Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories
1217 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 792 high, 374 medium, 17 low.
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux Red Hat Enterprise Linux advisories
High [CVE-2026-6859] Arbitrary code execution due to hardcoded `trust_remote_code=True`
Arbitrary code execution due to hardcoded `trust_remote_code=True`. Red Hat rates this important (CVSS 8.8). Weakness: CWE-829. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-32178] SMTP Command Injection and Header Injection via MailAddress parsing flaw
SMTP Command Injection and Header Injection via MailAddress parsing flaw. Red Hat rates this important (CVSS 7.5). Weakness: CWE-138. Affected package(s): dotnet8.0, dotnet10.0, dotnet8, dotnet9.0, dotnet9, dotnet10. Resolved in Red Hat advisory RHSA-2026:9080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.
High [CVE-2026-26171] .NET: Security Bypass and Denial of Service Vulnerability
.NET: Security Bypass and Denial of Service Vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected package(s): dotnet8.0, dotnet10.0, dotnet8, dotnet9.0, dotnet9, dotnet10. Resolved in Red Hat advisory RHSA-2026:9080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.
High [CVE-2026-32203] .NET: Denial of Service via stack overflow
.NET: Denial of Service via stack overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): dotnet8.0, dotnet10.0, dotnet8, dotnet9.0, dotnet9, dotnet10. Resolved in Red Hat advisory RHSA-2026:9080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.
High [CVE-2026-33116] .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform
.NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected package(s): dotnet8.0, dotnet10.0, dotnet8, dotnet9.0, dotnet9, dotnet10. Resolved in Red Hat advisory RHSA-2026:9080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.
High [CVE-2026-2332] HTTP request smuggling via chunked extension quoted-string parsing
HTTP request smuggling via chunked extension quoted-string parsing. Red Hat rates this important (CVSS 7.4). Weakness: CWE-444. Affected package(s): offline-knowledge-portal/rhokp-rhel9:1779996999, devspaces/pluginregistry-rhel9:1776717247, jmc, jetty-http, devspaces/openvsx-rhel9:1776716842. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Offline Knowledge Portal 1.2.7; Red Hat OpenShift Dev Spaces 3.27; OpenShift Developer Tools and Services; and 9 more.
High [CVE-2026-40164] Denial of Service via crafted JSON object causing hash collisions
Denial of Service via crafted JSON object causing hash collisions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-341. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, jq, rhcos, rhaiis/model-opt-cuda-rhel9:1780681984, rhaiis/vllm-rocm-rhel9:1782353093. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 19 more.
High [CVE-2026-39979] out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers
out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, jq, rhcos, rhaiis/model-opt-cuda-rhel9:1780681984, rhaiis/vllm-rocm-rhel9:1782353093. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 21 more.
High [CVE-2026-4786] Arbitrary code execution via command injection in webbrowser.open() API
Arbitrary code execution via command injection in webbrowser.open() API. Red Hat rates this important (CVSS 7.1). Weakness: CWE-88. Affected package(s): python3.11, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, rhpam, python3.9, python3.12. Resolved in Red Hat advisory RHSA-2026:35838 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 16 more.
High [CVE-2026-6100] Arbitrary code execution or information disclosure via use-after-free in decompression modules
Arbitrary code execution or information disclosure via use-after-free in decompression modules. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825. Affected package(s): python3.11, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, rhpam, python3.9, python3.12. Resolved in Red Hat advisory RHSA-2026:26187 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 16 more.
High [CVE-2026-5367] Information disclosure via crafted DHCPv6 packets
Information disclosure via crafted DHCPv6 packets. Red Hat rates this important (CVSS 8.6). Weakness: CWE-130. Affected package(s): ovn25.03, ovn25.09, ovn, ovn23.09, ovn24.03, ovn23.06. Resolved in Red Hat advisory RHSA-2026:11702 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Fast Datapath for Red Hat Enterprise Linux 10; Fast Datapath for Red Hat Enterprise Linux 8; Fast Datapath for Red Hat Enterprise Linux 9; Fast Datapath for RHEL 8; and 2 more.
High [CVE-2026-31419] Linux kernel: Use-after-free in bonding driver leads to denial of service
Linux kernel: Use-after-free in bonding driver leads to denial of service. Red Hat rates this important (CVSS 7). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 2 more.
High [CVE-2026-4154] Remote Code Execution via XPM File Parsing Integer Overflow
Remote Code Execution via XPM File Parsing Integer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:17533 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.
High [CVE-2026-4153] Remote Code Execution via PSP file parsing
Remote Code Execution via PSP file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:17533 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.
High [CVE-2026-4152] Remote Code Execution via malicious JP2 file parsing
Remote Code Execution via malicious JP2 file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Affected package(s): gimp. Resolved in Red Hat advisory RHSA-2026:25907 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.
High [CVE-2026-4151] Remote Code Execution via ANI File Parsing Integer Overflow
Remote Code Execution via ANI File Parsing Integer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): gimp. Resolved in Red Hat advisory RHSA-2026:16484 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-4150] Arbitrary code execution via specially crafted PSD file
Arbitrary code execution via specially crafted PSD file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:17533 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 9 more.
High [CVE-2026-34486] Missing Encryption of Sensitive Data due to EncryptInterceptor bypass
Missing Encryption of Sensitive Data due to EncryptInterceptor bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-807. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; and 8 more.
High [CVE-2026-29146] Information disclosure via Padding Oracle vulnerability in EncryptInterceptor
Information disclosure via Padding Oracle vulnerability in EncryptInterceptor. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1240. Affected package(s): jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; and 10 more.
High [CVE-2026-34734] HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file
HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.