Run environment Kernel vulnerabilities summary Vulnerabilities (other than kernel) with known fixes Vulnerabilities (other than kernel) with no known fixes
The kernel used in that image build is version 5.14.0. It is
affected by 21 vulnerabilities with no known fix,
and 5677 vulnerabilities which are fixed in later
releases*. There tend to be a long list of kernel vulnerabilities, so only
a summary is given here. For more details take a look at the accompanying
vex_report.kernel.json file.
The following table gives an idea of how many vulnerabilities with a known fix would be fixed by upgrading to a given kernel version. The upgrade versions are the current kernel LTS versions and the highest known patch of the kernel branch used for this build.
Some vulnerabilities received a fix outside of these branches, which is why the total doesn't exactly add up.
| Version to upgrade to | CVEs fixed out of 5677* |
|---|---|
| 5.14.21 | 135 (2.4%) |
| 5.15.197 (LTS) | 4541 (80.0%) |
| 6.1.160 (LTS) | 453 (8.0%) |
| 6.6.120 (LTS) | 189 (3.3%) |
| 6.12.65 (LTS) | 97 (1.7%) |
| Package ▲ | Version | Fixed in version | Fixed CVEs (severity) |
|---|---|---|---|
| libxml2 | 0:2.9.13-10.baseos.rpbatz_1_1.1r.aarch64 | 0:2.9.13-14.el9_7 |
|
| expat | 0:2.5.0-3.baseos.rpbatz_1.1.aarch64 | 0:2.5.0-5.el9_7.1 |
|
| openssl | 1:3.0.7-29.baseos.rpbatz_1_1.aarch64 | 1:3.5.1-4.el9_7 |
|
| openssl-libs | 1:3.0.7-29.baseos.rpbatz_1_1.aarch64 | 1:3.5.1-4.el9_7 |
|
| python3 | 0:3.9.18-3.apps.rpbatz_1.6.aarch64 | 0:3.9.25-2.el9_7 |
|
| python3-libs | 0:3.9.18-3.apps.rpbatz_1.6.aarch64 | 0:3.9.25-2.el9_7 |
|
| libsss_idmap | 0:2.9.4-6.apps.rpbatz_1.aarch64 | 0:2.9.7-4.el9_7.1 |
|
| libsss_nss_idmap | 0:2.9.4-6.apps.rpbatz_1.aarch64 | 0:2.9.7-4.el9_7.1 |
|
| krb5-libs | 0:1.21.1-2.baseos.rpbatz_1.aarch64 | 0:1.21.1-8.el9_6 |
|
| gnupg2 | 0:2.3.3-4.baseos.rpbatz_1.aarch64 | 0:2.3.3-5.el9_7 |
|
| sudo | 0:1.9.5p2-10.apps.rpbatz_1_1.aarch64 | 0:1.9.5p2-10.el9_6.1 |
|
| sssd-client | 0:2.9.4-6.apps.rpbatz_1.aarch64 | 0:2.9.7-4.el9_7.1 |
|
| libgcc | 0:11.3.1-4.3.el9.aarch64 | 0:11.5.0-5.el9_5 |
|
| glibc-gconv-extra | 0:2.34-100.baseos.rpbatz_1.4.aarch64 | 0:2.34-168.el9_6.23 |
|
| glibc | 0:2.34-100.baseos.rpbatz_1.4.aarch64 | 0:2.34-168.el9_6.23 |
|
| glibc-common | 0:2.34-100.baseos.rpbatz_1.4.aarch64 | 0:2.34-168.el9_6.23 |
|
| glibc-langpack-en | 0:2.34-100.baseos.rpbatz_1.4.aarch64 | 0:2.34-168.el9_6.23 |
|
| bzip2-libs | 0:1.0.8-8.baseos.rpbatz_1.1.aarch64 | 0:1.0.8-10.el9_5 |
|
| libstdc++ | 0:11.3.1-4.3.el9.aarch64 | 0:11.5.0-5.el9_5 |
|
| gmp | 1:6.2.0-10.el9.aarch64 | 1:6.2.0-13.el9 |
|
| libtasn1 | 0:4.16.0-8.baseos.rpbatz_1_1.1.aarch64 | 0:4.16.0-9.el9 |
|
| gnutls | 0:3.7.6-21.baseos.rpbatz.2.aarch64 | 0:3.8.3-6.el9_6.2 |
|
| tar | 2:1.34-6.apps.rpbatz_1.1.aarch64 | 2:1.34-9.el9_7 |
