CISA KEV · catalog date Nov 21, 2023 · first observed Jul 19, 2026
Evidence dossier
CVE-2023-4911
Glibc: buffer overflow in ld.so leading to privilege escalation
Exploited in the wild (CISA KEV since Nov 21, 2023). NVD reports CVSS 3.1 7.8. EPSS estimates 81.4% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
- State
- PUBLISHED
- Published
- Oct 3, 2023
- Updated
- Jul 14, 2026
- Evidence coverage
- 97%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAredhatOriginal evidence ↗
Record text: Glibc: buffer overflow in ld.so leading to privilege escalation
Inspect raw assertion
- Field
container- Value
- Glibc: buffer overflow in ld.so leading to privilege escalation
- Source dateSource date omittedFirst observed by CASCAsiemens-SADPOriginal evidence ↗
Record text: Container present
Inspect raw assertion
- Field
container- Value
- Container present
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: GNU C Library Buffer Overflow Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- GNU C Library Buffer Overflow Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 81.42% probability · 99.61th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.814220000000; percentile 0.996090000000
FIRST EPSS · score date Aug 26, 2026 · 99.6th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Glibc: buffer overflow in ld.so leading to privilege escalation
Inspect raw assertion
- Field
container- Value
- Glibc: buffer overflow in ld.so leading to privilege escalation
Container present
Inspect raw assertion
- Field
container- Value
- Container present
GNU C Library Buffer Overflow Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- GNU C Library Buffer Overflow Vulnerability
81.42% probability · 99.61th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.814220000000; percentile 0.996090000000
Applicability
Cited product scope
Grouped from 25 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
67 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:2.28-225.el8_8.6", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:2.28-225.el8_8.6", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:2.28-189.6.el8_6", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:2.34-60.el9_2.7", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:2.34-60.el9_2.7", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:2.34-28.el9_0.4", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:4.5.3-202312060823_8.6", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:2.28-189.6.el8_6", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "0:4.5.3-10.el8ev", "lessThan": "*", "versionType": "rpm"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "V3.1.5", "lessThan": "*", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.34", "lessThan": "2.39", "versionType": "custom"}]product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exactInspect raw assertions
cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b2e702d7-f8c0-49bf-9ffb-883017076e98
cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
359012f1-2c63-415a-88b8-6726a87830de
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertions
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fa6feec2-9f11-4643-8827-749718254fed
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
46d69dcc-ae4d-4ea5-861c-d60951444c6c
product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exactInspect raw assertions
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b8edb836-4e6a-4b71-b9b2-aa3e03e0f646
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cc559b26-5dfc-4b7a-a27c-b77de755dff9
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e30d0e6f-4ae8-4284-8716-991dfa48cc5d
product-65ad58d9be95aee69193bfee5d43d39b1b0bde729796531951ee6e2f71f191cbLinked exactInspect raw assertion
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 2.34; through excluding 2.39
- Match ID
71609239-5262-473e-acce-18ae51ab184e
product-c79e30c6ed7acc5d7d83b9d9dce7e90bfad6e78e29ab0723ece2f95db88f8029Linked exactInspect raw assertion
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
95ba156c-c977-4f0c-8dfb-3fae9cc8c02d
product-5b787f6fb0dbffca7d5383cfa87cd93654a14ed60ccdd59abc2ba697fe7ead69Linked exactInspect raw assertion
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f9c8c20-42eb-4ab5-bd97-212deb070c43
product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419Linked exactInspect raw assertion
