Red Hat / Openshift Container Platform
326 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-13002 | Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing | MEDIUM | 4.4 | Aug 14, 2026 |
| CVE-2026-19617 | Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser | MEDIUM | 5.5 | Aug 14, 2026 |
| CVE-2026-19548 | Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing | MEDIUM | 5.5 | Aug 12, 2026 |
| CVE-2026-71227 | Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return | MEDIUM | 5.1 | Aug 5, 2026 |
| CVE-2026-71226 | Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path | HIGH | 7.3 | Aug 5, 2026 |
| CVE-2026-71225 | Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries | MEDIUM | 6.5 | Aug 5, 2026 |
| CVE-2026-68743 | Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1 | HIGH | 7.1 | Aug 4, 2026 |
| CVE-2026-68744 | Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply | LOW | 3.3 | Aug 4, 2026 |
| CVE-2026-18477 | Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape | MEDIUM | 4.4 | Aug 3, 2026 |
| CVE-2026-18508 | Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite | MEDIUM | 4.4 | Aug 3, 2026 |
| CVE-2026-68742 | Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr | MEDIUM | 5.5 | Aug 3, 2026 |
| CVE-2026-13757 | P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing | MEDIUM | 6.2 | Jun 29, 2026 |
| CVE-2026-13595 | Util-linux: util-linux: heap use-after-free in libblkid nested partition probing | MEDIUM | 6.8 | Jun 29, 2026 |
| CVE-2026-55653 | Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of servi… | MEDIUM | 6.5 | Jun 23, 2026 |
| CVE-2026-12725 | Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies | MEDIUM | 5.9 | Jun 22, 2026 |
| CVE-2026-54100 | Windows-machine-config-operator: windows-machine-config-operator: ssh host key not verified enables credential theft | HIGH | 8.3 | Jun 22, 2026 |
| CVE-2026-54099 | Windows-machine-config-operator: windows-machine-config-operator: wicd csr extra-organization allows privilege escalation to system:masters | HIGH | 8.8 | Jun 22, 2026 |
| CVE-2026-44495 | Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge | HIGH | 7.7 | Jun 11, 2026 |
| CVE-2026-1784 | Ose-cluster-ingress-operator: remote code execution through haproxy configuration injection | HIGH | 8.8 | Jun 2, 2026 |
| CVE-2026-10533 | Openshift: openshift: non-admin user can bypass resourcequota and flood etcd with events causing cluster-wide api degradation | MEDIUM | 5.0 | Jun 1, 2026 |
| CVE-2026-42965 | Openshift/router: openshift/router: cloud metadata ssrf via fqdn-typed endpointslice bypasses destination validation | HIGH | 7.7 | May 29, 2026 |
| CVE-2026-46579 | Openshift/router: openshift/router: mtls client certificate spoofing via unstripped x-ssl-client headers on http frontend | HIGH | 7.5 | May 29, 2026 |
| CVE-2026-4408 | Samba: remote code execution in samr | CRITICAL | 9.8 | May 28, 2026 |
| CVE-2026-1933 | Samba: missing access check on reparse point operations | HIGH | 7.1 | May 27, 2026 |
| CVE-2026-2340 | Samba: vfs_worm does not block directory modification | MEDIUM | 6.5 | May 27, 2026 |
Showing 1 to 25 of 326 CVEs