Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1648 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 622 high, 819 medium, 170 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

High8.8Red Hat

High [CVE-2026-14676] PostgreSQL pg_stat_statements: Arbitrary code execution via heap buffer overflow

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. The pg_stat_statements extension must be loaded (via shared_preload_libraries) for the vulnerability to be exploitable. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:67280, RHSA-2026:67848. Affected products named by the advisory: Red Hat package: postgresql18.

CVE-2026-14676
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat

High [CVE-2026-14670] Arbitrary code execution via plperl tied hash heap buffer overflow

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. A flaw was found in PostgreSQL. This could lead to unauthorized access and control over the database system. By crafting a malicious function body, an attacker with low privileges can exploit a heap buffer overflow, leading to full compromise of the database system. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-805. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-14670
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat

High [CVE-2026-14669] Arbitrary code execution via long POSIX timezone abbreviation

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. An attacker can exploit this by supplying an overly long POSIX timezone abbreviation to execute arbitrary code as the database's operating system user, potentially resulting in complete system compromise. This risk is highest where untrusted users can modify timezone settings. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 12 more.

CVE-2026-14669
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-14668] Information disclosure via type confusion in ctid selectivity estimator

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. A flaw was found in PostgreSQL. This vulnerability, stemming from a type confusion issue in the ctid data type selectivity estimator, could allow an authenticated object creator to access and potentially recover sensitive information from memory. By manipulating input, an attacker could gain unauthorized insight into system memory. An Important-rated information disclosure vulnerability in PostgreSQL allows an authenticated user with object creation privileges to read arbitrary memory spans. Exploitation is limited to users possessing object creation rights Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H). Weakness: CWE-843. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-14668
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat

High [CVE-2026-14664] Arbitrary code execution via heap buffer overflow in regexp

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. A flaw was found in PostgreSQL. This can lead to unanticipated data growth, allowing the attacker to execute arbitrary code as the operating system user running the database. This flaw is rated as Important. This can lead to a complete compromise of the database server through specially crafted input that bypasses encoding validation. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-14664
Red Hat Enterprise Linux
Aug 13, 2026
High8.8Red Hat

High [CVE-2026-14662] Arbitrary code execution via integer wraparound in tsvector and tsquery functions

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. A flaw was found in PostgreSQL. While direct exploitation by application users is considered unlikely as these functions are typically used by application logic, the flaw could still be leveraged in specific scenarios where crafted large inputs are processed. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 12 more.

CVE-2026-14662
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-19654] Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected. This vulnerability in rsyslog allows an unauthenticated peer to crash the rsyslogd deamon, resulting a a Denial-of-Service, by sending a crafted input sequence. This happens because the malicious input ends creating an invalid internal message length, which crashes the rsyslogd receiving the input. This vulnerability is only exploitable when the following conditions are met: * imptcp module is explicitly loaded * There's an imptcp listener using the non-default framing.delimiter.regex mode * The attacker is able to establish a TCP connection to the target listener Although this vulnerability has been rated as having an Important severity in upstream, the Red Hat Product Security team has rated it as having a MODERATE severity in supported Red Hat Products. This happens because the conditions described above are not met in default configurations of the `rsyslog` package as shipped with Red Hat Enterprise Linux Versions. Weakness: CWE-125.

CVE-2026-19654
Red Hat Enterprise Linux
Aug 12, 2026
High7.6Vendor: MediumRed Hat

High [CVE-2026-18724] Stack buffer overflow in idbm record parsing

AI_ONLY_REPORT package: iscsi-initiator-utils-6.2.1.11-0.git4b3e853.el10 ------ Summary: Stack Buffer Overflow in idbm_recinfo_config via Malicious iSCSI Target: a crafted SendTargets TargetName can inject an extra configuration line into a persisted node record and later cause a stack buffer overflow when that record is reparsed. Requirements to exploit: An attacker must control an iSCSI target or tamper with SendTargets discovery traffic, return a crafted `TargetName` containing a newline and oversized injected key or value data, have the victim run persistent discovery, and then trigger a later node-record read such as update or login. Component affected: `iscsi-initiator-utils`; `usr/idbm.c:idbm_recinfo_config`, with attacker-controlled input reaching it through SendTargets handling in `usr/discovery.c` and later record serialization in `usr/idbm.c`. Version affected: `iscsi-initiator-utils-6.2.1.11-0.git4b3e853.el10` Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H - 7.5 (HIGH) AV:N - The attacker can supply the malicious data over the network in a SendTargets discovery response. AC:L - The target-name length cap still leaves enough room for a newline plus an overlong injected key; no race or unusual memory state is required.

