VDB

CVE-2026-14324

CVE-2026-14324 PUBLISHED CVSS 6.5 MEDIUM

Reported by redhat · Published July 1, 2026

RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 100:1.4.11-1.el10_2.1
Red HatRed Hat Enterprise Linux 90:1.4.11-1.el9_8.2
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 100:1.4.11-1.el10_2.1
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 90:1.4.11-1.el9_8.2
Red HatRed Hat Enterprise Linux 8

Timeline

  • Jul 1, 2026 CVE Published
  • Jul 2, 2026 EPSS Score
  • Jul 2, 2026 Coalition ESS Score
  • Jul 5, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 31, 2026 EPSS Score
  • Aug 31, 2026 Distribution Patch
  • Aug 31, 2026 Security Advisory
  • Aug 31, 2026 Distribution Patch
  • Aug 31, 2026 Security Advisory
  • Sep 9, 2026 EPSS Score
  • Sep 10, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›