Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories
1233 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 789 high, 388 medium, 25 low.
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux Red Hat Enterprise Linux advisories
Medium [CVE-2026-43740] Maliciously crafted web content may disclose process memory
Maliciously crafted web content may disclose process memory. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-15308] CPU Denial of Service in HTML parser via repeated unterminated markup declarations
CPU Denial of Service in HTML parser via repeated unterminated markup declarations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:44481 with package discovery/discovery-ui-rhel9:1784821750, python3-12-main-3.12.13-3.5.hum1, python3.12-0:3.12.13-3.el8_10, python3.12-0:3.12.13-3.el9_8.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-59899] Memory exhaustion in netty-codec-http (decompression bomb)
A flaw was found in the Netty netty-codec-http component. A remote attacker can send HTTP requests containing highly compressed data. This can lead to memory exhaustion and a denial of service (DoS), making the service unavailable to legitimate users. This is an Important vulnerability in Netty's HTTP decoder, which could lead to a denial of service. Red Hat products utilizing `netty-codec-http` are susceptible to memory exhaustion when processing specially crafted, highly compressed HTTP payloads. This allows a remote attacker to trigger excessive memory allocation, impacting system availability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-409. Affected products named by the advisory: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33; Red Hat build of Quarkus 3.27.4.SP3; Red Hat build of Quarkus 3.33.2.SP3; Cryostat 4; and 19 more.
Medium [CVE-2026-59856] Arbitrary code execution via crafted PHP file in omni-completion
Arbitrary code execution via crafted PHP file in omni-completion. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:47982 with package vim-2:8.2.2637-26.el9_8.13, vim-main-9.2.780-1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 9.
Medium [CVE-2026-59858] Arbitrary command execution via crafted tags file in C omni-completion
Arbitrary command execution via crafted tags file in C omni-completion. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:47982 with package vim-2:8.2.2637-26.el9_8.13, vim-main-9.2.780-1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 9.
Medium [CVE-2026-59921] CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
A flaw was found in Netty's HttpPostRequestEncoder, a widely used Java networking library component responsible for constructing multipart HTTP request bodies. The issue arises because user-supplied filenames and field names are directly embedded into Content-Disposition MIME headers without any validation or sanitization of CRLF (\r\n) characters. Since MIME headers are delimited by CRLF sequences, an attacker who controls the filename in a multipart upload can inject arbitrary MIME headers into the request body. This may lead to limited Content-Type spoofing or header manipulation against middleware or storage layers processing the request, though the practical impact is constrained by the context in which Netty is deployed. Moderate: A CRLF injection flaw in the Netty Java networking library's multipart message encoder allows remote attackers with low privileges to inject arbitrary MIME headers. This can lead to Content-Type spoofing, stored cross-site scripting, or manipulation of downstream application logic, compromising data confidentiality and integrity without user interaction. Red Hat severity: Moderate — CVSS 5.7 (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-93. Affected products named by the advisory: Red Hat build of Quarkus 3.27.4.SP3; Red Hat build of Quarkus 3.33.2.SP3; Cryostat 4; OpenShift Serverless; and 19 more.
Medium [CVE-2026-59898] Protocol version confusion in netty-codec-http (WebSocket)
A flaw was found in netty-codec-http. The WebSocket handshaker in this component fails to properly validate protocol version information during the WebSocket upgrade process. A remote attacker can exploit this vulnerability by manipulating the WebSocket handshake, leading to a bypass of security checks or the negotiation of unexpected protocol versions. This could potentially enable protocol-level attacks. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-358. Affected Red Hat products: Red Hat build of Quarkus 3.27.4.SP3; Red Hat build of Quarkus 3.33.2.SP3; Cryostat 4; OpenShift Serverless; Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat Data Grid 8; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; Red Hat Single Sign-On 7; streams for Apache Kafka 2; streams for Apache Kafka 3. Red Hat fixing advisory: RHSA-2026:47189, RHSA-2026:47172.
