Vulnerabilidades en Red Hat

1513 resultados
Análisis Vexday

Com 1.477 CVEs catalogadas e 232 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao Red Hat exige monitoramento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 1 CVE confirmada no CISA KEV — a CVE-2023-4911, que apresenta EPSS de 0,7861, indicando probabilidade elevada de exploração e merecendo atenção prioritária de equipes de resposta. Das 34 vulnerabilidades de severidade crítica, 18 contam com prova de conceito pública disponível, o que reduz a barreira técnica para exploração e aumenta o risco operacional. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites), padrão que frequentemente viabiliza vazamento de dados ou corrupção de memória e deve orientar revisões de hardening e priorização de patches.

CVE-2026-50262MEDIUMXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributesEPSS 0.1%CVE-2026-11837HIGHAnsible-collection-ansible-posix: ansible.posix authorized_key: local privilege escalation via symlink-following chownEPSS 0.1%CVE-2025-54770MEDIUMGrub2: use-after-free in net_set_vlanEPSS 0.1%CVE-2025-54771MEDIUMGrub2: use-after-free in grub_file_close()EPSS 0.1%CVE-2026-6845MEDIUMBinutils: binutils: denial of service via crafted elf fileEPSS 0.1%CVE-2026-3195HIGHQemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)EPSS 0.1%CVE-2026-12892MEDIUMGstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parserEPSS 0.1%CVE-2026-13201HIGHKubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruptionEPSS 0.1%CVE-2026-57965MEDIUMSpice-vdagent: integer overflow in udscs_write() leading to heap buffer overflowEPSS 0.1%CVE-2025-6017MEDIUMRhacm: users with clusterreader role can see credentials from managed-clustersEPSS 0.1%CVE-2026-48914MEDIUMQemu-kvm: heap buffer overflow in virtio-blk scsi request handlingEPSS 0.1%CVE-2026-52902MEDIUMAwxkit: path traversal via yaml !include directiveEPSS 0.1%CVE-2026-6420MEDIUMKeylime: keylime: security bypass due to hardcoded tpm quote nonceEPSS 0.1%CVE-2025-61664MEDIUMGrub2: missing unregister call for normal_exit command may lead to use-after-freeEPSS 0.1%CVE-2026-13757MEDIUMP11-kit: stack exhaustion via unbounded recursion in rpc attribute parsingEPSS 0.1%CVE-2026-9793MEDIUMKeycloak: keycloak: security policy bypass in jwe-encrypted request object processingEPSS 0.1%CVE-2026-12505HIGHCifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcallEPSS 0.1%CVE-2026-4948MEDIUMFirewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorizationEPSS 0.1%CVE-2026-10805MEDIUMNetworkmanager: networkmanager: local privilege escalation via malformed mud urls in dhclient backendEPSS 0.1%CVE-2025-14946MEDIUMLibnbd: libnbd: arbitrary code execution via ssh argument injection through a malicious uriEPSS 0.1%