VulnSea

rhcos vulnerabilities

CVEs whose affected-version data names the rhcos package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

15 CVEsRSS

CVE-2025-11395Medium· 5.5
6d ago

A flaw was found in Podman

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.

SunlitRed Hat · buildahEPSS 0.19%via NVD
CVE-2026-81665High· 7.5
2w ago

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds.…

TwilightRed Hat · corosyncEPSS 0.36%via NVD
CVE-2026-81666Medium· 6.5
2w ago

An integer overflow was found in Corosync's handling of membership commit token messages

An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected mess…

SunlitRed Hat · corosyncEPSS 0.27%via NVD
CVE-2026-72693High· 7.8
1mo ago

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc…

TwilightRed Hat · kbdEPSS 0.11%via NVD
CVE-2026-15816High· 7.5
1mo ago

A flaw was found in dracut

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROO…

TwilightRed Hat · dracutEPSS 0.30%via NVD
CVE-2026-16313High· 7.6
1mo ago

A flaw was found in sg3_utils

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-suppl…

TwilightRed Hat · sg3_utilsEPSS 0.29%via NVD
CVE-2026-14164High· 7.5PoC
2mo ago

A double free issue has been identified in libarchive's RAR5 reader

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent proc…

MidnightRed Hat · libarchiveEPSS 0.49%via NVD
CVE-2026-6893High· 7.5
3mo ago

A flaw was found in dracut

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracu…

TwilightRed Hat · dracutEPSS 1.3%via NVD
CVE-2026-33846High· 7.5
4mo ago

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type,…

TwilightRed Hat · gnutlsEPSS 1.3%via NVD
CVE-2025-11234High· 7.5
11mo ago

A flaw was found in QEMU

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel.…

TwilightRed Hat · qemuEPSS 0.86%via NVD
CVE-2025-9566High· 8.1
1y ago

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In…

TwilightRed Hat · podmanEPSS 1.1%via NVD
CVE-2025-7425High· 7.8PoC
1y ago

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the pro…

MidnightGNOME · libxml2EPSS 0.36%via NVD
CVE-2025-49796Critical· 9.1
1y ago

A vulnerability was found in libxml2

A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, res…

MidnightRed Hat · libxml2EPSS 1.6%via NVD
CVE-2025-49794Critical· 9.1
1y ago

A use-after-free vulnerability was found in libxml2

A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to …

MidnightRed Hat · libxml2EPSS 0.83%via NVD
CVE-2024-8176High· 7.5PoC
1y ago

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse ind…

MidnightRed Hat · libexpatEPSS 1.3%via NVD
rhcos vulnerabilities (CVEs) · VulnSea