Tagged “red-hat”
CVEs tagged red-hat, newest first.
2912 CVEsRSS
CVE-2026-89716Medium· 5.5kernel: zram: validate deflate params (CVE-2026-89716)
A flaw was found in the zram component of the Linux kernel. This vulnerability occurs because the system does not properly validate user-supplied deflate parameters, specifically `winbits` values. An attacker could exploit this by providin…
CVE-2026-89714Medium· 5.5kernel: NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails (CVE-2026-89714)
A flaw was found in the Linux kernel's Network File System (NFS) component. When an NFSv4 mount attempt fails, the nfs4_server_common_setup() function does not properly free a memory allocation for the delegation hash table. A client that …
CVE-2026-89701Medium· 5.5kernel: nfsd: validate nseconds in TIME_DELEG decode paths (CVE-2026-89701)
A flaw was found in the Linux kernel's Network File System Daemon (nfsd). The TIME_DELEG_ACCESS and TIME_DELEG_MODIFY decode paths do not properly validate the nanosecond (nseconds) value in timestamps. This allows a remote attacker to pro…
CVE-2026-89700Medium· 4.7In the Linux kernel, the following vulnerability has been resolved: nfsd: validate sockaddr length per family in listener_set nfsd_sock_nl_policy declares NFSD_A_SOCK_ADDR as a bare NLA_BINARY attribute with no minimum length
In the Linux kernel, the following vulnerability has been resolved: nfsd: validate sockaddr length per family in listener_set nfsd_sock_nl_policy declares NFSD_A_SOCK_ADDR as a bare NLA_BINARY attribute with no minimum length. A CAP_NE…
CVE-2026-89698Medium· 6.5In the Linux kernel, the following vulnerability has been resolved: nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain "struct sockaddr" (16 bytes)
In the Linux kernel, the following vulnerability has been resolved: nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage struct nfsd_genl_rqstp declares rq_daddr and rq_saddr as plain "struct sockaddr" (16 bytes). When an IPv…
CVE-2026-89693High· 7.0In the Linux kernel, the following vulnerability has been resolved: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() nfsd4_create() stores the return value of nfsd4_acl_to_attr() in status, but the switch(create->cr_type)…
In the Linux kernel, the following vulnerability has been resolved: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() nfsd4_create() stores the return value of nfsd4_acl_to_attr() in status, but the switch(create->cr_type)…
CVE-2026-89683High· 7.0kernel: nfsd: fix dentry ref leak on V4ROOT export filehandle lookup (CVE-2026-89683)
A flaw was found in the Linux kernel's nfsd (NFS daemon). A remote attacker could exploit this vulnerability by sending a specially crafted NFSv3 filehandle targeting a V4ROOT export's file system identifier (fsid). This action triggers a …
CVE-2026-89666High· 7.0kernel: nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops (CVE-2026-89666)
A flaw was found in the kernel. A remote attacker, acting as an NFSv3 client, can send malformed time values during SETATTR or create operations. This can lead to the corruption of on-disk metadata, resulting in incorrect timestamps for fi…
CVE-2026-89645Medium· 5.5kernel: btrfs: drop recovered reloc root refs on recovery failure (CVE-2026-89645)
A flaw was found in the btrfs file system in the Linux kernel. During relocation recovery, if an error occurs, such as a memory allocation failure, the system may not properly drop references to relocation roots. This oversight can lead to…
CVE-2026-89644Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix extent map leak in NOCOW direct I/O write btrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an extent map reference that must be dropped on al…
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix extent map leak in NOCOW direct I/O write btrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an extent map reference that must be dropped on al…
CVE-2026-89629Medium· 5.5kernel: HID: corsair-void: Check size of status and firmware events before reading them (CVE-2026-89629)
A flaw was found in the Linux kernel, specifically within the `corsair-void` driver for Human Interface Devices (HID). This vulnerability allows an attacker to cause an out-of-bounds read by sending malformed status and firmware events. Th…
CVE-2026-89625High· 7.0In the Linux kernel, the following vulnerability has been resolved: HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind For GHL (Guitar Hero Live) dongles, sony_probe() arms a periodic timer: ghl_magic_poke() (the timer cal…
