VEX report

Run environment

Distribution name
batz-2.2.0
Time of run
2025-12-04T11:32:08.923886

Kernel vulnerabilities summary

The kernel used in that image build is version 5.10.41. It is affected by 21 vulnerabilities with no known fix, and 4767 vulnerabilities which are fixed in later releases*. There tend to be a long list of kernel vulnerabilities, so only a summary is given here. For more details take a look at the accompanying vex_report.kernel.json file.

The following table gives an idea of how many vulnerabilities with a known fix would be fixed by upgrading to a given kernel version. The upgrade versions are the current kernel LTS versions and the highest known patch of the kernel branch used for this build.

Some vulnerabilities received a fix outside of these branches, which is why the total doesn't exactly add up.

Version to upgrade to CVEs fixed out of 4767*
5.10.2463563 (74.7%)
5.15.196 (LTS)389 (8.2%)
6.1.158 (LTS)298 (6.3%)
6.6.118 (LTS)189 (4.0%)
6.12.60 (LTS)87 (1.8%)

Affected by vulnerabilities with known fixes

Package VersionFixed in versionFixed CVEs (severity)
expat0:2.5.0-5.baseos.rpbatz_2.aarch640:2.5.0-5.el9_7.1
sqlite-libs0:3.34.1-7.baseos.rpbatz_1.aarch640:3.34.1-9.el9_7
libxml20:2.9.13-10.baseos.rpbatz_2.1r.aarch640:2.9.13-14.el9_7
libsss_idmap0:2.9.4-6.apps.rpbatz_1.aarch640:2.9.7-4.el9_7.1
libsss_nss_idmap0:2.9.4-6.apps.rpbatz_1.aarch640:2.9.7-4.el9_7.1
pam0:1.5.1-23.baseos.rpbatz_1.aarch640:1.5.1-26.el9_6
python30:3.9.21-2.apps.rpbatz_2.aarch640:3.9.21-2.el9_6.1
python3-libs0:3.9.21-2.apps.rpbatz_2.aarch640:3.9.21-2.el9_6.1
sudo0:1.9.5p2-10.apps.rpbatz_1_1.aarch640:1.9.5p2-10.el9_6.1
sssd-client0:2.9.4-6.apps.rpbatz_1.aarch640:2.9.7-4.el9_7.1
glibc-gconv-extra0:2.34-168.baseos.rpbatz_2.14.aarch640:2.34-168.el9_6.23
glibc-langpack-en0:2.34-168.baseos.rpbatz_2.14.aarch640:2.34-168.el9_6.23
glibc-common0:2.34-168.baseos.rpbatz_2.14.aarch640:2.34-168.el9_6.23
glibc0:2.34-168.baseos.rpbatz_2.14.aarch640:2.34-168.el9_6.23
gmp1:6.2.0-10.el9.aarch641:6.2.0-13.el9
gnutls0:3.7.6-21.baseos.rpbatz.2.aarch640:3.8.3-6.el9_6.2
jq0:1.6-17.apps.rpbatz_2.aarch640:1.6-17.el9_6.2
openssl1:3.2.2-6.baseos.rpbatz_2.1.aarch641:3.5.1-4.el9_7
openssl-libs1:3.2.2-6.baseos.rpbatz_2.1.aarch641:3.5.1-4.el9_7
systemd-libs0:252-51.baseos.rpbatz_2.3r.aarch640:252-55.el9_7.7
krb5-libs0:1.21.1-6.baseos.rpbatz_2.aarch640:1.21.1-8.el9_6
glib20:2.68.4-16.baseos.rpbatz_2.aarch640:2.68.4-16.el9_6.2
systemd-pam0:252-51.baseos.rpbatz_2.3r.aarch640:252-55.el9_7.7
systemd0:252-51.baseos.rpbatz_2.3r.aarch640:252-55.el9_7.7
iputils0:20210202-11.apps.rpbatz_2.aarch640:20210202-11.el9_6.3
perl-libs4:5.32.1-481.baseos.rpbatz_1.aarch644:5.32.1-481.1.el9_6
perl-interpreter4:5.32.1-481.baseos.rpbatz_1.aarch644:5.32.1-481.1.el9_6
libssh0:0.10.4-13.baseos.rpbatz_1.aarch640:0.10.4-15.el9_7
systemd-udev0:252-51.baseos.rpbatz_2.3r.aarch640:252-55.el9_7.7
ncurses-libs0:6.2-10.20210508.baseos.rpbatz_1.aarch640:6.2-10.20210508.el9_6.2
shadow-utils2:4.9-12.baseos.rpbatz_2.aarch642:4.9-15.el9
ncurses0:6.2-10.20210508.baseos.rpbatz_1.aarch640:6.2-10.20210508.el9_6.2

