Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1654 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 33 critical, 634 high, 815 medium, 170 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

Medium6.5Red Hat

Medium [CVE-2026-15813] memory corruption and out-of-bounds access via malformed network packet defragmentation

A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack of verification by transmitting malformed packets with corrupted sequence parameters. Under specific conditions, this forces the packet processing layer to parse data outside the designated bounds of the internal memory structures, causing an out-of-bounds memory access or heap corruption. This behavior can result in sudden application crashes or system instability. Red Hat Product Security rates this vulnerability's impact as Low. While memory corruption and out-of-bounds access conditions are technically severe flaw types (typically rated Moderate or Important), the deployment requirements drastically reduce the real-world threat vector. The flaw can only be reached if kronosnet is running completely unencrypted traffic (a setting unsupported for production) and the attacker is capable of spoofing a trusted IP address already authorized within the cluster infrastructure to pass initial Access Control Lists (ACLs). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more.

CVE-2026-15813
Red Hat Enterprise Linux
Jul 20, 2026
Medium5.0Red Hat

Medium [CVE-2026-52584] Information disclosure via Buffer Overflow in DecodeImageAPNG function

Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function A flaw was found in libjxl. The flaw occurs within the `DecodeImageAPNG` function, which can lead to unauthorized disclosure of data. Red Hat ships libjxl as a bundled component within Firefox and Thunderbird. The vulnerable code path is in the APNG decoder (DecodeImageAPNG), which is part of the extras module used by command-line tools. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-52584
Red Hat Enterprise Linux
Jul 17, 2026
Medium4.3Red Hat

Medium [CVE-2026-57077] YAML::Syck: YAML::Syck: Information disclosure via out-of-bounds read

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check. During block-scalar lexing at a document boundary the scan runs one byte past the heap lexer buffer. This is an incomplete fix of CVE-2025-11683, on a lexer path the earlier fix did not cover. Any caller that runs Load or LoadFile on an untrusted document with a block scalar at a document boundary reaches the over-read. An out-of-bounds read vulnerability exists due to an unbounded newline scan during block-scalar lexing. A remote attacker could exploit this by providing a specially crafted YAML document, leading to potential information disclosure. This issue is an incomplete fix for a previously identified vulnerability. Moderate: An out-of-bounds read flaw in `perl-YAML-Syck` can lead to information disclosure when processing specially crafted YAML documents. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-57077
Red Hat Enterprise Linux
Jul 16, 2026
Medium6.3Red Hat

Medium [CVE-2026-57076] YAML::Syck: Heap use-after-free via anchor name reuse

YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor. In the bundled libsyck an anchor name allocated by syck_strndup is stored both as node->anchor, freed when the node is freed, and as the key in the parser's anchors table. Freeing the node frees the shared key, and a later anchor redefinition makes st_delete compare against the freed key, so st_strcmp reads freed heap memory. Anchors are a standard YAML feature and need no special flags, so this is reached on the default Load path. Any caller that runs Load or LoadFile on an untrusted document that redefines an anchor reaches the read of freed memory. An attacker could exploit a heap use-after-free vulnerability by providing a specially crafted YAML document that reuses an anchor name as an anchors-table key. This flaw causes the software to read freed heap memory, which may lead to information disclosure or denial of service. This Important heap use-after-free vulnerability in `perl-YAML-Syck` can be triggered by processing a specially crafted YAML document. The flaw, exploitable through the default YAML loading mechanism, may lead to information disclosure or a denial of service in applications handling untrusted YAML input. Red Hat severity: Moderate — CVSS 6.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-825.

CVE-2026-57076
Red Hat Enterprise Linux
Jul 16, 2026
Medium6.5Red Hat

Medium [CVE-2026-57075] YAML::Syck: YAML::Syck: Information disclosure via out-of-bounds read in base64 decoder

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in the bundled libsyck indexes the 256-entry static table b64_xtable with a signed char, so any!!binary byte >= 0x80 sign-extends to a negative index and reads before the table. The decoder receives the raw bytes of any!!binary node, a standard YAML type not gated by $LoadBlessed or $LoadCode, so it is reached on the default Load path. Any caller that runs Load or LoadFile on an untrusted document containing a!!binary scalar with a high-bit byte triggers the read, and the value read can surface in the decoded result. An out-of-bounds read vulnerability exists in the base64 decoder, specifically in the `syck_base64dec` function. This occurs because the decoder uses a signed character to index a lookup table, allowing specially crafted `!!binary` YAML nodes with high-bit bytes to cause a read beyond the intended memory region. A remote attacker could exploit this by providing a malicious YAML document, potentially leading to information disclosure. This Moderate impact flaw in `perl-YAML-Syck` can lead to information disclosure. Exploitation requires an application to parse a specially crafted YAML file, making the impact dependent on the application's handling of untrusted input.

CVE-2026-57075
Red Hat Enterprise Linux
Jul 16, 2026
Medium4.0Red Hat

Medium [CVE-2026-47085] Information disclosure via URLAUTH token forgery

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.) A remote attacker could exploit a vulnerability related to URLAUTH token forgery, caused by a missing mailbox key. The likelihood of exploitation is low due to the obscurity of the URLAUTH feature. Red Hat severity: Moderate — CVSS 4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N). Weakness: CWE-341. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cyrus-imapd.

