Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1641 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 621 high, 814 medium, 169 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
Medium [CVE-2026-84890] Denial of Service via unbounded decompression of compressed responses
Denial of Service via unbounded decompression of compressed responses. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Medium [CVE-2026-84933] Cross-user cookie disclosure via Set-Cookie caching
Cross-user cookie disclosure via Set-Cookie caching. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-524. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Medium [CVE-2026-84947] Response truncation and connection termination
Response truncation and connection termination. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-130. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Medium [CVE-2026-85014] Denial of Service via WebSocketStream unclean close
Denial of Service via WebSocketStream unclean close. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-390. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Medium [CVE-2026-85024] Denial of Service via unhandled error in WebSocket permessage-deflate decompression
Denial of Service via unhandled error in WebSocket permessage-deflate decompression. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-431. Red Hat lists fixing advisory RHSA-2026:63782 with package nodejs26-main-26.8.2-0.1.hum1, grafana12-4-main-12.4.9-0.6.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.
Medium [CVE-2026-85534] HTTP/2 client crash in on_data_source_read_callback when SETTINGS INITIAL_WINDOW_SIZE shrinks during deferred body read
HTTP/2 client crash in on_data_source_read_callback when SETTINGS INITIAL_WINDOW_SIZE shrinks during deferred body read. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: libsoup3.
Medium [CVE-2026-81666] integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems
integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: corosync.
Medium [CVE-2026-85505] Denial of Service via stack-based buffer over-read in ipmi-oem
Denial of Service via stack-based buffer over-read in ipmi-oem. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freeipmi.
Medium [CVE-2026-84185] General JSON JWS kid binding bypass during JWKSet verification
General JSON JWS kid binding bypass during JWKSet verification. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-347. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: python-jwcrypto.
Medium [CVE-2026-85062] Denial of Service via oversized malformed color strings
Denial of Service via oversized malformed color strings. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 5 more. Affected products named by the advisory: Self-service automation portal 2; Red Hat package: grafana-pcp; Red Hat package: dotnet6.0; Red Hat package: dotnet7.0; and 1 more.
Medium [CVE-2026-19475] OOM DoS via $__timeGroup macro
OOM DoS via $__timeGroup macro. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-400. Affected products named by the advisory: Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; and 6 more. Affected products named by the advisory: Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 10; and 2 more.
Medium [CVE-2026-71224] stack overflow via alloca(i_height) in metadata walk
stack overflow via alloca(i_height) in metadata walk. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: gfs2-utils.
Medium [CVE-2026-71222] heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing
heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: gfs2-utils.
Medium [CVE-2026-71219] stack overflow via alloca(1<<di_depth) in hash table traversal
A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta. This vulnerability is assessed as Moderate impact because the alloca-based stack exhaustion results in a process crash (SIGSEGV) rather than controlled memory corruption. Exploitation requires local access and user interaction: an administrator must run a gfs2-utils tool (fsck.gfs2, gfs2_edit, or savemeta) on a crafted GFS2 filesystem image. The vulnerability does not affect the kernel GFS2 driver, which validates di_depth in gfs2_dinode_in(). Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gfs2-utils.
Medium [CVE-2026-85089] Information disclosure via uninitialized heap memory in Save Session Info PDU
Information disclosure via uninitialized heap memory in Save Session Info PDU. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
Medium [CVE-2026-85090] Heap Out-of-Bounds Read in AVC444 Chroma Combine
Heap Out-of-Bounds Read in AVC444 Chroma Combine. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
Medium [CVE-2026-78662] Denial of Service via channel request flooding
Denial of Service via channel request flooding. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-833. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; Confidential Compute Attestation; and 34 more. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Multicluster Engine for Kubernetes; OpenShift API for Data Protection; and 30 more.
Medium [CVE-2026-56855] Denial of Service via crafted messages
Denial of Service via crafted messages. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-833. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; Confidential Compute Attestation; and 34 more. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Multicluster Engine for Kubernetes; OpenShift API for Data Protection; and 30 more.
Medium [CVE-2026-84640] One byte overflow read in mail parser
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. A remote attacker could exploit this vulnerability by sending a maliciously constructed mail header. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: thunderbird.
Medium [CVE-2026-84373] Arbitrary File Read via Path Traversal in HMR WebSocket
Arbitrary File Read via Path Traversal in HMR WebSocket. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat Build of Keycloak; Red Hat Build of Podman Desktop; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Trusted Artifact Signer; and 1 more.