PatchSiren

Redhat CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Redhat CVE published 2026-06-25

CVE-2026-9799

CVE-2026-9799 is a vulnerability in Redhat Build Of Keycloak that allows an authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource to bypass per-resource access control. This can lead to unauthorized access to all resources of that type within the same resource server, even if the user does not have a ticket for those specific resources. The vulnerability requires t [truncated]

LOW Redhat CVE published 2026-04-30

CVE-2026-3832

CVE-2026-3832 was publicly disclosed on 2026-04-30. The issue is a logic error in GnuTLS OCSP handling that can affect TLS clients using OCSP verification. According to the NVD record and Red Hat references, a specially crafted multi-record OCSP response presented during handshake may cause a client to incorrectly accept a revoked server certificate, weakening trust validation.

HIGH Redhat CVE published 2026-03-30

CVE-2026-5121

CVE-2026-5121 is a high-severity libarchive flaw affecting zisofs block pointer allocation logic on 32-bit systems. A specially crafted ISO9660 image can trigger an integer overflow that may become a heap buffer overflow, so systems that process untrusted images should treat this as a priority patch item. The NVD record was published on 2026-03-30 and last modified on 2026-05-11, with Red Hat advisories a [truncated]

MEDIUM Redhat CVE published 2026-03-30

CVE-2026-5119

CVE-2026-5119 describes a cleartext transmission issue in libsoup during HTTPS tunneling through an HTTP proxy. In the initial HTTP CONNECT request, sensitive session cookies may be exposed before the tunnel is established. A network-positioned attacker or a malicious proxy could intercept those cookies and potentially reuse them for session hijacking or user impersonation.

LOW Redhat CVE published 2026-03-26

CVE-2026-0968

CVE-2026-0968, published on 2026-03-26 and last modified on 2026-05-19, affects libssh during SFTP file listing. A malicious server can send a malformed "longname" field in an SSH_FXP_NAME message, and the missing null check may cause an out-of-bounds read on the heap. The supplied record rates this as low severity with availability impact only, but it can still crash affected applications and cause a den [truncated]

MEDIUM Redhat CVE published 2026-03-26

CVE-2026-0967

CVE-2026-0967 is a denial-of-service issue in libssh affecting client-side hostname pattern handling. According to the published description, a remote attacker who can influence client configuration files or known_hosts entries may craft hostnames that trigger inefficient regular-expression backtracking in match_pattern(), leading to timeouts and resource exhaustion. NVD lists libssh versions through 0.11 [truncated]

HIGH Redhat CVE published 2026-03-26

CVE-2026-0966

CVE-2026-0966 is a network-reachable denial-of-service issue in libssh. According to the CVE record and NVD data, the flaw was published on 2026-03-26 and later modified on 2026-05-11. The issue affects ssh_get_hexa() when it processes zero-length input, and exploitation is tied to GSSAPI authentication with server logging verbosity set to SSH_LOG_PACKET (3) or higher. The practical result is a self-denia [truncated]

LOW Redhat CVE published 2026-03-26

CVE-2026-0965

CVE-2026-0965 is a low-severity local denial-of-service issue in libssh. During configuration parsing, affected versions may attempt to open arbitrary files. In misconfigured deployments or when a malicious configuration file is provided, this can cause the system to access sensitive targets such as block devices or large system files and disrupt normal operation.

MEDIUM Redhat CVE published 2026-03-26

CVE-2026-0964

CVE-2026-0964 describes a path-handling flaw in SCP transfers where a malicious server can send unexpected paths and cause the client to overwrite files outside the intended working directory. The issue can be abused to place malicious executables or configuration files and influence what the user runs. NVD maps the issue to CWE-22 and scores it CVSS 6.3 (Medium). The description says this is the same iss [truncated]

HIGH Redhat CVE published 2026-03-24

CVE-2026-4775

CVE-2026-4775 is a libtiff flaw involving a signed integer overflow in putcontig8bitYCbCr44tile. When triggered by a specially crafted TIFF file, the bad calculation can produce an out-of-bounds heap write, which may crash the application or create a path to code execution. The supplied NVD data also ties the issue to Red Hat and Debian advisory references and lists multiple affected platform CPEs.

