Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1641 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 621 high, 814 medium, 169 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

High7.3Red Hat

High [CVE-2026-52492] Arbitrary code execution via crafted TIFF image

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image A flaw was found in libtiff. This could potentially allow for arbitrary code execution. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:53467. Affected products named by the advisory: Red Hat package: libtiff.

CVE-2026-52492
Red Hat Enterprise Linux
Aug 24, 2026
High7.3Red Hat

High [CVE-2026-52490] Arbitrary code execution via process_command_opts function

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c A flaw was found in libtiff. This could lead to a complete compromise of the affected system. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Hardened Images; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:69095, RHSA-2026:53467. Affected products named by the advisory: Red Hat package: libtiff; Red Hat package: mingw-libtiff.

CVE-2026-52490
Red Hat Enterprise Linux
Aug 24, 2026
High7.5Red Hat

High [CVE-2026-62243] TLS hostname verification bypass via OpenSSL client path misconfiguration

TLS hostname verification bypass via OpenSSL client path misconfiguration. Red Hat rates this important (CVSS 7.5). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:66488 with package netty-handler. Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.3.SP1; Exploit Intelligence; OpenShift Serverless; Red Hat AMQ Broker 7; and 23 more. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; and 19 more.

CVE-2026-62243
Red Hat Enterprise Linux
Aug 22, 2026
High7.1Red Hat

High [CVE-2026-77219] Heap over-read leading to information disclosure via crafted image

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic; for sufficiently large values, the result wraps to a negative number, bypassing the bounds check and causing the pixel reader to access heap memory past the end of the allocated buffer. The over-read contents are interpreted as pixel color values and rendered on screen. By supplying a specially crafted image with large dimensions and an elevated maximum color index, the image loader's internal calculations can wrap to a negative number, bypassing memory bounds checks. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: emacs.

CVE-2026-77219
Red Hat Enterprise Linux
Aug 21, 2026
High7.5Red Hat

High [CVE-2026-54789] Denial of Service via malformed state cookie parsing

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation. A remote attacker can exploit this vulnerability by sending a specially crafted HTTP request with a malformed state cookie. This is an Important denial of service flaw in `mod_auth_openidc`. Exploitation could lead to service unavailability for systems configured with `mod_auth_openidc` for OpenID Connect Relying Party functionality. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125.

CVE-2026-54789
Red Hat Enterprise Linux
Aug 21, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-55893] Heap buffer overflow with potential code execution

Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking the fixed-size operands[] array. Repeated crafted instructions processed through cs_disasm_iter() or cs_disasm() with CS_ARCH_SH, CS_MODE_SH2A or CS_MODE_SH4A, CS_MODE_SHFPU, and CS_OPT_DETAIL can increment the operand count beyond the 176-byte sh_info allocation and perform a four-byte heap buffer overflow write. The corruption can crash the process and may enable code execution depending on heap layout. This issue is fixed in version 6.0.0-Alpha10. This vulnerability allows a local attacker to provide specially crafted SH2A FPU bytecode, leading to a heap buffer overflow. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-805. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:59419. Affected products named by the advisory: Red Hat package: capstone.

CVE-2026-55893
Red Hat Enterprise Linux
Aug 20, 2026
High7.5Red Hat

High [CVE-2026-53587] Denial of Service due to heap out-of-bounds read from malicious Git server

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. A flaw was found in libgit2. A fixed-size string comparison in the `set_data` function within `transports/smart_pkt.c` does not adequately verify the size of a network packet buffer. A remote attacker, operating a malicious Git server, can send a specially crafted packet-line capability buffer. This can lead to a heap out-of-bounds read, causing the client application to crash and resulting in a Denial of Service (DoS). Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125.

CVE-2026-53587
Red Hat Enterprise Linux
Aug 20, 2026
High7.7Red Hat

High [CVE-2026-63385] HTTP header handling bugs create risk of access control bypass.

HTTP header handling bugs create risk of access control bypass. Red Hat rates this important (CVSS 7.7). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:63388 with package libevent-main-2.1.13-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.

CVE-2026-63385
Red Hat Enterprise Linux
Aug 20, 2026
High8.6Red Hat

High [CVE-2026-63387] Off-by-one stack buffer overflow leading to denial of service or data corruption

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label check permits j plus label_len plus one to equal buf_len, after which the terminating null byte is written to buf[buf_len]. A crafted DNS server response containing PTR, CNAME, MX, NS, or SOA data can trigger the one-byte out-of-bounds write and crash or corrupt the process. A remote attacker could send a specially crafted DNS server response, which may lead to a crash or corruption of the process, resulting in a denial of service or potential information disclosure and integrity impact. This Important vulnerability in the libevent library's DNS parsing component can lead to a denial of service or data corruption due to an off-by-one stack buffer overflow. A remote attacker can exploit this flaw with low attack complexity by providing a specially crafted DNS server response to services utilizing libevent for DNS resolution. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-787.

