R

Redhat Security Vulnerabilities (CVE)

Explore vulnerabilities and security advisories affecting Redhat products.

31 known CVE vulnerabilities tracked

Critical
0
High
10
Medium
19
Low
2
None
0

Vulnerabilities By Year

Products Affected

All Redhat CVEs

CVE-2025-57849
6.4 medium

A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can l

Fuse Mar 13, 2026
CVE-2026-2376
4.9 medium

A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destina

Quay Mar 12, 2026
CVE-2025-13601
7.7 high

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped stri

Codeready Linux Builder Nov 26, 2025
CVE-2025-6170
2.5 low

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurati

Jboss Core Services Jun 16, 2025
CVE-2024-0193
7.8 high

A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unpri

Codeready Linux Builder For Eus Jan 2, 2024
CVE-2016-2183
7.5 high

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted sessi

Jboss Enterprise Application Platform Sep 1, 2016
CVE-2014-3566
3.4 low

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

Enterprise Linux Oct 15, 2014