Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1648 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 622 high, 819 medium, 170 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
Medium [CVE-2026-67299] Denial of Service via crafted WindowIcon async message
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order() frees window_icon.iconInfo, but the queued async message still retains and later dispatches that stale pointer. A malicious or compromised RDP server sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON can trigger use-after-free, leading to memory corruption and client crash. A flaw was found in FreeRDP. A malicious or compromised Remote Desktop Protocol (RDP) server can exploit a heap use-after-free vulnerability when a client connects with asynchronous updates enabled. This leads to memory corruption and a denial of service on the client system, but requires user interaction with a compromised server. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-416.
Medium [CVE-2026-67319] Information disclosure and data manipulation via prototype pollution
axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component. While the top-level merged config uses a null prototype, nested plain objects such as auth and paramsSerializer are cloned into ordinary objects and read without own-property checks. When an application passes placeholder nested objects such as auth: {} or paramsSerializer: {}, inherited username/password values can cause silent injection of an Authorization: Basic header, and inherited encode/serialize values can alter query-string serialization (full serializer replacement requires a function-valued pollution primitive). This is exploitable only in the presence of pre-existing prototype pollution. A flaw was found in axios. When the JavaScript environment's `Object.prototype` has been previously compromised through a technique known as prototype pollution, axios can inadvertently use malicious properties from nested configuration objects. This can lead to the silent injection of unauthorized authentication headers, potentially exposing sensitive credentials. Additionally, it could allow an attacker to alter how data is formatted for requests, leading to data manipulation.
Medium [CVE-2026-67288] Denial of Service via crafted smartcard cache requests
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process termination. A flaw was found in FreeRDP. This can lead to a null pointer dereference, causing the client process to terminate and disrupting active remote desktop sessions. A Moderate denial of service flaw affects FreeRDP in Red Hat products. When smartcard emulation is enabled, a remote attacker can exploit this vulnerability by sending malformed smartcard cache requests, leading to a null pointer dereference and subsequent termination of the FreeRDP client process. This can disrupt active remote desktop sessions for affected users. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 6 more.
Medium [CVE-2026-66402] Server Identity Verification Bypass via TLS Certificate Validation Weaknesses
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs, it (1) truncates DNS SAN values at embedded NUL bytes (accepting e.g. 'victim.example\0.attacker.example' as 'victim.example'), (2) accepts a matching Common Name even when non-matching DNS SAN entries are present, and (3) accepts IP-literal targets via DNS/CN matching without comparing iPAddress SANs. Under a trusted or misissued certificate chain, an attacker positioned to present such a certificate can bypass server identity verification, weakening TLS server authentication. A flaw was found in FreeRDP. This flaw involves multiple weaknesses in how FreeRDP validates TLS (Transport Layer Security) certificates. FreeRDP's custom validation logic can incorrectly process DNS Subject Alternative Name (SAN) values, accept Common Names without proper comparison to other SAN entries, and fail to validate IP address SANs for IP-literal targets. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more.
Medium [CVE-2026-67289] HTTP Proxy Request Injection via Redirection
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or compromised RDP server can send a crafted redirection PDU containing embedded control characters to inject arbitrary headers/requests into the HTTP proxy CONNECT request. A flaw was found in FreeRDP. This injection could allow an attacker to manipulate the proxy's behavior or bypass certain network security policies. Moderate: This client-side vulnerability in FreeRDP allows for HTTP proxy request injection. Exploitation requires a FreeRDP client to be configured to use an HTTP proxy and to connect to a malicious or compromised RDP server, which then sends a crafted redirection PDU. This limits the attack surface to specific client configurations and interactions with untrusted RDP endpoints. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L). Weakness: CWE-93.
Medium [CVE-2026-67293] Weakens TLS server authentication due to improper wildcard certificate hostname validation
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in.example.com, so it incorrectly accepts a wildcard certificate for multi-label subdomains like a.b.example.com (which OpenSSL's X509_check_host() rejects). This weakens TLS server authentication under wildcard-certificate conditions. A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP). The software's Transport Layer Security (TLS) hostname matcher incorrectly validates wildcard certificates, allowing it to accept certificates for multi-label subdomains that should not be covered. This vulnerability could enable a remote attacker to impersonate a legitimate server, potentially compromising the authenticity of the connection. This weakens the overall security of TLS server authentication. This could allow a malicious RDP server to impersonate a legitimate server if a client attempts to connect to a subdomain covered by an improperly validated wildcard certificate. Red Hat severity: Moderate — CVSS 4.2 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-295.
Medium [CVE-2026-68563] Information disclosure of PostgreSQL data via insecure backup permissions
A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on the managed node to read sensitive archived PostgreSQL data, leading to information disclosure. The vulnerability occurs when a specific Leapp remediation task, intended to back up and remove old PostgreSQL data, creates a world-readable archive in `/var/backups`. Exploitation requires local access to a managed node where this particular remediation workflow has been executed and `/var/lib/pgsql/data` existed. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-732. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: ansible-collection-redhat-leapp.
