VulnSea

openshift_container_platform vulnerabilities

CVEs whose affected-version data names the openshift_container_platform package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

478 CVEsRSS

CVE-2026-89533High· 7.0⚖ disputed
1w ago

kernel: svcrdma: Fix offset arithmetic in read_chunk_range (CVE-2026-89533)

A flaw was found in the `svcrdma` component of the Linux kernel. Incorrect offset arithmetic in the `svc_rdma_read_chunk_range()` function can lead to a `u32` underflow. This underflow can cause the system to attempt to allocate a large am…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.51%via CSAF
CVE-2026-89532High· 7.0⚖ disputed
1w ago

kernel: svcrdma: Fix pcl_for_each_segment for empty chunks (CVE-2026-89532)

A flaw was found in the Linux kernel's svcrdma component. A remote attacker could send a specially crafted network packet that causes an integer underflow in the `pcl_for_each_segment` function when processing a chunk with zero segments. T…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.51%via CSAF
CVE-2026-89525Medium· 5.5
1w ago

kernel: udf: reject VAT indexes equal to the entry count (CVE-2026-89525)

A flaw was found in the Linux kernel. A local attacker could craft a malicious Universal Disk Format (UDF) image to trigger an out-of-bounds read vulnerability in the `udf_get_pblock_virt15()` function. This occurs when the system attempts…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89515Medium· 5.5
1w ago

kernel: scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() (CVE-2026-89515)

A flaw was found in the Linux kernel's SCSI core component. When processing data transfers using scatter-gather lists, the system does not properly initialize padding bytes for unaligned data elements. This can result in the exposure of un…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89511Medium· 5.5⚖ disputed
1w ago

kernel: qede: Fix NULL pointer dereference in TPA fragment processing (CVE-2026-89511)

A flaw was found in the qede driver in the Linux kernel. Under specific memory pressure conditions, the driver can encounter a NULL pointer dereference when processing network traffic using TPA (TCP Segmentation Offload) continuation fragm…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.72%via CSAF
CVE-2026-89510High· 7.0
1w ago

kernel: RDMA/cxgb4: Cancel reg_work before freeing device on remove (CVE-2026-89510)

A flaw was found in the Linux kernel's RDMA/cxgb4 component. This vulnerability occurs when the `c4iw_remove()` function frees a device while its registration work (`reg_work`) is still pending or actively running. This timing issue can le…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89508Medium· 5.5⚖ disputed
1w ago

kernel: RDMA/ucma: Lock the handler in ucma_set_ib_path() (CVE-2026-89508)

A flaw was found in the Linux kernel's RDMA/ucma component. A race condition exists in the `ucma_set_ib_path()` function when handling events concurrently with `ucma_migrate_id()`. This can allow a local attacker with access to an RDMA dev…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.13%via CSAF
CVE-2026-89504Medium· 5.5⚖ disputed
1w ago

kernel: regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (CVE-2026-89504)

A flaw was found in the Linux kernel's regulator subsystem. This vulnerability arises from a programming error where a device tree node pointer is released too early, creating a "dangling pointer"—a reference to memory that is no longer va…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.14%via CSAF
CVE-2026-89498Medium· 5.5
1w ago

kernel: orangefs: fix double-free of trailer_buf on readdir copy failure (CVE-2026-89498)

A flaw was found in OrangeFS within the Linux kernel. A local client, by sending a specially crafted readdir downcall with a declared trailer_size exceeding the actual supplied bytes, can trigger a double-free vulnerability. This memory co…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.18%via CSAF
CVE-2026-89495Medium· 5.5⚖ disputed
1w ago

kernel: ocfs2: bound namelen in dlm_migrate_request_handler (CVE-2026-89495)

A flaw was found in ocfs2 in the Linux kernel. A malicious or compromised node within a Distributed Lock Manager (DLM) cluster can send specially crafted messages with unchecked length fields. This can lead to a heap out-of-bounds write, p…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.70%via CSAF
CVE-2026-89489Medium· 5.5⚖ disputed
1w ago

kernel: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall (CVE-2026-89489)

A flaw was found in the Linux kernel. The `sys_or1k_atomic()` syscall, specific to the openrisc architecture, does not adequately validate user-provided pointers. An unprivileged process can exploit this by supplying kernel addresses to th…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.14%via CSAF
CVE-2026-89488High· 7.0
1w ago

kernel: openvswitch: Fix CT limit teardown use-after-free (CVE-2026-89488)

A flaw was found in the Linux kernel's Open vSwitch (OVS) component. An unprivileged user, operating from a user and network namespace, can trigger a use-after-free vulnerability during network namespace teardown. This occurs because packe…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.13%via CSAF
CVE-2026-89487High· 7.0
1w ago

kernel: openvswitch: only skb_tx_error() a packet we are about to drop (CVE-2026-89487)

A flaw was found in openvswitch in the Linux kernel. This vulnerability occurs when the `queue_userspace_packet()` function incorrectly modifies a shared network packet buffer by stripping a critical flag. This action can lead to an unpriv…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.13%via CSAF
CVE-2026-89485High· 7.0⚖ disputed
1w ago

kernel: lockd: pin next file across nlm_inspect_file lock-drop (CVE-2026-89485)

A flaw was found in the `lockd` component of the Linux kernel. This use-after-free vulnerability occurs in the `nlm_traverse_files()` function when a file's memory is prematurely released while an iterator still holds a pointer to it. A re…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.70%via CSAF
CVE-2026-89483Medium· 5.5⚖ disputed
1w ago

kernel: nvme: zero the discard fallback page (CVE-2026-89483)