|
| systemd-libs | 0:252-32.baseos.rpbatz_1_1.7.3r.aarch64 | 0:252-55.el9_7.7 |
|
| openssh | 0:8.7p1-38.apps.rpbatz_1_1.5.aarch64 | 0:8.7p1-47.el9_7 |
|
| NetworkManager-libnm | 1:1.42.2-1.apps.rpbatz.aarch64 | 1:1.48.10-5.el9_5 |
|
| libssh | 0:0.10.4-13.baseos.rpbatz_1.aarch64 | 0:0.10.4-17.el9_7 |
|
| libgomp | 0:11.3.1-4.3.el9.aarch64 | 0:11.5.0-5.el9_5 |
|
| libcurl | 0:7.76.1-29.baseos.rpbatz_1.1.aarch64 | 0:7.76.1-31.el9_6.2 |
|
| curl | 0:7.76.1-29.baseos.rpbatz_1.1.aarch64 | 0:7.76.1-31.el9_6.2 |
|
| systemd-pam | 0:252-32.baseos.rpbatz_1_1.7.3r.aarch64 | 0:252-55.el9_7.7 |
|
| systemd | 0:252-32.baseos.rpbatz_1_1.7.3r.aarch64 | 0:252-55.el9_7.7 |
|
| systemd-udev | 0:252-32.baseos.rpbatz_1_1.7.3r.aarch64 | 0:252-55.el9_7.7 |
|
| NetworkManager | 1:1.42.2-1.apps.rpbatz.aarch64 | 1:1.48.10-5.el9_5 |
|
| NetworkManager-wifi | 1:1.42.2-1.apps.rpbatz.aarch64 | 1:1.48.10-5.el9_5 |
|
| openssh-clients | 0:8.7p1-38.apps.rpbatz_1_1.5.aarch64 | 0:8.7p1-47.el9_7 |
|
| openssh-server | 0:8.7p1-38.apps.rpbatz_1_1.5.aarch64 | 0:8.7p1-47.el9_7 |
|
| shadow-utils | 2:4.9-8.baseos.rpbatz_1.1.aarch64 | 2:4.9-15.el9 |
|
| Package ▲ | Version | CVEs (severity) |
|---|---|---|
| libbrotli | 0:1.0.9-7.baseos.rpbatz.aarch64 |
|
| qt5-srpm-macros | 0:5.15.3-1.el9.noarch |
|
| linux-firmware-whence | 0:20230310-137.apps.rpbatz.noarch |
|
| linux-firmware | 0:20230310-137.apps.rpbatz.noarch |
|
| libssh-config | 0:0.10.4-13.baseos.rpbatz_1.noarch |
|
| coreutils-common | 0:8.32-35.baseos.rpbatz_1.aarch64 |
|
| libuuid | 0:2.37.4-18.baseos.rpbatz_1.aarch64 |
|
| libsmartcols | 0:2.37.4-18.baseos.rpbatz_1.aarch64 |
|
| libmicrohttpd | 1:0.9.72-5.apps.rpbatz_1.aarch64 |
|
| cpio | 0:2.13-16.baseos.rpbatz.aarch64 |
|
| coreutils | 0:8.32-35.baseos.rpbatz_1.aarch64 |
|
| libblkid | 0:2.37.4-18.baseos.rpbatz_1.aarch64 |
|
| libmount | 0:2.37.4-18.baseos.rpbatz_1.aarch64 |
|
| libfdisk | 0:2.37.4-18.baseos.rpbatz_1.aarch64 |
|
| polkit-libs | 0:0.117-11.apps.rpbatz_1.1.aarch64 |
|
| util-linux-core | 0:2.37.4-18.baseos.rpbatz_1.aarch64 |
|
| python3-pip-wheel | 0:21.2.3-8.baseos.rpbatz_1.noarch |
|
| tpm2-tss | 0:3.2.2-2.baseos.rpbatz_1.aarch64 |
|
| wpa_supplicant | 1:2.10-5.apps.rpbatz_1.aarch64 |
|
| polkit | 0:0.117-11.apps.rpbatz_1.1.aarch64 |
|
| shim-aa64 | 0:15.8-3.apps.rpbatz.aarch64 |
|
| wget | 0:1.21.1-8.apps.rpbatz_1.aarch64 |
|
| pcre2-syntax | 0:10.40-5.baseos.rpbatz_1.noarch |
|
| elfutils-libelf | 0:0.190-2.baseos.rpbatz_1.aarch64 |
|
| pcre2 | 0:10.40-5.baseos.rpbatz_1.aarch64 |
|
| gawk | 0:5.1.0-6.baseos.rpbatz.aarch64 |
|
| unzip | 0:6.0-56.apps.rpbatz.aarch64 |
|
| elfutils-default-yama-scope | 0:0.190-2.baseos.rpbatz_1.noarch |
|
| elfutils-libs | 0:0.190-2.baseos.rpbatz_1.aarch64 |
|
| elfutils-debuginfod-client | 0:0.190-2.baseos.rpbatz_1.aarch64 |
|