In the Linux kernel, the following vulnerability has been resolved: HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind For GHL (Guitar Hero Live) dongles, sony_probe() arms a periodic timer: ghl_magic_poke() (the timer cal…
CVE-2026-89772High· 7.0kernel: btrfs: write-protect folios during data writeback (CVE-2026-89772)
A flaw was found in the Btrfs filesystem of the Linux kernel. This vulnerability allows a local attacker with write access to a memory-mapped file to modify data while it is being written to disk. This can lead to data corruption, where th…
CVE-2026-89770Medium· 5.5kernel: iomap: don't free integrity payload that doesn't exist (CVE-2026-89770)
A flaw was found in the `iomap` component of the Linux kernel. This vulnerability occurs when Protection Information (PI) verification is disabled on a block device, causing `fs_bio_integrity_alloc` to not allocate a bio integrity payload.…
CVE-2026-89768Medium· 5.5kernel: fs: fix user path of nested backing files (CVE-2026-89768)
A flaw was found in the Linux kernel's filesystem (fs) component. When using nested overlay filesystems (overlayfs), a local user could exploit an issue where the backing_file_open() function incorrectly derives the path for mapped files. …
CVE-2026-89766High· 7.0kernel: pidfd: hold exec_update_lock around namespace ioctl (CVE-2026-89766)
A flaw was found in the Linux kernel. A local attacker could exploit a race condition in the `pidfd` subsystem, specifically within the `PIDFD_GET_*_NAMESPACE` ioctls. This vulnerability occurs because the system does not properly hold a l…
CVE-2026-89759Medium· 5.5kernel: mm/kmemleak: avoid soft lockup when scanning task stacks (CVE-2026-89759)
A flaw was found in the Linux kernel's memory leak detector (kmemleak). When kmemleak_scan() attempts to scan task stacks on systems with a large number of threads, it can hold a CPU for an extended period without allowing other processes …
CVE-2026-89757Medium· 5.5kernel: mm/mglru: fix and remove redundant unevictable folio handling (CVE-2026-89757)
A flaw was found in the Linux kernel's memory management unit (MMU), specifically within the multi-generational Least Recently Used (mglru) mechanism. A bug in how the kernel handles unevictable memory pages can lead to these pages remaini…
CVE-2026-89745High· 7.0kernel: debugfs: Fix lockdown check for mmap_prepare (CVE-2026-89745)
A flaw was found in the Linux kernel's debugfs component. The lockdown mechanism, designed to enhance system integrity, did not properly account for files using the `mmap_prepare` operation. This oversight could allow an attacker to bypass…
CVE-2026-89740Medium· 5.5kernel: serial: imx: serialize imx_uart_ports[] lifetime (CVE-2026-89740)
A flaw was found in the Linux kernel's `serial: imx` component. The `imx_uart_probe()` function publishes a device-managed allocated port in the `imx_uart_ports[]` array before it is fully added. If the port addition fails or the port is r…
CVE-2026-89161High· 7.4In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
CVE-2026-89060High· 7.7A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources o…
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources o…
CVE-2026-45057Medium· 4.9matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk
matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself i…
CVE-2026-45056Medium· 6.9⚖ disputedmatrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients
matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the…
CVE-2026-90461Medium· 6.3OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
CVE-2026-78807High· 7.1An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
CVE-2026-68497High· 7.5PoCjackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLD…
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLD…
CVE-2026-80942Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subseque…
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subseque…
CVE-2026-89454Medium· 4.4In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() plda_init_interrupts() initializes IRQ domains and creates IRQ mapping but does not unwind…
In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() plda_init_interrupts() initializes IRQ domains and creates IRQ mapping but does not unwind…
CVE-2026-89453Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults iommu_call_iopf_notifier() looks up the requester with pci_get_domain_bus_and_slot(), which returns a PCI device wi…
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults iommu_call_iopf_notifier() looks up the requester with pci_get_domain_bus_and_slot(), which returns a PCI device wi…