Skip to content
COOEY

FAIL › dossier

enterprise linux

PRODUCT

· dossier confidence 50%

Enterprise Linux shows a critical security posture with 6 high-severity vulnerabilities and 1 critical flaw in core components (Samba, GLib, GnuTLS, Keylime) within a 12-month window, indicating systemic patching failures.

PROFILE
CategoryOperating SystemWhat they doEnterprise Linux is a commercial distribution of the Linux kernel, typically used in enterprise environments for its stability and security features.
SECURITY POSTURE

High vulnerability density with multiple critical and high-severity RCE flaws in core components (Samba, GLib, GnuTLS, Undertow, Keylime) within a 12-month window.

Notable failures
  • CVE-2026-1709: Critical Keylime registrar RCE
  • CVE-2026-4408: Critical Samba RCE0day
  • CVE-2026-42010: High GnuTLS RSA-PSK NUL char RCE
  • CVE-2026-33845: High GnuTLS DTLS integer underflow
  • CVE-2026-28369: High Undertow HTTP request parsing flaw
  • CVE-2026-58016: High GLib D-Bus state confusion
Patterns: Repeated unpatched edge-device RCEs; Core component vulnerabilities in Samba and GLib; Authentication bypasses in GnuTLS
FAILURE HISTORY · 9
DATEEVENTSEVSUMMARY
2026-05-28 CVE-2026-4408 critical A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed
2025-12-10 CVE-2025-14087 medium A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
2026-06-30 CVE-2026-58016 high A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> o
2026-05-07 CVE-2026-42010 high A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authe
2026-04-30 CVE-2026-33845 high A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of
2026-08-10 CVE-2026-59090 high CVE-2026-59090: A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsign
2026-03-27 CVE-2026-28369 high CVE-2026-28369: A flaw was found in Undertow. When Undertow receives an HTTP request where the f
2026-02-06 CVE-2026-1709 critical CVE-2026-1709: A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does n
2021-09-16 CVE-2021-40438 critical CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig
Open questions: What is the actual founding date of Enterprise Linux? · What is the actual headquarters location of Enterprise Linux? · What is the actual size of Enterprise Linux? · What is the actual ownership structure of Enterprise Linux? · What is the actual website of Enterprise Linux? · What is the actual security posture of Enterprise Linux?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-30 03:50:44.482717+00:00