Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1641 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 621 high, 814 medium, 169 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

High7.5Red Hat

High [CVE-2026-84143] Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15

Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-84143
Red Hat Enterprise Linux
Sep 1, 2026
High8.8Red Hat

High [CVE-2026-84125] Arbitrary code execution via use-after-free in DOM: Core & HTML

Arbitrary code execution via use-after-free in DOM: Core & HTML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: firefox.

CVE-2026-84125
Red Hat Enterprise Linux
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84124] Use-after-free in the DOM: Core & HTML component

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2026:67129, RHSA-2026:68549, RHSA-2026:67133, RHSA-2026:70642. Affected products named by the advisory: Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-84124
Red Hat Enterprise Linux
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84122] Use-after-free in the Audio/Video component

Use-after-free in the Audio/Video component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-84122
Red Hat Enterprise Linux
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84145] Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40

Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-84145
Red Hat Enterprise Linux
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84121] Sandbox escape due to use-after-free in the DOM: Security component

Sandbox escape due to use-after-free in the DOM: Security component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-84121
Red Hat Enterprise Linux
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84120] Use-after-free in the Audio/Video component

Use-after-free in the Audio/Video component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: firefox.

CVE-2026-84120
Red Hat Enterprise Linux
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84119] Sandbox escape due to use-after-free in the DOM: Navigation component

Sandbox escape due to use-after-free in the DOM: Navigation component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-84119
Red Hat Enterprise Linux
Sep 1, 2026
High7.0Red Hat

High [CVE-2026-13732] Gdb: gdb: out-of-bounds write in stabs parser read_member_functions via crafted elf

A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function list is copied to its final allocated array. An attacker can craft an ELF binary with malicious.stab and.stabstr sections that triggers this out-of-bounds write when a user opens the file in GDB and performs any symbol-inspection operation such as setting a breakpoint. The inferior process does not need to be executed. Under controlled conditions, this was demonstrated to achieve execution of arbitrary commands within the GDB process. While GCC removed STABS emitting support in GCC 13 and GDB deprecated STABS parsing in GDB 17, all deployed GDB versions parse STABS data without user opt-in. An attacker can embed STABS sections in any ELF binary, including one compiled with DWARF debug information, and GDB will parse both. The vulnerability requires the user to open the crafted binary in GDB and issue a symbol-inspection command, which is normal GDB usage. Red Hat severity: Important — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-13732
Red Hat Enterprise Linux
Aug 31, 2026
High7.5Red Hat

High [CVE-2026-82417] Denial of Service via improper validation in stringify function

Denial of Service via improper validation in stringify function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. Red Hat lists fixing advisory RHSA-2026:63164 with package grafana13-1-main-13.1.3-0.4.hum1, grafana13-2-main-13.2.1-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cost Management On Premise; Cryostat 4; Migration Toolkit for Applications 8; and 44 more. Affected products named by the advisory: Migration Toolkit for Containers; Node HealthCheck Operator; OpenShift Lightspeed; OpenShift Pipelines; and 40 more.

CVE-2026-82417
Red Hat Enterprise Linux
Aug 29, 2026
High7.4Red Hat

High [CVE-2026-73208] Authentication bypass via incorrect OAuth2 token validation

Authentication bypass via incorrect OAuth2 token validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-303. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-73208
Red Hat Enterprise Linux
Aug 28, 2026
High7.5Red Hat

High [CVE-2026-42391] Denial of Service via IMAP ID command with excessive parameters

Denial of Service via IMAP ID command with excessive parameters. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-42391
Red Hat Enterprise Linux
Aug 28, 2026
High7.5Red Hat

High [CVE-2026-40019] Denial of Service via truncated quoted argument in ManageSieve

Denial of Service via truncated quoted argument in ManageSieve. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-40019
Red Hat Enterprise Linux
Aug 28, 2026
High7.4Red Hat

High [CVE-2026-40018] MySQL multi-byte escaping wrong

MySQL multi-byte escaping wrong. Red Hat rates this important (CVSS 7.4). Weakness: CWE-89. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-40018
Red Hat Enterprise Linux
Aug 28, 2026
High7.5Red Hat

High [CVE-2026-33605] Denial of Service in ManageSieve login process

Denial of Service in ManageSieve login process. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-33605
Red Hat Enterprise Linux
Aug 28, 2026
High7.1Red Hat

High [CVE-2026-33263] Denial of Service and potential message duplication via connection limit exhaustion

Denial of Service and potential message duplication via connection limit exhaustion. Red Hat rates this important (CVSS 7.1). Weakness: CWE-910. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-33263
Red Hat Enterprise Linux
Aug 28, 2026
High7.5Red Hat

High [CVE-2026-27852] Denial of service via crafted email headers

Denial of service via crafted email headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-27852
Red Hat Enterprise Linux
Aug 28, 2026
High7.5Red Hat

High [CVE-2026-5680] Undertow-core: undertow: denial of service via websocket permessage-deflate processing

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Data Grid 8; Red Hat Enterprise Linux 9; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Process Automation 7; Red Hat Single Sign-On 7. Will not fix / out of support: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Process Automation 7; Red Hat Single Sign-On 7. Red Hat fixing advisory: RHSA-2026:70230, RHSA-2026:70228, RHSA-2026:70229. Affected products named by the advisory: Red Hat package: resteasy.

CVE-2026-5680
Red Hat Enterprise Linux
Aug 27, 2026
High7.5Red Hat

High [CVE-2026-78002] Denial of service via heap buffer overflow in RainerScript replace function

A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system. Red Hat Enterprise Linux systems configured to receive remote syslog messages are susceptible to this issue, potentially impacting logging availability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-131. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Update Infrastructure 5; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8. Red Hat lists Red Hat Enterprise Linux 6 as not affected. Red Hat fixing advisory: RHSA-2026:69541, RHSA-2026:69540, RHSA-2026:71603. Affected products named by the advisory: Red Hat package: rsyslog.

CVE-2026-78002
Red Hat Enterprise Linux
Aug 27, 2026
High7.5Red Hat

High [CVE-2026-80212] resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses

resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:62563 with package ruby4-0-main-4.0.6-37.2.hum1, ruby4-0-main-4.0.6-37.3.hum1, ruby3-4-main-3.4.10-31.6.hum1, ruby3-3-main-3.3.10-23.5.hum1. Affected products named by the advisory: Red Hat Hardened Images; Lightspeed Core; Red Hat 3scale API Management Platform 2; Red Hat Enterprise Linux 10; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-80212
Red Hat Enterprise Linux
Aug 27, 2026

← All Red Hat advisories