Red Hat Update Infrastructure
11 known vulnerabilities in Red Hat Update Infrastructure, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-90959 CVSS 8.1 high A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file…
- CVE-2026-84232 CVSS 5.4 medium A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original…
- CVE-2026-82327 CVSS 5.5 medium A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv…
- CVE-2026-78002 CVSS 7.5 high A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()`…
- CVE-2026-18477 CVSS 4.4 medium A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write…
- CVE-2026-18508 CVSS 4.4 medium A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the…
- CVE-2026-13757 CVSS 6.2 medium A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and…
- CVE-2026-54371 CVSS 8.4 high attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to…
- CVE-2026-54369 CVSS 8.4 high acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file()…
- CVE-2026-5704 CVSS 5.5 medium A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file…
- CVE-2025-5278 CVSS 4.4 medium A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may…