Evidence dossier

CVE-2023-4911

Glibc: buffer overflow in ld.so leading to privilege escalation

Exploited in the wild (CISA KEV since Nov 21, 2023). NVD reports CVSS 3.1 7.8. EPSS estimates 81.4% exploit likelihood as of Aug 26, 2026.

89.091.3Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

State
PUBLISHED
Published
Oct 3, 2023
Updated
Jul 14, 2026
Evidence coverage
97%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    redhat

    Record text: Glibc: buffer overflow in ld.so leading to privilege escalation

    Inspect raw assertion
    Field
    container
    Value
    Glibc: buffer overflow in ld.so leading to privilege escalation
    Original evidence ↗
  4. Source dateSource date omittedFirst observed by CASCA
    siemens-SADP

    Record text: Container present

    Inspect raw assertion
    Field
    container
    Value
    Container present
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: GNU C Library Buffer Overflow Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    GNU C Library Buffer Overflow Vulnerability
    Original evidence ↗
  6. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 81.42% probability · 99.61th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.814220000000; percentile 0.996090000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Nov 21, 2023 · first observed Jul 19, 2026

Exploit likelihood81.42%

FIRST EPSS · score date Aug 26, 2026 · 99.6th percentile · first observed Aug 26, 2026

SeverityCVSS 7.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
redhatOriginal assertion
Record text

Glibc: buffer overflow in ld.so leading to privilege escalation

Inspect raw assertion
Field
container
Value
Glibc: buffer overflow in ld.so leading to privilege escalation
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
siemens-SADPSource-declared origin
Record text

Container present

Inspect raw assertion
Field
container
Value
Container present
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

GNU C Library Buffer Overflow Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
GNU C Library Buffer Overflow Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

81.42% probability · 99.61th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.814220000000; percentile 0.996090000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
83Underlying assertions
49Canonical products
73Target assertions
10Constraint assertions

