{"resultsPerPage":6,"startIndex":0,"totalResults":6,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-20T18:56:52.117","vulnerabilities":[{"cve":{"id":"CVE-2024-45497","sourceIdentifier":"secalert@redhat.com","published":"2024-12-31T03:15:05.543","lastModified":"2026-07-19T09:16:58.797","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from private repositories. The mount is not read-only, which allows the attacker to overwrite it. By modifying the config.json file, the attacker can cause a denial of service by preventing the node from pulling new images and potentially exfiltrating sensitive secrets. This flaw impacts the availability of services dependent on image pulls and exposes sensitive information to unauthorized parties."},{"lang":"es","value":"Se encontró una falla en el proceso de compilación de OpenShift, donde el contenedor docker-build está configurado con un montaje de volumen hostPath que asigna el archivo /var/lib/kubelet/config.json del nodo al pod de compilación. Este archivo contiene credenciales confidenciales necesarias para extraer imágenes de repositorios privados. El montaje no es de solo lectura, lo que permite al atacante sobrescribirlo. Al modificar el archivo config.json, el atacante puede provocar una denegación de servicio al evitar que el nodo extraiga nuevas imágenes y potencialmente exfiltre secretos confidenciales. Esta falla afecta la disponibilidad de los servicios que dependen de la extracción de imágenes y expone información confidencial a terceros no autorizados."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"defaultStatus":"unknown","collectionURL":"https://github.com/openshift","packageName":"openshift","versions":[{"version":"4.16","versionType":"semver","status":"affected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.12","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-openshift-apiserver-operator","cpes":["cpe:/a:redhat:openshift:4.12::el8","cpe:/a:redhat:openshift:4.12::el9"],"versions":[{"version":"v4.12.0-202506062300.p0.gb870fc6.assembly.stream.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.13","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-openshift-apiserver-operator","cpes":["cpe:/a:redhat:openshift:4.13::el8","cpe:/a:redhat:openshift:4.13::el9"],"versions":[{"version":"v4.13.0-202507061330.p0.g9abb220.assembly.stream.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.14","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-openshift-apiserver-operator","cpes":["cpe:/a:redhat:openshift:4.14::el8","cpe:/a:redhat:openshift:4.14::el9"],"versions":[{"version":"v4.14.0-202506112307.p0.g700dc11.assembly.stream.el8","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.16","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-openshift-apiserver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.16::el9"],"versions":[{"version":"v4.16.0-202506062300.p0.gd26f300.assembly.stream.el9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.17","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-openshift-apiserver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.17::el9"],"versions":[{"version":"v4.17.0-202507011904.p0.g2b2ba3b.assembly.stream.el9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.18","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-cluster-openshift-apiserver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4.18::el9"],"versions":[{"version":"v4.18.0-202506062012.p0.g0a6f6eb.assembly.stream.el9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.2","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-openshift-controller-manager-rhel9","cpes":["cpe:/a:redhat:openshift:4.20::el9"],"versions":[{"version":"ose-openshift-controller-manager-container-v4.20.0-202509261327.p2.gd9e543d.assembly.stream.el9","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Fuse 7","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"org.arquillian.cube/arquillian-cube-openshift-api","cpes":["cpe:/a:redhat:jboss_fuse:7"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-openshift-apiserver-rhel8","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-12-31T15:53:54.435304Z","id":"CVE-2024-45497","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-732"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2025:10270","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:10294","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:10747","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:9269","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:9562","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:9759","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:9765","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-45497","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2308673","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-53689","sourceIdentifier":"cve@mitre.org","published":"2026-06-10T15:16:42.350","lastModified":"2026-07-19T09:17:02.473","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"sahlberg","product":"libnfs","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"55c18ea33a83d667f79f0ef209c96895795c729f","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-10T16:01:41.775187Z","id":"CVE-2026-53689","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@mitre.org","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"references":[{"url":"https://github.com/sahlberg/libnfs/commit/55c18ea33a83d667f79f0ef209c96895795c729f","source":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2026/07/msg00031.html","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-53367","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T09:17:01.773","lastModified":"2026-07-19T09:17:01.773","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: fix avdcache auditing\n\nThe per-task avdcache was incorrectly saving and reusing the\naudited vector computed by avc_audit_required() rather than\nrecomputing based on the currently requested permissions and\ndistinguishing the denied versus allowed cases. As a result,\nsome permission checks were not being audited, e.g.\ndirectory write checks after a previously cached directory\nsearch check.\n\n[PM: line wrap tweaks]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/selinux/hooks.c","security/selinux/include/objsec.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"dde3a5d0f4dce1d1a6095e6b8eeb59b75d28fb3b","lessThan":"e3e722ea88e051ae5361dc540c01ba18f87b5ffd","versionType":"git","status":"affected"},{"version":"dde3a5d0f4dce1d1a6095e6b8eeb59b75d28fb3b","lessThan":"bce6a32bc888dfebb6a7d4dee454228b71ed8369","versionType":"git","status":"affected"},{"version":"dde3a5d0f4dce1d1a6095e6b8eeb59b75d28fb3b","lessThan":"f92d542577db878acfd21cc18dab23d03023b217","versionType":"git","status":"affected"},{"version":"21879b76831fab52f6a615c531f86412c8d3c827","versionType":"git","status":"affected"},{"version":"6.17.10","lessThan":"6.18","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/selinux/hooks.c","security/selinux/include/objsec.