Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1648 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 622 high, 819 medium, 170 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

High8.6Red Hat

High [CVE-2026-44943] Privilege Escalation via Path Traversal

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e. This vulnerability, known as Path Traversal, allows remote Man-in-the-Middle (MITM) attackers to manipulate file paths. By doing so, attackers can create files with root privileges outside the intended database and inject malicious content into system records. This could lead to unauthorized system modification or privilege escalation. This is an Important vulnerability in the open-iscsi `iscsi-initiator-utils` package, enabling remote Man-in-the-Middle (MITM) attackers to achieve privilege escalation. The path traversal flaw allows creating root-owned files and injecting malicious data into system records, posing a significant risk of unauthorized system modification without requiring user interaction or prior authentication. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N). Weakness: CWE-22.

CVE-2026-44943
Red Hat Enterprise Linux
Jul 29, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-18107] container escape via rseq critical section hijack during checkpoint/restore

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, allowing it to spoof the process credentials saved in the checkpoint image. On restore, the container process gains elevated capabilities and zeroed UIDs/GIDs. The practical impact on Red Hat products is limited by several factors: checkpoint/restore requires root privileges (podman) or cluster-admin RBAC (OpenShift) to trigger and cannot be initiated from within the container itself; on OpenShift prior to 4.17 the feature required explicit opt-in, and on 4.17+ the kubelet checkpoint API RBAC is not configured by default; OpenShift enforces user namespaces by default for regular workloads (hostUsers is gated behind admin-only SCCs), which makes the spoofed capabilities namespace-scoped and ineffective for privilege escalation; SELinux type enforcement (container_t) blocks privilege transitions independently of capabilities; seccomp filters persist through checkpoint/restore and cannot be corrupted via the parasite; and kernel mount namespace ownership checks on RHEL 9/10 kernels prevent mount-based container escape even with spoofed capabilities. Red Hat severity: Moderate — CVSS 7.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVE-2026-18107
Red Hat Enterprise Linux
Jul 28, 2026
High7.6Red Hat

High [CVE-2026-16313] arbitrary command execution via udev property injection in sg_inq --export

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected. sg3_utils versions 1.34 through 1.48 contain a command injection flaw in the export_dev_ids() function of sg_inq. A crafted SCSI/USB device can embed a newline in this field, splitting sg_inq's udev KEY=VALUE output into two lines and injecting an arbitrary udev property, including REMOVE_CMD. On systems whose default udev rules invoke sg_inq --export for SCSI device identification and act on REMOVE_CMD when a device is removed, this allows a local attacker with physical access to a USB/SCSI port to achieve arbitrary command execution as root simply by disconnecting the crafted device. Exploitation requires physical access to attach the malicious device, consistent with Red Hat's Physical (AV:P) attack vector scoring. The upstream fix (udev-conforming character escaping for this field) has not yet been included in any tagged sg3_utils release; all Red Hat-shipped versions of sg3_utils in the 1.34-1.48 range are affected.

CVE-2026-16313
Red Hat Enterprise Linux
Jul 28, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-66759] out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted ICNS images

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted ICNS image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:50817. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-66759
Red Hat Enterprise Linux
Jul 27, 2026
High7.8Red Hat

High [CVE-2026-66758] integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted FITS images

A flaw was found in the file-fits plugin in GIMP. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted FITS image with GIMP, reducing the likelihood of exploitation. However, successful exploitation may potentially lead to arbitrary code execution or a denial of service. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to this reason, this flaw has been rated with an important severity. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-66758
Red Hat Enterprise Linux
Jul 27, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-45623] Information disclosure and denial of service via crafted CSS input

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to read any file readable by Node and leak the first ~10 bytes of its content through the resulting JSON.parse SyntaxError message. The bug also yields a precise file-existence oracle and a controllable-read primitive that may be combined with large-file targets for DoS. The behaviour is triggered with PostCSS's default options — no from, no map, no plugins required — and is therefore reachable from any pipeline that runs untrusted CSS through PostCSS (CMS themes, user-uploaded styles, browser-extension/userstyle processors, build pipelines for third-party packages, blog comment renderers, etc.). This issue has been fixed in version 8.5.12. A flaw was found in PostCSS, a tool that processes CSS files. An attacker who provides specially crafted CSS input containing a malicious source map comment can cause the system to read arbitrary files from the local filesystem.

CVE-2026-45623
Red Hat Enterprise Linux
Jul 27, 2026
High7.2Vendor: MediumRed Hat

High [CVE-2026-54272] Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table of known IPv6 special-use prefixes, returning Global unicast when nothing matches. That table had no entry for the IPv4-mapped range (::ffff:0:0/96), so every mapped address fell through to Global unicast; NAT64 addresses matched their own NAT64 … labels. The boolean checks isLoopback, isUnspecified, and isMulticast compared getType() against a fixed label and so returned false, while isLinkLocal and isULA checked only the native IPv6 ranges. The library already exposed isMapped4() and to4(), but did not apply them inside these checks, so a mapped or NAT64 address was never normalized to its embedded IPv4 address before classification. For IPv4-mapped addresses the host OS routes to the IPv4 stack, so the misclassification is reachable on any dual-stack host. For NAT64, the classification bypass is unconditional but end-to-end reachability additionally requires a NAT64/DNS64 gateway in the deployment network. This issue has been fixed in version 10.2.1. An attacker could exploit this misclassification to bypass network restrictions and potentially access or manipulate internal resources.

