Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1161 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 9 critical, 427 high, 594 medium, 129 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

High7.8Red Hat

High [CVE-2026-90947] Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file

A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to open a malicious preset file, potentially causing a crash or enabling arbitrary code execution. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp-devel-tools; Red Hat package: gimp-help-browser; Red Hat package: gimp-libs; Red Hat package: gimp.src.

CVE-2026-90947
Red Hat Enterprise Linux
Sep 14, 2026
High7.8Red Hat

High [CVE-2026-90949] Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mismatch

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. A remote attacker could exploit this vulnerability by crafting a malicious PSP file. Opening this file in GIMP could lead to a crash or arbitrary code execution. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp-devel-tools; Red Hat package: gimp-help-browser; Red Hat package: gimp-libs; Red Hat package: gimp.src.

CVE-2026-90949
Red Hat Enterprise Linux
Sep 14, 2026
High7.8Red Hat

High [CVE-2026-90948] Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png dimensions

A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocated, causing a heap-based buffer overflow when the decoded pixel data is written. A remote attacker could exploit this by crafting a malicious ICO file, which, when opened, could lead to arbitrary code execution or a crash. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp-devel-tools; Red Hat package: gimp-help-browser; Red Hat package: gimp-libs; Red Hat package: gimp.src.

CVE-2026-90948
Red Hat Enterprise Linux
Sep 14, 2026
Medium4.0Red Hat

Medium [CVE-2026-90996] Sssd: sssd: denial of service in nss responder via crafted zero-length requests

A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder. This flaw is rated Moderate. A local unprivileged attacker can trigger a denial of service in the SSSD NSS responder by sending a crafted request to its local UNIX socket. This impact is limited to availability and requires local access, preventing broader system compromise or remote exploitation. Red Hat severity: Moderate — CVSS 4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-191. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsss_autofs; Red Hat package: libsss_certmap; Red Hat package: libsss_nss_idmap-devel; Red Hat package: python3-libipa_hbac; and 27 more.

CVE-2026-90996
Red Hat Enterprise Linux
Sep 14, 2026
Medium5.5Red Hat

Medium [CVE-2026-90995] Sssd: sssd: local denial of service due to null pointer dereference in pam responder

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services. This Moderate impact denial of service vulnerability in SSSD's PAM responder requires local access and a non-default `pam_app_services` configuration. The default SSSD configuration is not affected. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsss_autofs; Red Hat package: libsss_certmap; Red Hat package: libsss_nss_idmap-devel; Red Hat package: python3-libipa_hbac; and 27 more.

CVE-2026-90995
Red Hat Enterprise Linux
Sep 14, 2026
Medium4.0Red Hat

Medium [CVE-2026-90994] Sssd: sssd: denial of service via malformed pam v1 requests

A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating protocol v1 and sending an empty or truncated PAM request body. This can trigger an out-of-bounds read, potentially causing the PAM responder to terminate or restart, leading to a local denial of service. Red Hat severity: Moderate — CVSS 4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsss_autofs; Red Hat package: libsss_certmap; Red Hat package: libsss_nss_idmap-devel; Red Hat package: python3-libipa_hbac; and 27 more. Affected products named by the advisory: Red Hat package: python3-libsss_nss_idmap; Red Hat package: python3-sss-murmur; Red Hat package: python3-sssdconfig; Red Hat package: sssd-ad; and 23 more.

CVE-2026-90994
Red Hat Enterprise Linux
Sep 14, 2026
Medium4.0Vendor: LowRed Hat

Medium [CVE-2026-90463] Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`)

A flaw was found in the sssd NSS responder. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure. Red Hat severity: Low — CVSS 4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsss_autofs; Red Hat package: libsss_certmap; Red Hat package: libsss_nss_idmap-devel; Red Hat package: python3-libipa_hbac; and 27 more. Affected products named by the advisory: Red Hat package: python3-libsss_nss_idmap; Red Hat package: python3-sss-murmur; Red Hat package: python3-sssdconfig; Red Hat package: sssd-ad; and 23 more.

CVE-2026-90463
Red Hat Enterprise Linux
Sep 14, 2026
High7.5Red Hat Updated

High [CVE-2026-90776] Denial of Service via crafted email headers

Denial of Service via crafted email headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Self-service automation portal 2; Red Hat package: grafana.

