Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1225 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 785 high, 384 medium, 25 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High7.5Linux Updated

High [CVE-2026-16360] Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153

Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16360
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16412] Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153

Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16412
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Vendor: MediumLinux Updated

High [CVE-2026-16357] Incorrect boundary conditions in the Graphics component

Incorrect boundary conditions in the Graphics component. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16357
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16356] Sandbox escape due to use-after-free in the Disability Access APIs component

Sandbox escape due to use-after-free in the Disability Access APIs component. Red Hat rates this important (CVSS 7.5). Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16356
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16355] JIT miscompilation in the JavaScript Engine: JIT component

JIT miscompilation in the JavaScript Engine: JIT component. Red Hat rates this important (CVSS 7.5). Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16355
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Vendor: MediumLinux Updated

High [CVE-2026-16369] Integer overflow in the JavaScript: WebAssembly component

Integer overflow in the JavaScript: WebAssembly component. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16369
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16368] Incorrect boundary conditions in the JavaScript: WebAssembly component

Incorrect boundary conditions in the JavaScript: WebAssembly component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16368
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Vendor: MediumLinux Updated

High [CVE-2026-16354] Information disclosure in the Graphics: ImageLib component

Information disclosure in the Graphics: ImageLib component. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16354
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Vendor: MediumLinux Updated

High [CVE-2026-16353] Invalid pointer in the DOM: Bindings (WebIDL) component

Invalid pointer in the DOM: Bindings (WebIDL) component. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16353
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16363] JIT miscompilation in the JavaScript: WebAssembly component

JIT miscompilation in the JavaScript: WebAssembly component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-733. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16363
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16352] Sandbox escape due to use-after-free in the Disability Access APIs component

Sandbox escape due to use-after-free in the Disability Access APIs component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16352
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16351] Sandbox escape due to use-after-free in the DOM: Navigation component

Sandbox escape due to use-after-free in the DOM: Navigation component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16351
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16362] Use-after-free in the WebRTC: Audio/Video component

Use-after-free in the WebRTC: Audio/Video component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16362
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Vendor: MediumLinux Updated

High [CVE-2026-16350] Incorrect boundary conditions in the Audio/Video: cubeb component

Incorrect boundary conditions in the Audio/Video: cubeb component. Red Hat rates this moderate (CVSS 7.5). Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16350
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16349] Same-origin policy bypass in the DOM: Navigation component

Same-origin policy bypass in the DOM: Navigation component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16349
Red Hat Enterprise Linux
Jul 21, 2026
High8.2Linux Updated

High [CVE-2026-60315] X Plugin unspecified vulnerability (CPU Jul 2026)

Oracle CPU describes the issue as following: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster and unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H). Weakness: CWE-248. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-60315
Red Hat Enterprise Linux
Jul 21, 2026
High8.4Linux Updated

High [CVE-2026-60163] Group Replication Plugin unspecified vulnerability (CPU Jul 2026)

Oracle CPU describes the issue as following: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update. Red Hat severity: Important — CVSS 8.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-266. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-60163
Red Hat Enterprise Linux
Jul 21, 2026
High7.2Linux Updated

High [CVE-2026-61094] Replication unspecified vulnerability (CPU Jul 2026)

Oracle CPU describes the issue as following: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update. Red Hat severity: Important — CVSS 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-266. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-61094
Red Hat Enterprise Linux
Jul 21, 2026
High7.2Linux Updated

High [CVE-2026-60316] X Plugin unspecified vulnerability (CPU Jul 2026)

Oracle CPU describes the issue as following: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update. Red Hat severity: Important — CVSS 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-648. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-60316
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-55833] Denial of Service via SPDY header decompression amplification

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into much larger raw header data and causes compression-amplified CPU and allocation churn. By sending a specially crafted, small compressed header block, the attacker can cause it to expand significantly during decompression, leading to excessive CPU usage and memory allocation. This can result in a denial of service (DoS) due to resource exhaustion. This is an Important denial of service vulnerability in Netty's SPDY header decoding. A remote, unauthenticated attacker can send a small, compressed SPDY header block that, during decompression, expands significantly beyond configured limits. This leads to excessive CPU and memory consumption, potentially causing resource exhaustion and service unavailability in affected Red Hat products that utilize Netty with SPDY. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-409.

CVE-2026-55833
Red Hat Enterprise Linux
Jul 20, 2026

← All Linux advisories