Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1641 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 621 high, 814 medium, 169 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

Medium5.9Red Hat

Medium [CVE-2026-80489] Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang. Some EUC_JISX0213 sequences decode to two code points. If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call. The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used. The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117. A flaw was found in glibc. Impact is limited to process hang (availability only). Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-80489
Red Hat Enterprise Linux
Aug 27, 2026
Medium6.5Red Hat

Medium [CVE-2026-47892] Header Predicate Bypass in WebFlux Functional Endpoints

Header Predicate Bypass in WebFlux Functional Endpoints. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-807. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat OpenShift Dev Spaces; and 1 more. Affected products named by the advisory: Red Hat package: resteasy.

CVE-2026-47892
Red Hat Enterprise Linux
Aug 27, 2026
Medium5.4Red Hat

Medium [CVE-2026-47887] Open redirect vulnerability in UrlFileNameViewController

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier This could allow an attacker to redirect users to arbitrary malicious websites, potentially leading to phishing attacks or other social engineering exploits. An unauthenticated remote attacker can exploit this by enticing a user to follow a specially crafted URL, leading to an external redirection to an arbitrary domain. Because redirection occurs entirely within the context of browser navigation and application-level routing, default system isolation mechanisms like SELinux or non-root container boundaries do not mitigate the flaw. Technical impact is limited to phishing and user redirection without direct impact to server integrity or confidentiality. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-601. Affected Red Hat products: Red Hat build of Apache Camel - HawtIO 4; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat OpenShift Dev Spaces. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-47887
Red Hat Enterprise Linux
Aug 27, 2026
Medium5.7Red Hat

Medium [CVE-2026-80185] unprivileged-local and adjacent-LE-peer leads to arbitrary code execution as root

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd. Red Hat severity: Moderate — CVSS 5.7 (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-843. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: bluez.

CVE-2026-80185
Red Hat Enterprise Linux
Aug 25, 2026
Medium4.4Red Hat

Medium [CVE-2026-80101] Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validation

A flaw was found in the file-xwd plugin in GIMP. This incorrect validation leads to improper bounds checking, causing a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service, or a limited information disclosure of heap memory contents into the produced image. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted XWD image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-80101
Red Hat Enterprise Linux
Aug 25, 2026
Medium5.3Red Hat

Medium [CVE-2025-32907 +1] quadratic CPU denial of service in HTTP Range coalescing after CVE-2025-32907 fix

An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed memory amplification when a client repeated the same range many times in a single Range header. Commit 9bb92f7a corrected merge correctness in soup_message_headers_get_ranges_internal() in libsoup/soup-message-headers.c, but the coalescing loop still removes merged ranges using g_array_remove_index() for each coalesced element. Because GArray is contiguous, each mid-array removal performs an O(N) memmove. When many identical satisfiable ranges are supplied (for example bytes=0-0 repeated thousands of times), the loop performs O(N²) work coalescing them into a single range. The vulnerable path is reachable server-side from handle_partial_get() in libsoup/server/http1/soup-server-message-io-http1.c when a SoupServer handler returns HTTP 200 with a non-empty body. No authentication is required. The number of ranges is bounded only by the maximum request header size (~100 KiB), allowing roughly 25,000 ranges per request. Reporter measurements on libsoup HEAD containing the CVE-2025-32907 fix show ~90 ms single-core CPU per such request at the wire maximum, blocking the server's event loop for that duration. This is a CPU exhaustion / availability issue only. No memory corruption or information disclosure occurs.

CVE-2025-32907CVE-2026-77680
Red Hat Enterprise Linux
Aug 25, 2026
Medium4.3Red Hat

Medium [CVE-2026-79020] Out of bounds read in Skia

Out of bounds read in Skia. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: webkitgtk4; and 1 more. Affected products named by the advisory: Red Hat package: webkit2gtk3.

CVE-2026-79020
Red Hat Enterprise Linux
Aug 25, 2026
Medium4.3Red Hat

Medium [CVE-2026-79144] Information leak in Skia

Information leak in Skia. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-346. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: firefox; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-79144
Red Hat Enterprise Linux
Aug 25, 2026
Medium5.9Red Hat

Medium [CVE-2026-78958] Uninitialized resource in Skia

Uninitialized resource in Skia. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: firefox; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-78958
Red Hat Enterprise Linux
Aug 25, 2026
Medium5.5Red Hat

Medium [CVE-2026-61555] Denial of Service via crafted EXR image file

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable to crashing. This occurs when Imf::GetChannelsInMultiPartFile() processes a crafted EXR with an empty multiView header attribute and Imf::viewFromChannelName() indexes the empty vector for a dotless channel name. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14. When processing a specially crafted EXR image file, an attacker could trigger an application crash. This occurs because the software attempts to access an empty list of image views when a specific header attribute is empty, leading to a Denial of Service (DoS) for the application. Red Hat products ship OpenEXR versions that are affected by this vulnerability. Upstream has provided fixes only for the 3.2.x (3.2.11), 3.3.x (3.3.13), and 3.4.x (3.4.14) series. Products shipping older branches (1.x, 2.x, 3.0.x, 3.1.x) remain vulnerable as no fixes are available for these versions. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-61555
Red Hat Enterprise Linux
Aug 25, 2026
Medium6.5Red Hat

Medium [CVE-2026-16599] Denial of Service via crafted FTP OPIE/S-KEY authentication challenge

GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation. This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa This challenge contains a sequence number that, when processed by wget, can lead to an excessive number of cryptographic computations. This prolonged computation can cause wget to become unresponsive, resulting in a denial of service. All versions of wget as shipped with Red Hat Enterprise Linux, Red Hat In-Vehicle Operating System, and Fedora are affected. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-835. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more.

CVE-2026-16599
Red Hat Enterprise Linux
Aug 25, 2026
Medium5.9Red Hat

Medium [CVE-2026-77117] Non-progress DoS in SHIFT_JISX0213 -&gt

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang. Some SHIFT_JISX0213 sequences decode to two code points. If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call. The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used. The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489. A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text.

CVE-2026-77117
Red Hat Enterprise Linux
Aug 25, 2026
Medium6.5Red Hat

Medium [CVE-2026-11610 +1] incomplete fix may introduce a connection-stall DoS

A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaustion and a Denial of Service (DoS) for the server. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Directory Server 13.2; Red Hat Directory Server 11; Red Hat Directory Server 12; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:64785, RHSA-2026:64784, RHSA-2026:65119. Affected products named by the advisory: Red Hat package: 389-ds-base.

CVE-2026-11610CVE-2026-78701
Red Hat Enterprise Linux
Aug 25, 2026
Medium6.8Red Hat

Medium [CVE-2026-19499] Buffer Overflow in strfmon right-justification padding

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller. At the time of publication, no network-facing application impact is known. A flaw was found in glibc. This occurs because an incorrect length is used for an internal memory operation, causing data to be written beyond its intended buffer. An attacker could exploit this by providing specially crafted input, potentially leading to arbitrary code execution or other severe impacts. This Moderate impact buffer overflow in `strfmon` or `strfmon_l` within glibc occurs when an application uses right-justified width padding with a specific buffer size, leading to an out-of-bounds write. Exploitation requires a vulnerable application code path that processes attacker-controlled formatting input or uses a fixed susceptible formatting pattern, limiting its general exploitability in typical Red Hat deployments.

CVE-2026-19499
Red Hat Enterprise Linux
Aug 25, 2026
Medium6.5Red Hat

Medium [CVE-2026-78322] stack buffer overflow in parse_progress_line for 7z and RAR handlers

A flaw was found in file-roller. The vulnerability, a stack buffer overflow, occurs when file paths from archive entries exceed fixed-size buffers during progress line parsing, causing the application to terminate. Exploitation requires user interaction and is difficult for arbitrary code execution on hardened Red Hat systems. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: file-roller.

CVE-2026-78322
Red Hat Enterprise Linux
Aug 25, 2026
Medium4.2Red Hat

Medium [CVE-2026-19542] Fix out-of-bounds array write in tdelete

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree. Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete. The written value is a pointer into a tree node and is not directly attacker controlled. No affected application in common distributions has been identified. A flaw was found in glibc. An out-of-bounds array write vulnerability exists within the `tdelete` function. This issue occurs due to incorrect management of array sizes, which can lead to memory corruption. A local attacker with low privileges could potentially exploit this to cause a denial of service or disclose sensitive information. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more.

CVE-2026-19542
Red Hat Enterprise Linux
Aug 25, 2026
Medium5.5Red Hat

Medium [CVE-2026-59183] Integer Overflow Vulnerability Leading to Application Crash

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication in OpenEXRCore's unpack_sample_table() can overflow while decoding a crafted deep tiled EXR file, producing an invalid pointer that leads to a read from an unmapped memory address and a crash. Because the overflow occurs in the standard decoding path (exr_decoding_run), any application that decodes deep tiled EXR files is affected. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14. A flaw was found in OpenEXR. This overflow can lead to an invalid memory pointer, causing applications that process these files to crash. This issue results in a denial of service. Red Hat has determined that versions of OpenEXR shipped in Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, and Red Hat In-Vehicle OS 2 are within the affected version range (3.1.0 through 3.4.13). This flaw has been rated Moderate and is not currently planned to be addressed in future updates. For additional information, refer to the Mitigation section or the linked CVE page. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected products named by the advisory: Red Hat package: openexr.

CVE-2026-59183
Red Hat Enterprise Linux
Aug 25, 2026
Medium6.2Red Hat

Medium [CVE-2026-55373] Denial of Service via infinite loop in sample count processing.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop vulnerability in SampleCountChannel. The helper roundListSizeUp() rounds a sample-list size up to the next power of two using repeated unsigned left shifts, which terminates for normal values but fails for UINT_MAX: the sequence reaches 0x80000000, and the next left shift wraps the 32-bit value to 0. Because 0 remains less than UINT_MAX, the loop never progresses and never exits. The bug is reachable through public OpenEXRUtil APIs, either by editing the sample-count buffer through SampleCountChannel::Edit (whose destructor calls endEdit()) or by calling SampleCountChannel::set(x, y, UINT_MAX) on a valid pixel. This issue has been fixed in versions 3.2.10, 3.3.12, and 3.4.13. A flaw was found in OpenEXR. An attacker could trigger an infinite loop by providing a specially crafted sample count value (UINT_MAX) when processing image data. This vulnerability, located in the `SampleCountChannel` component, prevents the application from progressing, leading to a denial of service. Red Hat Enterprise Linux 6 and 7 ship OpenEXR 1.x, which does not include this component and is not affected.

CVE-2026-55373
Red Hat Enterprise Linux
Aug 25, 2026
Medium5.5Red Hat

Medium [CVE-2026-55059] Heap out-of-bounds write leads to denial of service

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write in Imf_4_0::SampleCountChannel::set(int r, unsigned int newNumSamples[]). The row-based sample-count setter computes the target Y coordinate with dataWindow.min.x instead of dataWindow.min.y. For a valid deep image data window where min.x!= min.y, a valid row index can be translated into an invalid Y coordinate, causing writes before the allocated _numSamples buffer. The vulnerability is reachable through the public OpenEXRUtil DeepImage API and can lead to heap corruption and process crashes. This issue has been fixed in versions 3.2.10, 3.3.12 and 3.4.13. A user processing a specially crafted image file could trigger a heap out-of-bounds write vulnerability in the `SampleCountChannel::set` function. This occurs due to an incorrect computation of the target Y coordinate, leading to writes before an allocated buffer. Successful exploitation can result in heap corruption and process crashes, potentially causing a denial of service. This flaw affects the SampleCountChannel component of OpenEXR, which was introduced in version 2.0. Red Hat Enterprise Linux 6 and 7 ship OpenEXR 1.x, which does not include this component and is not affected.

CVE-2026-55059
Red Hat Enterprise Linux
Aug 25, 2026
Medium5.9Vendor: LowRed Hat

Medium [CVE-2026-63073] untrusted sender DN used as format string in CMP response validation

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender. Percent characters survive the conversion, so a sender DN such as "CN=%s%n" reaches BIO_vsnprintf() as an attacker-controlled format string with no matching variadic arguments. This path is only reached when the caller configures an expected sender or pins a server certificate, which is the normal configuration for a CMP client validating server responses. Since the attacker controls the format string but none of the variadic arguments, such specifiers as %s and %n dereference or write through unrelated stack contents and crash the client. The reliable consequence is a denial of service, when the response comes from a malicious or intercepted CMP endpoint. There is no controlled memory write, arbitrary-address read, or reliable path to remote code execution. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. A flaw was found in OpenSSL. This can lead to a crash in the CMP client, resulting in a denial of service.

CVE-2026-63073
Red Hat Enterprise Linux
Aug 25, 2026

← All Red Hat advisories