Medium [CVE-2026-59900] Improper header neutralization in netty-codec-http2
A flaw was found in Netty's netty-codec-http2 component. The HTTP/2 encoder does not properly handle special characters in HTTP headers. This vulnerability allows a remote attacker to craft specific HTTP/2 requests, leading to HTTP response splitting and header injection attacks. Such attacks can enable an attacker to manipulate web content or inject malicious headers. This Moderate impact flaw in Netty's HTTP/2 encoder allows attackers to inject arbitrary header content via specially crafted HTTP/2 requests. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N). Affected Red Hat products: Red Hat build of Quarkus 3.27.4.SP3; Red Hat build of Quarkus 3.33.2.SP3; Cryostat 4; OpenShift Serverless; Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat Data Grid 8; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces; Red Hat Single Sign-On 7; streams for Apache Kafka 2; streams for Apache Kafka 3. Red Hat fixing advisory: RHSA-2026:47189, RHSA-2026:47172.
High [CVE-2026-39822] Go os.Root: Symlink following vulnerability allows directory traversal
Go os.Root: Symlink following vulnerability allows directory traversal. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:44624 with package podman-6:5.8.2-5.el9_8, rhosdt/tempo-query-rhel9:1784775793, golang-0:1.26.5-1.el10_2, buildah-2:1.43.1-4.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-55999] glamor Font Atlas Heap Buffer Overflow
glamor Font Atlas Heap Buffer Overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:38486 with package xorg-x11-server-0:1.20.11-34.el9_8.3, xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.3, xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.3, xorg-x11-server-0:1.20.11-28.el8_10.3. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-56001] BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow. Red Hat rates this important (CVSS 7.3). Red Hat lists fixing advisory RHSA-2026:47079 with package libXfont2-0:2.0.3-2.el8_10.1, libXfont2-0:2.0.6-5.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-56002] PCF Font Parsing Heap Buffer Overflow
PCF Font Parsing Heap Buffer Overflow. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47079 with package libXfont2-0:2.0.3-2.el8_10.1, libXfont2-0:2.0.6-5.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-59691] rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer
rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer. Red Hat rates this important (CVSS 7.1). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47180 with package gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2.6. Affected product named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-59692] DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback
DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback. Red Hat rates this important (CVSS 7.5). Weakness: CWE-121. Red Hat lists fixing advisory RHSA-2026:47180 with package gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2.6. Affected product named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-56003] computeProps Property Buffer Heap Buffer Overflow
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:47103.
Medium [CVE-2026-56000] GLX contextTags Use-After-Free in CommonMakeCurrent
GLX contextTags Use-After-Free in CommonMakeCurrent(). Red Hat rates this important (CVSS 6.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:38490 with package xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.3, xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.3. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-11610] Heap buffer overflow in sasl_io_recv via padded SASL UNBIND
Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:36209 with package redhat-ds:11-8060020260702180044.0ca98e7e, 389-ds:1.4-8060020260626130540.824efc52, redhat-ds:12-9040020260703055735.1674d574, redhat-ds:11-8100020260702145313.37ed7c03. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.
High [CVE-2026-14474] sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation
sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1188. Red Hat lists fixing advisory RHSA-2026:42122 with package sssd-0:2.9.4-5.el8_10.5, sssd-0:2.9.8-4.el9_8.1, sssd-0:2.12.0-3.el10_2.1, sssd-0:2.10.2-3.el10_0.5. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-14476] GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass
GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass. Red Hat rates this moderate (CVSS 8). Weakness: CWE-23. Red Hat lists fixing advisory RHSA-2026:42122 with package sssd-0:2.9.4-5.el8_10.5, sssd-0:2.9.8-4.el9_8.1, sssd-0:2.12.0-3.el10_2.1, sssd-0:2.10.2-3.el10_0.5. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-58384] Gimp: gimp: integer overflow in read_rle_channel
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. Affected product named by the advisory: Red Hat Enterprise Linux 9.