Medium [CVE-2026-68562] Information disclosure via Leapp report tampering
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials. When an operator subsequently runs the `leapp_corrupted_grubenv_file` remediation, the Ansible controller may be tricked into disclosing sensitive controller-local files to the compromised managed node, crossing a trust boundary. Exploitation depends on both prior compromise of the managed node and specific operator action. Red Hat severity: Moderate — CVSS 6.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N). Weakness: CWE-610. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: ansible-collection-redhat-leapp.
Medium [CVE-2026-59881] Denial of Service via unnegotiated WebSocket compression
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This issue is fixed in version 3.14.2. A flaw was found in AIOHTTP. The WebSocket client in AIOHTTP processes compressed data frames even when the compression mechanism, known as permessage-deflate, has not been properly negotiated. A malicious server can exploit this by sending specially crafted compressed frames. This can lead to unexpected and excessive consumption of the system's central processing unit (CPU) and memory, potentially resulting in a denial of service (DoS) for legitimate users. Red Hat rates this flaw as Moderate with a CVSS score of 5.3 because exploitation requires an aiohttp WebSocket client to connect to an attacker-controlled server. In typical Red Hat product deployments, aiohttp serves as an HTTP client library for internal service communication rather than establishing WebSocket connections to untrusted endpoints. The resulting resource consumption is limited to the individual process running the affected client and does not propagate to other services or the host system. Weakness: CWE-409.
Medium [CVE-2026-18369] ACME HTTP-01 validation SSRF via IP literal identifiers and unvalidated redirects
A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error. Red Hat rates this Moderate because exploitation is limited to HTTP GET requests (no integrity impact), the attacker cannot read internal responses on production-supported backends (low confidentiality impact), and the ACME responder must be explicitly deployed. The Scope is Changed (S:C) because the ACME responder causes the Dogtag server to make outbound requests to services outside its own trust boundary, but the actual information gained on supported configurations is limited to network topology probing. While the SSRF is GET-only and does not directly allow data modification, administrators should be aware that internal services reachable from the Dogtag host which perform actions on HTTP GET (such as cloud instance metadata endpoints that issue temporary credentials) could be indirectly affected.
Medium [CVE-2026-56850] mTLS client identities can be reused due to HTTPS Agent connection flaw
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. A flaw was found in Node.js. The HTTPS Agent, responsible for managing secure connections, can incorrectly reuse client identities across different requests. As a result, a client's identity, established through mutual TLS (mTLS) authentication, could be mistakenly applied to another request, potentially leading to unauthorized access or identity spoofing. This can lead to unintended identity confusion if applications are configured to use different client certificates with reused connections, potentially enabling unauthorized access within the mTLS context. Red Hat severity: Moderate — CVSS 4.1 (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-303. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Hardened Images. Red Hat fixing advisory: RHSA-2026:48273, RHSA-2026:48305, RHSA-2026:48537. Affected products named by the advisory: Red Hat package: nodejs22; Red Hat package: nodejs24.
Medium [CVE-2026-16531] Arbitrary file creation via path traversal in pmproxy logger servlet
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service. This can lead to a denial of service or other impacts on systems where pmproxy is exposed on TCP port 44322, as the logger servlet is unconditionally active. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-22. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: pcp.
Medium [CVE-2026-16530] Remote denial of service and information leakage
A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory. This Moderate impact flaw in the PCP `pmproxy` service allows a remote, unauthenticated attacker to trigger a denial of service or information leakage. The vulnerability stems from a bypassed bounds check in the `pmLogLoadInDom()` function, which can lead to service instability or memory exposure. Exploitation requires the `pmproxy` service to be reachable on its default TCP port 44322. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: pcp.
Medium [CVE-2026-17914] Side-channel information leakage in Skia
Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Weakness: CWE-205. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:74084. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.
Medium [CVE-2026-17891] Use after free in ANGLE
Use after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:74084, RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.
Medium [CVE-2026-17790] Uninitialized Use in ANGLE
Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) An uninitialized use flaw was found in the ANGLE component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-824. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:74084, RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.
Medium [CVE-2026-17785] Uninitialized Use in ANGLE
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) An uninitialized use flaw was found in the ANGLE component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-824. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:74084, RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.
Medium [CVE-2026-17771] Uninitialized Use in Skia
Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) An uninitialized use flaw was found in the Skia component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-824. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:74084. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.
Medium [CVE-2026-17714] Uninitialized Use in ANGLE
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) An uninitialized use flaw was found in the ANGLE component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-824. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:74084, RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.
Medium [CVE-2026-62946] Denial of Service via integer overflow in JNX decoder on 32-bit systems
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27. A flaw was found in ImageMagick. This overflow leads to a heap buffer over-write, which can cause the application to crash, resulting in a denial of service. This Moderate impact flaw in ImageMagick affects 32-bit systems, where processing an exceptionally large JNX image file can trigger an integer overflow. Red Hat severity: Moderate — CVSS 5.1 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.