CVE-2026-18724
Red Hat Enterprise Linux
Aug 12, 2026
High8.8Red Hat

High [CVE-2026-5917] Arbitrary code execution via shell command injection in SSH backend

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository path directly into a shell command string without escaping special characters before passing it to libssh2_channel_exec(), enabling an attacker to craft a malicious submodule URL in a.gitmodules file that, when processed during a recursive clone, causes the remote server's shell to interpret injected commands under the victim's SSH user account. By crafting a malicious repository path containing unescaped shell metacharacters, an attacker can inject commands that are then interpreted by the remote server's shell during operations like a recursive clone. This could lead to arbitrary code execution under the victim's SSH user account. This is an Important flaw. Red Hat products utilizing libgit2 with the libssh2 SSH backend are susceptible to remote arbitrary code execution. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-5917
Red Hat Enterprise Linux
Aug 11, 2026
High8.2Red Hat

High [CVE-2026-19550] trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory. This flaw only affects Identity Management (IdM/FreeIPA) servers where a cross-forest trust with Active Directory has been established (via ipa-adtrust-install and ipa trust-add). Servers without an active AD trust are not affected, since the trust object and the ADTRUST component required to reach the vulnerable code path do not exist in that configuration. Exploitation requires an ordinary, non-administrative IdM user account to trigger the vulnerable trust-fetch-domains command against a server of the attacker's choosing — no delegated administrative privilege of any kind is required. On its own, this lets an authenticated non-admin user force the IdM server to launch a privileged helper process and initiate a network connection to attacker-controlled infrastructure.

CVE-2026-19550
Red Hat Enterprise Linux
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-73241] Authentication bypass via incorrect RDSTLS PDU handling

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waiting for RDSTLS_TYPE_AUTHREQ, leaving resultCode at RDSTLS_RESULT_SUCCESS and allowing a remote unauthenticated client to bypass the RedirectionGuid, username, domain, or password checks. This issue is fixed in version 3.30.0. By sending a crafted capabilities PDU instead of the expected authentication request, an attacker can gain an authenticated session without valid credentials. An Important flaw in FreeRDP 3.0+ allows remote, unauthenticated attackers to bypass authentication and gain session access. This vulnerability only affects servers explicitly configured with the non-default RdstlsSecurity = TRUE setting. Because RDSTLS was introduced in version 3.0, RHEL 9 and older releases are completely unaffected. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-287. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:61378. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-73241
Red Hat Enterprise Linux
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-73089] Denial of Service via unbounded memory growth from distinct query results

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker who can influence repeated browserslist() query values, including valid since `--` queries, to bypass the caller-controlled BROWSERSLIST_DISABLE_CACHE mitigation and cause linear memory growth followed by an out-of-memory process crash. This issue is fixed in version 4.28.7. This issue can cause the application to consume excessive memory, resulting in an out-of-memory process crash and a Denial of Service (DoS) for affected systems. This is an Important denial of service vulnerability in the `browserslist` library, which is used across several Red Hat products and services. The flaw allows an attacker to trigger unbounded memory growth by influencing query values, potentially leading to an out-of-memory crash and service unavailability. This is considered Important due to the potential for remote exploitation and significant impact on service stability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.

CVE-2026-73089
Red Hat Enterprise Linux
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-73088] Prototype pollution leading to denial of service

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats, and CLI --stats data with an unguarded for...in loop and plain-object bracket access and assignment, allowing inherited Object.prototype keys including __proto__, toString, valueOf, constructor, hasOwnProperty, and isPrototypeOf to cause an uncaught TypeError or modify the prototype of the returned normalized object. This issue is fixed in version 4.28.7. An attacker could provide specially crafted statistics data, which the tool processes without proper validation. This improper handling of untrusted data can lead to prototype pollution, potentially causing the application to crash and resulting in a denial of service. This is an Important vulnerability. The browserslist package, a front-end development tool, is vulnerable to prototype pollution when processing untrusted statistics data. This flaw can lead to a denial of service, as malicious input can crash applications that use the affected library. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-915.

