VulnSea

openshift/ose-rhel-coreos-9 vulnerabilities

CVEs whose affected-version data names the openshift/ose-rhel-coreos-9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

35 CVEsRSS

CVE-2026-93834High· 8.8PoC
2d ago

A use-after-free vulnerability was found in QEMU's 9pfs subsystem

A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path cont…

▾ MidnightRed Hat · qemu-kvmvia NVD
CVE-2026-94640High· 7.5
5d ago

A flaw was found in rpcbind

A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedur…

▾ TwilightRed Hat · rpcbindEPSS 0.61%via NVD
CVE-2026-90462Medium· 5.4PoC
5d ago

A flaw was found in SSSD

A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. Thi…

▾ TwilightRed Hat · sssdEPSS 0.21%via NVD
CVE-2026-95619High· 7.7
5d ago

A flaw was found in libstdc++

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corrup…

▾ TwilightRed Hat · gcc-mainEPSS 0.36%via NVD
CVE-2026-95508High· 7.4
5d ago

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply bu…

▾ TwilightRed Hat · libslirpEPSS 0.57%via NVD
CVE-2026-92574High· 8.8
6d ago

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities…

▾ TwilightRed Hat · openshift-sandboxed-containers/osc-monitor-rhel9EPSS 0.65%via NVD
CVE-2026-81627High· 8.2PoC
1w ago

A flaw was found in QEMU

A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked S…

▾ MidnightRed Hat · qemu-kvmEPSS 0.19%via NVD
CVE-2026-76781Medium· 5.5
1w ago

A flaw was found in libxml2

A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` …

▾ SunlitRed Hat · libxml2-mainEPSS 0.17%via NVD
CVE-2026-79705Medium· 4.5
1w ago

A flaw was found in the buildah/copier Go package

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended de…

▾ SunlitRed Hat · ansible-automation-platform-24/eda-controller-rhel8EPSS 0.38%via NVD
CVE-2026-90996Medium· 4.0
1w ago

A flaw was found in sssd

A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS respon…

▾ SunlitRed Hat · sssdEPSS 0.16%via NVD
CVE-2026-90995Medium· 5.5
1w ago

A flaw was found in SSSD (System Security Services Daemon)

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_service…

▾ SunlitRed Hat · sssdEPSS 0.15%via NVD
CVE-2026-90994Medium· 4.0
1w ago

A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data()

A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating p…

▾ SunlitRed Hat · sssdEPSS 0.17%via NVD
CVE-2026-90463Medium· 4.0
1w ago

A flaw was found in the sssd NSS responder

A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of…

▾ SunlitRed Hat · sssdEPSS 0.15%via NVD
CVE-2026-89329Medium· 6.2
2w ago

A flaw was found in `multipathd`

A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` list…

▾ SunlitRed Hat · device-mapper-multipathEPSS 0.16%via NVD
CVE-2026-88264Medium· 5.6
2w ago

A flaw was found in crun

A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected …

▾ Sunlitcontainers · crunEPSS 0.15%via NVD
CVE-2026-84042High· 7.8
2w ago

A flaw was found in crun

A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The iss…

▾ TwilightRed Hat · crunEPSS 0.14%via NVD
CVE-2026-84828Medium· 6.5
2w ago

A flaw was found in PCS (Pacemaker Configuration System)

A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the fi…

▾ SunlitRed Hat · pcsEPSS 0.14%via NVD
CVE-2026-87853High· 7.5
2w ago

A flaw was found in SSSD's IdP authentication provider

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of …

▾ TwilightRed Hat · sssdEPSS 0.48%via NVD
CVE-2026-74860High· 8.5
2w ago

A flaw was found in libxml2 with Python bindings enabled

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This…

▾ TwilightRed Hat · libxml2EPSS 0.66%via NVD
CVE-2026-86469Medium· 5.3PoC
2w ago

A flaw was found in GLib2

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation …

▾ TwilightRed Hat · glib2EPSS 0.14%via NVD
CVE-2026-81665High· 7.5
3w ago

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds.…

▾ TwilightRed Hat · corosyncEPSS 0.35%via NVD
CVE-2026-18743Low· 2.5
3w ago

A flaw was found in popt

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `po…

▾ Sunlitrpm-software-management · poptEPSS 0.14%via NVD
CVE-2026-43961High· 7.8
1mo ago

A flaw was found in Vim's netrw plugin

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be levera…

▾ Twilightvim · vimEPSS 0.22%via NVD
CVE-2026-72693High· 7.8
1mo ago

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc…

▾ TwilightRed Hat · kbdEPSS 0.16%via NVD
CVE-2026-6426Medium· 4.4
1mo ago

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int32_t. On little-endian hosts, a crafted…

▾ SunlitRed Hat · qemu-kvmEPSS 0.39%via NVD
CVE-2026-15816High· 7.5
1mo ago

A flaw was found in dracut

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROO…

▾ TwilightRed Hat · dracutEPSS 0.37%via NVD
CVE-2026-16313High· 7.6
2mo ago

A flaw was found in sg3_utils

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-suppl…

▾ TwilightRed Hat · sg3_utilsEPSS 0.35%via NVD
CVE-2026-16730Medium· 5.5
2mo ago

A flaw was found in dbus-broker

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open ma…

▾ SunlitRed Hat · dbus-brokerEPSS 0.11%via NVD
CVE-2026-16517Low· 2.9
2mo ago

A signed integer overflow vulnerability was found in libarchive's ZIP writer

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the a…

▾ SunlitRed Hat · libarchiveEPSS 0.08%via NVD
CVE-2026-15588Medium· 5.3PoC
2mo ago

A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib

A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticat…

▾ TwilightRed Hat · glib2EPSS 0.48%via NVD
openshift/ose-rhel-coreos-9 vulnerabilities (CVEs) · VulnSea