Red Hat / Enterprise Linux
1,925 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-82343 | Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling | MEDIUM | 6.1 | Aug 28, 2026 |
| CVE-2026-82330 | Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check | MEDIUM | 6.1 | Aug 28, 2026 |
| CVE-2026-82328 | Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count | MEDIUM | 6.1 | Aug 28, 2026 |
| CVE-2026-82324 | Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0 | MEDIUM | 6.1 | Aug 28, 2026 |
| CVE-2026-80101 | Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validation | MEDIUM | 4.4 | Aug 25, 2026 |
| CVE-2026-78475 | Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader | MEDIUM | 6.1 | Aug 24, 2026 |
| CVE-2026-11861 | Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships | CRITICAL | 9.6 | Aug 20, 2026 |
| CVE-2026-73198 | Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read | HIGH | 7.5 | Aug 20, 2026 |
| CVE-2026-13097 | Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore | HIGH | 8.7 | Aug 20, 2026 |
| CVE-2026-73196 | Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding | MEDIUM | 6.5 | Aug 20, 2026 |
| CVE-2026-73197 | Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body read | HIGH | 7.5 | Aug 20, 2026 |
| CVE-2026-13002 | Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing | MEDIUM | 4.4 | Aug 14, 2026 |
| CVE-2026-58224 | Samba: ctdb fails to do integrity checking of received packets | MEDIUM | 6.5 | Aug 14, 2026 |
| CVE-2026-19617 | Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser | MEDIUM | 5.5 | Aug 14, 2026 |
| CVE-2026-73584 | Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling | MEDIUM | 6.3 | Aug 13, 2026 |
| CVE-2026-73583 | Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr | MEDIUM | 6.6 | Aug 13, 2026 |
| CVE-2026-73585 | Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack | MEDIUM | 6.3 | Aug 13, 2026 |
| CVE-2026-18728 | Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing | MEDIUM | 6.5 | Aug 13, 2026 |
| CVE-2026-18727 | Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing | MEDIUM | 6.5 | Aug 12, 2026 |
| CVE-2026-18726 | Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing | MEDIUM | 6.5 | Aug 12, 2026 |
| CVE-2026-19654 | Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd | HIGH | 7.5 | Aug 12, 2026 |
| CVE-2026-73433 | Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd parsing leading to out-of-bounds read/write | MEDIUM | 6.6 | Aug 12, 2026 |
| CVE-2026-73434 | Gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing | MEDIUM | 6.1 | Aug 12, 2026 |
| CVE-2026-19548 | Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing | MEDIUM | 5.5 | Aug 12, 2026 |
| CVE-2026-19550 | Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes | HIGH | 8.2 | Aug 11, 2026 |
Showing 1 to 25 of 1,925 CVEs