CVE-2026-90776
Red Hat Enterprise Linux
Sep 13, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-90781] Denial of Service via off-by-one stack buffer overflow

Denial of Service via off-by-one stack buffer overflow. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: alsa-lib.

CVE-2026-90781
Red Hat Enterprise Linux
Sep 13, 2026
Medium6.7Red Hat Updated

Medium [CVE-2022-42917] Privilege escalation via TOCTOU race condition

Privilege escalation via TOCTOU race condition. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: frr.

CVE-2022-42917
Red Hat Enterprise Linux
Sep 13, 2026
High7.8Red Hat Updated

High [CVE-2026-90616] Arbitrary code execution via missing symlink protection

Arbitrary code execution via missing symlink protection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.

CVE-2026-90616
Red Hat Enterprise Linux
Sep 12, 2026
High7.5Red Hat Updated

High [CVE-2026-87776] Denial of Service via memory leak on premature response close

Denial of Service via memory leak on premature response close. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: Gatekeeper 3; Migration Toolkit for Containers; Node HealthCheck Operator; OpenShift Lightspeed; and 29 more. Affected products named by the advisory: OpenShift Pipelines; Red Hat 3scale API Management Platform 2; Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; and 25 more.

CVE-2026-87776
Red Hat Enterprise Linux
Sep 11, 2026
High7.4Red Hat Updated

High [CVE-2026-89161] Memory corruption vulnerability in pcre2_jit_match

Memory corruption vulnerability in pcre2_jit_match. Red Hat rates this important (CVSS 7.4). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: bootc; Red Hat package: mariadb10.11; and 3 more.

CVE-2026-89161
Red Hat Enterprise Linux
Sep 11, 2026
High7.1Red Hat Updated

High [CVE-2026-78807] Security bypass via missing PMKSA validation

Security bypass via missing PMKSA validation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-322. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: wpa_supplicant.

CVE-2026-78807
Red Hat Enterprise Linux
Sep 11, 2026
Medium6.2Red Hat Updated

Medium [CVE-2026-89329] Local Denial of Service via Blocking IPC Send Operations

Local Denial of Service via Blocking IPC Send Operations. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-1322. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: device-mapper-multipath.

CVE-2026-89329
Red Hat Enterprise Linux
Sep 11, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-87859] Log Injection via unescaped double quote in log fields

Log Injection via unescaped double quote in log fields. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-117. Affected products named by the advisory: Cryostat 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 6 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Openshift Data Foundation 4; Red Hat package: linux-sgx; Red Hat package: nodejs22; and 2 more.

CVE-2026-87859
Red Hat Enterprise Linux
Sep 11, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-89158] Out-of-bounds write via integer overflow on 32-bit platforms

Out-of-bounds write via integer overflow on 32-bit platforms. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: bootc; Red Hat package: mariadb10.11; and 3 more.

CVE-2026-89158
Red Hat Enterprise Linux
Sep 11, 2026
Medium5.7Red Hat Updated

Medium [CVE-2026-89157] Out-of-bounds write via large pattern input

Out-of-bounds write via large pattern input. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 5 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: mariadb10.11; Red Hat package: mariadb11.8; Red Hat package: mingw-pcre2; and 1 more.

CVE-2026-89157
Red Hat Enterprise Linux
Sep 11, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-77159] Unsafe chown in qemuTPMEmulatorPrepareHost allows arbitrary file ownership change via symlink

Unsafe chown in qemuTPMEmulatorPrepareHost() allows arbitrary file ownership change via symlink. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-61. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: libvirt.

CVE-2026-77159
Red Hat Enterprise Linux
Sep 11, 2026
Low2.9Red Hat Updated

Low [CVE-2026-89162] Information disclosure via pcre2_serialize_encode

Information disclosure via pcre2_serialize_encode. Red Hat rates this low (CVSS 2.9). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more. Affected products named by the advisory: Red Hat package: mariadb10.11; Red Hat package: mariadb11.8.

CVE-2026-89162
Red Hat Enterprise Linux
Sep 11, 2026

← All Red Hat advisories