CVE-2026-54272
Red Hat Enterprise Linux
Jul 27, 2026
High7.4Red Hat

High [CVE-2026-15928] Cross-Site Scripting in error page component

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component. A remote attacker could exploit this by tricking a user into clicking a specially crafted link. Successful exploitation could lead to the execution of malicious scripts in the user's browser, potentially resulting in information disclosure or session hijacking. This reflected cross-site scripting (XSS) vulnerability relies entirely on client-side interaction through a web browser. If executed, the script runs within the context of the user's browser session, making sensitive session tokens or client-side data accessible to the attacker. While external CVSSv4 scoring rates this flaw to an 8.2 High, Red Hat bounds the severity to CVSS 7.4 based on explicit CIA triad mechanics. The impact is strictly confined to Confidentiality (C:H) via potential browser-side data disclosure. The flaw carries zero impact on system Integrity (I:N) or Availability (A:N), as it cannot alter server-side application logic, modify stored data, or disrupt underlying XML-RPC services.

CVE-2026-15928
Red Hat Enterprise Linux
Jul 27, 2026
High7.3Red Hat

High [CVE-2026-51235] Buffer Overflow vulnerability in image processing

A flaw was found in LibRaw, an open-source library for processing raw image files. This vulnerability is a buffer overflow, which occurs in the `stretch()` and `fuji_rotate()` functions. A buffer overflow can allow an attacker to overwrite memory, potentially leading to a denial of service or the execution of unauthorized code. Successful exploitation requires a local attacker to trick a user into processing a specially crafted raw image file, which could lead to arbitrary code execution or a denial of service. Red Hat Enterprise Linux 9 is affected, while Red Hat Enterprise Linux 8 and older versions are not vulnerable as they ship with older, unaffected versions of LibRaw or do not contain the vulnerable code. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat fixing advisory: RHSA-2026:51105, RHSA-2026:61353, RHSA-2026:61352. Affected products named by the advisory: Red Hat package: libraw.

CVE-2026-51235
Red Hat Enterprise Linux
Jul 27, 2026
HighRed Hat

High [CVE-2026-64218] fix report_work leak on backbone_gw purge

In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: fix report_work leak on backbone_gw purge batadv_bla_purge_backbone_gw() removes stale backbone gateway entries, but fails to properly handle their associated report_work: - If report_work is running, the purge must wait for it to finish before freeing the backbone_gw, otherwise the worker may access freed memory (e.g. bat_priv). - If report_work is pending, the purge must cancel it and release the reference held for that pending work item. The previous implementation called hlist_for_each_entry_safe() inside a spin_lock_bh() section, but cancel_work_sync() may sleep and therefore cannot be called from within a spinlock-protected region. Restructure the loop to handle one entry per spinlock critical section: acquire the lock, find the next entry to purge, remove it from the hash list, then release the lock before calling cancel_work_sync() and dropping the hash_entry reference. Repeat until no more entries require purging. Red Hat severity: Important. Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-64218
Red Hat Enterprise LinuxLinux Kernel
Jul 24, 2026
High7.8Red Hat

High [CVE-2026-60122] Arbitrary OS command execution via code injection in gpsprof utility

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode. A flaw was found in gpsd. This unsanitized input is then processed by `gnuplot`, enabling the attacker to run commands as the user executing `gpsprof`. This Important flaw in the `gpsprof` utility, part of the `gpsd` package, allows arbitrary OS command execution. Exploitation requires a local attacker to provide specially crafted GPS input data and for a user to process this malicious data with `gpsprof`. This can lead to a complete system compromise. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:65162, RHSA-2026:65606. Affected products named by the advisory: Red Hat package: gpsd-minimal.

CVE-2026-60122
Red Hat Enterprise Linux
Jul 23, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-64611] cpu exhaustion via infinite loop in cfieee1284normalizemakemodel

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service. A Moderate denial-of-service vulnerability in libcupsfilters allows network attackers to exhaust CPU resources by sending malformed IEEE-1284 device IDs. Red Hat rates this as Moderate because the vulnerable component, cups-browsed, is disabled by default in RHEL. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:56965. Affected products named by the advisory: Red Hat package: libcupsfilters.

CVE-2026-64611
Red Hat Enterprise Linux
Jul 23, 2026
High7.5Red Hat

High [CVE-2026-11331] Potential wildcard CNAME RPZ policy bypass

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. A flaw was found in BIND 9, a widely used Domain Name System (DNS) software. A remote attacker could exploit this by sending specially crafted, excessively long DNS queries. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-20. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4.22; Red Hat Hardened Images. Red Hat fixing advisory: RHSA-2026:55437, RHSA-2026:54509, RHSA-2026:54510, RHSA-2026:55442, RHSA-2026:57189, RHSA-2026:55441, RHSA-2026:62549, RHSA-2026:65851, RHSA-2026:60440, RHSA-2026:54071.