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6770b6c3-732e-4e22-bf1c-2d2fd610061c
Affected-product evidence
Accepted scope and product mapping
39 canonical links · 1 source-reported links
vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-033988d8044dec156a49f5acd0582a6c2ae55446b339ee0706acfa8ca3732935
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d85c629d-3435-40e0-97b5-6678d43f26fbed254f1b-c76e-4dcf-8d06-8d4aefc4c294f281da1e-f5a4-47ab-a5b3-70418f86869affe8bcc7-04e6-492a-a68d-fba0ccbdb77cvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-19e25a323a33d2e95ae9af9c6f5d3c68dd2ffbbccb9a61583d6723e58fce1183
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0cf6c664-dbd2-4f45-9e37-cd7e346f418057992c59-df2c-4f27-8621-90c9b367850d5e5d50e6-e703-45cb-b955-27c7ec075c96d1705254-cb51-43af-9eda-a9a19830a8fevendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8a1e1c21-90df-4b19-a2d7-b6ffcd0f71909c302745-340c-4062-bfdc-ada9d9c80584a9f422d9-e85c-41aa-8399-4d9cc36372fdvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4c436bd3-b940-4e1d-80be-27199009d386ced4ca97-87ef-4aac-85e9-8f6b05dbc086df8ad3af-605b-40b7-9797-6b00fb5d737dvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e0be0888-6d37-42a3-aae6-672923c75cccvendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b96b75b8-f8aa-4ccd-b459-85a17d6d57f4d606dbe8-82eb-4279-ab5e-7783b3c26a76vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
33235854-ada6-4099-92fd-5dc2c46b4778vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-55c79a3110dcb66254ae9d1a443809916ae8420dace75455bc0fdbcf9b04cb6a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
67ae1376-81f4-48f4-8e3f-182e3e226502vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-5b647cbf10edba654fbfb5f3617b5887cae2cdbd5242317dd9286e31cb74c078
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
dcf657b1-a4d4-4717-8237-2d7dab3b7184vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-5eabef33289b791d9a3247dd63dbd3db38ba7d17d36e7e6b97c60658d9c8e2c8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2615846f-08f0-488c-84ab-70a24a38d180vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-6077d17fbbe710b7e004df2ce68ca2ecda6ca6818bc290d21e2eb259438463ba
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e89eb08c-bb3f-4777-b828-baf35ac9f2c1vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-61b3b6bd164968eec028750df4dba593ae4b12f5cc56f27df25c3b8b443d1973
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e0d1330f-bba9-4e50-99a0-22d49a0cdb80vendor-ce0a6137728edb55b880ea27b2d87517ea80c349daf77b7a40a61473d57af2da · product-65ad58d9be95aee69193bfee5d43d39b1b0bde729796531951ee6e2f71f191cb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2a074c59-00f2-4580-a05e-23fee53c6b8avendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0b5020cb-767a-4931-ae44-6538ed578d90c3b42a83-0911-48f5-b0ef-67162150a2bcd5962bcd-319a-403b-b22f-f1b9c922ccfbf8cdf8e4-38fb-42db-90b9-f303fce514d7vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7aac0d6df4011739a665cef59b909f27ef0f5f1f717c6cf81d56972ed234ca1c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
397e5f45-370d-475b-a36c-72776db5962a601cfed0-833e-4680-af25-3bd0ef26e7e4dde9b20c-43c3-4d26-9580-4abb2a67c273vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7aec7957e3121391f4443eb4bf8f5cc25eecb5871e114401091e27e6bcc1a414
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3ed55a38-03c7-4973-93f7-aa392d99b3f8vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7ce3aa9d5ccf00dbe1d056c7af556a21690db3daba9e04563b174c187d08062d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
44fcad13-929c-40f5-b43e-09db323dda5fvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-84030d766658c17495bdbc091c964ac1d5a4a9ac59b713addcf94ef9ae692836
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1ffc3223-bc64-45e2-95f2-6e8f607c632124fdbf0b-d761-4332-a87c-7543f54c4e6a5563ac78-4e01-48fb-bae0-6c28f30bb202d34fa27d-9ff7-4e12-997c-2b4dac48a436vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
07d18aa4-762a-481f-9035-6a1deb7cc78f78c2bcbc-b60d-41eb-8d21-76875ce855407982270d-bb85-40e1-a811-f3f23313fa15ce8db6c7-852e-42d6-8a2a-807f249e2ee6vendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
38ebff26-add6-4dba-8632-825397f08cfd40db11f4-cb76-4cc1-974f-56480b57fd40vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-a29b5595b3d2a9b5738f4a4515b77cf292f7915044138b7e9367b90ddc00d096