Affected by vulnerabilities with unknown fixes

Package VersionCVEs (severity)
qt5-srpm-macros0:5.15.3-1.el9.noarch
sqlite-libs0:3.34.1-7.baseos.rpbatz_1.aarch64
lz4-libs0:1.9.3-5.baseos.rpbatz.aarch64
tar2:1.34-7.apps.rpbatz_2.aarch64
libmicrohttpd1:0.9.72-5.apps.rpbatz_1.aarch64
cpio0:2.13-16.baseos.rpbatz.aarch64
linux-firmware-whence0:20230310-137.apps.rpbatz.noarch
linux-firmware0:20230310-137.apps.rpbatz.noarch
libssh-config0:0.10.4-13.baseos.rpbatz_1.noarch
coreutils-common0:8.32-39.baseos.rpbatz_2.aarch64
coreutils0:8.32-39.baseos.rpbatz_2.aarch64
glib20:2.68.4-16.baseos.rpbatz_2.aarch64
wpa_supplicant1:2.11-2.apps.rpbatz_2.aarch64
openssh0:8.7p1-45.apps.rpbatz_2.aarch64
polkit-libs0:0.117-13.apps.rpbatz_2.aarch64
polkit0:0.117-13.apps.rpbatz_2.aarch64
python3-pip-wheel0:21.3.1-1.baseos.rpbatz_2.noarch
python30:3.9.21-2.apps.rpbatz_2.aarch64
python3-libs0:3.9.21-2.apps.rpbatz_2.aarch64
libssh0:0.10.4-13.baseos.rpbatz_1.aarch64
libcurl0:7.76.1-29.baseos.rpbatz_1.1.aarch64
curl0:7.76.1-29.baseos.rpbatz_1.1.aarch64
tpm2-tss0:3.2.3-1.baseos.rpbatz_2.aarch64
go-srpm-macros0:3.6.0-10.apps.rpbatz_2.noarch
openssh-clients0:8.7p1-45.apps.rpbatz_2.aarch64
openssh-server0:8.7p1-45.apps.rpbatz_2.aarch64
wget0:1.21.1-8.apps.rpbatz_1.aarch64
libgcc0:11.3.1-4.3.el9.aarch64
pcre2-syntax0:10.40-6.baseos.rpbatz_2.noarch
ncurses-base0:6.2-10.20210508.baseos.rpbatz_1.noarch
ncurses-libs0:6.2-10.20210508.baseos.rpbatz_1.aarch64
libstdc++0:11.3.1-4.3.el9.aarch64
elfutils-libelf0:0.190-2.baseos.rpbatz_1.aarch64
expat0:2.5.0-5.baseos.rpbatz_2.aarch64
libxml20:2.9.13-10.baseos.rpbatz_2.1r.aarch64
pcre20:10.40-6.baseos.rpbatz_2.aarch64
gawk0:5.1.0-6.baseos.rpbatz.aarch64
unzip0:6.0-56.apps.rpbatz.aarch64
ncurses0:6.2-10.20210508.baseos.rpbatz_1.aarch64
jq0:1.6-17.apps.rpbatz_2.aarch64
openssl1:3.2.2-6.baseos.rpbatz_2.1.aarch64
openssl-libs1:3.2.2-6.baseos.rpbatz_2.1.aarch64
elfutils-default-yama-scope0:0.190-2.baseos.rpbatz_1.noarch
elfutils-libs0:0.190-2.baseos.rpbatz_1.aarch64
gnupg20:2.3.3-4.baseos.rpbatz_1.aarch64
elfutils-debuginfod-client0:0.190-2.baseos.rpbatz_1.aarch64
libgomp0:11.3.1-4.3.el9.aarch64