Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

RED HAT — Vulnerabilities & Security Advisories 676

Browse all 676 CVE security advisories affecting RED HAT. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2022-3596 Instack-undercloud: rsync leaks information to undercloud — Red Hat OpenStack Platform 13.0 - ELSCWE-402 7.5 High2023-09-20
CVE-2022-3916 Keycloak: session takeover with oidc offline refreshtokens — Red Hat Single Sign-On 7CWE-384 6.8 Medium2023-09-20
CVE-2022-1438 Keycloak: xss on impersonation under specific circumstances — Red Hat Single Sign-On 7CWE-79 6.4 Medium2023-09-20
CVE-2023-4853 Quarkus: http security policy bypass — Openshift Serverless 1 on RHEL 8CWE-148 8.1 High2023-09-20
CVE-2023-4806 Glibc: potential use-after-free in getaddrinfo() — Red Hat Enterprise Linux 8CWE-416 5.9 Medium2023-09-18
CVE-2023-4527 Glibc: stack read overflow in getaddrinfo in no-aaaa mode — Red Hat Enterprise Linux 8CWE-121 6.5 Medium2023-09-18
CVE-2023-0923 Odh-notebook-controller-container: missing authorization allows for file contents disclosure — RHODS-1.22-RHEL-8CWE-862 8.8 High2023-09-15
CVE-2022-3466 Cri-o: security regression of cve-2022-27652 — Red Hat OpenShift Container Platform 4.12CWE-276 4.8 Medium2023-09-15
CVE-2023-4959 Quay: cross-site request forgery (csrf) on config-editor page — Red Hat Quay 3CWE-352 6.5 Medium2023-09-15
CVE-2023-3255 Qemu: vnc: infinite loop in inflate_buffer() leads to denial of service — Red Hat Enterprise Linux 8CWE-835 6.5 Medium2023-09-13
CVE-2023-4813 Glibc: potential use-after-free in gaih_inet() — Red Hat Enterprise Linux 8CWE-416 5.9 Medium2023-09-12
CVE-2022-1415 Drools: unsafe data deserialization in streamutils — RHPAM 7.13.1 asyncCWE-502 8.1 High2023-09-11
CVE-2023-38201 Keylime: challenge-response protocol bypass during agent registration — Red Hat Enterprise Linux 9CWE-639 6.5 Medium2023-08-25
CVE-2023-4042 Ghostscript: incomplete fix for cve-2020-16305 — Red Hat Enterprise Linux 8CWE-125 5.5 Medium2023-08-23
CVE-2023-3899 Subscription-manager: inadequate authorization of com.redhat.rhsm1 d-bus interface allows local users to modify configuration — Red Hat Enterprise Linux 7CWE-285 7.8 High2023-08-23
CVE-2023-4459 Kernel: vmxnet3: null pointer dereference in vmxnet3_rq_cleanup() — Red Hat Enterprise Linux 8.2 Advanced Update SupportCWE-476 5.5 Medium2023-08-21
CVE-2023-4456 Openshift-logging: lokistack authorisation is cached too broadly — RHOL-5.5-RHEL-8CWE-1220 5.7 Medium2023-08-21
CVE-2023-4387 Kernel: vmxnet3: use-after-free in vmxnet3_rq_alloc_rx_buf() — Red Hat Enterprise Linux 8CWE-416 7.1 High2023-08-16
CVE-2023-4385 Kernel: jfs: null pointer dereference in dbfree() — Red Hat Enterprise Linux 6CWE-476 5.5 Medium2023-08-16
CVE-2023-39418 Postgresql: merge fails to enforce update or select row security policies — Red Hat Enterprise Linux 8CWE-1220 3.1 Low2023-08-11
CVE-2023-39417 Postgresql: extension script @substitutions@ within quoting allow sql injection — Red Hat Advanced Cluster Security 4.2CWE-89 7.5 High2023-08-11
CVE-2023-4273 Kernel: exfat: stack overflow in exfat_get_uniname_from_ext_entry — Red Hat Enterprise Linux 9CWE-121 6.0 Medium2023-08-09
CVE-2023-4194 Kernel: tap: tap_open(): correctly initialize socket uid next fix of i_uid to current_fsuid — Red Hat Enterprise Linux 9CWE-843 5.5 Medium2023-08-07
CVE-2023-4147 Kernel: netfilter: nf_tables_newrule when adding a rule with nfta_rule_chain_id leads to use-after-free — Red Hat Enterprise Linux 9CWE-416 7.8 High2023-08-07
CVE-2023-4132 Kernel: smsusb: use-after-free caused by do_submit_urb() — Red Hat Enterprise Linux 8CWE-416 5.5 Medium2023-08-03
CVE-2023-4133 Kernel: cxgb4: use-after-free in ch_flower_stats_cb() — Red Hat Enterprise Linux 8CWE-416 5.5 Medium2023-08-03
CVE-2023-38560 Ghostscript: integer overflow in pcl/pl/plfont.c:418 in pl_glyph_name — Red Hat Enterprise Linux 6CWE-190 5.5 Medium2023-08-01
CVE-2023-38559 Ghostscript: out-of-bound read in base/gdevdevn.c:1973 in devn_pcx_write_rle could result in dos — Red Hat Enterprise Linux 8CWE-125 5.5 Medium2023-08-01
CVE-2023-4010 Kernel: usb: hcd: malformed usb descriptor leads to infinite loop in usb_giveback_urb() — Red Hat Enterprise Linux 6CWE-835 4.6 Medium2023-07-31
CVE-2023-4004 Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove() — Red Hat Enterprise Linux 8CWE-416 7.8 High2023-07-31

This page lists every published CVE security advisory associated with RED HAT. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.