A flaw was found in the Linux kernel's Non-Volatile Memory Express (NVMe) subsystem. Under specific memory pressure conditions, a local user could trigger a scenario where uninitialized kernel memory is used and potentially exposed. This c…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.56%via CSAF
CVE-2026-89604Medium· 5.5
1w ago

kernel: efivarfs: Rate limit statfs() handler (CVE-2026-89604)

A flaw was found in the Linux kernel's efivarfs component. An unprivileged local user can exploit this by repeatedly calling the `statfs()` handler on the `efivarfs` mount point. This action triggers a flood of calls to the `QueryVariableI…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89603High· 7.0
1w ago

kernel: entry: Fix seccomp bypass after ptrace with TSYNC (CVE-2026-89603)

A flaw was found in the Linux kernel. A race condition exists where a seccomp filter, intended to restrict system calls, can be bypassed by an unprivileged process. This occurs when a thread is stopped for tracing (ptrace) and another thre…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.14%via CSAF
CVE-2026-89598Medium· 5.5
1w ago

kernel: fbdev: ssd1307fb: defer I2C transfers from damage callbacks (CVE-2026-89598)

A flaw was found in the Linux kernel's fbdev (framebuffer device) subsystem, specifically within the ssd1307fb driver. This vulnerability occurs when display damage callbacks, which handle updates to the display, perform synchronous I2C (I…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89595Medium· 5.5
1w ago

kernel: fsnotify: Fix stale object mask after concurrent mark updates (CVE-2026-89595)

A flaw was found in the Linux kernel's fsnotify subsystem, affecting fanotify and inotify. A race condition can occur during concurrent updates to event marks, where the object mask becomes stale. This can lead to a denial of service or in…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89587High· 7.0
1w ago

kernel: ACPI: pfr_update: fix stack buffer overflow in query_capability() (CVE-2026-89587)

A flaw was found in the Linux kernel's ACPI Platform Firmware Runtime Update (pfr_update) component. The `query_capability()` function, responsible for handling ACPI buffer objects from firmware, performs an unchecked memory copy operation…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.14%via CSAF
CVE-2026-89586Medium· 5.5⚖ disputed
1w ago

kernel: ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes (CVE-2026-89586)

A flaw was found in the Linux kernel's `libata-scsi` component. This vulnerability occurs when the system attempts to perform Data Set Management (DSM) TRIM operations on storage devices with logical sector sizes exceeding 2048 bytes. Due …

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.61%via CSAF
CVE-2026-89583High· 7.0
1w ago

kernel: Bluetooth: eir: Fix OOB read in eir_get_service_data() (CVE-2026-89583)

A flaw was found in the Linux kernel's Bluetooth subsystem. An out-of-bounds (OOB) read vulnerability exists in the `eir_get_service_data()` function due to incorrect length calculation when parsing Extended Inquiry Response (EIR) advertis…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.27%via CSAF
CVE-2026-89582High· 7.0
1w ago

kernel: bnx2x: fix double free in bnx2x_init_firmware() error path (CVE-2026-89582)

A flaw was found in the `bnx2x` component of the Linux kernel. This flaw occurs due to a double free vulnerability within the `bnx2x_init_firmware()` function's error handling path. Memory pointers are freed without being set to NULL, allo…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89579High· 7.0
1w ago

kernel: bpf: Harden bloom filter sizing and indexing on 32-bit kernels (CVE-2026-89579)

A flaw was found in the Linux kernel's Berkeley Packet Filter (BPF) component, specifically impacting 32-bit systems. This vulnerability stems from incorrect sizing and indexing of bloom filters, which can lead to out-of-bounds memory acce…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89576Medium· 5.5
1w ago

kernel: dm-era: fix shadowed superblock leak on take-snap failure (CVE-2026-89576)

A flaw was found in the Linux kernel's device-mapper era (dm-era) component. When a snapshot operation fails, a block of metadata is allocated but not properly freed. This leads to a permanent leak of system resources with each failed atte…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89575High· 7.0
1w ago

kernel: dm raid1: reserve space for NUL-terminator in build_constructor_string() (CVE-2026-89575)

A flaw was found in the Linux kernel's device mapper (dm-raid1) component. This vulnerability occurs in the `build_constructor_string()` function, where insufficient space is reserved for a NUL-terminator when formatting a string with `spr…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.23%via CSAF
CVE-2026-89569High· 7.0
1w ago

kernel: Bluetooth: RFCOMM: serialize security confirmation handling (CVE-2026-89569)

A flaw was found in the Linux kernel's Bluetooth RFCOMM subsystem. This vulnerability arises because the system does not properly manage memory when handling Bluetooth security confirmations. A race condition allows a part of the system to…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.34%via CSAF
CVE-2026-89565Medium· 5.5
1w ago

kernel: ipip: fix skb leak in collect_md mode when metadata_dst allocation fails (CVE-2026-89565)

A flaw was found in the Linux kernel's IP over IP (ipip) tunnel driver. When operating in collect_md mode, the ipip_tunnel_rcv() function fails to free a network packet buffer (skb) if the metadata_dst allocation fails. This oversight lead…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89563High· 7.0
1w ago

kernel: ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() (CVE-2026-89563)

A flaw was found in the `ip6_tunnel` module of the Linux kernel. Incorrect handling of socket buffers (skb) during headroom reallocation in the `ip6_tnl_xmit()` function can lead to a double-free vulnerability. This occurs when an error pa…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.14%via CSAF
CVE-2026-89559High· 7.0
1w ago

kernel: libnvdimm/labels: Prevent integer overflow in __nd_label_validate() (CVE-2026-89559)

A flaw was found in the Linux kernel's `libnvdimm/labels` component. An integer overflow vulnerability exists in the `__nd_label_validate()` function, where a 32-bit calculation of a namespace index field (`nslot`) can wrap around. This al…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.16%via CSAF
openshift_container_platform vulnerabilities (CVEs) — page 6 · VulnSea