VEX report

Run environment Kernel vulnerabilities summary Vulnerabilities (other than kernel) with known fixes Vulnerabilities (other than kernel) with no known fixes

Run environment

Distribution name
batz-2.1-update
Time of run
2026-01-17T11:40:07.439989

Kernel vulnerabilities summary

The kernel used in that image build is version 5.15.71. It is affected by 21 vulnerabilities with no known fix, and 4807 vulnerabilities which are fixed in later releases*. There tend to be a long list of kernel vulnerabilities, so only a summary is given here. For more details take a look at the accompanying vex_report.kernel.json file.

The following table gives an idea of how many vulnerabilities with a known fix would be fixed by upgrading to a given kernel version. The upgrade versions are the current kernel LTS versions and the highest known patch of the kernel branch used for this build.

Some vulnerabilities received a fix outside of these branches, which is why the total doesn't exactly add up.

Version to upgrade to CVEs fixed out of 4807*
5.15.1973688 (76.7%)
6.1.160 (LTS)522 (10.9%)
6.6.120 (LTS)214 (4.5%)
6.12.65 (LTS)107 (2.2%)

Vulnerabilities (other than kernel) with known fixes

Package VersionFixed in versionFixed CVEs (severity)
expat0:2.5.0-3.baseos.rpbatz_1.1.aarch640:2.5.0-5.el9_7.1
libxml20:2.9.13-10.baseos.rpbatz_1_1.1r.aarch640:2.9.13-14.el9_7
openssl1:3.0.7-29.baseos.rpbatz_1_1.aarch641:3.5.1-4.el9_7
openssl-libs1:3.0.7-29.baseos.rpbatz_1_1.aarch641:3.5.1-4.el9_7
python30:3.9.18-3.apps.rpbatz_1.6.aarch640:3.9.25-2.el9_7
python3-libs0:3.9.18-3.apps.rpbatz_1.6.aarch640:3.9.25-2.el9_7
libsss_idmap0:2.9.4-6.apps.rpbatz_1.aarch640:2.9.7-4.el9_7.1
libsss_nss_idmap0:2.9.4-6.apps.rpbatz_1.aarch640:2.9.7-4.el9_7.1
krb5-libs0:1.21.1-2.baseos.rpbatz_1.aarch640:1.21.1-8.el9_6
gnupg20:2.3.3-4.baseos.rpbatz_1.aarch640:2.3.3-5.el9_7
sudo0:1.9.5p2-10.apps.rpbatz_1_1.aarch640:1.9.5p2-10.el9_6.1
sssd-client0:2.9.4-6.apps.rpbatz_1.aarch640:2.9.7-4.el9_7.1
libgcc0:11.3.1-4.3.el9.aarch640:11.5.0-5.el9_5
glibc-gconv-extra0:2.34-100.baseos.rpbatz_1.4.aarch640:2.34-168.el9_6.23
glibc0:2.34-100.baseos.rpbatz_1.4.aarch640:2.34-168.el9_6.23
glibc-common0:2.34-100.baseos.rpbatz_1.4.aarch640:2.34-168.el9_6.23
glibc-langpack-en0:2.34-100.baseos.rpbatz_1.4.aarch640:2.34-168.el9_6.23
bzip2-libs0:1.0.8-8.baseos.rpbatz_1.1.aarch640:1.0.8-10.el9_5
libstdc++0:11.3.1-4.3.el9.aarch640:11.5.0-5.el9_5
gmp1:6.2.0-10.el9.aarch641:6.2.0-13.el9
libtasn10:4.16.0-8.baseos.rpbatz_1_1.1.aarch640:4.16.0-9.el9
gnutls0:3.7.6-21.baseos.rpbatz.2.aarch640:3.8.3-6.el9_6.2
tar2:1.34-6.apps.rpbatz_1.1.aarch642:1.34-9.el9_7
systemd-libs0:252-32.baseos.rpbatz_1_1.7.3r.aarch640:252-55.el9_7.7
openssh0:8.7p1-38.apps.rpbatz_1_1.5.aarch640:8.7p1-47.el9_7
NetworkManager-libnm1:1.42.2-1.apps.rpbatz.aarch641:1.48.10-5.el9_5
libssh0:0.10.4-13.baseos.rpbatz_1.aarch640:0.10.4-17.el9_7
libcurl0:7.76.1-29.baseos.rpbatz_1.1.aarch640:7.76.1-31.el9_6.2
curl0:7.76.1-29.baseos.rpbatz_1.1.aarch640:7.76.1-31.el9_6.2
systemd-pam0:252-32.baseos.rpbatz_1_1.7.3r.aarch640:252-55.el9_7.7
systemd0:252-32.baseos.rpbatz_1_1.7.3r.aarch640:252-55.el9_7.7
systemd-udev0:252-32.baseos.rpbatz_1_1.7.3r.aarch640:252-55.el9_7.7
NetworkManager1:1.42.2-1.apps.rpbatz.aarch641:1.48.10-5.el9_5
NetworkManager-wifi1:1.42.2-1.apps.rpbatz.aarch641:1.48.10-5.el9_5
openssh-clients0:8.7p1-38.apps.rpbatz_1_1.5.aarch640:8.7p1-47.el9_7
openssh-server0:8.7p1-38.apps.rpbatz_1_1.5.aarch640:8.7p1-47.el9_7
libgomp0:11.3.1-4.3.el9.aarch640:11.5.0-5.el9_5
shadow-utils2:4.9-8.baseos.rpbatz_1.1.aarch642:4.9-15.el9

