Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1654 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 33 critical, 634 high, 815 medium, 170 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

High7.8Red Hat

High [CVE-2026-58459] Command Injection via GPS device subtype allows arbitrary code execution

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow. A flaw was found in gpsd, a service application that monitors one or more GPSes or AIS receivers. When a user processes a specially crafted plot through gpsprof and gnuplot, these embedded commands can be executed, leading to arbitrary code execution on the system. Exploitation requires user interaction. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:51075, RHSA-2026:51153. Affected products named by the advisory: Red Hat package: gpsd-minimal.

CVE-2026-58459
Red Hat Enterprise Linux
Jul 9, 2026
High7.3Red Hat

High [CVE-2026-12080] Local privilege escalation via symlink attack in guest-ssh-add-authorized-keys

A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating symbolic links. This can occur either through a deterministic directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race. Successful exploitation allows the attacker to gain ownership of arbitrary root-owned files or directories, leading to root access. This vulnerability requires an external management layer (e.g., libvirt) to trigger the affected code path. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-61. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7 as not affected. Will not fix / out of support: Red Hat Enterprise Linux for NVIDIA 26. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: qemu-kvm.

CVE-2026-12080
Red Hat Enterprise Linux
Jul 9, 2026
High7.5Red Hat

High [CVE-2026-59939] Denial of Service via unbounded decompression of HTTP response bodies

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0. This unbounded decompression can lead to a Denial of Service (DoS) by causing the client application to run out of memory and crash. This Important vulnerability in `httplib2` allows a remote attacker to trigger a Denial of Service (DoS) in client applications. By sending a specially crafted, compressed HTTP response, a malicious server can cause the client to exhaust its memory due to unbounded decompression, leading to application crashes. This poses a significant risk to Red Hat products that use `httplib2` to process untrusted HTTP content. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-409.

CVE-2026-59939
Red Hat Enterprise Linux
Jul 8, 2026
High7.8Red Hat

High [CVE-2026-39822] Go os.Root: Symlink following vulnerability allows directory traversal

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root. Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root. This vulnerability allows an attacker to bypass intended directory restrictions by crafting a path that ends with a symbolic link and a trailing slash. When a file is opened in `os.Root` with such a path, the symbolic link is improperly followed, potentially leading to access to locations outside of the defined root directory. This could result in information disclosure or unauthorized file system access. A flaw was found in Go's os.Root implementation. This is because `openat()` with `O_NOFOLLOW` does not prevent symlink resolution when the path has a trailing /. An attacker able to create symlinks within an os.Root directory could use this to read or write files outside the intended root. Go versions prior to 1.24 are not affected. This issue is fixed in Go 1.25.12 and Go 1.26.5. The following symbols are affected: * `OpenInRoot`: Opens a file or directory within an `os.Root`. * `Root. Create`: Creates a file inside an `os.Root`. * `Root. Open`: Opens a path relative to an `os.Root`. * `Root.

CVE-2026-39822
Red Hat Enterprise Linux
Jul 8, 2026
High7.5Red Hat

High [CVE-2026-59877] Denial of Service via crafted.proto schema

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted.proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6. A remote attacker could exploit this vulnerability by providing a specially crafted.proto schema. This leads to a Denial of Service (DoS), making the affected system unresponsive. The `protobufjs` library, used in Red Hat products, is susceptible to a Denial of Service when processing a specially crafted `.proto` schema. This is considered Important due to the potential for significant disruption to services that handle external protobuf definitions. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Enterprise Linux 10; Red Hat Ansible Automation Platform 2.1; Red Hat Ansible Automation Platform 2.2; and 16 more.

CVE-2026-59877
Red Hat Enterprise Linux
Jul 8, 2026
High7.5Red Hat

High [CVE-2026-59874] Denial of Service via malformed tar archive header

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header causes the archive scanner to enter an infinite loop, repeatedly parsing the same header and preventing further processing. This can lead to a denial of service (DoS) condition, making the affected system or application unresponsive. This Important denial of service flaw in node-tar affects Red Hat products that process untrusted tar archives. A remote attacker can provide a specially crafted archive with a malformed header, leading to an infinite loop during parsing and causing the application to become unresponsive. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-606. Affected products named by the advisory: Red Hat AMQ Broker 7.13.6; Red Hat AMQ Broker 7.14.1; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 30 more.

CVE-2026-59874
Red Hat Enterprise Linux
Jul 8, 2026
High7.5Red Hat

High [CVE-2026-59873] Denial of Service via crafted gzip bomb

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. The primary impact is a Denial of Service (DoS), making the affected system or application unavailable. This vulnerability in node-tar is rated as Important. A remote attacker can exploit the lack of strict limits on decompressed data and entry counts within the library's archive processing to craft a gzip bomb. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected products named by the advisory: Red Hat AMQ Broker 7.13.6; Red Hat AMQ Broker 7.14.1; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 33 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Ansible Automation Platform 2.2; Red Hat Migration Toolkit 1.8; Red Hat OpenShift AI 2.25; and 29 more.

CVE-2026-59873
Red Hat Enterprise Linux
Jul 8, 2026
High7.5Red Hat

High [CVE-2026-59869] Denial of Service via crafted YAML documents

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0. A remote attacker could exploit this vulnerability by providing a specially crafted YAML document containing a chain of mappings with merge keys. This could cause the parser to consume excessive CPU resources, leading to a Denial of Service (DoS) for the affected system. This vulnerability is rated as Important. Red Hat products utilizing `js-yaml` to process untrusted YAML input are susceptible to a denial of service, as a remote attacker can provide a crafted document that consumes excessive CPU resources. This is considered Important due to the potential for service disruption without requiring authentication or complex attack vectors. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-606. Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat AMQ Broker 7.13.6; Red Hat AMQ Broker 7.14.1; Red Hat Ansible Automation Platform 2.5 for RHEL 8; and 46 more.

CVE-2026-59869
Red Hat Enterprise Linux
Jul 8, 2026
High7.7Red Hat

High [CVE-2026-60002] Use-after-free vulnerability during host key re-exchange on the client side

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) A flaw was found in OpenSSH. This could lead to high impact on confidentiality and integrity, and low impact on availability. Red Hat severity: Important — CVSS 7.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.22; Red Hat Hardened Images; Red Hat Update Infrastructure 5. Red Hat fixing advisory: RHSA-2026:47757, RHSA-2026:65900, RHSA-2026:47756, RHSA-2026:66410, RHSA-2026:54769, RHSA-2026:37382, RHSA-2026:54387, RHSA-2026:58981. Affected products named by the advisory: Red Hat package: openssh.

CVE-2026-60002
Red Hat Enterprise Linux
Jul 8, 2026
High7.5Red Hat

High [CVE-2026-59999] OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. When `DisableForwarding=yes` is configured to prevent network traffic forwarding, it incorrectly fails to take precedence over `PermitTunnel=yes`. This allows a remote attacker to bypass intended security restrictions and establish a tunnel, potentially leading to unauthorized network access or circumvention of security policies, even when forwarding is explicitly disabled. This Moderate severity flaw in OpenSSH `sshd` allows `PermitTunnel=yes` to override `DisableForwarding=yes`, potentially bypassing intended security controls. In Red Hat environments where `DisableForwarding` is used to restrict SSH session capabilities, an attacker who compromises a user's session could still establish a tunnel, leading to unauthorized network access or data exfiltration. This bypass occurs even when administrators explicitly attempt to prevent forwarding, though `PermitTunnel` is not enabled by default. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-358. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat OpenShift Container Platform 4.

CVE-2026-59999
Red Hat Enterprise Linux
Jul 8, 2026
High7.5Red Hat

High [CVE-2026-55999] glamor Font Atlas Heap Buffer Overflow

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks. A flaw was found in the glamor_font_get() function of the xorg-x11-server. This vulnerability, a heap buffer overflow, occurs when the server processes a specially crafted PCF font file where individual glyph metrics exceed the declared maximum bounds. An authenticated X client can exploit this by loading a malicious font and drawing text, potentially leading to arbitrary code execution with attacker-controlled content and extent. This affects servers utilizing the glamor acceleration backend, such as Xorg with the modesetting driver and Xwayland. This Important flaw in xorg-x11-server allows an authenticated X client to achieve arbitrary code execution. This vulnerability primarily impacts Red Hat systems running Xorg with the modesetting driver or Xwayland, typically found in desktop environments. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-805.

CVE-2026-55999
Red Hat Enterprise Linux
Jul 8, 2026
High7.3Red Hat

High [CVE-2026-56001] BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow

A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont A flaw was found in libXfont2. In the BitmapScaleBitmaps() function, an integer overflow can occur when calculating the memory needed for font glyphs. This overflow leads to a heap buffer overflow, where a smaller-than-required memory buffer is allocated. A local attacker can exploit this by loading a specially crafted PCF font, potentially leading to arbitrary code execution or a denial of service. This flaw in libXfont2 is rated as Important. A local attacker could exploit an integer overflow in the `BitmapScaleBitmaps()` function, leading to a heap buffer overflow and potential arbitrary code execution or denial of service. This vulnerability requires the processing of a specially crafted PCF font, typically through an X server or an application configured to load untrusted font files. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-56001
Red Hat Enterprise Linux
Jul 8, 2026
High7.3Red Hat

High [CVE-2026-56002] PCF Font Parsing Heap Buffer Overflow

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within the X server. A flaw was found in libXfont2. A specially crafted PCF (Portable Compiled Format) font file, when processed by libXfont2, can lead to a buffer overflow. This occurs because the font parsing process does not properly validate the size of a bitmap buffer against the glyph metrics provided in the malicious font file. An attacker could exploit this vulnerability by providing a malicious font, potentially leading to arbitrary code execution or a denial of service. This is an Important flaw in libXfont2, affecting Red Hat Enterprise Linux. A heap buffer overflow during PCF font file parsing can lead to arbitrary code execution or denial of service. Exploitation requires processing a specially crafted font file, but does not necessitate rendering. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-56002
Red Hat Enterprise Linux
Jul 8, 2026
High7.1Red Hat

High [CVE-2026-59691] rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer

A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption. This vulnerability is rated as Important severity because it is a heap out-of-bounds write reachable over the network, though exploitation requires user interaction (connecting to a malicious VNC server). The rfbsrc plugin is shipped as part of gstreamer1-plugins-bad-free in Red Hat Enterprise Linux 8, 9, 10, and Red Hat In-Vehicle Operating System (RHIVOS). A user must actively connect a GStreamer pipeline to a malicious RFB/VNC server to trigger this vulnerability. Code execution has not been demonstrated but cannot be ruled out for heap overflows. This is in the same code area as CVE-2026-52720, a few lines further down. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H). Weakness: CWE-787.

CVE-2026-59691
Red Hat Enterprise Linux
Jul 8, 2026
High7.5Red Hat

High [CVE-2026-59692] DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service. This vulnerability is rated as Important severity because it is remotely triggerable without authentication or user interaction during a DTLS handshake. However, the actual impact is limited to denial of service. Remote code execution is not achievable because X509_NAME_print_ex() escapes all binary and control characters to printable ASCII sequences, preventing arbitrary byte injection into the overflow. Combined with stack canary protection (-fstack-protector-strong) in Red Hat builds, return address corruption cannot be exploited. The DTLS plugin is shipped as part of gstreamer1-plugins-bad-free in Red Hat Enterprise Linux 8, 9, 10, and RHIVOS. It is used by GStreamer WebRTC pipelines. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-121.

CVE-2026-59692
Red Hat Enterprise Linux
Jul 8, 2026
High7.3Red Hat

High [CVE-2026-56003] computeProps Property Buffer Heap Buffer Overflow

A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Affected Red Hat products: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:51061, RHSA-2026:51063, RHSA-2026:47103, RHSA-2026:51060, RHSA-2026:51066, RHSA-2026:51067, RHSA-2026:51062, RHSA-2026:51058, RHSA-2026:51059.

CVE-2026-56003
Red Hat Enterprise Linux
Jul 8, 2026
High8.1Red Hat

High [CVE-2026-14739] Heap overflow when preparsing SQL statements with excessive placeholders

DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders. This vulnerability, a heap overflow, occurs when the software attempts to preparse SQL statements containing an extremely large number of placeholders. This could allow a remote attacker to cause a denial of service or potentially execute arbitrary code. A heap overflow can occur when processing SQL statements with an exceptionally large number of placeholders, potentially leading to a denial of service or arbitrary code execution. While requiring an extreme number of placeholders, this flaw could impact applications utilizing DBI in Red Hat environments that handle untrusted or maliciously crafted SQL queries. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-131. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Insights proxy 1.5; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2026:49514, RHSA-2026:52772, RHSA-2026:62667, RHSA-2026:49612, RHSA-2026:53371. Affected products named by the advisory: Red Hat package: perl-dbi.

CVE-2026-14739
Red Hat Enterprise Linux
Jul 7, 2026
High8.8Red Hat

High [CVE-2026-14380] Arbitrary code execution via caller-influenced Profile attribute

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl code execution, including calls to run system commands. The Profile attribute can be set from three different sources that can carry untrusted data: the DBI_PROFILE environment variable, a direct attribute assignment, and a DSN driver-attribute clause dbi:Driver(Profile=>SPEC):db. An attacker controlling any of those inputs runs arbitrary Perl in the host process. The strongest remote position is a network-exposed DBI::Gofer / DBI::ProxyServer whose per-request DSN reaches the Profile attribute, letting a client execute code on the broker host. A flaw was found in the DBI component for Perl. This vulnerability allows an attacker to inject and execute arbitrary code by manipulating the Profile attribute of a DBI handle. When a string is assigned to this attribute, the component processes it without proper validation, enabling the execution of unauthorized Perl code, including system commands.

CVE-2026-14380
Red Hat Enterprise Linux
Jul 7, 2026
High8.8Red Hat

High [CVE-2026-11610] Heap buffer overflow in sasl_io_recv via padded SASL UNBIND

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. Red Hat rates this issue as Important impact. Exploitation requires a valid SASL-authenticated LDAP session, not Directory Manager access. Any user who can bind with SASL mechanisms such as GSSAPI/Kerberos or DIGEST-MD5 can trigger the denial of service. In deployments where domain users, enrolled hosts, and service accounts routinely authenticate to the directory over Kerberos, the attack surface includes any such principal with network access to LDAP. This flaw is independent of CVE-2025-14905, which patched a separate heap overflow in schema.c and did not modify sasl_io.c. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2026-11610
Red Hat Enterprise Linux
Jul 7, 2026
High8.8Red Hat

High [CVE-2026-14474] sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts. Red Hat has rated this as Important because the attack requires only low-privilege delegated LDAP write access to any subtree, which is a common delegation pattern in enterprise environments. The default ldap_sudo_search_base configuration searches the entire directory tree, allowing sudo rule injection from outside the intended sudoers container. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-1188. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 20 more.

CVE-2026-14474
Red Hat Enterprise Linux
Jul 7, 2026

← All Red Hat advisories