Grouped from 25 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

67 scope groups

redhat · source assertedRed HatRed Hat Enterprise Linux 6Direct source scope
Version details are available in the raw assertion
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[]
redhat · source assertedRed HatRed Hat Enterprise Linux 7Direct source scope
Version details are available in the raw assertion
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[]
redhat · source assertedRed HatRed Hat Enterprise Linux 7Direct source scope
Version details are available in the raw assertion
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[]
redhat · source assertedRed HatRed Hat Enterprise Linux 8Direct source scope
Unaffected: 0:2.28-225.el8_8.6 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:2.28-225.el8_8.6", "lessThan": "*", "versionType": "rpm"}]
redhat · source assertedRed HatRed Hat Enterprise Linux 8Direct source scope
Unaffected: 0:2.28-225.el8_8.6 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:2.28-225.el8_8.6", "lessThan": "*", "versionType": "rpm"}]
redhat · source assertedRed HatRed Hat Enterprise Linux 8.6 Extended Update SupportDirect source scope
Unaffected: 0:2.28-189.6.el8_6 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:2.28-189.6.el8_6", "lessThan": "*", "versionType": "rpm"}]
redhat · source assertedRed HatRed Hat Enterprise Linux 9Direct source scope
Unaffected: 0:2.34-60.el9_2.7 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:2.34-60.el9_2.7", "lessThan": "*", "versionType": "rpm"}]
redhat · source assertedRed HatRed Hat Enterprise Linux 9Direct source scope
Unaffected: 0:2.34-60.el9_2.7 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:2.34-60.el9_2.7", "lessThan": "*", "versionType": "rpm"}]
redhat · source assertedRed HatRed Hat Enterprise Linux 9.0 Extended Update SupportDirect source scope
Unaffected: 0:2.34-28.el9_0.4 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:2.34-28.el9_0.4", "lessThan": "*", "versionType": "rpm"}]
redhat · source assertedRed HatRed Hat Virtualization 4 for Red Hat Enterprise Linux 8Direct source scope
Unaffected: 0:4.5.3-202312060823_8.6 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:4.5.3-202312060823_8.6", "lessThan": "*", "versionType": "rpm"}]
redhat · source assertedRed HatRed Hat Virtualization 4 for Red Hat Enterprise Linux 8Direct source scope
Unaffected: 0:2.28-189.6.el8_6 to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:2.28-189.6.el8_6", "lessThan": "*", "versionType": "rpm"}]
redhat · source assertedRed HatRed Hat Virtualization 4 for Red Hat Enterprise Linux 8Direct source scope
Unaffected: 0:4.5.3-10.el8ev to before * (rpm comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "unaffected", "version": "0:4.5.3-10.el8ev", "lessThan": "*", "versionType": "rpm"}]
siemens-SADP · source assertedSiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFPDirect source scope
Affected: V3.1.5 to before * (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]
siemens-SADP · source assertedSiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFPDirect source scope
Affected: V3.1.5 to before * (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]
siemens-SADP · source assertedSiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFPDirect source scope
Affected: V3.1.5 to before * (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]
siemens-SADP · source assertedSiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFPDirect source scope
Affected: V3.1.5 to before * (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]
siemens-SADP · source assertedSiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFPDirect source scope
Affected: V3.1.5 to before * (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]
redhat · source assertedVendor unspecified by sourceProduct unspecified by sourceDirect source scope
Affected: 2.34 to before 2.39 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "2.34", "lessThan": "2.39", "versionType": "custom"}]
NVD CPE · OPERATING SYSTEMcanonicalubuntu_linuxVulnerable target · 2 assertions
Version 22.04; Version 23.04Canonical identity product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b2e702d7-f8c0-49bf-9ffb-883017076e98
  2. cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    359012f1-2c63-415a-88b8-6726a87830de
NVD CPE · OPERATING SYSTEMdebiandebian_linuxVulnerable target · 2 assertions
Version 11.0; Version 12.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fa6feec2-9f11-4643-8827-749718254fed
  2. cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    46d69dcc-ae4d-4ea5-861c-d60951444c6c
NVD CPE · OPERATING SYSTEMfedoraprojectfedoraVulnerable target · 3 assertions
Version 37; Version 38; Version 39Canonical identity product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b8edb836-4e6a-4b71-b9b2-aa3e03e0f646
  2. cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cc559b26-5dfc-4b7a-a27c-b77de755dff9
  3. cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e30d0e6f-4ae8-4284-8716-991dfa48cc5d
NVD CPE · APPLICATIONgnuglibcVulnerable target · 1 assertions
Any version (unconstrained) (>= 2.34, < 2.39)Canonical identity product-65ad58d9be95aee69193bfee5d43d39b1b0bde729796531951ee6e2f71f191cbLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 2.34; through excluding 2.39
    Match ID
    71609239-5262-473e-acce-18ae51ab184e
NVD CPE · OPERATING SYSTEMnetappbootstrap_osVulnerable target · 1 assertions
Version not applicableCanonical identity product-c79e30c6ed7acc5d7d83b9d9dce7e90bfad6e78e29ab0723ece2f95db88f8029Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    95ba156c-c977-4f0c-8dfb-3fae9cc8c02d
NVD CPE · HARDWAREnetapph300sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-5b787f6fb0dbffca7d5383cfa87cd93654a14ed60ccdd59abc2ba697fe7ead69Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f9c8c20-42eb-4ab5-bd97-212deb070c43
NVD CPE · OPERATING SYSTEMnetapph300s_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6770b6c3-732e-4e22-bf1c-2d2fd610061c

Affected-product evidence

Accepted scope and product mapping

39 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-033988d8044dec156a49f5acd0582a6c2ae55446b339ee0706acfa8ca3732935

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d85c629d-3435-40e0-97b5-6678d43f26fbed254f1b-c76e-4dcf-8d06-8d4aefc4c294f281da1e-f5a4-47ab-a5b3-70418f86869affe8bcc7-04e6-492a-a68d-fba0ccbdb77c
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-19e25a323a33d2e95ae9af9c6f5d3c68dd2ffbbccb9a61583d6723e58fce1183

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0cf6c664-dbd2-4f45-9e37-cd7e346f418057992c59-df2c-4f27-8621-90c9b367850d5e5d50e6-e703-45cb-b955-27c7ec075c96d1705254-cb51-43af-9eda-a9a19830a8fe
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
8a1e1c21-90df-4b19-a2d7-b6ffcd0f71909c302745-340c-4062-bfdc-ada9d9c80584a9f422d9-e85c-41aa-8399-4d9cc36372fd
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fd

