Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1653 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 33 critical, 627 high, 820 medium, 171 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

Medium5.1Red Hat

Medium [CVE-2026-62946] Denial of Service via integer overflow in JNX decoder on 32-bit systems

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27. A flaw was found in ImageMagick. This overflow leads to a heap buffer over-write, which can cause the application to crash, resulting in a denial of service. This Moderate impact flaw in ImageMagick affects 32-bit systems, where processing an exceptionally large JNX image file can trigger an integer overflow. Red Hat severity: Moderate — CVSS 5.1 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-62946
Red Hat Enterprise Linux
Jul 30, 2026
Medium5.0Red Hat

Medium [CVE-2026-62363] Denial of Service via crafted argument in fx operation

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27. A flaw was found in ImageMagick. This could lead to a denial of service. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-62363
Red Hat Enterprise Linux
Jul 30, 2026
Medium4.7Red Hat

Medium [CVE-2026-62343] Denial of Service via heap buffer over-write in morphology operation with invalid kernel

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. A local user could provide a specially crafted, invalid kernel during a morphology operation. This action could trigger a heap buffer over-write, leading to a denial of service (DoS) for the ImageMagick application. This vulnerability primarily impacts the availability of the image processing service. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-805. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-62343
Red Hat Enterprise Linux
Jul 29, 2026
Medium5.3Red Hat

Medium [CVE-2026-64685] Information Disclosure via Crafted Image File

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27. A remote attacker could exploit a vulnerability in the BGR decoder by providing a specially crafted image file. This flaw, caused by a missing end-of-file check, can lead to a heap buffer over-read, potentially resulting in the disclosure of sensitive information. Moderate: ImageMagick's BGR decoder is vulnerable to a heap buffer over-read when processing specially crafted image files. This flaw could lead to information disclosure if applications using ImageMagick process untrusted images, potentially exposing sensitive memory contents. The impact is limited to information disclosure and does not directly enable arbitrary code execution. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-64685
Red Hat Enterprise Linux
Jul 29, 2026
Medium5.9Red Hat

Medium [CVE-2026-13346] Arbitrary file installation via malicious package indexes

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time. A flaw was found in pip. When processing doubly-encoded package URLs from malicious package indexes, pip incorrectly handles the file paths. A remote attacker could exploit this by convincing a user to download or install a package from such an index. This could allow for files to be installed to arbitrary locations on the system, potentially leading to system compromise. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L). Weakness: CWE-22. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:48788. Affected products named by the advisory: Red Hat package: python-pip.

CVE-2026-13346
Red Hat Enterprise Linux
Jul 29, 2026
Medium4.7Red Hat

Medium [CVE-2026-52791] Privilege Escalation Vulnerability via SUID/SGID Bit Preservation

fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. This issue is fixed in version 1.17. This vulnerability allows a low-privileged process to retain SUID (Set User ID) and SGID (Set Group ID) permissions on files after they are truncated or opened with the O_TRUNC flag. This can enable a local attacker to manipulate file permissions, potentially leading to privilege escalation within the system. On currently supported Red Hat Enterprise Linux releases (RHEL >= 8.5 / RHEL 9 / RHEL 10), rootless Podman uses native kernel overlayfs by default; fuse-overlayfs is only invoked as a fallback or when explicitly configured via storage.conf's mount_program option, or in nested/unprivileged container scenarios (e.g. rootless Buildah image builds) that lack CAP_SYS_ADMIN. Exploitation additionally requires a pre-existing file in the container's lower image layer that already carries the SUID or SGID bit and is writable by a low-privileged process, an atypical container image configuration.

CVE-2026-52791
Red Hat Enterprise Linux
Jul 29, 2026
Medium5.6Red Hat

Medium [CVE-2026-56390] Arbitrary file overwrite via grammar-defined output paths

GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this behavior allows directing generated files to arbitrary writable locations on the filesystem, potentially overwriting existing files accessible to the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 8d101c19d4d9aaedf83a448c925513742d4efcf0. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. Consequently, generated files can be directed to any writable location on the filesystem, potentially overwriting existing files and leading to data integrity issues. Red Hat severity: Moderate — CVSS 5.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L). Weakness: CWE-22. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-56390
Red Hat Enterprise Linux
Jul 29, 2026
Medium5.5Red Hat

Medium [CVE-2026-56389] Arbitrary Code Execution via malicious grammar file

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. Exploitation requires user interaction to process a malicious grammar file, which limits the attack surface to scenarios where untrusted input is explicitly processed. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6.

CVE-2026-56389
Red Hat Enterprise Linux
Jul 29, 2026
Medium5.3Red Hat

Medium [CVE-2026-66299] Denial of Service via WebSocket chat example

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. This can lead to the affected system becoming unresponsive or crashing. The impact is limited as the vulnerable component is part of an example application, which is generally not deployed in production environments. Exploitation requires the example application to be present and accessible. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-770. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:56039. Affected products named by the advisory: Red Hat package: tomcat9; Red Hat package: pki-servlet-engine.

CVE-2026-66299
Red Hat Enterprise Linux
Jul 28, 2026
Medium6.5Red Hat

Medium [CVE-2026-18047] ACME admin enable/disable endpoint authentication bypass via trailing slash

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service. Red Hat rates this as Moderate because the impact of the authentication bypass is limited in scope and consequence. The vulnerability only affects the ACME enable/disable admin endpoints — other PKI subsystems (CA, KRA, OCSP, TPS) enforce authorization at the application layer and are not affected by this flaw. An attacker who exploits this flaw can only toggle the ACME service on or off. While re-enabling a disabled ACME service restores the full ACME protocol stack, certificate issuance through ACME still requires completing the standard RFC 8555 challenge-response flow, including proof of domain control — the enable/disable bypass alone does not grant the ability to obtain certificates. The ACME responder requires explicit installation and deployment and is not present in default PKI server configurations. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-288.

CVE-2026-18047
Red Hat Enterprise Linux
Jul 28, 2026
Medium6.5Red Hat

Medium [CVE-2026-58224] CTDB fails to do integrity checking of received packets

A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings, or inconsistent packet sizes to be processed without adequate bounds checking. A remote attacker with access to the CTDB private network may trigger a denial of service through process crashes or excessive memory consumption and, in limited cases, disclose adjacent memory contents. CTDB is an optional clustering component of Samba used strictly for multi-node active/active file sharing and is not installed, configured, or running by default on standard Red Hat Enterprise Linux (RHEL) deployments. Red Hat historically supported CTDB in RHEL High Availability and Resilient Storage configurations (including RHEL 6 and RHEL 7) and officially deprecated standalone CTDB usage as of RHEL 8.4 in favor of Pacemaker-managed cluster deployments. Network Architecture Mitigations: For legacy or historical environments actively utilizing CTDB via supported RHEL High Availability or Resilient Storage cluster configurations, Red Hat’s official Support Policies for RHEL High Availability Clusters explicitly mandate that CTDB private interconnect traffic must run on a dedicated, isolated private network segment segregated from client networks.

CVE-2026-58224
Red Hat Enterprise Linux
Jul 28, 2026
Medium5.4Red Hat

Medium [CVE-2026-53669] Open Redirect vulnerability via backslashes in navigation components

React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0. A remote attacker could exploit this vulnerability by crafting a malicious link that uses backslashes within the or useNavigate components. This could lead to an Open Redirect, allowing the attacker to redirect users to arbitrary external websites, potentially for phishing or other malicious purposes. This could facilitate phishing attacks against users. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-601. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Exploit Intelligence; Gatekeeper 3; and 41 more. Affected products named by the advisory: Migration Toolkit for Virtualization; Multicluster Engine for Kubernetes; Network Observability Operator; Node HealthCheck Operator; and 37 more.

CVE-2026-53669
Red Hat Enterprise Linux
Jul 27, 2026
Medium6.5Red Hat

Medium [CVE-2026-55685] @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests

React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue has been fixed in version 7.18.0. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and impacting the availability of the application. Repeated, targeted requests to this endpoint place heavy load on the server and can degrade or deny service for other users. Applications using Declarative Mode () or Data Mode (createBrowserRouter/) do not run this server-side code path and are not affected. This mirrors the same re-scoring applied to the predecessor flaw, CVE-2026-42342, for the same endpoint family. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4; Exploit Intelligence; Network Observability Operator; and 14 more.

CVE-2026-55685
Red Hat Enterprise Linux
Jul 27, 2026
Medium6.1Red Hat

Medium [CVE-2026-53666] Information disclosure via client-side constructor execution

React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which would in turn trigger an outbound network request. This is only possible with very specific (and unlikely) application-layer code. Note that this does not impact an application if it is using Declarative Mode. It only impacts Framework Mode and Data Mode applications that perform manual SSR/hydration. This issue has been fixed in version 7.18.0. This execution could lead to an outbound network request, potentially resulting in limited information disclosure or unintended network activity. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-502. Affected products named by the advisory: Cryostat 4; Exploit Intelligence; Gatekeeper 3; Migration Toolkit for Applications 8; and 41 more. Affected products named by the advisory: Migration Toolkit for Containers; Migration Toolkit for Virtualization; Multicluster Engine for Kubernetes; Network Observability Operator; and 37 more.

CVE-2026-53666
Red Hat Enterprise Linux
Jul 27, 2026
Medium5.5Red Hat

Medium [CVE-2026-66757] signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on RLE SGI images

A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize * zsize overflows the standard 32-bit int boundary before being passed to calloc. This integer overflow issue results in undefined behavior, aborting the plugin and causing a denial of service. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-66757
Red Hat Enterprise Linux
Jul 27, 2026
Medium5.3Red Hat

Medium [CVE-2026-64643] Information disclosure via Server Action ID exposure

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used. Server Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references). By itself, this disclosure is typically a recon/enumeration primitive; however, it can increase risk when combined with other weaknesses. This issue has been fixed in versions 15.5.21 and 16.2.11. A flaw was found in Next.js. This bypasses authentication on pages where these endpoints are used, leading to information disclosure. This Moderate information disclosure vulnerability in Next.js applications allows unauthenticated users to obtain Server Action IDs from publicly served client artifacts. While primarily a reconnaissance primitive, this exposure could increase overall risk when chained with other weaknesses. Red Hat products and services that incorporate Next.js, such as Red Hat AMQ, Red Hat Enterprise Linux AI, and cloud.redhat.com offerings, are affected. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-201.

CVE-2026-64643
Red Hat Enterprise Linux
Jul 27, 2026
Medium5.6Red Hat

Medium [CVE-2026-15003] Heap-buffer-overflow in linker leads to information disclosure and denial of service

A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing. This vulnerability is rated as High. A heap-buffer-overflow in the GNU Binutils linker (`ld`) can lead to information disclosure and denial of service when processing specially crafted 32-bit XCOFF object files. This occurs because the linker uses an unvalidated field from untrusted input as an array index, potentially exposing heap metadata or causing a crash during the linking process. Red Hat severity: Moderate — CVSS 5.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:47171.

CVE-2026-15003
Red Hat Enterprise Linux
Jul 27, 2026
Medium5.3Red Hat

Medium [CVE-2026-64538] Fix null-ptr-deref in fib6_nh_mtu_change

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change(). fib6_nh_mtu_change() re-fetches idev via __in6_dev_get(arg->dev) and dereferences idev->cnf.mtu6 without a NULL check. addrconf_ifdown() clears dev->ip6_ptr with RCU_INIT_POINTER() after rt6_disable_ip() has released tb6_lock, so the RA-driven MTU walk can observe a NULL idev and oops. The caller rt6_mtu_change_route() guards its own __in6_dev_get(), but this re-fetch is unguarded; nexthop-backed routes survive addrconf_ifdown()'s flush, so the walk still reaches it after ip6_ptr is nulled. Return 0 when idev is NULL, matching rt6_mtu_change_route() and the fib6_mtu() fix in commit 5ad509c1fdad ("ipv6: Fix null-ptr-deref in fib6_mtu()."). Oops: general protection fault,... KASAN: null-ptr-deref in range [0x00000000000002a8-0x00000000000002af] RIP: 0010:fib6_nh_mtu_change+0x203/0x990 rt6_mtu_change_route+0x141/0x1d0 __fib6_clean_all+0xd0/0x160 rt6_mtu_change+0xb4/0x100 ndisc_router_discovery+0x24b5/0x2cb0 icmpv6_rcv+0x12e9/0x1710 ipv6_rcv+0x39b/0x410 A flaw was found in the Linux kernel's IPv6 networking component. A null pointer dereference vulnerability exists in the `fib6_nh_mtu_change()` function. An attacker could potentially trigger this condition, leading to a kernel crash and a Denial of Service (DoS).

CVE-2026-64538
Red Hat Enterprise LinuxLinux Kernel
Jul 27, 2026
Medium6.5Red Hat

Medium [CVE-2026-66337] heap buffer over-read via integer underflow in soup_filter_input_stream_read_until

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory. A malicious HTTP server can trigger this against any libsoup client using SoupMultipartInputStream by sending a crafted multipart response with a boundary string longer than the internal buffer. This issue is related to but distinct from CVE-2026-1761. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.

CVE-2026-66337
Red Hat Enterprise Linux
Jul 24, 2026
Medium5.4Vendor: LowRed Hat

Medium [CVE-2026-66338] http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests. The practical impact is limited because libsoup servers are rarely deployed in internet-facing infrastructure behind reverse proxies. This issue is distinct from CVE-2026-1801 which covers bare LF tolerance. Red Hat severity: Low — CVSS 5.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N). Weakness: CWE-444. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.

CVE-2026-66338
Red Hat Enterprise Linux
Jul 24, 2026

← All Red Hat advisories