RPM是Rpm团队开源的一款操作系统软件包管理工具。 RPM存在数字错误漏洞,该漏洞源于处理特制NDB数据库文件时计算错误导致内存分配不正确,可能导致拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 6 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Hardened Images | 6.0.1-6.2.hum1< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Hardened Images | 6.0.1-6.2.hum1 ~ * |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10059 | 9.1 CRITICAL | Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cl |
| CVE-2026-10090 | 9.0 CRITICAL | Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit u |
| CVE-2026-15572 | 8.8 HIGH | Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows p |
| CVE-2026-15573 | 8.1 HIGH | Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching i |
| CVE-2026-16102 | 8.1 HIGH | Keycloak-services: keycloak-services: default dcr policy allows role forgery via user prop |
| CVE-2026-16443 | 7.4 HIGH | Keycloak-services: keycloak-services: saml broker metadata import disables response signat |
| CVE-2026-16442 | 7.4 HIGH | Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only r |
| CVE-2026-16100 | 6.5 MEDIUM | Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics v |
| CVE-2026-49331 | 6.5 MEDIUM | Openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on |
| CVE-2026-16071 | 5.4 MEDIUM | Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users |
No comments yet