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4c436bd3-b940-4e1d-80be-27199009d386ced4ca97-87ef-4aac-85e9-8f6b05dbc086df8ad3af-605b-40b7-9797-6b00fb5d737d
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e0be0888-6d37-42a3-aae6-672923c75ccc
Mapping establishedEvidence supported

vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b96b75b8-f8aa-4ccd-b459-85a17d6d57f4d606dbe8-82eb-4279-ab5e-7783b3c26a76
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
33235854-ada6-4099-92fd-5dc2c46b4778
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-55c79a3110dcb66254ae9d1a443809916ae8420dace75455bc0fdbcf9b04cb6a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
67ae1376-81f4-48f4-8e3f-182e3e226502
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-5b647cbf10edba654fbfb5f3617b5887cae2cdbd5242317dd9286e31cb74c078

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
dcf657b1-a4d4-4717-8237-2d7dab3b7184
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-5eabef33289b791d9a3247dd63dbd3db38ba7d17d36e7e6b97c60658d9c8e2c8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2615846f-08f0-488c-84ab-70a24a38d180
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-6077d17fbbe710b7e004df2ce68ca2ecda6ca6818bc290d21e2eb259438463ba

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e89eb08c-bb3f-4777-b828-baf35ac9f2c1
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-61b3b6bd164968eec028750df4dba593ae4b12f5cc56f27df25c3b8b443d1973

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e0d1330f-bba9-4e50-99a0-22d49a0cdb80
Mapping establishedEvidence supported

vendor-ce0a6137728edb55b880ea27b2d87517ea80c349daf77b7a40a61473d57af2da · product-65ad58d9be95aee69193bfee5d43d39b1b0bde729796531951ee6e2f71f191cb

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2a074c59-00f2-4580-a05e-23fee53c6b8a
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aae

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0b5020cb-767a-4931-ae44-6538ed578d90c3b42a83-0911-48f5-b0ef-67162150a2bcd5962bcd-319a-403b-b22f-f1b9c922ccfbf8cdf8e4-38fb-42db-90b9-f303fce514d7
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7aac0d6df4011739a665cef59b909f27ef0f5f1f717c6cf81d56972ed234ca1c

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
397e5f45-370d-475b-a36c-72776db5962a601cfed0-833e-4680-af25-3bd0ef26e7e4dde9b20c-43c3-4d26-9580-4abb2a67c273
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7aec7957e3121391f4443eb4bf8f5cc25eecb5871e114401091e27e6bcc1a414

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3ed55a38-03c7-4973-93f7-aa392d99b3f8
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7ce3aa9d5ccf00dbe1d056c7af556a21690db3daba9e04563b174c187d08062d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
44fcad13-929c-40f5-b43e-09db323dda5f
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-84030d766658c17495bdbc091c964ac1d5a4a9ac59b713addcf94ef9ae692836

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1ffc3223-bc64-45e2-95f2-6e8f607c632124fdbf0b-d761-4332-a87c-7543f54c4e6a5563ac78-4e01-48fb-bae0-6c28f30bb202d34fa27d-9ff7-4e12-997c-2b4dac48a436
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
07d18aa4-762a-481f-9035-6a1deb7cc78f78c2bcbc-b60d-41eb-8d21-76875ce855407982270d-bb85-40e1-a811-f3f23313fa15ce8db6c7-852e-42d6-8a2a-807f249e2ee6
Mapping establishedEvidence supported

vendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
38ebff26-add6-4dba-8632-825397f08cfd40db11f4-cb76-4cc1-974f-56480b57fd40
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-a29b5595b3d2a9b5738f4a4515b77cf292f7915044138b7e9367b90ddc00d096

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b503cd08-a657-4162-bc59-7f5c9bb73a48
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-aaa2bb3b641aad5c2982a3c03b2f1df21a2506ac0d8a27fdee572af90d36f203

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
18a9df61-9275-443e-907e-057b88ef4eb821817e6f-df52-46be-8162-08c956905a8dd59c0b2c-2946-4b99-bf96-a781e2e5e945e120f4db-f680-4429-a525-224010fff9a6
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
8c54f60c-2abf-48c9-87f1-29c418c37ad7
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc21aa5dab2a412aef9570b514ef0e2d033cf0ebc75eadff51969247fea73111

