Apply updates per vendor instructions.
Evidence dossier
CVE-2019-11043
Underflow in PHP-FPM can lead to RCE
gen-409cbd0cNormalized restatement
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
- State
- PUBLISHED
- Published
- Oct 28, 2019
- Updated
- Oct 21, 2025
- Evidence coverage
- 72%
2026-07-18 · v2026.06.15 · percentile 99.9%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
Probability 0.994700000000; percentile 0.999400000000
Applicability
Cited product scope
Grouped from 6 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.
Identity source boundaries
- cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
24 scope groups
[{"status": "affected", "version": "7.1.x", "lessThan": "7.1.33", "versionType": "custom"}, {"status": "affected", "version": "7.2.x", "lessThan": "7.2.24", "versionType": "custom"}, {"status": "affected", "version": "7.3.x", "lessThan": "7.3.11", "versionType": "custom"}]Version 12.04; Version 14.04; Version 16.04; Version 18.04; Version 19.04; Version 19.10Canonical identity product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2linked exactInspect 6 returned assertions
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
23a7c53f-b80f-4e6a-afa9-58eea84be11d
cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a31c8344-3e02-4eb8-8bd8-4c84b7959624
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8d305f7a-d159-4716-ab26-5e38bb5cd991
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
815d70a8-47d3-459c-a32c-9feaca0659d1
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f7016a2a-8365-4f1a-89a2-7a19f2bcae5b
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cd783b0c-9246-47d9-a937-6144fe8bff0f
Version 10.0; Version 9.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447elinked exactInspect 2 returned assertions
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
deece5fc-cacf-4496-a3e7-164736409252
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07b237a9-69a3-4a9c-9da0-4e06bd37ae73
Version 29; Version 30; Version 31Canonical identity product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47linked exactInspect 3 returned assertions
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d100f7ce-fc64-4cc6-852a-6136d72da419
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97a4b8df-58da-4ab6-a1f9-331b36409ba3
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
80f0fa5d-8d3b-4c0e-81e2-87998286af33
Any version (unconstrained) (>= 7.1.0, < 7.1.33); Any version (unconstrained) (>= 7.2.0, < 7.2.24); Any version (unconstrained) (>= 7.3.0, < 7.3.11)Canonical identity product-e6438e3fdd6f4fab833b9e95f3122542080fe89ddf2636dd7eb83d66f8118f15linked exactInspect 3 returned assertions
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 7.1.0; through excluding 7.1.33
- Match ID
d1c2f51f-19aa-4313-ae96-59f46f55d200
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 7.2.0; through excluding 7.2.24
- Match ID
d6f43ff3-d1eb-473c-9b3a-96c21f63117d
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 7.3.0; through excluding 7.3.11
- Match ID
86c83e2a-d2fd-4a12-bd6a-6d48edffacc4
Version 8.0Canonical identity product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844eelinked exactInspect 1 returned assertions
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f4cff558-3c47-480d-a2f0-babf26042943
Version 6.0; Version 7.0Canonical identity product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aelinked exactInspect 2 returned assertions
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
33c068a4-3780-4eab-a937-6082df847564
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ee249e1b-a1fd-4e08-aa71-a0e1f10ffe97
Version 7.7; Version 8.1; Version 8.2; Version 8.4; Version 8.6; Version 8.8Canonical identity product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378linked exactInspect 6 returned assertions
cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0e3f09b5-569f-4c58-9fca-3c0953d107b5
cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
62c31522-0a17-4025-b269-855c7f4b45c2
cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
92bc9265-6959-4d37-be5e-8c45e98992f8
cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6c3741b8-851f-475d-b428-523f4f722350
cpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
83737173-e12e-4641-bc49-0bd84a6b29d0
cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
831f0f47-3565-4763-b16f-c87b1ff2035e
Version 7.7Canonical identity product-9ff3bc0adcc5343851d69d4a833815e08f0c8d24134495b38f50fdf38d2f17b2linked exactInspect 1 returned assertions
cpe:2.3:o:redhat:enterprise_linux_eus_compute_node:7.7:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6daa8c42-870a-42b4-ae9f-7c67f4122ed3
Version 8.0_aarch64Canonical identity product-5b647cbf10edba654fbfb5f3617b5887cae2cdbd5242317dd9286e31cb74c078linked exactInspect 1 returned assertions
cpe:2.3:o:redhat:enterprise_linux_for_arm_64:8.0_aarch64:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5a47ef78-a5b6-4b89-8b74-eeb0647c549f
Version 8.1_aarch64; Version 8.2_aarch64; Version 8.4_aarch64; Version 8.6_aarch64; Version 8.8_aarch64Canonical identity product-19e25a323a33d2e95ae9af9c6f5d3c68dd2ffbbccb9a61583d6723e58fce1183linked exactInspect 5 returned assertions
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.1_aarch64:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2ff1a19f-8a15-471a-b496-e1b4ba788356
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.4_aarch64:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ae49dca5-1b01-4478-a1e9-2e87e948a0c1
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.2_aarch64:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ead7ec1d-5979-42e6-9da6-355b53431f3b
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.8_aarch64:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
213593d4-eb5a-4a1b-bdf3-3f043c5f6a6c
cpe:2.3:o:redhat:enterprise_linux_for_arm_64_eus:8.6_aarch64:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
37b7ce5c-bfea-4f96-9759-d511ef189059
Version 6.0_s390x; Version 7.0_s390x; Version 8.0_s390xCanonical identity product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0blinked exactInspect 3 returned assertions
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.0_s390x:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c84eaae7-0249-4ea1-b8d3-e039b03acdc3
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0_s390x:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
32af225e-94c0-4d07-900c-dd868c05f554
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0_s390x:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2148300c-ecbd-4ed5-a164-79629859dd43
Version 7.7_s390x; Version 8.1_s390x; Version 8.2_s390x; Version 8.4_s390x; Version 8.6_s390x; Version 8.8_s390xCanonical identity product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fdlinked exactInspect 6 returned assertions
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.6_s390x:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b758edc9-6421-422c-899e-a273d2936d8e
