Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1641 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 621 high, 814 medium, 169 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
High [CVE-2026-85218] AVRCP ListPlayerAttributes double stack overflow in avrcp_list_player_attributes_rsp/avrcp_get_current_player_value
AVRCP ListPlayerAttributes double stack overflow in avrcp_list_player_attributes_rsp/avrcp_get_current_player_value. Red Hat rates this important (CVSS 7.1). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: bluez.
High [CVE-2026-84292] Authority Injection via Unvalidated Port Serialization
Authority Injection via Unvalidated Port Serialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-140. Red Hat lists fixing advisory RHSA-2026:68044 with package grafana13-1-main-13.1.3-0.6.hum1, openshift4/nmstate-console-plugin-rhel9:1789567849, rhmtc/openshift-migration-ui-rhel8:1789546373, devspaces/dashboard-rhel9:1789162884. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.1; Red Hat Ansible Automation Platform 2.2; Red Hat Hardened Images; Migration Toolkit for Applications 8; and 28 more. Affected products named by the advisory: Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; OpenShift Lightspeed; and 24 more.
High [CVE-2026-84838] Command injection in rpmuncompress via unescaped filenames passed to popen
Command injection in rpmuncompress via unescaped filenames passed to popen(). Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Hardened Images; Red Hat package: rpm.
High [CVE-2026-84837] Command Injection in `rpmbuild -t*` (`getTarSpec`) via Unescaped Tarball Path
Command Injection in `rpmbuild -t*` (`getTarSpec`) via Unescaped Tarball Path. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: rpm.
High [CVE-2026-78410] restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection
restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-367. Red Hat lists fixing advisory RHSA-2026:63162 with package util-linux-main-2.42.2-3.4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat package: util-linux.
High [CVE-2026-78408] nsenter --join-cgroup leaks root cgroup migration authority
nsenter --join-cgroup leaks root cgroup migration authority. Red Hat rates this important (CVSS 7.9). Weakness: CWE-775. Red Hat lists fixing advisory RHSA-2026:63162 with package util-linux-main-2.42.2-3.4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat package: util-linux.
High [CVE-2026-76642] failed external mount helper still runs privileged X-mount post-hooks
failed external mount helper still runs privileged X-mount post-hooks. Red Hat rates this important (CVSS 7.8). Weakness: CWE-390. Red Hat lists fixing advisory RHSA-2026:63162 with package util-linux-main-2.42.2-3.4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat package: util-linux.
High [CVE-2026-84375] Denial of Service vulnerability in YAML parsing
Denial of Service vulnerability in YAML parsing. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:68044 with package rhmtc/openshift-migration-ui-rhel8:1789546373, rhem/flightctl-ui-ocp-rhel10:1789485920, rhem/flightctl-ui-rhel9:1789486750, grafana13-2-main-13.2.1-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Migration Toolkit for Applications 8; Migration Toolkit for Containers; and 48 more. Affected products named by the advisory: Multicluster Engine for Kubernetes; Network Observability Operator; Node HealthCheck Operator; OpenShift Lightspeed; and 44 more.
High [CVE-2026-84639] Uninitialized memory in MIME parsing
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-824. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: thunderbird.
High [CVE-2026-84637] Arbitrary code execution via malicious calendar invitation attachments
Arbitrary code execution via malicious calendar invitation attachments. Red Hat rates this important (CVSS 8.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: thunderbird.
High [CVE-2026-84268] Gvfs: sftp: heap-based buffer overflow in read_reply
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution. To exploit this issue, an attacker needs a user to connect to a malicious SFTP share (for example, by clicking a crafted sftp:// link or intercepting an unverified connection), limiting its exposure. For these reasons, this vulnerability has been rated with an important severity. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) memory protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-122.
High [CVE-2026-83619] @xmldom/xmldom: xmldom: Denial of Service via crafted XML input
@xmldom/xmldom: xmldom: Denial of Service via crafted XML input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:69248 with package rhdh/rhdh-hub-rhel9:1789554285. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat package: grafana.
High [CVE-2026-83617] @xmldom/xmldom: xmldom: XML injection via embedded line terminator in element/attribute names
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and attribute name checks use the anchored QName_exact expression produced by reg() in lib/grammar.js, which inherits the multiline flag. A name with a valid first line followed by U+000A, U+000D, U+2028, or U+2029 and breakout markup therefore passes validation and is emitted verbatim in element start and end tags or attribute names. This bypasses the strict-serialization checks introduced for the earlier element-name and attribute-name injection advisories, while the default serialization path remains outside the strict guarantee. This issue is fixed in @xmldom/xmldom version 0.9.12. A flaw was found in the @xmldom/xmldom library. The requireWellFormed validation for XML element and attribute names can be bypassed by embedding specific line terminator characters. This allows an attacker to inject malformed XML into the document, potentially leading to XML injection vulnerabilities and bypassing security checks designed to prevent such issues. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-91. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-83616] XML Structure Injection via Unvalidated Processing Instruction Targets
XML Structure Injection via Unvalidated Processing Instruction Targets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-91. Red Hat lists fixing advisory RHSA-2026:69248 with package rhdh/rhdh-hub-rhel9:1789554285. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat package: grafana.
High [CVE-2026-83615] @xmldom/xmldom: xmldom: Denial of Service via quadratic memory consumption
@xmldom/xmldom: xmldom: Denial of Service via quadratic memory consumption. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:69248 with package rhdh/rhdh-hub-rhel9:1789554285. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat package: grafana.
High [CVE-2026-83614] @xmldom/xmldom: xmldom: Denial of Service via quadratic-time XML parsing
@xmldom/xmldom: xmldom: Denial of Service via quadratic-time XML parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:69248 with package rhdh/rhdh-hub-rhel9:1789554285. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat package: grafana.
High [CVE-2026-83613] @xmldom/xmldom: xmldom: Denial of Service due to quadratic-time attribute processing
@xmldom/xmldom: xmldom: Denial of Service due to quadratic-time attribute processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:69248 with package rhdh/rhdh-hub-rhel9:1789554285. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat package: grafana.
High [CVE-2026-83609] @xmldom/xmldom: xmldom: Markup injection via embedded line terminators in XML names
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in lib/grammar.js compiles the anchored QName_exact validator with the multiline flag, so ^ and $ validate only one line instead of the complete name. createElementNS, createAttributeNS, createDocumentType, and createAttribute consequently accept a malformed XML name whose first line is valid and whose later text injects markup when serialized through either the default path or requireWellFormed: true. The triggering ECMAScript line terminators are U+000A, U+000D, U+2028, and U+2029. This issue is fixed in @xmldom/xmldom version 0.9.12. A flaw was found in xmldom. The XML DOM (Document Object Model) parser incorrectly validates XML names, allowing embedded line terminators. This vulnerability enables an attacker to inject additional markup into XML documents during serialization, potentially leading to malformed XML output. This is an Important flaw in the xmldom library, affecting Red Hat products that process XML documents using this component. The vulnerability allows for markup injection due to insufficient validation of XML names containing line terminators. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-91.
High [CVE-2026-83607] Cross-site scripting via unvalidated element name injection
Cross-site scripting via unvalidated element name injection. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:69248 with package rhdh/rhdh-hub-rhel9:1789554285. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat package: grafana.
High [CVE-2026-83605] @xmldom/xmldom: xmldom: Attribute injection allows client-side script execution
@xmldom/xmldom: xmldom: Attribute injection allows client-side script execution. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:69248 with package rhdh/rhdh-hub-rhel9:1789554285. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat package: grafana.