VEX report

Run environment Kernel vulnerabilities summary Vulnerabilities (other than kernel) with known fixes Vulnerabilities (other than kernel) with no known fixes

Run environment

Distribution name
batz-2.2-update
Time of run
2026-01-17T05:46:14.088130

Kernel vulnerabilities summary

The kernel used in that image build is version 6.6.32. It is affected by 21 vulnerabilities with no known fix, and 3402 vulnerabilities which are fixed in later releases*. There tend to be a long list of kernel vulnerabilities, so only a summary is given here. For more details take a look at the accompanying vex_report.kernel.json file.

The following table gives an idea of how many vulnerabilities with a known fix would be fixed by upgrading to a given kernel version. The upgrade versions are the current kernel LTS versions and the highest known patch of the kernel branch used for this build.

Some vulnerabilities received a fix outside of these branches, which is why the total doesn't exactly add up.

Version to upgrade to CVEs fixed out of 3402*
6.6.1203062 (90.0%)
6.12.65 (LTS)158 (4.6%)

Vulnerabilities (other than kernel) with known fixes

Package VersionFixed in versionFixed CVEs (severity)
expat0:2.5.0-5.baseos.rpbatz_2.aarch640:2.5.0-5.el9_7.1
libxml20:2.9.13-10.baseos.rpbatz_2.1r.aarch640:2.9.13-14.el9_7
python30:3.9.21-2.apps.rpbatz_2.aarch640:3.9.25-2.el9_7
python3-libs0:3.9.21-2.apps.rpbatz_2.aarch640:3.9.25-2.el9_7
libsss_idmap0:2.9.4-6.apps.rpbatz_1.aarch640:2.9.7-4.el9_7.1
libsss_nss_idmap0:2.9.4-6.apps.rpbatz_1.aarch640:2.9.7-4.el9_7.1
gnupg20:2.3.3-4.baseos.rpbatz_1.aarch640:2.3.3-5.el9_7
sudo0:1.9.5p2-10.apps.rpbatz_1_1.aarch640:1.9.5p2-10.el9_6.1
sssd-client0:2.9.4-6.apps.rpbatz_1.aarch640:2.9.7-4.el9_7.1
glibc-gconv-extra0:2.34-168.baseos.rpbatz_2.14.aarch640:2.34-168.el9_6.23
glibc0:2.34-168.baseos.rpbatz_2.14.aarch640:2.34-168.el9_6.23
glibc-common0:2.34-168.baseos.rpbatz_2.14.aarch640:2.34-168.el9_6.23
glibc-langpack-en0:2.34-168.baseos.rpbatz_2.14.aarch640:2.34-168.el9_6.23
gmp1:6.2.0-10.el9.aarch641:6.2.0-13.el9
gnutls0:3.7.6-21.baseos.rpbatz.2.aarch640:3.8.3-6.el9_6.2
tar2:1.34-7.apps.rpbatz_2.aarch642:1.34-9.el9_7
openssl1:3.2.2-6.baseos.rpbatz_2.1.aarch641:3.5.1-4.el9_7
openssl-libs1:3.2.2-6.baseos.rpbatz_2.1.aarch641:3.5.1-4.el9_7
systemd-libs0:252-51.baseos.rpbatz_2.3r.aarch640:252-55.el9_7.7
glib20:2.68.4-16.baseos.rpbatz_2.aarch640:2.68.4-16.el9_6.2
systemd-pam0:252-51.baseos.rpbatz_2.3r.aarch640:252-55.el9_7.7
systemd0:252-51.baseos.rpbatz_2.3r.aarch640:252-55.el9_7.7
openssh0:8.7p1-45.apps.rpbatz_2.aarch640:8.7p1-47.el9_7
iputils0:20210202-11.apps.rpbatz_2.aarch640:20210202-11.el9_6.3
libssh0:0.10.4-13.baseos.rpbatz_1.aarch640:0.10.4-17.el9_7
krb5-libs0:1.21.1-6.baseos.rpbatz_2.aarch640:1.21.1-8.el9_6
libcurl0:7.76.1-29.baseos.rpbatz_1.1.aarch640:7.76.1-31.el9_6.2
curl0:7.76.1-29.baseos.rpbatz_1.1.aarch640:7.76.1-31.el9_6.2
systemd-udev0:252-51.baseos.rpbatz_2.3r.aarch640:252-55.el9_7.7
jq0:1.6-17.apps.rpbatz_2.aarch640:1.6-17.el9_6.2
openssh-clients0:8.7p1-45.apps.rpbatz_2.aarch640:8.7p1-47.el9_7
openssh-server0:8.7p1-45.apps.rpbatz_2.aarch640:8.7p1-47.el9_7
shadow-utils2:4.9-12.baseos.rpbatz_2.aarch642:4.9-15.el9

Vulnerabilities (other than kernel) with no known fixes

Package Version CVEs (severity)
libbrotli 0:1.0.9-7.baseos.rpbatz.aarch64
qt5-srpm-macros 0:5.15.3-1.el9.noarch
libssh-config 0:0.10.4-13.baseos.rpbatz_1.noarch
coreutils-common 0:8.32-39.baseos.rpbatz_2.aarch64
libuuid 0:2.37.4-21.baseos.rpbatz_2.aarch64
libsmartcols 0:2.37.4-21.baseos.rpbatz_2.aarch64
libmicrohttpd 1:0.9.72-5.apps.rpbatz_1.aarch64
cpio 0:2.13-16.baseos.rpbatz.aarch64
coreutils 0:8.32-39.baseos.rpbatz_2.aarch64
libblkid 0:2.37.4-21.baseos.rpbatz_2.aarch64
libmount 0:2.37.4-21.baseos.rpbatz_2.aarch64
libfdisk 0:2.37.4-21.baseos.rpbatz_2.aarch64
util-linux-core 0:2.37.4-21.baseos.rpbatz_2.aarch64
wpa_supplicant 1:2.11-2.apps.rpbatz_2.aarch64
polkit-libs 0:0.117-13.apps.rpbatz_2.aarch64
polkit 0:0.117-13.apps.rpbatz_2.aarch64
python3-pip-wheel 0:21.3.1-1.baseos.rpbatz_2.noarch
tpm2-tss 0:3.2.3-1.baseos.rpbatz_2.aarch64
go-srpm-macros 0:3.6.0-10.apps.rpbatz_2.noarch
wget 0:1.21.1-8.apps.rpbatz_1.aarch64
libgcc 0:11.3.1-4.3.el9.aarch64
pcre2-syntax 0:10.40-6.baseos.rpbatz_2.noarch
libstdc++ 0:11.3.1-4.3.el9.aarch64
elfutils-libelf 0:0.190-2.baseos.rpbatz_1.aarch64
pcre2 0:10.40-6.baseos.rpbatz_2.aarch64
gawk 0:5.1.0-6.baseos.rpbatz.aarch64
unzip 0:6.0-56.apps.rpbatz.aarch64
elfutils-default-yama-scope 0:0.190-2.baseos.rpbatz_1.noarch
elfutils-libs 0:0.190-2.baseos.rpbatz_1.aarch64
elfutils-debuginfod-client 0:0.190-2.baseos.rpbatz_1.aarch64
libgomp 0:11.3.1-4.3.el9.aarch64