Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1217 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 792 high, 374 medium, 17 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High7.5Linux

High [CVE-2026-50559] Authorization bypass in HTTP path-based policies via encoded characters

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping. Versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 contain a patch. A flaw was found in Quarkus. This could allow unauthorized access to protected static resources, leading to information disclosure. This is critical in deployments where Quarkus applications serve sensitive static content and rely solely on path-based authorization. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-551. Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Quarkus 3.20.6.SP2; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 10 more.

CVE-2026-50559
Red Hat Enterprise Linux
Jun 17, 2026
High7.5Linux

High [CVE-2026-48779] Denial of Service via memory exhaustion from small WebSocket fragments

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0. This action forces the affected component to allocate and hold structural wrappers that consume excessive memory. Consequently, this leads to process termination and a denial of service (DoS) for the remote peer. This is an Important denial of service vulnerability in the `ws` WebSocket library. This can result in service disruption for Red Hat products that utilize `ws` for WebSocket communication. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1050. Affected products named by the advisory: Cluster Observability Operator 1.5.0; Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9; Red Hat Discovery 2; and 29 more.

CVE-2026-48779
Red Hat Enterprise Linux
Jun 16, 2026
High7.5Linux

High [CVE-2026-12329] Memory safety bug fixed in Thunderbird ESR 140.12

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-12329
Red Hat Enterprise Linux
Jun 16, 2026
High7.5Linux

High [CVE-2026-12328] Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-12328
Red Hat Enterprise Linux
Jun 16, 2026
High7.5Linux

High [CVE-2026-12299] JIT miscompilation in the DOM: Core & HTML component

JIT miscompilation in the DOM: Core & HTML component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-733. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); and 22 more.

CVE-2026-12299
Red Hat Enterprise Linux
Jun 16, 2026
High7.5Linux

High [CVE-2026-12298] Memory safety bug fixed in Firefox ESR 140.12

Memory safety bug fixed in Firefox ESR 140.12. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); and 22 more.

CVE-2026-12298
Red Hat Enterprise Linux
Jun 16, 2026
High7.5Linux

High [CVE-2026-12297] Sandbox escape due to incorrect boundary conditions in the Networking component

Sandbox escape due to incorrect boundary conditions in the Networking component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); and 22 more.

CVE-2026-12297
Red Hat Enterprise Linux
Jun 16, 2026
High7.5Linux

High [CVE-2026-12296] Sandbox escape in the Security: Process Sandboxing component

Sandbox escape in the Security: Process Sandboxing component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-403. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); and 22 more.

CVE-2026-12296
Red Hat Enterprise Linux
Jun 16, 2026
High7.5Linux

High [CVE-2026-12295] Sandbox escape in the DOM: Navigation component

Sandbox escape in the DOM: Navigation component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); and 22 more.

CVE-2026-12295
Red Hat Enterprise Linux
Jun 16, 2026
High7.5Linux

High [CVE-2026-12294] Sandbox escape in the DOM: Workers component

Sandbox escape in the DOM: Workers component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); and 22 more.

CVE-2026-12294
Red Hat Enterprise Linux
Jun 16, 2026
High7.5Linux

High [CVE-2026-12292] Incorrect boundary conditions in the Web Audio component

Incorrect boundary conditions in the Web Audio component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); and 22 more.

CVE-2026-12292
Red Hat Enterprise Linux
Jun 16, 2026
High7.5Linux

High [CVE-2026-12291] Use-after-free in the Networking: HTTP component

Use-after-free in the Networking: HTTP component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); and 22 more.

CVE-2026-12291
Red Hat Enterprise Linux
Jun 16, 2026
High7.5Linux

High [CVE-2026-12290] Memory safety bug fixed in Thunderbird ESR 140.12

Memory safety bug fixed in Thunderbird ESR 140.12. Red Hat rates this important (CVSS 7.5). Weakness: CWE-823. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); and 22 more.

CVE-2026-12290
Red Hat Enterprise Linux
Jun 16, 2026
High7.5Linux

High [CVE-2026-12289] Privilege escalation in the Graphics: WebRender component

Privilege escalation in the Graphics: WebRender component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); and 22 more.

CVE-2026-12289
Red Hat Enterprise Linux
Jun 16, 2026
High8.6Linux

High [CVE-2026-10649] Denial of Service via integer overflow in remote message decompression

Denial of Service via integer overflow in remote message decompression. Red Hat rates this important (CVSS 8.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat OpenShift Container Platform 4; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; and 9 more.

CVE-2026-10649
Red Hat Enterprise Linux
Jun 16, 2026
High7.8Linux

High [CVE-2026-12505] local privilege escalation via forged cifs.spnego key description in cifs.upcall

local privilege escalation via forged cifs.spnego key description in cifs.upcall. Red Hat rates this important (CVSS 7.8). Weakness: CWE-250. Affected package(s): cifs-utils. Resolved in Red Hat advisory RHSA-2026:32990 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-12505
Red Hat Enterprise Linux
Jun 16, 2026
High7.1Linux

High [CVE-2026-53704] Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer fileinfo metadata parser

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from attacker-controlled data without validation, which can cause an infinite loop. A crafted RealMedia file can cause the application to crash, hang, or potentially read limited adjacent memory contents. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.

CVE-2026-53704
Red Hat Enterprise Linux
Jun 15, 2026
High7.1Linux

High [CVE-2026-53703] Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer audio stream header parser

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-53703
Red Hat Enterprise Linux
Jun 15, 2026
High7.8Linux

High [CVE-2026-8357] Arbitrary code execution via heap buffer overflow in formula compilation

Arbitrary code execution via heap buffer overflow in formula compilation. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; and 6 more.

CVE-2026-8357
Red Hat Enterprise Linux
Jun 15, 2026
High7.3Linux

High [CVE-2026-6040] Heap use-after-free allows arbitrary code execution via malformed ODF number format

Heap use-after-free allows arbitrary code execution via malformed ODF number format. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-6040
Red Hat Enterprise Linux
Jun 15, 2026

← All Linux advisories