HIGH Redhat CVE published 2026-03-19

CVE-2026-4424

CVE-2026-4424 is a high-severity information-disclosure issue in libarchive's RAR handling. A specially crafted RAR archive can trigger a heap out-of-bounds read and expose sensitive heap memory, with no authentication or user interaction required.

MEDIUM Redhat CVE published 2026-03-17

CVE-2026-4271

CVE-2026-4271 was published on 2026-03-17 and later modified on 2026-05-11. According to the official CVE and NVD records, the issue is a use-after-free in libsoup's HTTP/2 server implementation. A remote attacker can send specially crafted HTTP/2 requests that cause authentication failures, leading the application to access freed memory and potentially crash. The documented impact is denial of service, w [truncated]

MEDIUM Redhat CVE published 2025-12-11

CVE-2025-14512

CVE-2025-14512 is a medium-severity vulnerability in GLib’s GIO handling that can be triggered when escape_byte_string() processes malicious file or remote filesystem attribute values. The flaw is an integer overflow that can lead to a heap buffer overflow and denial of service. NVD rates the issue as network-reachable with low attack complexity and user interaction required, and the supplied Red Hat refe [truncated]

MEDIUM Redhat CVE published 2025-12-10

CVE-2025-14087

CVE-2025-14087 describes a flaw in GLib’s GVariant parser that can be triggered by maliciously crafted input strings. The result can be heap corruption, which may lead to denial of service and, in some cases, potential code execution. NVD records this as a medium-severity issue, and Red Hat-linked references show affected GLib versions before 2.86.3 as well as multiple Red Hat Enterprise Linux streams.

HIGH Redhat CVE published 2025-11-26

CVE-2025-13601

CVE-2025-13601 is a high-severity heap-based buffer overflow in GLib's g_escape_uri_string() function. The flaw comes from an incorrect buffer-size calculation: when the input contains a very large number of characters that must be escaped, the computed escaped length can overflow and the newly allocated buffer may be written past its end. The risk is most relevant to systems and applications that use the [truncated]

MEDIUM Redhat CVE published 2025-06-10

CVE-2023-4806

CVE-2023-4806 is a narrowly triggered glibc use-after-free in getaddrinfo that can lead to an application crash. The issue is publicly dated 2023-09-18 and, per the NVD record, was later modified on 2026-05-12. The exposure is unusual: it requires an NSS module that implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks, omits _nss_*_gethostbyname3_r, and is hit through a getaddrinfo [truncated]

MEDIUM Redhat CVE published 2025-06-10

CVE-2023-4527

CVE-2023-4527 is a glibc flaw that can leak limited stack contents and trigger a crash when getaddrinfo is used with AF_UNSPEC on systems configured for no-aaaa mode. The issue is network-triggered, has no user interaction requirement, and is tracked by NVD with a medium CVSS score of 6.5.

MEDIUM Redhat CVE published 2025-04-07

CVE-2023-48795

CVE-2023-48795, known as the Terrapin attack, is an SSH transport protocol weakness that can let a remote attacker omit some packets during extension negotiation and weaken session security. The issue affects OpenSSH before 9.6 and a wide range of SSH clients, libraries, and appliances listed in the CVE record.

HIGH Redhat CVE published 2024-02-05

CVE-2023-50781

CVE-2023-50781 is a high-severity m2crypto issue that may allow a remote attacker to decrypt captured TLS messages on servers that use RSA key exchanges, creating a confidentiality risk for sensitive data. NVD rates the issue 7.5 (High) with network attackability, no privileges required, and no user interaction, and classifies it as CWE-203.

HIGH Redhat CVE published 2024-01-25

CVE-2023-52356

CVE-2023-52356 is a high-severity availability issue in libtiff. According to the supplied NVD record, a crafted TIFF file can trigger a segmentation fault and heap-buffer overflow in TIFFReadRGBATileExt(), allowing a remote attacker to cause denial of service. The record does not indicate impact to confidentiality or integrity, but it does map to a network-reachable, no-authentication attack surface with [truncated]

LOW Redhat CVE published 2017-03-03

CVE-2015-2877

CVE-2015-2877 describes an information-disclosure side channel in Linux Kernel Samepage Merging (KSM). The NVD record ties it to Linux kernel versions 2.6.32 through 4.x and some Red Hat Enterprise Linux releases, with low CVSS impact and a local attack vector. The supplied description also notes the vendor position that if this attack vector matters, deduplication should be disabled, which frames the iss [truncated]

MEDIUM Redhat CVE published 2017-02-16

CVE-2017-6011

CVE-2017-6011 is a medium-severity memory-safety issue in icoutils 0.31.1 that affects icotool. NVD describes it as an out-of-bounds read in simple_vec() within extract.c, with the potential to lead to a buffer overflow and a denial-of-service-style availability impact.