CVE-2026-11331
Red Hat Enterprise Linux
Jul 22, 2026
High8.6Red Hat

High [CVE-2026-13321] DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. An attacker controlling any DNSSEC-signed zone can craft NSEC records that span into victim zones, enabling cross-zone cache poisoning with authenticated denial-of-service responses (AD=1). Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N). Weakness: CWE-345. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4.22; Red Hat Hardened Images; Red Hat Enterprise Linux 6; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:55437, RHSA-2026:60383, RHSA-2026:54509, RHSA-2026:54654, RHSA-2026:54510, RHSA-2026:55442, RHSA-2026:57189, RHSA-2026:55441, RHSA-2026:62549, RHSA-2026:65851, RHSA-2026:57362, RHSA-2026:54071.

CVE-2026-13321
Red Hat Enterprise Linux
Jul 22, 2026
High7.5Red Hat

High [CVE-2026-11622] Potential memory usage beyond configured limits

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the `max-cache-size` parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. This Important flaw in BIND's DNSSEC-validating resolver can lead to a denial of service. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-400. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.22; Red Hat Hardened Images; Red Hat Enterprise Linux 6; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:55437, RHSA-2026:60383, RHSA-2026:54509, RHSA-2026:54654, RHSA-2026:54510, RHSA-2026:55442, RHSA-2026:57189, RHSA-2026:55441, RHSA-2026:57362, RHSA-2026:54071.

CVE-2026-11622
Red Hat Enterprise Linux
Jul 22, 2026
High7.5Red Hat

High [CVE-2026-11721] Cache poisoning via label count discrepancy, RRSIG, wildcards

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-345. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.22; Red Hat Hardened Images; Red Hat Enterprise Linux 6; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:55437, RHSA-2026:60383, RHSA-2026:54509, RHSA-2026:54654, RHSA-2026:54510, RHSA-2026:55442, RHSA-2026:57189, RHSA-2026:55441, RHSA-2026:57362, RHSA-2026:66357, RHSA-2026:54071.

CVE-2026-11721
Red Hat Enterprise Linux
Jul 22, 2026
High7.5Red Hat

High [CVE-2026-13204] Unexpected exit with NSEC and NSEC3 both present

If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-617. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.22; Red Hat Hardened Images; Red Hat Enterprise Linux 6; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:55437, RHSA-2026:60383, RHSA-2026:54509, RHSA-2026:54654, RHSA-2026:54510, RHSA-2026:55442, RHSA-2026:57189, RHSA-2026:55441, RHSA-2026:57362, RHSA-2026:66357, RHSA-2026:54071. Affected products named by the advisory: Red Hat package: bind9.16; Red Hat package: bind9.18.

CVE-2026-13204
Red Hat Enterprise Linux
Jul 22, 2026
High8.6Red Hat

High [CVE-2026-44690] Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. A flaw was found in Unbound. The primary impact is the integrity of DNS resolution, potentially leading to users being directed to malicious websites or services. This Important flaw in Unbound allows a remote attacker to perform DNS cache poisoning. By controlling a delegated zone, a malicious actor can manipulate DNS resolution for arbitrary sibling zones under NSEC-signed parent domains, potentially redirecting users to malicious destinations. This poses a significant integrity risk to systems relying on Unbound for DNS resolution.

CVE-2026-44690
Red Hat Enterprise Linux
Jul 22, 2026
High7.5Red Hat

High [CVE-2026-55973] Denial of Service via malformed EDNS Report-Channel option

In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the iterator via a subquery to send out the DNS Error Report and when Unbound tries to walk that query name during 'find_closest_of_type()', it strips labels using the query name length rather than stopping at the embedded root, walks one byte past it, and feeds the first garbage byte to 'dname_query_hash()' as a label length writing over the stack variable 'labuf'. One ordinary upstream response from a delegated zone the attacker controls is sufficient to terminate the daemon. A flaw was found in Unbound. When the 'dns-error-reporting: yes' option is enabled, a remote attacker can send a specially crafted DNS response containing a malformed EDNS Report-Channel option from a delegated zone they control. This can lead to a stack variable overwrite, causing the Unbound daemon to terminate. This vulnerability results in a denial of service.

CVE-2026-55973
Red Hat Enterprise Linux
Jul 22, 2026
High7.5Red Hat

High [CVE-2026-47063] Enhance Jar handling (Oracle CPU 2026-07)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). A flaw was found in OpenJDK. There exists a potential existential forgery vulnerability in CMS and protocols which use CMS. In Java, CMS is used to sign JAR files. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-347. Affected products named by the advisory: OPENJDK ELS 11.0.32; Red Hat Build of OpenJDK 17.0.20; Red Hat Build of OpenJDK 21.0.12; Red Hat Build of OpenJDK 25.0.4; and 22 more. Affected products named by the advisory: Red Hat Build of OpenJDK 8u502; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 18 more.

CVE-2026-47063
Red Hat Enterprise Linux
Jul 21, 2026

← All Red Hat advisories