Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

RED HAT — Vulnerabilities & Security Advisories 676

Browse all 676 CVE security advisories affecting RED HAT. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2023-39194 Kernel: xfrm: out-of-bounds read in __xfrm_state_filter_match() — Red Hat Enterprise Linux 8CWE-125 3.2 Low2023-10-09
CVE-2023-39193 Kernel: netfilter: xtables sctp out-of-bounds read in match_flags() — Red Hat Enterprise Linux 8CWE-125 6.1 Medium2023-10-09
CVE-2023-39192 Kernel: netfilter: xtables out-of-bounds read in u32_match_it() — Red Hat Enterprise Linux 8CWE-125 6.7 Medium2023-10-09
CVE-2023-39189 Kernel: netfilter: nftables out-of-bounds read in nf_osf_match_one() — Red Hat Enterprise Linux 8CWE-125 5.1 Medium2023-10-09
CVE-2023-42755 Kernel: rsvp: out-of-bounds read in rsvp_classify() — Red Hat Enterprise Linux 8CWE-125 6.5 Medium2023-10-05
CVE-2023-42754 Kernel: ipv4: null pointer dereference in ipv4_send_dest_unreach() — Red Hat Enterprise Linux 8CWE-476 5.5 Medium2023-10-05
CVE-2023-39191 Kernel: ebpf: insufficient stack type checks in dynptr — Red Hat Enterprise Linux 9CWE-20 8.2 High2023-10-04
CVE-2023-3576 Libtiff: memory leak in tiffcrop.c — Red Hat Enterprise Linux 9CWE-119 5.5 Medium2023-10-04
CVE-2023-3428 Imagemagick: heap-buffer-overflow in coders/tiff.c — Red Hat Enterprise Linux 6CWE-122 6.2 Medium2023-10-04
CVE-2023-3971 Controller: html injection in custom login info — Red Hat Ansible Automation Platform 2.3 for RHEL 8CWE-80 7.3 High2023-10-04
CVE-2023-4380 Platform: token exposed at importing project — Red Hat Ansible Automation Platform 2.4 for RHEL 8CWE-532 6.3 Medium2023-10-04
CVE-2023-4237 Platform: ec2_key module prints out the private key directly to the standard output — Red Hat Ansible Automation Platform 2.4 for RHEL 8CWE-497 7.3 High2023-10-04
CVE-2023-2422 Keycloak: oauth client impersonation — Red Hat Single Sign-On 7CWE-295 5.5 Medium2023-10-04
CVE-2023-4586 Hotrod-client: hot rod client does not enable hostname validation when using tls that lead to a mitm attack — Red Hat Data Grid 8.4.6CWE-20 7.4 High2023-10-04
CVE-2023-4732 Kernel: race between task migrating pages and another task calling exit_mmap to release those same pages getting invalid opcode bug in include/linux/swapops.h — Red Hat Enterprise Linux 8CWE-366 4.7 Medium2023-10-03
CVE-2023-4886 Foreman: world readable file containing secrets — Red Hat Satellite 6.13 for RHEL 8CWE-200 6.7 Medium2023-10-03
CVE-2023-42756 Kernel: netfilter: race condition between ipset_cmd_add and ipset_cmd_swap — Red Hat Enterprise Linux 9CWE-362 4.4 Medium2023-09-28
CVE-2023-5215 Libnbd: crash or misbehaviour when nbd server returns an unexpected block size — Red Hat Enterprise Linux 9CWE-241 5.3 Medium2023-09-28
CVE-2023-4066 Operator: passwords defined in secrets shown in statefulset yaml — RHEL-8 based Middleware ContainersCWE-313 5.5 Medium2023-09-27
CVE-2023-3223 Undertow: outofmemoryerror due to @multipartconfig handling — Red Hat Fuse 7.12.1CWE-789 7.5 High2023-09-27
CVE-2023-5157 Mariadb: node crashes with transport endpoint is not connected mysqld got signal 6 — Red Hat Enterprise Linux 8CWE-400 7.5 High2023-09-26
CVE-2023-4065 Operator: plaintext password in operator log — RHEL-8 based Middleware ContainersCWE-117 5.5 Medium2023-09-26
CVE-2023-42753 Kernel: netfilter: potential slab-out-of-bound access due to integer underflow — Red Hat Enterprise Linux 7CWE-787 7.0 High2023-09-25
CVE-2022-4318 Cri-o: /etc/passwd tampering privesc — Red Hat OpenShift Container Platform 4.11CWE-538 7.8 High2023-09-25
CVE-2022-4245 Codehaus-plexus: xml external entity (xxe) injection — RHINT Camel-K-1.10.1CWE-91 4.3 Medium2023-09-25
CVE-2022-4244 Codehaus-plexus: directory traversal — RHINT Camel-K-1.10.1CWE-22 7.5 High2023-09-25
CVE-2022-4137 Keycloak: reflected xss attack — Red Hat Single Sign-On 7CWE-81 8.1 High2023-09-25
CVE-2023-5156 Glibc: dos due to memory leak in getaddrinfo.c — Red Hat Enterprise Linux 6CWE-401 7.5 High2023-09-25
CVE-2022-3962 Kiali: error message spoofing in kiali ui — Red Hat OpenShift Service Mesh 2.3 for RHEL 8CWE-74 4.3 Medium2023-09-23
CVE-2022-4039 Rhsso-container-image: unsecured management interface exposed to adjecent network — RHEL-8 based Middleware ContainersCWE-276 8.0 High2023-09-22

This page lists every published CVE security advisory associated with RED HAT. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.