CVE-2026-63387
Red Hat Enterprise Linux
Aug 20, 2026
High7.5Red Hat

High [CVE-2026-63384] Denial of Service via integer conversion error in `evtag_unmarshal_header`

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. A flaw was found in Libevent. An incorrect integer conversion in the `evtag_unmarshal_header` function allows a remote attacker to provide a specially crafted payload length. This can lead to a wrapped large allocation request, resulting in a denial of service (DoS) for the affected system. This is an Important flaw. A remote attacker can trigger a denial of service in applications utilizing Libevent's event tagging feature by sending a specially crafted payload. The incorrect integer conversion can lead to excessive memory allocation, causing resource exhaustion. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Cert Manager support for Red Hat OpenShift release 1.20; and 6 more.

CVE-2026-63384
Red Hat Enterprise Linux
Aug 20, 2026
High7.7Red Hat

High [CVE-2026-63382] Multiple HTTP Parser Bugs Enable Request Smuggling

Multiple HTTP Parser Bugs Enable Request Smuggling. Red Hat rates this important (CVSS 7.7). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:63388 with package libevent-main-2.1.13-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.

CVE-2026-63382
Red Hat Enterprise Linux
Aug 20, 2026
High7.5Red Hat

High [CVE-2026-63495] Remote denial of service via unbounded memory accumulation in WebSocket server

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenticated remote client can repeatedly send fragmented WebSocket frames below WS_MAX_RECV_FRAME_SZ with FIN=0, causing the evbuffer to grow without bound until the process or host exhausts memory. This issue is fixed in version 2.2.2-alpha. A flaw was found in Libevent. Due to a lack of a total message-size limit, these fragmented frames accumulate in memory without bound, leading to memory exhaustion and a denial of service (DoS) for the process or host. Important: A remote denial of service flaw exists in the libevent WebSocket server due to unbounded memory accumulation. An unauthenticated attacker can exploit this by sending fragmented WebSocket frames, leading to memory exhaustion and service unavailability. This is rated Important because it allows a remote attacker to cause a complete denial of service without authentication or user interaction, impacting the availability of affected systems. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 6; Red Hat OpenShift Container Platform 4.

CVE-2026-63495
Red Hat Enterprise Linux
Aug 20, 2026
High7.5Red Hat

High [CVE-2026-63383] Denial of Service via malformed RPC data

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates using the full logical buffer length. A fragmented evbuffer containing a six-byte malformed tag can therefore advance past the pullup window and trigger an out-of-bounds read, which can crash a process that decodes attacker-controlled tagged RPC data. A remote attacker could exploit an out-of-bounds read vulnerability in the `decode_tag_internal()` function by sending specially crafted, attacker-controlled tagged RPC (Remote Procedure Call) data. This could lead to a denial of service, causing the process that decodes the data to crash. This Important flaw in libevent can lead to a denial of service. An attacker could send specially crafted RPC data to a service utilizing libevent, causing an out-of-bounds read and crashing the application. This vulnerability primarily affects applications that process untrusted RPC data using libevent. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Cert Manager support for Red Hat OpenShift release 1.20; and 6 more.

CVE-2026-63383
Red Hat Enterprise Linux
Aug 20, 2026
High8.4Red Hat

High [CVE-2026-63388] Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into bufferevent_private.conn_address. Release builds compiled with NDEBUG disable the EVUTIL_ASSERT length guard, and the evhttp accept path can pass a 110-byte sockaddr from accept() into the 28-byte field. An unauthenticated local peer able to connect to an AF_UNIX listener can overwrite the adjacent dns_request pointer and heap data, causing memory corruption with confidentiality, integrity, and availability impact. A flaw was found in Libevent. A heap out-of-bounds write vulnerability in the `bufferevent_socket_set_conn_address_` function allows an unauthenticated local peer to achieve arbitrary code execution. By connecting to an AF_UNIX listener, an attacker can overwrite critical heap data, leading to memory corruption and potentially full control over the affected system. By connecting to an AF_UNIX listener, an attacker can trigger a heap out-of-bounds write, leading to memory corruption and high impact on system confidentiality, integrity, and availability. The local attack vector limits the immediate threat, but the unauthenticated nature and severe consequences elevate its importance.

CVE-2026-63388
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18309] Remote Code Execution via APNG file parsing integer overflow

GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of APNG files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29401. A flaw was found in GIMP. Successful exploitation requires user interaction, such as opening a malicious file. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18309
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18308] Remote Code Execution via TIF File Parsing Integer Overflow

GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29405. A flaw was found in GIMP. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18308
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18307] Remote code execution via TIF file parsing heap-based buffer overflow

GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29404. A flaw was found in GIMP. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-131. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:62507, RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18307
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18306] Remote Code Execution via SGI File Parsing Integer Overflow

GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SGI files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29396. A flaw was found in GIMP. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:62507, RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18306
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18305] Remote Code Execution via TIF file parsing integer overflow

GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29406. A flaw was found in GIMP, an image manipulation program. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:62507, RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18305
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18304] Arbitrary code execution via crafted TIF file parsing

GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29403. A flaw was found in GIMP. This vulnerability allows a remote attacker to execute arbitrary code by tricking a user into opening a specially crafted TIF file. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:62507, RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18304
Red Hat Enterprise Linux
Aug 20, 2026

← All Red Hat advisories