Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1161 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 9 critical, 427 high, 594 medium, 129 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
High [CVE-2026-90947] Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file
A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to open a malicious preset file, potentially causing a crash or enabling arbitrary code execution. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp-devel-tools; Red Hat package: gimp-help-browser; Red Hat package: gimp-libs; Red Hat package: gimp.src.
High [CVE-2026-90949] Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mismatch
A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. A remote attacker could exploit this vulnerability by crafting a malicious PSP file. Opening this file in GIMP could lead to a crash or arbitrary code execution. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp-devel-tools; Red Hat package: gimp-help-browser; Red Hat package: gimp-libs; Red Hat package: gimp.src.
High [CVE-2026-90948] Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png dimensions
A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocated, causing a heap-based buffer overflow when the decoded pixel data is written. A remote attacker could exploit this by crafting a malicious ICO file, which, when opened, could lead to arbitrary code execution or a crash. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp-devel-tools; Red Hat package: gimp-help-browser; Red Hat package: gimp-libs; Red Hat package: gimp.src.
Medium [CVE-2026-90996] Sssd: sssd: denial of service in nss responder via crafted zero-length requests
A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder. This flaw is rated Moderate. A local unprivileged attacker can trigger a denial of service in the SSSD NSS responder by sending a crafted request to its local UNIX socket. This impact is limited to availability and requires local access, preventing broader system compromise or remote exploitation. Red Hat severity: Moderate — CVSS 4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-191. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsss_autofs; Red Hat package: libsss_certmap; Red Hat package: libsss_nss_idmap-devel; Red Hat package: python3-libipa_hbac; and 27 more.
Medium [CVE-2026-90995] Sssd: sssd: local denial of service due to null pointer dereference in pam responder
A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services. This Moderate impact denial of service vulnerability in SSSD's PAM responder requires local access and a non-default `pam_app_services` configuration. The default SSSD configuration is not affected. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsss_autofs; Red Hat package: libsss_certmap; Red Hat package: libsss_nss_idmap-devel; Red Hat package: python3-libipa_hbac; and 27 more.
Medium [CVE-2026-90994] Sssd: sssd: denial of service via malformed pam v1 requests
A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating protocol v1 and sending an empty or truncated PAM request body. This can trigger an out-of-bounds read, potentially causing the PAM responder to terminate or restart, leading to a local denial of service. Red Hat severity: Moderate — CVSS 4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsss_autofs; Red Hat package: libsss_certmap; Red Hat package: libsss_nss_idmap-devel; Red Hat package: python3-libipa_hbac; and 27 more. Affected products named by the advisory: Red Hat package: python3-libsss_nss_idmap; Red Hat package: python3-sss-murmur; Red Hat package: python3-sssdconfig; Red Hat package: sssd-ad; and 23 more.
Medium [CVE-2026-90463] Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`)
A flaw was found in the sssd NSS responder. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure. Red Hat severity: Low — CVSS 4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsss_autofs; Red Hat package: libsss_certmap; Red Hat package: libsss_nss_idmap-devel; Red Hat package: python3-libipa_hbac; and 27 more. Affected products named by the advisory: Red Hat package: python3-libsss_nss_idmap; Red Hat package: python3-sss-murmur; Red Hat package: python3-sssdconfig; Red Hat package: sssd-ad; and 23 more.
High [CVE-2026-90776] Denial of Service via crafted email headers
Denial of Service via crafted email headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Self-service automation portal 2; Red Hat package: grafana.
Medium [CVE-2026-90781] Denial of Service via off-by-one stack buffer overflow
Denial of Service via off-by-one stack buffer overflow. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: alsa-lib.
Medium [CVE-2022-42917] Privilege escalation via TOCTOU race condition
Privilege escalation via TOCTOU race condition. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: frr.
High [CVE-2026-90616] Arbitrary code execution via missing symlink protection
Arbitrary code execution via missing symlink protection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.
High [CVE-2026-87776] Denial of Service via memory leak on premature response close
Denial of Service via memory leak on premature response close. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: Gatekeeper 3; Migration Toolkit for Containers; Node HealthCheck Operator; OpenShift Lightspeed; and 29 more. Affected products named by the advisory: OpenShift Pipelines; Red Hat 3scale API Management Platform 2; Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; and 25 more.
High [CVE-2026-89161] Memory corruption vulnerability in pcre2_jit_match
Memory corruption vulnerability in pcre2_jit_match. Red Hat rates this important (CVSS 7.4). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: bootc; Red Hat package: mariadb10.11; and 3 more.
High [CVE-2026-78807] Security bypass via missing PMKSA validation
Security bypass via missing PMKSA validation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-322. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: wpa_supplicant.
Medium [CVE-2026-89329] Local Denial of Service via Blocking IPC Send Operations
Local Denial of Service via Blocking IPC Send Operations. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-1322. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: device-mapper-multipath.
Medium [CVE-2026-87859] Log Injection via unescaped double quote in log fields
Log Injection via unescaped double quote in log fields. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-117. Affected products named by the advisory: Cryostat 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 6 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Openshift Data Foundation 4; Red Hat package: linux-sgx; Red Hat package: nodejs22; and 2 more.
Medium [CVE-2026-89158] Out-of-bounds write via integer overflow on 32-bit platforms
Out-of-bounds write via integer overflow on 32-bit platforms. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: bootc; Red Hat package: mariadb10.11; and 3 more.
Medium [CVE-2026-89157] Out-of-bounds write via large pattern input
Out-of-bounds write via large pattern input. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 5 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: mariadb10.11; Red Hat package: mariadb11.8; Red Hat package: mingw-pcre2; and 1 more.
Medium [CVE-2026-77159] Unsafe chown in qemuTPMEmulatorPrepareHost allows arbitrary file ownership change via symlink
Unsafe chown in qemuTPMEmulatorPrepareHost() allows arbitrary file ownership change via symlink. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-61. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: libvirt.
Low [CVE-2026-89162] Information disclosure via pcre2_serialize_encode
Information disclosure via pcre2_serialize_encode. Red Hat rates this low (CVSS 2.9). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more. Affected products named by the advisory: Red Hat package: mariadb10.11; Red Hat package: mariadb11.8.