Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1648 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 622 high, 819 medium, 170 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

Medium6.5Red Hat

Medium [CVE-2026-18726] Denial of service in iscsiuio Router Advertisement parsing

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unresponsive and impacting system availability. A secondary risk of out-of-bounds reads exists with a short IPv6 payload, though no memory corruption or data exposure has been confirmed. Moderate: This flaw in `iscsiuio` can lead to a denial of service when processing a specially crafted ICMPv6 Router Advertisement. Exploitation requires an attacker to be on the same Layer 2 network segment as an IPv6-enabled interface handled by `iscsiuio`, limiting its reachability. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: iscsi-initiator-utils.

CVE-2026-18726
Red Hat Enterprise Linux
Aug 12, 2026
Medium6.6Red Hat

Medium [CVE-2026-73433] unsigned integer underflow in avidemux FUJIFILM strd parsing leading to out-of-bounds read/write

A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the counter underflows to a very large unsigned value, causing subsequent null-terminated string scanning to read far beyond the allocated heap buffer. Date-format normalization may also write beyond the buffer end. Confirmed impacts include heap out-of-bounds read, out-of-bounds write, heap information disclosure (adjacent data appearing in parsed metadata), and application crash/denial of service. The avidemux element is auto-plugged by playbin, decodebin, and gst-discoverer, so opening or previewing a crafted AVI is sufficient to trigger the issue. Red Hat severity: Moderate — CVSS 6.6 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H). Weakness: CWE-191. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2026:55434, RHSA-2026:65959, RHSA-2026:56966, RHSA-2026:55436. Affected products named by the advisory: Red Hat package: gstreamer1-plugins-good.

CVE-2026-73433
Red Hat Enterprise Linux
Aug 12, 2026
Medium6.1Red Hat

Medium [CVE-2026-73434] out-of-bounds read in avidemux vprp video field descriptor parsing

A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This can cause the parser to treat more field descriptors as available than fit in the input buffer, resulting in out-of-bounds reads. Processing a crafted AVI via playbin/decodebin can crash the application (denial of service). Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2026:55434, RHSA-2026:65959, RHSA-2026:56966, RHSA-2026:55436. Affected products named by the advisory: Red Hat package: gstreamer1-plugins-good.

CVE-2026-73434
Red Hat Enterprise Linux
Aug 12, 2026
Medium5.5Red Hat

Medium [CVE-2026-19548] Multiple Use-After-Free in add_archive_element via LTO plugin processing

Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element: 1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive) 2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call 3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable. An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault).

CVE-2026-19548
Red Hat Enterprise Linux
Aug 12, 2026
Medium6.3Red Hat

Medium [CVE-2026-18725] Out-of-bounds access in iscsiuio ICMPv6 echo handling

AI_ONLY_REPORT package: iscsi-initiator-utils-6.2.1.11-0.git4b3e853.el10 ------ Summary: Out-of-Bounds Write and Information Disclosure via Unvalidated IPv6 Payload Length: crafted ICMPv6 Echo Requests can cause `iscsiuio` to trust an inflated `ipv6_plen` larger than the actual received payload, leading to MTU-bounded out-of-bounds reads and a potential one-byte out-of-bounds write that may disclose data beyond the valid packet boundary. Requirements to exploit: Adjacent-network access on the same L2 segment as a system running `iscsiuio` on an interface that processes IPv6/NDP traffic, plus the ability to send a crafted ICMPv6 Echo Request with a forged `IPv6.plen`. No authentication or user interaction is required. Component affected: `iscsi-initiator-utils` (`iscsiuio`): `iscsiuio/src/uip/ipv6.c` in `ipv6_icmp_handle_echo_request()` and `ipv6_insert_protocol_chksum()`. Version affected: `iscsi-initiator-utils-6.2.1.11-0.git4b3e853.el10` when `iscsiuio` is processing IPv6/NDP traffic on a reachable interface. Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L - 6.3 (MEDIUM) AV:A - Reachability is limited to an attacker on the same L2 segment who can send crafted IPv6/ICMPv6 traffic to the affected interface.

CVE-2026-18725
Red Hat Enterprise Linux
Aug 12, 2026
Medium5.9Red Hat

Medium [CVE-2026-18663] pre-authentication double-free in get_ldapmessage_controls_ext via critical Session Tracking control

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the same pointer again, causing a double-free. An unauthenticated remote attacker can trigger this with a single BIND request carrying a critical Session Tracking control, resulting in heap corruption and potential denial of service. Red Hat rates this issue as Moderate severity primarily because the exploitation requires sending an unauthenticated BIND request with a critical Session Tracking control, but on RHEL 10 and RHDS 13 the ns-slapd process uses jemalloc, which absorbs the double-free without crashing. Live testing confirmed the error path is hit but the server continues running. Impact is limited to heap corruption; no information disclosure or privilege escalation has been demonstrated. Reliable denial of service only occurs on builds using the glibc allocator (upstream/Fedora), not on RHEL product builds. Other versions are not affected as they lack the Session Tracking control feature. Weakness: CWE-415. Affected Red Hat products: Red Hat Directory Server 13; Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: 389-ds-base.

