VEX report

Run environment

Distribution name
batz-2.0-update
Time of run
2025-12-16T06:07:18.830761

Kernel vulnerabilities summary

The kernel used in that image build is version 5.14.0. It is affected by 21 vulnerabilities with no known fix, and 5116 vulnerabilities which are fixed in later releases*. There tend to be a long list of kernel vulnerabilities, so only a summary is given here. For more details take a look at the accompanying vex_report.kernel.json file.

The following table gives an idea of how many vulnerabilities with a known fix would be fixed by upgrading to a given kernel version. The upgrade versions are the current kernel LTS versions and the highest known patch of the kernel branch used for this build.

Some vulnerabilities received a fix outside of these branches, which is why the total doesn't exactly add up.

Version to upgrade to CVEs fixed out of 5116*
5.14.21135 (2.6%)
5.15.196 (LTS)4091 (80.0%)
6.1.158 (LTS)339 (6.6%)
6.6.118 (LTS)203 (4.0%)
6.12.60 (LTS)98 (1.9%)

Affected by vulnerabilities with known fixes

Package VersionFixed in versionFixed CVEs (severity)
glibc-gconv-extra0:2.34-60.baseos.rpbatz.17.x86_640:2.34-100.el9
glibc0:2.34-60.baseos.rpbatz.17.x86_640:2.34-100.el9
glibc-common0:2.34-60.baseos.rpbatz.17.x86_640:2.34-100.el9
glibc-langpack-en0:2.34-60.baseos.rpbatz.17.x86_640:2.34-100.el9
pam0:1.5.1-15.baseos.rpbatz.x86_640:1.5.1-19.el9
libsss_idmap0:2.8.2-5.apps.rpbatz.5.x86_640:2.8.2-5.el9_2.6
libsss_nss_idmap0:2.8.2-5.apps.rpbatz.5.x86_640:2.8.2-5.el9_2.6
krb5-libs0:1.20.1-9.baseos.rpbatz.x86_640:1.21.1-6.el9
libcurl0:7.76.1-23.baseos.rpbatz.7.x86_640:7.76.1-26.el9_3.3
curl0:7.76.1-23.baseos.rpbatz.7.x86_640:7.76.1-26.el9_3.3
grub2-tools-minimal1:2.06-61.baseos.rpbatz.9.x86_641:2.06-77.el9
grub2-tools1:2.06-61.baseos.rpbatz.9.x86_641:2.06-77.el9
sudo0:1.9.5p2-9.apps.rpbatz.2.x86_640:1.9.5p2-10.el9_3
sssd-client0:2.8.2-5.apps.rpbatz.5.x86_640:2.8.2-5.el9_2.6
libgcc0:11.3.1-4.3.el9.x86_640:11.3.1-4.4.el9_2
libstdc++0:11.3.1-4.3.el9.x86_640:11.3.1-4.4.el9_2
gmp1:6.2.0-10.el9.x86_641:6.2.0-13.el9
libgcrypt0:1.10.0-10.baseos.rpbatz.x86_640:1.10.0-11.el9
gnutls0:3.7.6-21.baseos.rpbatz.2.x86_640:3.8.3-6.el9
squashfs-tools0:4.4-8.git1.apps.rpbatz.x86_640:4.4-10.git1.el9
libmicrohttpd1:0.9.72-4.apps.rpbatz.x86_641:0.9.72-5.el9
openssl1:3.0.7-18.baseos.rpbatz.x86_641:3.0.7-27.el9
openssl-libs1:3.0.7-18.baseos.rpbatz.x86_641:3.0.7-27.el9
openssh0:8.7p1-30.apps.rpbatz.8.x86_640:8.7p1-45.el9
python30:3.9.16-1.apps.rpbatz.8.x86_640:3.9.21-2.el9
python3-libs0:3.9.16-1.apps.rpbatz.8.x86_640:3.9.21-2.el9
libssh0:0.10.4-9.baseos.rpbatz.x86_640:0.10.4-13.el9
libgomp0:11.3.1-4.3.el9.x86_640:11.3.1-4.4.el9_2
tpm2-tss0:3.0.3-8.baseos.rpbatz.x86_640:3.2.2-2.el9
rpm-libs0:4.16.1.3-24.baseos.rpbatz.x86_640:4.16.1.3-27.el9_3
rpm0:4.16.1.3-24.baseos.rpbatz.x86_640:4.16.1.3-27.el9_3
wpa_supplicant1:2.10-4.apps.rpbatz.x86_641:2.10-5.el9
rpm-build-libs0:4.16.1.3-24.baseos.rpbatz.x86_640:4.16.1.3-27.el9_3
iputils0:20210202-8.apps.rpbatz.1.x86_640:20210202-8.el9_2.4
perl-libs4:5.32.1-480.baseos.rpbatz.x86_644:5.32.1-481.el9
perl-interpreter4:5.32.1-480.baseos.rpbatz.x86_644:5.32.1-481.el9
rpm-sign-libs0:4.16.1.3-24.baseos.rpbatz.x86_640:4.16.1.3-27.el9_3
python3-rpm0:4.16.1.3-24.baseos.rpbatz.x86_640:4.16.1.3-27.el9_3
openssh-clients0:8.7p1-30.apps.rpbatz.8.x86_640:8.7p1-45.el9
openssh-server0:8.7p1-30.apps.rpbatz.8.x86_640:8.7p1-45.el9
file-libs0:5.39-12.1.baseos.rpbatz.x86_640:5.39-16.el9
shadow-utils2:4.9-6.baseos.rpbatz.x86_642:4.9-15.el9
file0:5.39-12.1.baseos.rpbatz.x86_640:5.39-16.el9
procps-ng0:3.3.17-11.baseos.rpbatz.x86_640:3.3.17-13.el9