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:7.7_s390x:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ffc68d88-3cd3-4a3d-a01b-e9dbacd9b9cb
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.1_s390x:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
00966ac5-1c84-4b5f-9665-5e99d4aeb3a2
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.8_s390x:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
22c65f53-d624-48a9-a9b7-4c78a31e19f9
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.2_s390x:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0d04f433-cb52-4f3d-8711-39d3bda27fe3
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4_s390x:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07332196-7e36-4e95-81bc-dd959629c1be
Version 6.0_ppc64; Version 7.0_ppc64Canonical identity product-fd0893ef7253031c8ee72effb6fcc65181f9b3f5e01f8f48b6a6ab89a31380a9linked exactInspect 2 returned assertions
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.0_ppc64:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6d8d654f-2442-4ea0-af89-6ac2cd214772
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0_ppc64:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8bcf87fd-9358-42a5-9917-25df0180a5a6
Version 7.7_ppc64Canonical identity product-c09e1a6c06a60f75d4f5a3a91108bcb8e8b7418b4d0bcbe56608e9eba3cd934blinked exactInspect 1 returned assertions
cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.7_ppc64:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8036e2ae-4e44-4fa5-affb-a3724bfdd654
Version 7.0_ppc64le; Version 8.0_ppc64leCanonical identity product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429linked exactInspect 2 returned assertions
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0_ppc64le:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a584aaa-a14f-4c64-8fed-675dc36f69a3
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0_ppc64le:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
23d471ac-7dca-4425-ad91-e5d928753a8c
Version 7.7_ppc64le; Version 8.1_ppc64le; Version 8.2_ppc64le; Version 8.4_ppc64le; Version 8.6_ppc64le; Version 8.8_ppc64leCanonical identity product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5linked exactInspect 6 returned assertions
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.1_ppc64le:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f505d098-2143-4218-a528-d92bfc017ffd
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.6_ppc64le:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 35
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d9c30c59-07f7-4cce-b057-052eccd36db8
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:7.7_ppc64le:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
418488a5-2912-406c-9337-b8e85d0c2b57
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.2_ppc64le:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
96e5cec7-d3b9-4895-96e9-e26d2acf1ae3
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.8_ppc64le:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 36
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f91f9255-4ee1-43c7-8831-d2b6c228bfd9
cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4_ppc64le:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 34
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bb28cf82-799f-4a6e-b1db-0ab423e6c05d
Version 7.0Canonical identity product-d22fc88b6b85afc426c8220428110aecfb39a59d3b7ddf5757cf39cb9f5feb2flinked exactInspect 1 returned assertions
cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 37
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
37ce1dc7-72c5-483c-8921-0b462c8284d1
Version 6.0; Version 7.0Canonical identity product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9dealinked exactInspect 2 returned assertions
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 39
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
51ef4996-72f4-4fa4-814f-f5991e7a8318
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 38
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9bbcd86a-e6c7-4444-9d74-f861084090f0
Version 7.7; Version 8.2; Version 8.4; Version 8.6Canonical identity product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aaelinked exactInspect 4 returned assertions
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 42
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e28f226a-cbc7-4a32-be58-398fa5b42481
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 43
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
76c24d94-834a-4e9d-8f73-624afa99aaa2
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 40
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7431abc1-9252-419e-8cc1-311b41360078
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 41
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6897676d-53f9-45b3-b27f-7ff9a4c58d33
Version 7.7; Version 8.2; Version 8.4; Version 8.6; Version 8.8Canonical identity product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71dalinked exactInspect 5 returned assertions
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 46
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ac10d919-57fd-4725-b8d2-39ecb476902f
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 45
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b09acf2d-d83f-4a86-8185-9569605d8ee1
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 48
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f1ca946d-1665-4874-9d41-c7d963dd1f56
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 44
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
17f256a9-d3b9-4c72-b013-4efd878bfea8
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 47
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1272df03-7674-4bd4-8e64-94004b195448
Version 6.0; Version 7.0Canonical identity product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9linked exactInspect 2 returned assertions
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 49
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e5ed5807-55b7-47c5-97a6-03233f4fbc3a
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 50
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
825ece2d-e232-46e0-a047-074b34db1e97
Version 1.0Canonical identity product-ca784b1cfa46e7693787bdfda9b774a55e292d3cbfbb2944f6927553fd92cf5dlinked exactInspect 1 returned assertions
cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9d7ee4b6-a6ec-4b9b-91df-79615796673f
Any version (unconstrained) (< 5.19.0)Canonical identity product-2a04e270d265cc60bf7ebd5aeadda41d1530be7f39d773f24a7628595a449eedlinked exactInspect 1 returned assertions
cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 5.19.0
- Match ID
41dba7c7-8084-45f6-b59d-13a9022c34df
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:NCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:NLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.