CVE-2026-18663
Red Hat Enterprise Linux
Aug 12, 2026
Medium6.4Red Hat

Medium [CVE-2026-73242] Out-of-bounds memory access in Kerberos decryption

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowing a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption. This issue is fixed in version 3.30.0. This occurs during CredSSP/NLA decryption and can lead to a denial of service or information disclosure. An Important out-of-bounds memory vulnerability in FreeRDP's CredSSP/NLA Kerberos decryption allows a malicious RDP endpoint to execute arbitrary code or expose sensitive information on connected clients and servers. This flaw only affects FreeRDP 3.0.0 and newer, meaning RHEL 9 and older versions are not affected. Red Hat severity: Moderate — CVSS 6.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:61378. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-73242
Red Hat Enterprise Linux
Aug 11, 2026
Medium5.4Red Hat

Medium [CVE-2026-73283] Tunnel forwarding restriction bypass

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. The `restrict` keyword, designed to limit tunnel forwarding within the `authorized_keys` file, was not correctly enforced for tunnel forwarding. This issue could allow a local attacker to bypass intended security restrictions, potentially leading to unauthorized network access or resource usage through tunnels. An authorization bypass flaw was found in OpenSSH's sshd daemon. When processing SSH public key authentication, sshd fails to enforce the restrict keyword in authorized_keys against TUN/TAP tunnel forwarding requests. An authenticated user holding a restricted key can still establish virtual network interface tunnels if tunnel forwarding is globally enabled on the server. This allows authorized users to bypass intended per-key restriction policies, posing a Moderate impact to confidentiality and integrity. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-305. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: openssh.

CVE-2026-73283
Red Hat Enterprise Linux
Aug 11, 2026
Medium5.6Red Hat

Medium [CVE-2026-73282] Information disclosure and data corruption via use-after-free in ssh client

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. A flaw was found in OpenSSH. This can occur if a remote forwarding is added via the local session multiplexing socket while a remote forwarding open request is pending with the server. A remote attacker with high attack complexity could potentially exploit this to achieve low impact on confidentiality and integrity. Red Hat severity: Moderate — CVSS 5.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: openssh.

CVE-2026-73282
Red Hat Enterprise Linux
Aug 11, 2026
Medium6.5Red Hat

Medium [CVE-2026-72712] Denial of Service via zero-length TCP option packet

Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash. A flaw was found in Nmap. A remote attacker can exploit this denial of service vulnerability by sending a specially crafted packet that includes a zero-length Transmission Control Protocol (TCP) option. This malformed packet forces the application to enter an infinite loop during packet processing, consuming excessive memory and ultimately causing the Nmap application to crash. The impact is limited to the availability of the Nmap process itself, typically affecting active network scanning operations rather than persistent services. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-72712
Red Hat Enterprise Linux
Aug 11, 2026
Medium6.7Red Hat

Medium [CVE-2026-32791] Escalation of Privilege via Untrusted Search Path

Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. An unprivileged, authenticated local attacker could exploit an untrusted search path vulnerability. This could lead to an escalation of privilege, allowing the attacker to gain higher access rights. Due to improper path resolution, an authenticated local attacker with low privileges can place a malicious shared library or executable binary in a directory searched by PCM applications. When a privileged user or service executes PCM, it loads the attacker's binary, leading to local privilege escalation and full compromise of system confidentiality, integrity, and availability. Red Hat severity: Moderate — CVSS 6.7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).

CVE-2026-32791
Red Hat Enterprise Linux
Aug 11, 2026
Medium5.7Red Hat

Medium [CVE-2025-31936] Privilege escalation via improper memory range handling in SMM

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. Improper handling of overlap between protected memory ranges may allow a local attacker with privileged user access to escalate privileges. This Important privilege escalation flaw affects Intel Xeon 6 Processors when Intel TDX is enabled, allowing a privileged local attacker to escalate privileges within the System Management Mode (SMM). Exploitation requires a high complexity attack and specific internal knowledge, impacting the confidentiality and integrity of the system. Red Hat severity: Moderate — CVSS 5.7 (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-823.

CVE-2025-31936
Red Hat Enterprise Linux
Aug 11, 2026
Medium5.3Red Hat

Medium [CVE-2026-14180] Undertow:HTTP request smuggling via oversized chunk-size bit overlap

A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, "smuggled" request to be processed out of sync, potentially bypassing security controls. The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires a frontend proxy to forward oversized, non-standard chunk-size values to the backend Undertow server. Successful exploitation allows an attacker to perform HTTP request smuggling, leading to request desynchronization. The vulnerability's root cause is an internal bitmask overlap in the ChunkReader state management logic where large chunk-size values collide with internal parser flags. Weakness: CWE-444. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat Data Grid 8; Red Hat Enterprise Linux 10; and 9 more.

