Codeready Linux Builder For IBM Z Systems
16 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Codeready Linux Builder For IBM Z Systems, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Codeready Linux Builder For IBM Z Systems CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 2 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High9
- Medium7
Latest CVEs
The 15 most recently published vulnerabilities affecting Codeready Linux Builder For IBM Z Systems.
- CVE-2025-13601Glib: integer overflow in in g_escape_uri_string()7.7
- CVE-2025-3155Yelp: arbitrary file read7.4
- CVE-2025-2784Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content7.0
- CVE-2023-3758Sssd: race condition during authorization leads to gpo policies functioning inconsistently7.1
- CVE-2024-1488Unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation8.0
- CVE-2024-0193Kernel: netfilter: use-after-free in nft_trans_gc_catchall_sync leads to privilege escalation7.8
- CVE-2023-4641Shadow-utils: possible password leak during passwd(1) change4.7
- CVE-2023-5633Kernel: vmwgfx: reference count issue leads to use-after-free in surface handling7.8
- CVE-2023-4911Glibc: buffer overflow in ld.so leading to privilege escalation7.8
- CVE-2023-4806Glibc: potential use-after-free in getaddrinfo()5.9
- CVE-2023-4527Glibc: stack read overflow in getaddrinfo in no-aaaa mode6.5
- CVE-2023-4042Ghostscript: incomplete fix for cve-2020-163055.5
- CVE-2021-3733There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression...6.5
- CVE-2021-3737A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infin...7.5
- CVE-2021-3930An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f)...6.5
Product grouping is registry-driven, with AI assist and human review. How it works