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.30","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.7","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/bce6a32bc888dfebb6a7d4dee454228b71ed8369","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3e722ea88e051ae5361dc540c01ba18f87b5ffd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f92d542577db878acfd21cc18dab23d03023b217","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-53370","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T09:17:02.153","lastModified":"2026-07-19T09:17:02.153","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel: Improve validation and configuration of ACR masks\n\nCurrently there are several issues on the user space ACR mask validation\nand configuration.\n- The validation for user space ACR mask (attr.config2) is incomplete,\n  e.g., the ACR mask could include the index which belongs to another\n  ACR events group, but it's not validated.\n- An early return on an invalid ACR mask caused all subsequent ACR groups\n  to be skipped.\n- The stale hardware ACR mask (hw.config1) is not cleared before setting\n  new hardware ACR mask.\n\nThe following changes address all of the above issues.\n- Figure out the event index group of an ACR group. Any bits in the\n  user-space mask not present in the index group are now dropped.\n- Instead of an early return on invalid bits, drop only the invalid\n  portions and continue iterating through all ACR events to ensure full\n  configuration.\n- Explicitly clear the stale hardware ACR mask for each event prior to\n  writing the new configuration.\n\nBesides, a non-leader event member of ACR group could be disabled in\ntheory. This could cause bit-shifting errors in the acr_mask of remaining\ngroup members. But since ACR sampling requires all events to be active,\nthis should not be a big concern in real use case. Add a \"FIXME\" comment\nto notice this risk."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/events/intel/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ec980e4facef8110f6fce27e5b6344660117f01f","lessThan":"aab56b95bee3ff79176b13443cd9d7cfe9747df0","versionType":"git","status":"affected"},{"version":"ec980e4facef8110f6fce27e5b6344660117f01f","lessThan":"c05e01cef47d9b4969eae2dcf9467e2a555bcb4f","versionType":"git","status":"affected"},{"version":"ec980e4facef8110f6fce27e5b6344660117f01f","lessThan":"5ad732a56be46aabf158c16aa0c095291727aaef","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/events/intel/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.30","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.7","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5ad732a56be46aabf158c16aa0c095291727aaef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aab56b95bee3ff79176b13443cd9d7cfe9747df0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c05e01cef47d9b4969eae2dcf9467e2a555bcb4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-53371","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T09:17:02.260","lastModified":"2026-07-19T09:17:02.260","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/ionic: bound node_desc sysfs read with %.64s\n\nnode_desc[64] in struct ib_device is not guaranteed to be NUL-\nterminated. The core IB sysfs handler uses \"%.64s\" for exactly this\nreason (drivers/infiniband/core/sysfs.c:1307), since node_desc_store()\nperforms a raw memcpy of up to IB_DEVICE_NODE_DESC_MAX bytes with no NUL\ntermination:\n\n  memcpy(desc.node_desc, buf, min_t(int, count, IB_DEVICE_NODE_DESC_MAX));\n\nIf exactly 64 bytes are written via the node_desc sysfs file, the array\ncontains no NUL byte. The ionic hca_type_show() handler uses unbounded\n\"%s\" and will read past the end of node_desc into adjacent fields of\nstruct ib_device until it encounters a NUL.\n\nionic supports IB_DEVICE_MODIFY_NODE_DESC, so this is triggerable by\nuserspace.\n\nMatch the core handler and bound the format specifier."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/ionic/ionic_ibdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2075bbe8ef03914aa2211035eec45d1d3a5c4ff2","lessThan":"61df14f306f153bffa2f3c74a94ff5a85c99fa39","versionType":"git","status":"affected"},{"version":"2075bbe8ef03914aa2211035eec45d1d3a5c4ff2","lessThan":"a3e9372203afde2c62576356bb9a17890bc7fd6c","versionType":"git","status":"affected"},{"version":"2075bbe8ef03914aa2211035eec45d1d3a5c4ff2","lessThan":"654a27f25530d052eeedf086e6c3e2d585c203bd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/ionic/ionic_ibdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.30","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.7","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/61df14f306f153bffa2f3c74a94ff5a85c99fa39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/654a27f25530d052eeedf086e6c3e2d585c203bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3e9372203afde2c62576356bb9a17890bc7fd6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-53372","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-19T09:17:02.367","lastModified":"2026-07-19T09:17:02.367","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Block PASID attachment to nested domain with dirty tracking\n\nKernel lacks dirty tracking support on nested domain attached to PASID,\nfails the attachment early if nesting parent domain is dirty tracking\nconfigured, otherwise dirty pages would be lost."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/intel/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"67f6f56b59126b3bf4fc6f4ea564e450fcfcf9f6","lessThan":"3ea9ce757bd3de955b56e7bc5672fc479e40b045","versionType":"git","status":"affected"},{"version":"67f6f56b59126b3bf4fc6f4ea564e450fcfcf9f6","lessThan":"9009c1af5458322469fa9a4371081a4449c5947d","versionType":"git","status":"affected"},{"version":"67f6f56b59126b3bf4fc6f4ea564e450fcfcf9f6","lessThan":"cc5bd898ff70710ffc41cd8e5c2741cb64750047","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/intel/nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.30","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.0.7","lessThanOrEqual":"7.0.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3ea9ce757bd3de955b56e7bc5672fc479e40b045","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9009c1af5458322469fa9a4371081a4449c5947d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cc5bd898ff70710ffc41cd8e5c2741cb64750047","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}}]}