CVE-2026-14180
Red Hat Enterprise Linux
Aug 11, 2026
Medium5.3Red Hat

Medium [CVE-2026-71218] Unbounded peer-controlled allocation in iperf3 JSON_read allows unauthenticated remote memory exhaustion

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-789. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: iperf3.

CVE-2026-71218
Red Hat Enterprise Linux
Aug 11, 2026
Medium6.5Red Hat

Medium [CVE-2026-19391] Incomplete credential redaction exposes SSSD bind passwords and Pacemaker fence credentials in uploaded archives

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com. The default insights-client configuration is affected, leading to potential exposure of sensitive credentials to individuals with access to these uploaded archives. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-312. Affected Red Hat products: Pen Drive Powered by Red Hat Lightspeed; Red Hat Certification Program for Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat lists Red Hat Satellite 6 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: insights-core.

CVE-2026-19391
Red Hat Enterprise Linux
Aug 11, 2026
Medium5.9Red Hat

Medium [CVE-2026-62899] .NET:.NET Core:.NET Security Feature Bypass Vulnerability

Inconsistent interpretation of http requests ('http request/response smuggling') in.NET allows an unauthorized attacker to bypass a security feature over a network. This Moderate impact flaw in System. Net.HttpListener on Red Hat platforms running.NET Core allows for a security feature bypass. The vulnerability arises from incorrect parsing of the Content-Length header, potentially affecting applications that utilize HttpListener to process HTTP requests. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-444. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images; Red Hat OpenShift Dev Spaces. Red Hat fixing advisory: RHSA-2026:54541, RHSA-2026:54590, RHSA-2026:55858, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:54538, RHSA-2026:54542, RHSA-2026:54550, RHSA-2026:54574, RHSA-2026:55856, RHSA-2026:55857, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:44914, RHSA-2026:55142, RHSA-2026:55405. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-62899
Red Hat Enterprise Linux
Aug 11, 2026
Medium5.9Red Hat

Medium [CVE-2026-62900] .NET:.NET Information Disclosure Vulnerability

Improper removal of sensitive information before storage or transfer in.NET allows an unauthorized attacker to disclose information over a network. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-212. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images; Red Hat OpenShift Dev Spaces. Red Hat fixing advisory: RHSA-2026:54541, RHSA-2026:54590, RHSA-2026:55858, RHSA-2026:58566, RHSA-2026:58567, RHSA-2026:54538, RHSA-2026:54542, RHSA-2026:54550, RHSA-2026:54574, RHSA-2026:55856, RHSA-2026:55857, RHSA-2026:58568, RHSA-2026:58569, RHSA-2026:58570, RHSA-2026:44914, RHSA-2026:55142, RHSA-2026:55405. Affected products named by the advisory: Red Hat package: dotnet8.0; Red Hat package: dotnet9.0; Red Hat package: dotnet10.0.

CVE-2026-62900
Red Hat Enterprise Linux
Aug 11, 2026
Medium4.4Vendor: LowRed Hat

Medium [CVE-2026-6426] vhost inflight migration VMState integer type mismatch causes out-of-bounds access

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by the VMS_VBUFFER load path as a signed int32_t. On little-endian hosts, a crafted incoming migration state with bit 31 set causes the value to be interpreted as negative and then implicitly converted to a very large size_t, leading qemu_get_buffer() to copy migration-stream data beyond the bounds of the mmap-backed inflight region. This can result in a crash of the QEMU process or memory corruption. Exploitation requires control of the migration producer or write access to the migration channel, combined with a destination configured to use vhost inflight migration. Red Hat severity: Low — CVSS 4.4 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-681. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux for NVIDIA 26. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: qemu-kvm-ma.

CVE-2026-6426
Red Hat Enterprise Linux
Aug 10, 2026
Medium5.9Red Hat

Medium [CVE-2026-6791] Denial of Service via stack exhaustion during tilde expansion

When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash. A flaw was found in glibc. When processing paths that start with a tilde (~) followed by a username, the `wordexp` function can be forced to allocate an excessive amount of memory on the program's stack. A remote attacker could exploit this by providing a very long username, leading to a stack exhaustion and causing a denial of service (DoS) for the affected application. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-6791
Red Hat Enterprise Linux
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-6368] Process abort due to invalid memory in wordexp

Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process. A flaw was found in glibc (GNU C Library). This invalid memory, when subsequently processed by wordfree, may cause the process to abort, leading to a Denial of Service (DoS). This flaw in glibc has Moderate impact, as it can lead to a denial of service. Exploitation requires an application to specifically call `wordexp` with the `WRDE_APPEND` flag, followed by a `wordfree` call, which can result in a process abort. This vulnerability affects applications that utilize this particular programming pattern. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1341. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Hardened Images as not affected. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:53069. Affected products named by the advisory: Red Hat package: glibc; Red Hat package: compat-glibc.

CVE-2026-6368
Red Hat Enterprise Linux
Aug 10, 2026

← All Red Hat advisories