Vulnerabilities (other than kernel) with no known fixes

Package Version CVEs (severity)
libbrotli 0:1.0.9-7.baseos.rpbatz.aarch64
qt5-srpm-macros 0:5.15.3-1.el9.noarch
linux-firmware-whence 0:20230310-137.apps.rpbatz.noarch
linux-firmware 0:20230310-137.apps.rpbatz.noarch
libssh-config 0:0.10.4-13.baseos.rpbatz_1.noarch
coreutils-common 0:8.32-35.baseos.rpbatz_1.aarch64
libuuid 0:2.37.4-18.baseos.rpbatz_1.aarch64
libsmartcols 0:2.37.4-18.baseos.rpbatz_1.aarch64
libmicrohttpd 1:0.9.72-5.apps.rpbatz_1.aarch64
cpio 0:2.13-16.baseos.rpbatz.aarch64
coreutils 0:8.32-35.baseos.rpbatz_1.aarch64
libblkid 0:2.37.4-18.baseos.rpbatz_1.aarch64
libmount 0:2.37.4-18.baseos.rpbatz_1.aarch64
libfdisk 0:2.37.4-18.baseos.rpbatz_1.aarch64
util-linux-core 0:2.37.4-18.baseos.rpbatz_1.aarch64
polkit-libs 0:0.117-11.apps.rpbatz_1.1.aarch64
python3-pip-wheel 0:21.2.3-8.baseos.rpbatz_1.noarch
tpm2-tss 0:3.2.2-2.baseos.rpbatz_1.aarch64
wpa_supplicant 1:2.10-5.apps.rpbatz_1.aarch64
polkit 0:0.117-11.apps.rpbatz_1.1.aarch64
wget 0:1.21.1-8.apps.rpbatz_1.aarch64
pcre2-syntax 0:10.40-5.baseos.rpbatz_1.noarch
elfutils-libelf 0:0.190-2.baseos.rpbatz_1.aarch64
pcre2 0:10.40-5.baseos.rpbatz_1.aarch64
gawk 0:5.1.0-6.baseos.rpbatz.aarch64
unzip 0:6.0-56.apps.rpbatz.aarch64
elfutils-default-yama-scope 0:0.190-2.baseos.rpbatz_1.noarch
elfutils-libs 0:0.190-2.baseos.rpbatz_1.aarch64
elfutils-debuginfod-client 0:0.190-2.baseos.rpbatz_1.aarch64