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
971895cc-9e8c-4952-8fb6-954c740bf5b9
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71da

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6c40d3a4-3228-4d05-b227-76be96e277dc
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-c09e1a6c06a60f75d4f5a3a91108bcb8e8b7418b4d0bcbe56608e9eba3cd934b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5b5adfe1-e2fc-4368-b257-63d996bb23aa
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481ae

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ac90dd51-840a-43fb-b2d4-c8b57bf14042
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c79e30c6ed7acc5d7d83b9d9dce7e90bfad6e78e29ab0723ece2f95db88f8029

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ca29e573-cfff-43e9-8fd3-fd3e1572334e
Mapping establishedEvidence supported

vendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
49ead562-5703-4725-9428-e2cba126b69561804efe-98c5-491f-8d6f-a019d2fabcf08961dccf-9ac1-4c9e-8551-90d69e59072e
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
95452874-3056-4911-8f81-b042c7c5e853
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-dce6b2225fa5e56152bdc66540e68bf243b135fd00684a7262378fbfd0331e98

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d790c6eb-6b32-4811-9a3e-163a09d96bee
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e3235f956d0b03fab02bfdf933b8dd4d42ff19662d2806bb68896fc45140504e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e4b086ca-423f-46cd-9cae-1254a9f64fb7
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-e8ced5e85118fc9f9f1278beed5b7649193508cd851d4301a339783d96fde4d0

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5e630a73-cb70-4a8e-9200-b6ccb72b2731a2a23f0e-7e0e-40e6-b532-b297776f1764f66fc9b8-5f70-4d6c-80e5-b0b50f8478fc
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844ee

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
384dc986-9068-4dbd-a4d5-023f54d3673def00a4fc-e374-4356-baac-f998340bcaed
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7b111608-b2b0-48d0-bd9e-c9a6999bf069
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-f3a4a3479acb68a8ee1edf6cfd717b49ddd1780419c426d1b2f5450061435237

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3ce19af2-6017-49e0-b477-84e8b9b7bcfc7df0592e-f915-4a0e-9453-4b92128063bea42c9555-27cc-4657-83b4-6ca7eb3f8d02f3b8ca96-26a6-4545-9b5f-e6a91bf83aff
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
350c45a5-4321-491b-a608-ef0b37972245
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-fbf3d7a9bdbb9b8a6bf0819e767f17a55d5349b4a51f96fdeaff8c200f17d432

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c86827ef-aa9b-45cb-8291-9bd16d09c4d0
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-fdc70f3228f57dc527b2af77480c3fca34c64a0bd200746fb82fed5c93884222

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
bd0f444a-6e3c-4ab9-887d-129a2dc5b5ec
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
18
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
214b4d79-072c-48dd-9dd8-b222d603e96123cf7c07-c74f-4fa6-a4fa-7e9e0bec869426eb16b8-06c6-4d4d-9348-92afdd062e2c2d806a63-9a71-4aeb-8c0b-b66a3d22941049c0b252-be77-4d6d-8b4f-dfa71bbb5be64f91b432-24c0-426d-9b8f-46bd7499e429535f0de2-87b4-457c-b25b-c76d4338eadc54c92565-015e-47ad-8446-c5fca3a0f329570b37a8-1cbd-4b0b-aabf-c0e96cf48e4262432e89-fa3d-4812-b93b-bb84cdc8e6aa78898975-76ff-4b3e-abd9-0267b8f23e76797000c4-5d89-4a51-af16-392199bd5135acf5a288-b460-43c8-bbc2-070d6708467ab5029af6-4b2c-4319-99c2-b8d4497a5262c8dccd5b-5b94-49bb-a515-7a4ec894aaaacd66d97f-35af-484d-879f-58f84af8aca1dac668dd-7767-4ed7-87e4-552044ca4b5cec619a42-cb8c-428d-8df9-561165d4993b

Assessments

CVSS by origin

7.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
secalert@redhat.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
redhatCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

7.8Priority eligible

redhat

CVSS 3.1 · Primary · Original assertion · rank 1

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
7.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.