product of redhat

hardened images

20 thingsrelated by NVD

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
CVE-2026-71227
Severity medium
libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi's one-shot AIO path
CVE-2026-71226
Severity high
libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
CVE-2026-71225
Severity medium
libssh: libssh: denial of service via automatic certificate authentication loop
CVE-2026-59849
Severity high
libssh: libssh: information disclosure via short GSSAPI Curve25519 public key
CVE-2026-59842
Severity medium
openssh: Heap out-of-bounds read in Red Hat Enterprise Linux versions of OpenSSH GSSAPI indicator cleanup due to missing NULL sentinel…
CVE-2026-55654
Severity low
libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
CVE-2026-48864
Severity high
nginx: NGINX: Arbitrary code execution or Denial of Service via heap-based buffer overflow with crafted HTTP/2 headers
CVE-2026-42055
Severity high
gnutls: gnutls: Authentication Bypass via NUL Character in Username
CVE-2026-42010
Severity critical
gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
CVE-2026-42009
Severity high
libdm: lvm2: libdm: Denial of Service via uncontrolled recursion in config parser
CVE-2026-19617
Severity medium
libssh: libssh: stack buffer overflow in SFTP server longname construction
CVE-2026-15370
Severity high
p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing
CVE-2026-13757
Severity medium
tar: tar: Hidden file injection via crafted archives
CVE-2026-5704
Severity medium
libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing
CVE-2026-5121
Severity high
libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing
CVE-2026-4775
Severity high
libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing
CVE-2026-4424
Severity high
gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
CVE-2026-3833
Severity high
gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response
CVE-2026-3832
Severity low
p11-kit: NULL dereference via C_DeriveKey with specific NULL parameters
CVE-2026-2100
Severity high