Home/Product/redhat virtualization host
Product

redhat virtualization host

84 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-3758
all versions
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to
7.1HIGH
CVE-2023-6536
all versions
A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of craft
6.5MEDIUM
CVE-2023-6535
all versions
A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of craft
6.5MEDIUM
CVE-2023-6356
all versions
A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of craft
6.5MEDIUM
CVE-2023-4911
all versions
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment varia
7.8HIGH
CVE-2022-0207
all versions
A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored
4.7MEDIUM
CVE-2021-3669
all versions
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts
5.5MEDIUM
CVE-2021-20316
all versions
A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to
6.8MEDIUM
CVE-2021-3659
all versions
A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user
5.5MEDIUM
CVE-2022-0435
all versions
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious
8.8HIGH
CVE-2022-0330
all versions
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicio
7.8HIGH
CVE-2022-1011
all versions
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a loc
7.8HIGH
CVE-2022-0847
all versions
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_
7.8HIGH
CVE-2022-0516
all versions
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel.
7.8HIGH
CVE-2021-3656
all versions
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual
8.8HIGH
CVE-2021-3744
all versions
A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allo
5.5MEDIUM
CVE-2022-0492
all versions
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw,
7.8HIGH
CVE-2021-3620
all versions
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials i
5.5MEDIUM
CVE-2021-3609
all versions
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsy
7.0HIGH
CVE-2021-44142
all versions
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients
8.8HIGH
CVE-2020-25717
all versions
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possibl
8.1HIGH
CVE-2016-2124
all versions
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext passw
5.9MEDIUM
CVE-2021-3752
all versions
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and discon
7.1HIGH
CVE-2021-3560
all versions
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the
7.8HIGH
CVE-2021-45417
all versions
AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpf
7.8HIGH
CVE-2021-3621
all versions
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire s
8.8HIGH
CVE-2021-3501
all versions
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array i
7.1HIGH
CVE-2020-10711
all versions
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while i
5.9MEDIUM
CVE-2019-14821
all versions
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor im
8.8HIGH
CVE-2019-14835
all versions
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates
7.8HIGH
CVE-2019-1125
all versions
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacke
5.6MEDIUM
CVE-2019-10161
all versions
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXM
7.8HIGH
CVE-2019-11479
all versions
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP
7.5HIGH
CVE-2019-3888
all versions
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log file
9.8CRITICAL
CVE-2019-3460
all versions
A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.
6.5MEDIUM
CVE-2019-1559
all versions
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to
5.9MEDIUM
CVE-2018-16881
all versions
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to
7.5HIGH
CVE-2018-18397
all versions
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as dem
5.5MEDIUM
CVE-2018-14660
all versions
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A re
6.5MEDIUM
CVE-2018-14661
all versions
It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluste
6.5MEDIUM
CVE-2018-14659
all versions
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOST
6.5MEDIUM
CVE-2018-14654
all versions
The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with ac
6.5MEDIUM
CVE-2018-18559
all versions
In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind o
8.1HIGH
CVE-2018-1000805
all versions
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server
8.8HIGH
CVE-2018-1114
all versions
It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cau
6.5MEDIUM
CVE-2018-10930
all versions
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write
6.5MEDIUM
CVE-2018-10929
all versions
A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create
8.8HIGH
CVE-2018-10928
all versions
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file path
8.8HIGH
CVE-2018-10927
all versions
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak i
8.1HIGH
CVE-2018-10926
all versions
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw
8.8HIGH
CVE-2018-10923
all versions
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authe
8.1HIGH
CVE-2018-10914
all versions
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will re
6.5MEDIUM
CVE-2018-10913
all versions
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs
6.5MEDIUM
CVE-2018-10911
all versions
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could us
7.5HIGH
CVE-2018-10907
all versions
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c al
8.8HIGH
CVE-2018-10904
all versions
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which i
8.8HIGH
CVE-2018-10858
all versions
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba
4.3MEDIUM
CVE-2018-10873
all versions
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked suff
8.3HIGH
CVE-2018-10875
all versions
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plu
7.8HIGH
CVE-2018-10874
all versions
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are u
7.8HIGH
CVE-2018-1120
all versions
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containin
2.8LOW
CVE-2018-1073
all versions
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passw
5.3MEDIUM
CVE-2018-5848
all versions
In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large
7.8HIGH
CVE-2018-5803
all versions
In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" fun
5.5MEDIUM
CVE-2018-1067
all versions
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server
6.1MEDIUM
CVE-2018-11237
all versions
An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write d
7.8HIGH
CVE-2018-11236
all versions
stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to
9.8CRITICAL
CVE-2018-1118
all versions
Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host op
2.3LOW
CVE-2018-10675
all versions
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service
7.8HIGH
CVE-2018-10237
all versions
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service a
5.9MEDIUM
CVE-2018-10322
all versions
The xfs_dinode_verify function in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.16.3 allows local users to cause a d
5.5MEDIUM
CVE-2018-1088
all versions
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could
8.1HIGH
CVE-2018-8088
all versions
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended acce
9.8CRITICAL
CVE-2018-1068
all versions
A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user
6.7MEDIUM
CVE-2018-7740
all versions
The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (
5.5MEDIUM
CVE-2018-6927
all versions
The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service
7.8HIGH
CVE-2017-7525
all versions
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an un
9.8CRITICAL
CVE-2018-6485
all versions
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.
9.8CRITICAL
CVE-2018-1000001
all versions
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destinat
7.8HIGH
CVE-2018-5750
all versions
The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive
5.5MEDIUM
CVE-2018-5968
all versions
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incom
8.1HIGH
CVE-2017-7536
all versions
In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permis
7.0HIGH
CVE-2017-1000407
all versions
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be tr
7.4HIGH
CVE-2017-1000410
all versions
The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - Conf
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin