Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1219 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 795 high, 375 medium, 17 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High7.0Linux

High [CVE-2026-46117] Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()

Remove user triggerable WARN_ON() in mana_ib_create_qp_rss(). Red Hat rates this important (CVSS 7). Weakness: CWE-1288. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:30129 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-46117
Red Hat Enterprise Linux
May 28, 2026
High7.0Linux

High [CVE-2026-46145] Validate rx_hash_key_len

Validate rx_hash_key_len. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-46145
Red Hat Enterprise Linux
May 28, 2026
High7.0Linux

High [CVE-2026-46189] Fix double free on pvrdma_alloc_ucontext() error path

Fix double free on pvrdma_alloc_ucontext() error path. Red Hat rates this important (CVSS 7). Weakness: CWE-1341. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:30848 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream E4S (v.9.2); Red Hat Enterprise Linux AppStream E4S (v.9.4); Red Hat Enterprise Linux AppStream EUS (v.9.6); and 34 more.

CVE-2026-46189
Red Hat Enterprise Linux
May 28, 2026
High7.0Linux

High [CVE-2026-46176] Fix error path fall-through in mlx5_ib_dev_res_srq_init()

Fix error path fall-through in mlx5_ib_dev_res_srq_init(). Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:34094 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.

CVE-2026-46176
Red Hat Enterprise Linux
May 28, 2026
High7.0Linux

High [CVE-2026-46166] use safe list iteration in radar detect work

use safe list iteration in radar detect work. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.

CVE-2026-46166
Red Hat Enterprise Linux
May 28, 2026
High7.5Linux

High [CVE-2026-46195] validate dacloffset before building DACL pointers

validate dacloffset before building DACL pointers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:21745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-46195
Red Hat Enterprise Linux
May 28, 2026
High8.0Linux

High [CVE-2026-8643] Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite

Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite. Red Hat rates this important (CVSS 8). Weakness: CWE-22. Affected package(s): rhoai/odh-th06-cuda130-torch210-py312-rhel9:1782136276, rhoai/odh-training-rocm62-torch25-py311-rhel9:1782132236, rhoai/odh-th06-cpu-torch210-py312-rhel9:1782135464, rhoai/odh-training-cuda128-torch29-py312-rhel9:1782132240, rhai/base-image-rocm-rhel9:1782914721, rhai/base-image-spyre-rhel9:1782916020. Resolved in Red Hat advisory RHSA-2026:34748 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Discovery 2; Red Hat Hardened Images; and 16 more.

CVE-2026-8643
Red Hat Enterprise Linux
May 27, 2026
High7.1Linux

High [CVE-2026-1933] Missing access check on reparse point operations

Missing access check on reparse point operations. Red Hat rates this important (CVSS 7.1). Weakness: CWE-284. Affected package(s): samba, rhcos. Resolved in Red Hat advisory RHSA-2026:29863 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 6 more.

CVE-2026-1933
Red Hat Enterprise Linux
May 27, 2026
High8.0Linux

High [CVE-2026-3012] group policy certificate enrollment uses http:// without validation

group policy certificate enrollment uses http:// without validation. Red Hat rates this important (CVSS 8). Weakness: CWE-345. Affected package(s): samba, rhcos. Resolved in Red Hat advisory RHSA-2026:29863 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 6 more.

CVE-2026-3012
Red Hat Enterprise Linux
May 27, 2026
High8.1Linux

High [CVE-2026-8450] HTTP::Daemon: Arbitrary code execution via OS command injection in send_file()

HTTP::Daemon: Arbitrary code execution via OS command injection in send_file(). Red Hat rates this important (CVSS 8.1). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-8450
Red Hat Enterprise Linux
May 27, 2026
High7.8Linux

High [CVE-2026-48962] Arbitrary code execution via attacker-controlled output glob

Arbitrary code execution via attacker-controlled output glob. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94. Affected package(s): perl:5.32, perl-IO-Compress. Resolved in Red Hat advisory RHSA-2026:30115 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-48962
Red Hat Enterprise Linux
May 27, 2026
High7.8Linux

High [CVE-2026-45984] Fix use-after-free in iomap inline data write path

Fix use-after-free in iomap inline data write path. Red Hat rates this important (CVSS 7.8). Weakness: CWE-826. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:33743 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream E4S (v.9.4); Red Hat Enterprise Linux AppStream EUS (v.9.6); Red Hat Enterprise Linux AppStream (v. 9); Red Hat Enterprise Linux BaseOS (v. 8); and 22 more.

CVE-2026-45984
Red Hat Enterprise Linux
May 27, 2026
High7.0Linux

High [CVE-2026-46099] fix NOREF dst use in seg6 and rpl lwtunnels

fix NOREF dst use in seg6 and rpl lwtunnels. Red Hat rates this important (CVSS 7). Weakness: CWE-911. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-46099
Red Hat Enterprise Linux
May 27, 2026
High7.0Linux

High [CVE-2026-45972] fix potential UAF and double free in smb2_open_file()

fix potential UAF and double free in smb2_open_file(). Red Hat rates this important (CVSS 7). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-45972
Red Hat Enterprise Linux
May 27, 2026
High7.0Linux

High [CVE-2026-46090] Fix peer runtime UAF during format-change stop

Fix peer runtime UAF during format-change stop. Red Hat rates this important (CVSS 7). Weakness: CWE-364. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-46090
Red Hat Enterprise Linux
May 27, 2026
High7.0Linux

High [CVE-2026-46033] authencesn - reject short ahash digests during instance creation

authencesn - reject short ahash digests during instance creation. Red Hat rates this important (CVSS 7). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-46033
Red Hat Enterprise Linux
May 27, 2026
High7.0Linux

High [CVE-2026-45998] Fix potential UAF after skb_unshare() failure

Fix potential UAF after skb_unshare() failure. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:34911 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-45998
Red Hat Enterprise Linux
May 27, 2026
High7.0Linux

High [CVE-2026-46054] fix overlayfs mmap() and mprotect() access checks

fix overlayfs mmap() and mprotect() access checks. Red Hat rates this important (CVSS 7). Weakness: CWE-280. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:30848 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-46054
Red Hat Enterprise Linux
May 27, 2026
High7.0Linux

High [CVE-2026-45898] Fix workqueue list corruption by removing work_list

Fix workqueue list corruption by removing work_list. Red Hat rates this important (CVSS 7). Weakness: CWE-1341. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:30129 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.

CVE-2026-45898
Red Hat Enterprise Linux
May 27, 2026
High7.0Linux

High [CVE-2026-45852] Fix double free in rxe_srq_from_init

Fix double free in rxe_srq_from_init. Red Hat rates this important (CVSS 7). Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 5 more.

CVE-2026-45852
Red Hat Enterprise Linux
May 27, 2026

← All Linux advisories