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b503cd08-a657-4162-bc59-7f5c9bb73a48vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-aaa2bb3b641aad5c2982a3c03b2f1df21a2506ac0d8a27fdee572af90d36f203
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
18a9df61-9275-443e-907e-057b88ef4eb821817e6f-df52-46be-8162-08c956905a8dd59c0b2c-2946-4b99-bf96-a781e2e5e945e120f4db-f680-4429-a525-224010fff9a6vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8c54f60c-2abf-48c9-87f1-29c418c37ad7vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc21aa5dab2a412aef9570b514ef0e2d033cf0ebc75eadff51969247fea73111
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
971895cc-9e8c-4952-8fb6-954c740bf5b9vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71da
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6c40d3a4-3228-4d05-b227-76be96e277dcvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-c09e1a6c06a60f75d4f5a3a91108bcb8e8b7418b4d0bcbe56608e9eba3cd934b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5b5adfe1-e2fc-4368-b257-63d996bb23aavendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481ae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ac90dd51-840a-43fb-b2d4-c8b57bf14042vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c79e30c6ed7acc5d7d83b9d9dce7e90bfad6e78e29ab0723ece2f95db88f8029
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ca29e573-cfff-43e9-8fd3-fd3e1572334evendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
49ead562-5703-4725-9428-e2cba126b69561804efe-98c5-491f-8d6f-a019d2fabcf08961dccf-9ac1-4c9e-8551-90d69e59072evendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
95452874-3056-4911-8f81-b042c7c5e853vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-dce6b2225fa5e56152bdc66540e68bf243b135fd00684a7262378fbfd0331e98
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d790c6eb-6b32-4811-9a3e-163a09d96beevendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e3235f956d0b03fab02bfdf933b8dd4d42ff19662d2806bb68896fc45140504e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e4b086ca-423f-46cd-9cae-1254a9f64fb7vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-e8ced5e85118fc9f9f1278beed5b7649193508cd851d4301a339783d96fde4d0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5e630a73-cb70-4a8e-9200-b6ccb72b2731a2a23f0e-7e0e-40e6-b532-b297776f1764f66fc9b8-5f70-4d6c-80e5-b0b50f8478fcvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844ee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
384dc986-9068-4dbd-a4d5-023f54d3673def00a4fc-e374-4356-baac-f998340bcaedvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7b111608-b2b0-48d0-bd9e-c9a6999bf069vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-f3a4a3479acb68a8ee1edf6cfd717b49ddd1780419c426d1b2f5450061435237
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3ce19af2-6017-49e0-b477-84e8b9b7bcfc7df0592e-f915-4a0e-9453-4b92128063bea42c9555-27cc-4657-83b4-6ca7eb3f8d02f3b8ca96-26a6-4545-9b5f-e6a91bf83affvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
350c45a5-4321-491b-a608-ef0b37972245vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-fbf3d7a9bdbb9b8a6bf0819e767f17a55d5349b4a51f96fdeaff8c200f17d432
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c86827ef-aa9b-45cb-8291-9bd16d09c4d0vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-fdc70f3228f57dc527b2af77480c3fca34c64a0bd200746fb82fed5c93884222
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bd0f444a-6e3c-4ab9-887d-129a2dc5b5ecCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 18
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
214b4d79-072c-48dd-9dd8-b222d603e96123cf7c07-c74f-4fa6-a4fa-7e9e0bec869426eb16b8-06c6-4d4d-9348-92afdd062e2c2d806a63-9a71-4aeb-8c0b-b66a3d22941049c0b252-be77-4d6d-8b4f-dfa71bbb5be64f91b432-24c0-426d-9b8f-46bd7499e429535f0de2-87b4-457c-b25b-c76d4338eadc54c92565-015e-47ad-8446-c5fca3a0f329570b37a8-1cbd-4b0b-aabf-c0e96cf48e4262432e89-fa3d-4812-b93b-bb84cdc8e6aa78898975-76ff-4b3e-abd9-0267b8f23e76797000c4-5d89-4a51-af16-392199bd5135acf5a288-b460-43c8-bbc2-070d6708467ab5029af6-4b2c-4319-99c2-b8d4497a5262c8dccd5b-5b94-49bb-a515-7a4ec894aaaacd66d97f-35af-484d-879f-58f84af8aca1dac668dd-7767-4ed7-87e4-552044ca4b5cec619a42-cb8c-428d-8df9-561165d4993bAssessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
redhat
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 7.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.