hat Enterprise Linux 8.8 Extended Update Support; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.2 Extended Update Support; Red Hat Virtualization 4 for Red Hat Enterprise Linux 8; RHOL-5.7-RHEL-8.
Medium [CVE-2024-0443] blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs from being freed after they are made offline. This issue may allow an attacker with a local access to cause system instability, such as an out of memory error. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.2 Extended Update Support; Red Hat Enterprise Linux 9.
Medium [CVE-2023-6393] potential invalid reuse of context when @cacheresult on a uni is used
A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial "completion" context, the processing switches to the cached Uni instead of the request context. This is a problem if the cached Uni context contains sensitive information, and could allow a malicious user to benefit from a POST request returning the response that is meant for another user, gaining access to sensitive data. Affected products named by the advisory: Red Hat build of Quarkus 2.13.9.Final; Red Hat build of Quarkus.
Medium [CVE-2023-5090] improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs
A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Extended Update Support.
Medium [CVE-2023-4693] out-of-bounds read at fs/ntfs.c
An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting a high Confidentiality risk. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2023-4806] potential use-after-free in getaddrinfo
A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.6 Extended Update Support; Red Hat Enterprise Linux 9; Red Hat Virtualization 4 for Red Hat Enterprise Linux 8; and 1 more. Affected products named by the advisory: Red Hat Enterprise Linux 7.
Medium [CVE-2023-4527] stack read overflow in getaddrinfo in no-aaaa mode
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2023-3384] stored cross site scripting
A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an image. This flaw allows an attacker to publish a malicious image to a public registry containing a script that can be executed via Cross-site scripting (XSS). Affected product named by the advisory: Red Hat Quay 3.
Medium [CVE-2018-13405 +1] security regression for CVE-2018-13405
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.4 Extended Update Support.
Medium [CVE-2013-0270] openstack keystone: denial of service via large http request with long tenant name
A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system. Affected products named by the advisory: OpenStack Folsom for RHEL 6; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.