CVE-2026-73088
Red Hat Enterprise Linux
Aug 11, 2026
High7.4Red Hat

High [CVE-2026-73086] Predictable ID generation due to integer overflow

nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide CSPRNG poolOffset in fillPool(), which causes subsequent session tokens, CSRF tokens, API keys, and unique identifiers to become the deterministic string "uuuuuuuuuuuuuuuuuuuuu" until the process restarts. This issue is fixed in versions 3.3.12 and 5.1.11. A flaw was found in nanoid, a JavaScript library for generating unique string IDs. A remote attacker could exploit an integer overflow vulnerability by providing a specific input to the `nanoid(size)` function. This issue causes the internal random number generator to become predictable, leading to the generation of identical identifiers for session tokens, security tokens (Cross-Site Request Forgery (CSRF) tokens), and API keys. Such predictability could allow an attacker to bypass security measures that rely on unique and random identifiers. The attack requires specific conditions, contributing to its Important severity rather than Critical. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-1241.

CVE-2026-73086
Red Hat Enterprise Linux
Aug 11, 2026
High7.2Red Hat

High [CVE-2025-35973] Privilege escalation in Ring 0 via improper value handling

Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and require no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts. Red Hat is aware of a hardware vulnerability affecting some Intel processors that could allow a local attacker who already has privileged access to escalate privileges by exploiting improper handling of internal processor values during Ring 0 execution. In the most severe case, this could allow a privileged workload running inside a virtual machine to escalate access into the underlying hypervisor. Exploitation requires local access, existing privileged access, and a high degree of attack complexity, including detailed knowledge of the processor's internal behavior.

CVE-2025-35973
Red Hat Enterprise LinuxLinux Kernel
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-73078] Arbitrary Code Execution via Crafted Netrw Menu Entries

Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed:menu commands. s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), g:netrw_menu_escape, EX_TRLBAR, and netrw#MakeTgt() fail to neutralize the | command separator or single quotes at five construction sites, allowing a crafted path browsed or bookmarked in GUI Vim to execute arbitrary Ex and operating-system commands. This issue is fixed in version 9.2.0840. Browsing or bookmarking a maliciously crafted path in GUI Vim allows attackers to execute arbitrary OS commands as the running user. By crafting a malicious directory path, an attacker could exploit improper neutralization of special characters when the path is browsed or bookmarked, leading to command injection. This issue specifically impacts GUI installations and requires user interaction. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-77. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat package: vim.

CVE-2026-73078
Red Hat Enterprise Linux
Aug 11, 2026
High7.3Red Hat

High [CVE-2026-73077] Arbitrary Code Execution via Insecure Shell Command Handling

Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating shell arguments. fnameescape() and PATH_ESC_CHARS do not neutralize shell metacharacters before ShKeywordPrg, ZshKeywordPrg, or GetHelp invokes bash, zsh, or PowerShell, allowing arbitrary operating-system commands to execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0839. A vulnerability in Vim's shell script plugins (sh.vim, zsh.vim, ps1.vim) allows arbitrary code execution if a user selects maliciously crafted text in Visual mode and triggers a keyword lookup, due to improperly escaped shell metacharacters. This does not affect RHEL 8 and older versions. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:66336, RHSA-2026:66366. Affected products named by the advisory: Red Hat package: vim.

CVE-2026-73077
Red Hat Enterprise Linux
Aug 11, 2026
High7.3Red Hat

High [CVE-2026-73076] Arbitrary command execution via crafted vimball

Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named. VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through:!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847. A vulnerability in Vim allows remote attackers to execute arbitrary commands by crafting a malicious. VimballRecord file that injects OS commands executed when processed by the vimball#RmVimball() function. This is an Important vulnerability in Vim where a crafted vimball can lead to arbitrary command execution. The flaw allows an attacker to embed malicious commands within a `.VimballRecord` file, which are then executed with user privileges during a later, unrelated vimball installation or removal. This extends the impact of processing untrusted vimball files beyond the initial installation. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-73076
Red Hat Enterprise Linux
Aug 11, 2026
High7.8Red Hat

High [CVE-2026-73072] Heap buffer overflow allows arbitrary code execution

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846. A heap buffer overflow in Vim allows a local attacker to cause a denial of service or potentially execute arbitrary code. The flaw is triggered by processing a specially crafted spell file, where the set_sofo() function fails to reset internal data between sections, leading to an out-of-bounds write. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat lists Red Hat Hardened Images; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:66336, RHSA-2026:66348, RHSA-2026:66366. Affected products named by the advisory: Red Hat package: vim.

CVE-2026-73072
Red Hat Enterprise Linux
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-14380 +1] Incomplete fix for CVE-2026-14380 DBI: Arbitrary code execution via caller-influenced Profile attribute

A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-94. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:65887, RHSA-2026:66179. Affected products named by the advisory: Red Hat package: perl-dbi.

CVE-2026-14380CVE-2026-19546
Red Hat Enterprise Linux
Aug 11, 2026

← All Red Hat advisories