openshift/ose-rhel-coreos-9 vulnerabilities
CVEs whose affected-version data names the openshift/ose-rhel-coreos-9 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
35 CVEsRSS
CVE-2026-93834High· 8.8PoCA use-after-free vulnerability was found in QEMU's 9pfs subsystem
A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path cont…
CVE-2026-94640High· 7.5A flaw was found in rpcbind
A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedur…
CVE-2026-90462Medium· 5.4PoCA flaw was found in SSSD
A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. Thi…
CVE-2026-95619High· 7.7A flaw was found in libstdc++
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corrup…
CVE-2026-95508High· 7.4A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply bu…
CVE-2026-92574High· 8.8A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context
A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities…
CVE-2026-81627High· 8.2PoCA flaw was found in QEMU
A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked S…
CVE-2026-76781Medium· 5.5A flaw was found in libxml2
A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` …
CVE-2026-79705Medium· 4.5A flaw was found in the buildah/copier Go package
A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended de…
CVE-2026-90996Medium· 4.0A flaw was found in sssd
A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS respon…
CVE-2026-90995Medium· 5.5A flaw was found in SSSD (System Security Services Daemon)
A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_service…
CVE-2026-90994Medium· 4.0A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data()
A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating p…
CVE-2026-90463Medium· 4.0A flaw was found in the sssd NSS responder
A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of…
CVE-2026-89329Medium· 6.2A flaw was found in `multipathd`
A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` list…
CVE-2026-88264Medium· 5.6A flaw was found in crun
A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected …
CVE-2026-84042High· 7.8A flaw was found in crun
A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The iss…
CVE-2026-84828Medium· 6.5A flaw was found in PCS (Pacemaker Configuration System)
A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the fi…
CVE-2026-87853High· 7.5A flaw was found in SSSD's IdP authentication provider
A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of …
CVE-2026-74860High· 8.5A flaw was found in libxml2 with Python bindings enabled
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This…
CVE-2026-86469Medium· 5.3PoCA flaw was found in GLib2
A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation …
CVE-2026-81665High· 7.5A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly
A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds.…
CVE-2026-18743Low· 2.5A flaw was found in popt
A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory corruption issue. This occurs because of an error in how the `po…
CVE-2026-43961High· 7.8A flaw was found in Vim's netrw plugin
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be levera…
CVE-2026-72693High· 7.8`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc…
CVE-2026-6426Medium· 4.4A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling
A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int32_t. On little-endian hosts, a crafted…
CVE-2026-15816High· 7.5A flaw was found in dracut
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROO…
CVE-2026-16313High· 7.6A flaw was found in sg3_utils
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-suppl…
CVE-2026-16730Medium· 5.5A flaw was found in dbus-broker
A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open ma…
CVE-2026-16517Low· 2.9A signed integer overflow vulnerability was found in libarchive's ZIP writer
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the a…
CVE-2026-15588Medium· 5.3PoCA denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticat…