Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1220 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 794 high, 375 medium, 17 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High7.5Linux

High [CVE-2026-34986] Denial of Service via crafted JSON Web Encryption (JWE) object

Denial of Service via crafted JSON Web Encryption (JWE) object. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131. Affected package(s): odf4/mcg-core-rhel9:1776403991, openshift-service-mesh/pilot-rhel8:1777319850, openshift-service-mesh/istio-cni-rhel8:1777374598, odf4/odf-cloudnative-pg-rhel9-operator:1776406131, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-engine/assisted-installer-agent-rhel9:1776351169. Resolved in Red Hat advisory RHSA-2026:25194 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); and 77 more.

CVE-2026-34986
Red Hat Enterprise LinuxLinux Kernel
Apr 6, 2026
High8.8Linux

High [CVE-2026-34588] Arbitrary code execution and information disclosure via crafted EXR file

Arbitrary code execution and information disclosure via crafted EXR file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. Affected package(s): openexr, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-cuda-rhel9:1782352847. Resolved in Red Hat advisory RHSA-2026:15888 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Extended Update Support; and 2 more.

CVE-2026-34588
Red Hat Enterprise Linux
Apr 6, 2026
High8.2Linux

High [CVE-2026-34982] arbitrary command execution via modeline sandbox bypass

arbitrary command execution via modeline sandbox bypass. Red Hat rates this important (CVSS 8.2). Weakness: CWE-78. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, vim, rhui5/haproxy-rhel9:1779798164, rhui5/rhua-rhel9:1779798222, rhaiis/vllm-rocm-rhel9:1782353093. Resolved in Red Hat advisory RHSA-2026:28049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 13 more.

CVE-2026-34982
Red Hat Enterprise Linux
Apr 6, 2026
High7.4Linux

High [CVE-2026-35535] Privilege escalation due to failure in privilege drop calls

Privilege escalation due to failure in privilege drop calls. Red Hat rates this important (CVSS 7.4). Weakness: CWE-272. Affected package(s): rhcos, sudo, rhui5/rhua-rhel9:1779798222, rhaiis/vllm-rocm-rhel9:1782353093, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:20040 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 18 more.

CVE-2026-35535
Red Hat Enterprise Linux
Apr 3, 2026
High7.8Linux

High [CVE-2026-31402] fix heap overflow in NFSv4.0 LOCK replay cache

fix heap overflow in NFSv4.0 LOCK replay cache. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION); Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION); Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux for Real Time (v. 7 ELS); and 60 more.

CVE-2026-31402
Red Hat Enterprise Linux
Apr 3, 2026
High7.5Linux

High [CVE-2026-35385] Privilege escalation via scp legacy protocol when not preserving file mode

Privilege escalation via scp legacy protocol when not preserving file mode. Red Hat rates this important (CVSS 7.5). Weakness: CWE-281. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, openssh, rhcos, rhui5/rhua-rhel9:1779798222, rhaiis/model-opt-cuda-rhel9:1780681984. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 22 more.

CVE-2026-35385
Red Hat Enterprise Linux
Apr 2, 2026
High8.1Linux

High [CVE-2026-23401] Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling

Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling. Red Hat rates this important (CVSS 8.1). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; and 6 more.

CVE-2026-23401
Red Hat Enterprise Linux
Apr 1, 2026
High8.1Linux

High [CVE-2026-4800] Arbitrary code execution via untrusted input in template imports

Arbitrary code execution via untrusted input in template imports. Red Hat rates this important (CVSS 8.1). Weakness: CWE-94. Affected package(s): odf4/ocs-client-console-rhel9:1778050558, odf4/mcg-core-rhel9:1776403991, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, odf4/ocs-client-rhel9-operator:1778049818, odf4/odf-cloudnative-pg-rhel9-operator:1776406131, satellite/iop-remediations-rhel9:1776194798. Resolved in Red Hat advisory RHSA-2026:29795 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Cryostat 4 on RHEL 9; Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux High Availability EUS (v. 10.0); and 84 more.

CVE-2026-4800
Red Hat Enterprise Linux
Mar 31, 2026
High7.5Linux

High [CVE-2026-5201] Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image

Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image. Red Hat rates this important (CVSS 7.5). Weakness: CWE-122. Affected package(s): gdk-pixbuf2, rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1779223654, rhaiis/vllm-cuda-rhel9:1778274666, rhaiis/vllm-spyre-rhel9:1778244546, rhaiis/model-opt-cuda-rhel9:1780681984. Resolved in Red Hat advisory RHSA-2026:10707 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 12 more.

CVE-2026-5201
Red Hat Enterprise Linux
Mar 31, 2026
High7.5Linux

High [CVE-2026-33984] Heap buffer overflow allows arbitrary code execution via crafted pixel data

Heap buffer overflow allows arbitrary code execution via crafted pixel data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:8945 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 9 more.

CVE-2026-33984
Red Hat Enterprise Linux
Mar 30, 2026
High7.5Linux

High [CVE-2026-33983] Denial of Service via specially crafted Remote Desktop Protocol messages

Denial of Service via specially crafted Remote Desktop Protocol messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:8945 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 9 more.

CVE-2026-33983
Red Hat Enterprise Linux
Mar 30, 2026
High7.5Linux

High [CVE-2026-21710] Denial of Service due to crafted HTTP `__proto__` header

Denial of Service due to crafted HTTP `__proto__` header. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Affected package(s): nodejs:20, nodejs:22, nodejs22, nodejs24, nodejs:24. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.

CVE-2026-21710
Red Hat Enterprise Linux
Mar 30, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-5121] Arbitrary code execution via integer overflow in ISO9660 image processing

Arbitrary code execution via integer overflow in ISO9660 image processing. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-190. Affected package(s): libarchive, rhcos, rhpam, rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1778274666, rhui5/cds-kubernetes-tp-rhel9:1777459441. Resolved in Red Hat advisory RHSA-2026:20040 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 24 more.

CVE-2026-5121
Red Hat Enterprise Linux
Mar 30, 2026
High8.8Linux

High [CVE-2026-20664] Processing maliciously crafted web content may lead to an unexpected process crash

Processing maliciously crafted web content may lead to an unexpected process crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected package(s): webkit2gtk3, webkitgtk4. Resolved in Red Hat advisory RHSA-2026:19206 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-20664
Red Hat Enterprise Linux
Mar 28, 2026
High8.8Linux

High [CVE-2026-28859] A malicious website may be able to process restricted web content outside the sandbox

A malicious website may be able to process restricted web content outside the sandbox. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected package(s): webkit2gtk3, webkitgtk4. Resolved in Red Hat advisory RHSA-2026:19206 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-28859
Red Hat Enterprise Linux
Mar 28, 2026
High8.2Linux

High [CVE-2026-33941] Arbitrary code execution via CLI precompiler input sanitization flaw

Arbitrary code execution via CLI precompiler input sanitization flaw. Red Hat rates this important (CVSS 8.2). Weakness: CWE-94. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, devspaces/code-rhel9:1776744110. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 1 more.

CVE-2026-33941
Red Hat Enterprise Linux
Mar 27, 2026
High8.1Linux

High [CVE-2026-33940] Arbitrary code execution via crafted template context

Arbitrary code execution via crafted template context. Red Hat rates this important (CVSS 8.1). Weakness: CWE-94. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, devspaces/code-rhel9:1776744110. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 1 more.

CVE-2026-33940
Red Hat Enterprise Linux
Mar 27, 2026
High7.5Linux

High [CVE-2026-33939] Denial of Service via malformed decorator syntax in template compilation

Denial of Service via malformed decorator syntax in template compilation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, devspaces/code-rhel9:1776744110. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-33939
Red Hat Enterprise Linux
Mar 27, 2026
High8.1Linux

High [CVE-2026-33938] Arbitrary code execution via @partial-block overwrite

Arbitrary code execution via @partial-block overwrite. Red Hat rates this important (CVSS 8.1). Weakness: CWE-917. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539, devspaces/code-rhel9:1776744110. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 8.

CVE-2026-33938
Red Hat Enterprise Linux
Mar 27, 2026
High7.4Linux

High [CVE-2026-33896] Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance

Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, automation-gateway, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; and 8 more.

CVE-2026-33896
Red Hat Enterprise Linux
Mar 27, 2026

← All Linux advisories