Affected by vulnerabilities with unknown fixes

Package VersionCVEs (severity)
qt5-srpm-macros0:5.15.3-1.el9.noarch
linux-firmware-whence0:20230310-137.apps.rpbatz.noarch
linux-firmware0:20230310-137.apps.rpbatz.noarch
libssh-config0:0.10.4-9.baseos.rpbatz.noarch
coreutils-common0:8.32-35.baseos.rpbatz.x86_64
lz4-libs0:1.9.3-5.baseos.rpbatz.x86_64
tar2:1.34-6.apps.rpbatz.1.x86_64
libmicrohttpd1:0.9.72-4.apps.rpbatz.x86_64
cpio0:2.13-16.baseos.rpbatz.x86_64
coreutils0:8.32-35.baseos.rpbatz.x86_64
polkit-libs0:0.117-11.apps.rpbatz.1.x86_64
grub2-common1:2.06-61.baseos.rpbatz.9.noarch
openssh0:8.7p1-30.apps.rpbatz.8.x86_64
python3-pip-wheel0:21.2.3-6.baseos.rpbatz.noarch
python30:3.9.16-1.apps.rpbatz.8.x86_64
python3-libs0:3.9.16-1.apps.rpbatz.8.x86_64
libssh0:0.10.4-9.baseos.rpbatz.x86_64
libcurl0:7.76.1-23.baseos.rpbatz.7.x86_64
tpm2-tss0:3.0.3-8.baseos.rpbatz.x86_64
curl0:7.76.1-23.baseos.rpbatz.7.x86_64
grub2-tools-minimal1:2.06-61.baseos.rpbatz.9.x86_64
wpa_supplicant1:2.10-4.apps.rpbatz.x86_64
grub2-tools1:2.06-61.baseos.rpbatz.9.x86_64
polkit0:0.117-11.apps.rpbatz.1.x86_64
openssh-clients0:8.7p1-30.apps.rpbatz.8.x86_64
openssh-server0:8.7p1-30.apps.rpbatz.8.x86_64
wget0:1.21.1-7.apps.rpbatz.1.x86_64
libgcc0:11.3.1-4.3.el9.x86_64
pcre2-syntax0:10.40-2.baseos.rpbatz.noarch
libstdc++0:11.3.1-4.3.el9.x86_64
pcre20:10.40-2.baseos.rpbatz.x86_64
gawk0:5.1.0-6.baseos.rpbatz.x86_64
unzip0:6.0-56.apps.rpbatz.x86_64
openssl1:3.0.7-18.baseos.rpbatz.x86_64
openssl-libs1:3.0.7-18.baseos.rpbatz.x86_64
libgomp0:11.3.1-4.3.el9.x86_64
gnupg20:2.3.3-2.baseos.rpbatz.x86_64