MEDIUM Redhat CVE published 2017-02-16

CVE-2017-6010

CVE-2017-6010 is a denial-of-service flaw in icoutils 0.31.1. The vulnerable code is the extract_icons function in extract.c, where a corrupted ICO file can trigger a buffer overflow and crash icotool. NVD classifies the issue as CWE-119 with a CVSS 3.0 score of 5.5 (local access, low complexity, no privileges, user interaction required, availability impact only). The CVE was published on 2017-02-16 and l [truncated]

MEDIUM Redhat CVE published 2017-02-16

CVE-2017-6009

CVE-2017-6009 is a buffer overflow in icoutils 0.31.1, specifically in the decode_ne_resource_id function used by wrestool. The flaw is triggered by an unchecked memcpy length that can become negative, creating a denial-of-service risk and possible memory corruption. Because the CVSS vector requires local access and user interaction, this is most relevant on systems where untrusted inputs are processed with wrestool.

HIGH Redhat CVE published 2017-02-15

CVE-2016-9560

CVE-2016-9560 describes a stack-based buffer overflow in JasPer's jpc_tsfb_getbands2 function. The NVD record ties the issue to JasPer versions before 1.900.30 and downstream distro packages, and rates it HIGH with high confidentiality, integrity, and availability impact. Because the record combines a remote-attacker description with a CVSS vector of AV:L/UI:R, defenders should focus on actual image-proce [truncated]

HIGH Redhat CVE published 2017-02-13

CVE-2016-2568

CVE-2016-2568 is a high-severity local privilege escalation issue affecting pkexec when used with --user nonpriv. A local attacker can use a crafted TIOCSTI ioctl call to push characters into the terminal input buffer and escape to the parent session on vulnerable systems.

HIGH Redhat CVE published 2017-02-12

CVE-2017-3302

CVE-2017-3302 is a high-severity availability issue in libmysqlclient.so. NVD rates it 7.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and classifies the weakness as CWE-416. The vulnerable scope includes Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5, plus MariaDB through 5.5.54, 10.0.29, 10.1.21, and 10.2.3. NVD also links downstream Debian and Red Hat advisories, indicating packaged consumers may [truncated]

HIGH Redhat CVE published 2017-02-09

CVE-2017-5848

CVE-2017-5848 is a remotely reachable denial-of-service issue in GStreamer’s gst-plugins-bad MPEG demuxer path. The published description says gst_ps_demux_parse_psm() can perform an invalid memory read and crash while parsing PSM data. NVD assigns a High CVSS 3.1 score and classifies the weakness as CWE-125, so the practical impact is service interruption rather than known code execution or data theft.

CRITICAL Redhat CVE published 2017-01-28

CVE-2017-5205

CVE-2017-5205 is a critical buffer overflow in tcpdump’s ISAKMP parser, specifically in print-isakmp.c:ikev2_e_print(). NVD lists tcpdump versions before 4.9.0 as vulnerable and assigns a CVSS 3.0 score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). In practical terms, malformed network traffic can trigger memory corruption while tcpdump parses packet data, so systems that inspect untrusted captures should [truncated]

CRITICAL Redhat CVE published 2017-01-28

CVE-2017-5204

CVE-2017-5204 is a critical buffer overflow in tcpdump’s IPv6 parsing path, specifically print-ip6.c:ip6_print(), affecting tcpdump versions before 4.9.0. The NVD record rates the issue 9.8 (CVSS v3.0) with network attack vector, no privileges required, and no user interaction. In practical terms, any environment that uses tcpdump to analyze untrusted packet data should treat this as an urgent patch item [truncated]