Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1641 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 621 high, 814 medium, 169 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

Medium4.3Red Hat

Medium [CVE-2026-61911] Sieve fileinto mailbox existence oracle

Sieve fileinto mailbox existence oracle. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-497. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: cyrus-imapd.

CVE-2026-61911
Red Hat Enterprise Linux
Sep 10, 2026
Medium4.2Red Hat

Medium [CVE-2026-61910] Mailbox/set let sharee change special-use role on shared mailboxes

Mailbox/set let sharee change special-use role on shared mailboxes. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: cyrus-imapd.

CVE-2026-61910
Red Hat Enterprise Linux
Sep 10, 2026
Medium5.0Red Hat

Medium [CVE-2026-61909] CalDAV/CardDAV multiget bypasses per-href ACL

CalDAV/CardDAV multiget bypasses per-href ACL. Red Hat rates this moderate (CVSS 5). Weakness: CWE-420. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: cyrus-imapd.

CVE-2026-61909
Red Hat Enterprise Linux
Sep 10, 2026
Medium4.3Red Hat

Medium [CVE-2026-61908] JMAP email-header blob ID out-of-bounds index

JMAP email-header blob ID out-of-bounds index. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: cyrus-imapd.

CVE-2026-61908
Red Hat Enterprise Linux
Sep 10, 2026
Medium4.3Red Hat

Medium [CVE-2026-61907] JMAP snooze bypasses destination-mailbox ACL

JMAP snooze bypasses destination-mailbox ACL. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: cyrus-imapd.

CVE-2026-61907
Red Hat Enterprise Linux
Sep 9, 2026
Medium4.3Red Hat

Medium [CVE-2026-87602] ANGLE in Google Chrome: Information disclosure via crafted HTML page

ANGLE in Google Chrome: Information disclosure via crafted HTML page. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: webkitgtk4; and 1 more. Affected products named by the advisory: Red Hat package: webkit2gtk3.

CVE-2026-87602
Red Hat Enterprise Linux
Sep 9, 2026
Medium4.3Red Hat

Medium [CVE-2026-87875] Heap out-of-bounds read in cupsUTF32ToUTF8 via missing source-length bound

Heap out-of-bounds read in cupsUTF32ToUTF8() via missing source-length bound. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:66600 with package cups-main-2.4.19-4.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: cups.

CVE-2026-87875
Red Hat Enterprise Linux
Sep 9, 2026
Medium6.8Red Hat

Medium [CVE-2026-74859] Gnome-tweaks: path traversal in theme installer

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using../ path traversal, absolute paths, or symlink entries. This vulnerability is rated Moderate because it requires a user to actively install a specially crafted GNOME Shell theme via the `gnome-tweaks` utility. Exploitation is not possible without user interaction and the deliberate installation of a malicious theme, limiting the attack surface in typical Red Hat desktop environments. Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H). Weakness: CWE-22. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gnome-tweaks.

CVE-2026-74859
Red Hat Enterprise Linux
Sep 8, 2026
Medium5.3Red Hat

Medium [CVE-2026-86469] TOCTOU Symlink Race in `G_FILE_CREATE_REPLACE_DESTINATION` Fallback Path

TOCTOU Symlink Race in `G_FILE_CREATE_REPLACE_DESTINATION` Fallback Path. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: glib2; and 1 more.

CVE-2026-86469
Red Hat Enterprise Linux
Sep 7, 2026
Medium6.8Red Hat

Medium [CVE-2026-78254] Arbitrary file write via path traversal in ftp and scp tasks

Arbitrary file write via path traversal in ftp and scp tasks. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-22. Affected products named by the advisory: Migration Toolkit for Applications 8; OpenShift Developer Tools and Services; Red Hat build of Apicurio Registry 3; Red Hat Enterprise Linux 10; and 23 more. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 19 more.

CVE-2026-78254
Red Hat Enterprise Linux
Sep 7, 2026
Medium6.2Red Hat

Medium [CVE-2026-86315] Out-of-bounds write leads to Denial of Service

Out-of-bounds write leads to Denial of Service. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-787. Affected products named by the advisory: OpenShift Lightspeed; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Update Service; and 4 more.

CVE-2026-86315
Red Hat Enterprise Linux
Sep 7, 2026
Medium6.5Red Hat

Medium [CVE-2026-19931] Information disclosure via incorrect connection reuse with Negotiate authentication

Information disclosure via incorrect connection reuse with Negotiate authentication. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-488. Red Hat lists fixing advisory RHSA-2026:63161 with package curl-main-8.22.0-0.1.hum1, rust-main-1.98.0-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; and 5 more.

CVE-2026-19931
Red Hat Enterprise Linux
Sep 6, 2026
Medium5.0Red Hat

Medium [CVE-2026-18238] Information disclosure via out-of-bounds read in rpcap client

Information disclosure via out-of-bounds read in rpcap client. Red Hat rates this moderate (CVSS 5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.

CVE-2026-18238
Red Hat Enterprise Linux
Sep 5, 2026
Medium4.3Red Hat

Medium [CVE-2026-18313] Denial of Service via memory leak in rpcapd

Denial of Service via memory leak in rpcapd. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.

CVE-2026-18313
Red Hat Enterprise Linux
Sep 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-6554] Denial of Service via infinite loop in BPF interpreter

Denial of Service via infinite loop in BPF interpreter. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.

CVE-2026-6554
Red Hat Enterprise Linux
Sep 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-6244] Denial of Service via crafted BPF filter program

Denial of Service via crafted BPF filter program. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-369. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.

CVE-2026-6244
Red Hat Enterprise Linux
Sep 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-31911] Denial of Service via crafted BPF opcode

Denial of Service via crafted BPF opcode. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.

CVE-2026-31911
Red Hat Enterprise Linux
Sep 5, 2026
Medium6.1Red Hat

Medium [CVE-2026-31912] Denial of service via crafted BPF filter program

Denial of service via crafted BPF filter program. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.

CVE-2026-31912
Red Hat Enterprise Linux
Sep 5, 2026
Medium6.5Red Hat

Medium [CVE-2026-53769] Unauthorized attachment modification via authorization bypass

Unauthorized attachment modification via authorization bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-639. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift GitOps; and 2 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat package: golang.

CVE-2026-53769
Red Hat Enterprise Linux
Sep 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-18149] Denial of Service due to orphaned response body in retry handler

Denial of Service due to orphaned response body in retry handler. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-911. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; OpenShift Pipelines; Red Hat Build of Podman Desktop; Red Hat Developer Hub; and 6 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; and 2 more.

CVE-2026-18149
Red Hat Enterprise Linux
Sep 4, 2026

← All Red Hat advisories