Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1641 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 621 high, 814 medium, 169 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
Medium [CVE-2026-84371] stored XSS via SVG SMIL URI-list scheme-policy bypass
stored XSS via SVG SMIL URI-list scheme-policy bypass. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected products named by the advisory: Cost Management On Premise; Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Enterprise Linux 10; and 6 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Quay 3; and 2 more.
Medium [CVE-2026-84270] Gvfs: mtp: out-of-bounds read in do_read
A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more bytes than requested, this unrestricted length is passed directly to memcpy(). This causes the operation to read memory outside the intended boundaries. This allows an attacker who plugs in a malicious MTP device to cause a segmentation fault when a file is read and crash the gvfsd-mtp process, resulting in a denial of service. To exploit this issue, an attacker needs to plug in a malicious MTP device, limiting its exposure. Furthermore, the direct security impact of this flaw is a denial of service due to the out-of-bounds read. There is no information disclosure. For these reasons, this vulnerability has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gvfs.
Medium [CVE-2026-84269] Gvfs: afp: heap-based buffer overflow in dsi read path
A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service. To exploit this issue, an attacker needs a user to connect to a malicious AFP share (for example, by clicking a crafted afp:// link), limiting its exposure. Furthermore, the direct security impact of this flaw is a denial of service due to the heap-based buffer overflow. For these reasons, this vulnerability has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-122. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gvfs.
Medium [CVE-2026-84267] Gvfs: sftp: uninitialized heap disclosure in read_string
A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing uninitialized heap contents. If the server sends a short FXP_HANDLE reply, these uninitialized bytes are taken as the file handle. The client will then echo these uninitialized bytes back to the server on all subsequent requests using that handle. With a length of 128 bytes, this issue allows the malicious server to deterministically read uninitialized heap memory from the gvfsd-sftp process, leaking its heap base and the load address of the libgio library, resulting in a deterministic defeat of Address Space Layout Randomization (ASLR). To exploit this issue, an attacker needs a user to connect to a malicious SFTP share (for example, by clicking a crafted sftp:// link or intercepting an unverified connection), limiting its exposure. Furthermore, the direct security impact of this flaw is limited to an information disclosure of specific memory contents, specifically the heap base of the gvfsd-sftp process and the load address of the libgio library but it does not expose any user data. For these reasons, this vulnerability has been rated with a moderate severity.
Medium [CVE-2026-83557] com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: Path traversal via incomplete type validation
com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: Path traversal via incomplete type validation. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-1287. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 35 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 31 more.
Medium [CVE-2026-83611] Malformed XML end tag parsing leads to content discard and security bypass
Malformed XML end tag parsing leads to content discard and security bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1286. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 1 more.
Medium [CVE-2026-83610] @xmldom/xmldom: xmldom: XML fragment injection via invalid EntityReference serialization
@xmldom/xmldom: xmldom: XML fragment injection via invalid EntityReference serialization. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-91. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 1 more.
Medium [CVE-2026-84131] Privilege escalation due to invalid pointer in the Graphics component
Privilege escalation due to invalid pointer in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: firefox.
Medium [CVE-2026-11873] empty request to Dogtag /ca/rest/certrequests causes HTTP 500, java exception, and stacktrace disclosure
empty request to Dogtag /ca/rest/certrequests causes HTTP 500, java exception, and stacktrace disclosure. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-209. Affected products named by the advisory: Red Hat Certificate System 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: dogtag-pki; Red Hat package: pki-core.
Medium [CVE-2026-19032] com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: Jackson-databind: Uncontrolled URI scheme resolution in Path deserialization
com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: Jackson-databind: Uncontrolled URI scheme resolution in Path deserialization. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-502. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 35 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 31 more.
Medium [CVE-2026-82677] Denial of Service via double free in Module Timer subsystem
A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch. This flaw could lead to a denial of service. Execution remains confined within the process runtime environment, mitigated by default SELinux policies and container isolation preventing host-level escalation. Red Hat severity: Moderate — CVSS 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1341. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:61884. Affected products named by the advisory: Red Hat package: valkey.
Medium [CVE-2024-58379] Denial of Service via specially crafted emails with data URLs or embedded attachments
Denial of Service via specially crafted emails with data URLs or embedded attachments. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Self-service automation portal 2; Red Hat package: grafana.
Medium [CVE-2026-82556] Server-side request forgery via repository migration
Server-side request forgery via repository migration. Red Hat rates this moderate (CVSS 6.3). Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; AWS Load Balancer Operator; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; and 53 more. Affected products named by the advisory: Compliance Operator; Confidential Compute Attestation; Cryostat 4; Custom Metric Autoscaler operator for Red Hat Openshift; and 49 more.
Medium [CVE-2026-55858] Silent data corruption due to character set mismatch
Silent data corruption due to character set mismatch. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-838. Affected products named by the advisory: OpenShift Pipelines; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; and 12 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 8 more.
Medium [CVE-2026-55857] Information Disclosure via Insecure PAM Dialog Authentication
Information Disclosure via Insecure PAM Dialog Authentication. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-319. Affected products named by the advisory: OpenShift Pipelines; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; and 12 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 8 more.
Medium [CVE-2026-55856] Cleartext password disclosure via man-in-the-middle during initial handshake
Cleartext password disclosure via man-in-the-middle during initial handshake. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-295. Affected products named by the advisory: OpenShift Pipelines; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; and 13 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 9 more.
Medium [CVE-2026-82343] Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling
A flaw was found in the file-psd plugin in GIMP. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read and a stack out-of-bounds access. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of memory contents. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted PSD image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.
Medium [CVE-2026-82328] Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count
A flaw was found in the file-ico plugin in GIMP. This incorrect validation leads to improper memory bounds checking, resulting in a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted ICO image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.
Medium [CVE-2026-82327] out-of-bounds write in repo_write via unvalidated directory id from vertical/paged.solv filelist data
A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with.solv repository cache files. When libsolv rewrites a.solv cache file, it reads directory-id values from the file's compressed filelist data without validating that they fall within the expected range. A corrupted or specially crafted.solv cache file (for example, one left in a torn state after an unclean system shutdown) can cause an out-of-bounds memory write when a tool such as dnf, yum, or zypper next processes it. Successful exploitation is expected to result in a crash of the affected tool (denial of service); it is not expected to allow arbitrary code execution because the out-of-bounds write always stores a fixed, non-attacker-controlled value. The vulnerable code path is the vertical/paged (lazily loaded) filelist decoder used by repo_write(), reached only when a consumer (e.g. dnf/libdnf) rewrites a.solv cache after having loaded one containing SOLVABLE_FILELIST data stored with KEY_STORAGE_VERTICAL_OFFSET. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-129. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 5 more.
Medium [CVE-2026-82324] Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0
A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. This causes a row size mismatch that bypasses memory bounds checking, resulting in heap out-of-bounds reads. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of heap memory contents. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted IFF/ILBM image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.