Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1280 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 818 high, 411 medium, 17 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

Medium6.7Linux

Medium [CVE-2026-48914] Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux for NVIDIA 26; and 1 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-48914
Red Hat Enterprise Linux
Jun 12, 2026
Medium5.5Linux

Medium [CVE-2026-50262] out-of-bounds read/write in GLX ChangeDrawableAttributes

out-of-bounds read/write in GLX ChangeDrawableAttributes. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected package(s): xorg-x11-server, xorg-x11-server-Xwayland, tigervnc. Resolved in Red Hat advisory RHSA-2026:26562 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-50262
Red Hat Enterprise Linux
Jun 2, 2026
Medium5.5Linux

Medium [CVE-2026-50263] use-after-free information disclosure in CreateSaverWindow()

use-after-free information disclosure in CreateSaverWindow(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-416. Affected package(s): xorg-x11-server, xorg-x11-server-Xwayland, tigervnc. Resolved in Red Hat advisory RHSA-2026:26562 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-50263
Red Hat Enterprise Linux
Jun 2, 2026
Medium6.8Vendor: HighLinux

Medium [CVE-2026-46125] remove station if connection prep fails

remove station if connection prep fails. Red Hat rates this important (CVSS 6.8). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 2 more.

CVE-2026-46125
Red Hat Enterprise Linux
May 28, 2026
Medium6.5Vendor: CriticalLinux

Medium [CVE-2026-48710] Security restriction bypass via malformed HTTP Host header

Security restriction bypass via malformed HTTP Host header. Red Hat rates this critical (CVSS 6.5). Weakness: CWE-1289. Affected package(s): rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1782132660, rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1782133865, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1782132444, satellite/iop-host-inventory-rhel9:1780414237, satellite/foreman-mcp-server-rhel9:1780492012, rhoai/odh-trustyai-nemo-guardrails-server-rhel9:1782420349. Resolved in Red Hat advisory RHSA-2026:34526 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.3; Red Hat Ansible Automation Platform 2.6; Red Hat Ansible Automation Platform 2.7; Red Hat OpenShift AI 3.3; and 8 more.

CVE-2026-48710
Red Hat Enterprise Linux
May 26, 2026
Medium6.5Linux

Medium [CVE-2026-9150] Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums

Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-121. Affected package(s): libsolv, libsolv-main. Resolved in Red Hat advisory RHSA-2026:28236 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Hardened Images; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; and 3 more.

CVE-2026-9150
Red Hat Enterprise Linux
May 20, 2026
Medium6.5Linux

Medium [CVE-2026-9149] Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file

Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted.solv file. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-122. Affected package(s): libsolv, libsolv-main. Resolved in Red Hat advisory RHSA-2026:28236 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Hardened Images; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more.

CVE-2026-9149
Red Hat Enterprise Linux
May 20, 2026
Medium6.7Vendor: HighLinux

Medium [CVE-2026-46331] extend the writable skb range per key

extend the writable skb range per key. Red Hat rates this important (CVSS 6.7). Weakness: CWE-787. Affected package(s): kernel, rhcos, kernel-rt, kpatch-patch. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NVIDIA for RHEL 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 18 more.

CVE-2026-46331
Red Hat Enterprise Linux
May 18, 2026
Medium6.5Linux

Medium [CVE-2026-3833] Policy bypass due to case-sensitive nameConstraints comparison

Policy bypass due to case-sensitive nameConstraints comparison. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-178. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 12 more.

CVE-2026-3833
Red Hat Enterprise Linux
Apr 30, 2026
Medium6.6Linux

Medium [CVE-2026-42014] Use-after-free in gnutls_pkcs11_token_set_pin

Use-after-free in gnutls_pkcs11_token_set_pin. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-825. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 11 more.

CVE-2026-42014
Red Hat Enterprise Linux
Apr 29, 2026
Medium5.3Linux

Medium [CVE-2026-42015] Memory corruption due to off-by-one error in PKCS#12 bag handling

Memory corruption due to off-by-one error in PKCS#12 bag handling. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-193. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 11 more.

CVE-2026-42015
Red Hat Enterprise Linux
Apr 29, 2026
Medium5.5Linux

Medium [CVE-2026-4367] Denial of Service via out-of-bounds read in XPM file parsing

Denial of Service via out-of-bounds read in XPM file parsing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected package(s): libxpm-main. Resolved in Red Hat advisory RHSA-2026:30354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 2 more.

CVE-2026-4367
Red Hat Enterprise Linux
Apr 21, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-0636] LDAP injection vulnerability in LDAPStoreHelper.java

LDAP injection vulnerability in LDAPStoreHelper.java. Red Hat rates this important (CVSS 6.5). Weakness: CWE-90. Affected package(s): bcprov-jdk15to18, eap8-bouncycastle, devspaces/openvsx-rhel9:1779528224, bcprov-ext-jdk15on, bcprov-ext-jdk18on, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:14276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat OpenShift Dev Spaces 3.28; and 11 more.

CVE-2026-0636
Red Hat Enterprise Linux
Apr 15, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-35469] Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code. Red Hat rates this important (CVSS 6.5). Weakness: CWE-770. Affected package(s): openshift4/ose-node-feature-discovery-rhel9:1779252023, openshift4/ose-sriov-network-config-daemon:1780955979, container-native-virtualization/virt-exportserver-rhel9:1782358244, openshift4/ose-sriov-network-webhook-rhel9:1779249801, advanced-cluster-security/rhacs-roxctl-rhel8:1777986630, multicluster-engine/assisted-service. Resolved in Red Hat advisory RHSA-2026:29795 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: RHEM 1.0 for RHEL 9; Red Hat OpenShift Container Platform 4.19; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 29 more.

CVE-2026-35469
Red Hat Enterprise Linux
Apr 13, 2026
Medium5.0Linux

Medium [CVE-2026-6845] Denial of Service via crafted ELF file

Denial of Service via crafted ELF file. Red Hat rates this moderate (CVSS 5). Weakness: CWE-476. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:34924 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more.

CVE-2026-6845
Red Hat Enterprise Linux
Apr 13, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-34756] Denial of Service via excessively large 'n' parameter in OpenAI-compatible API

Denial of Service via excessively large 'n' parameter in OpenAI-compatible API. Red Hat rates this important (CVSS 6.5). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-34756
Red Hat Enterprise Linux
Apr 6, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-34755] Denial of Service due to excessive video frame processing

Denial of Service due to excessive video frame processing. Red Hat rates this important (CVSS 6.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-34755
Red Hat Enterprise Linux
Apr 6, 2026
Medium5.0Linux

Medium [CVE-2026-5704] Tar: tar: hidden file injection via crafted archives

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N). Weakness: CWE-434. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-5704
Red Hat Enterprise Linux
Apr 6, 2026
Medium6.7Vendor: HighLinux

Medium [CVE-2026-4878] Privilege escalation via TOCTOU race condition in cap_set_file()

Privilege escalation via TOCTOU race condition in cap_set_file(). Red Hat rates this important (CVSS 6.7). Weakness: CWE-367. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, libcap, rhui5/haproxy-rhel9:1779798164, rhcos, libcap-main. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 38 more.

CVE-2026-4878
Red Hat Enterprise Linux
Apr 6, 2026
Medium5.5Linux

Medium [CVE-2026-4948] Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-279. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Under investigation: Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHBA-2026:28238.

CVE-2026-4948
Red Hat Enterprise Linux
Mar 27, 2026

← All Linux advisories