CVE-2026-47085
Red Hat Enterprise Linux
Jul 16, 2026
Medium6.5Red Hat

Medium [CVE-2026-47084] Unauthorized mailbox deletion via ACL bypass

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the admin-only LOCALDELETE IMAP command and delete mailboxes for which they had no permissions. This allowed them to delete mailboxes for which they did not have the necessary permissions, leading to unauthorized data integrity compromise. This Moderate flaw in Cyrus IMAP allows an authenticated user to bypass Access Control List (ACL) restrictions, enabling unauthorized mailbox deletion. The impact is considered Moderate as it requires prior authentication and specific command usage, limiting exploitation to existing users. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-266. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cyrus-imapd.

CVE-2026-47084
Red Hat Enterprise Linux
Jul 16, 2026
Medium5.4Red Hat

Medium [CVE-2026-47082] ACL bypass in vacation 'fcc' feature allows unauthorized mailbox writes

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user with low privileges can exploit a vulnerability in the vacation "fcc" feature. By crafting a specific Sieve script, the user can bypass access control lists and deliver vacation auto-reply messages into any mailbox, leading to unauthorized modification of mailbox content. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-279. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cyrus-imapd.

CVE-2026-47082
Red Hat Enterprise Linux
Jul 16, 2026
Medium4.3Red Hat

Medium [CVE-2026-47083] Information disclosure via ESEARCH command

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would return UIDs of messages matching the search, creating a content oracle (without allowing arbitrary reads of the target's content). An authenticated user can exploit the ESEARCH command to discover the existence of folder names belonging to other user accounts. This vulnerability leads to information disclosure, allowing an attacker to gain unauthorized knowledge about the structure of other users' mailboxes. While it does not permit arbitrary content reads, this vulnerability could expose the structure of other users' mailboxes, potentially aiding further reconnaissance. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-201. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cyrus-imapd.

CVE-2026-47083
Red Hat Enterprise Linux
Jul 16, 2026
Medium4.3Red Hat

Medium [CVE-2026-47089] Information disclosure via LISTRIGHTS

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user can exploit this vulnerability by using the IMAP LISTRIGHTS command. This allows the user to learn the access permissions of any mailbox they can name, which should be restricted to administrators. This leads to unauthorized information disclosure regarding mailbox access controls. While requiring prior authentication, this bypasses intended administrative restrictions, potentially exposing sensitive access control configurations within a Red Hat deployment. The impact is limited to information disclosure and does not grant further privileges or data modification. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-266. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cyrus-imapd.

CVE-2026-47089
Red Hat Enterprise Linux
Jul 16, 2026
Medium4.3Red Hat

Medium [CVE-2026-47086] Information disclosure via URLAUTH token bypass of Access Control Lists

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions. This allows bypassing Access Control Lists (ACLs), which are rules that control access to mailboxes. Consequently, an attacker could read mail from any mailbox, even without having been granted explicit read permissions. This flaw in cyrus-imapd allows an authenticated attacker to bypass Access Control Lists (ACLs) by minting a URLAUTH token via the GENURLAUTH command. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-639. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cyrus-imapd.

CVE-2026-47086
Red Hat Enterprise Linux
Jul 16, 2026
Medium6.1Red Hat

Medium [CVE-2026-15779] pam_winbind mkhomedir chowns critical system paths without validation

A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation. Red Hat Product Security rates this flaw's impact as Moderate. Exploitation requires mkhomedir to be explicitly enabled in pam_winbind.conf, a non-default option used specifically in Active Directory domain-integration deployments, and a PAM session to be opened for an account whose home directory resolves to /. While the most direct trigger is root running su to such an account, a non-root user holding a narrow sudo delegation to run a command as that account can reach the same code path. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more.

CVE-2026-15779
Red Hat Enterprise Linux
Jul 15, 2026
Medium4.8Vendor: LowRed Hat

Medium [CVE-2026-15812] access control list bypass via link ID spoofing on unencrypted dynamic links

A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). When the framework is explicitly configured to manage dynamic links (accepting network traffic from any IP address) without network payload encryption, the validation architecture implicitly trusts the link ID provided within incoming data packets. A remote, unauthenticated attacker can exploit this lack of validation by spoofing a legitimate link ID inside crafted network frames. This allows the attacker to fully bypass the ACL framework and inject arbitrary data packets into the application layer, potentially leading to data corruption or service instabilities. Red Hat Product Security rates this vulnerability's impact as Low. Although the vulnerability allows an unauthenticated remote attacker to completely bypass the internal ACL layer and introduce arbitrary traffic, it depends entirely on a non-production configuration. The exploit requires that kronosnet actively accept connections from any arbitrary IP (dynamic links) while simultaneously running completely unencrypted traffic. Furthermore, this issue does not affect Red Hat Enterprise Linux High Availability (RHEL HA) or any official layered products, as Red Hat configurations securely enable network encryption by default, entirely mitigating the vulnerability's attack prerequisites.

CVE-2026-15812
Red Hat Enterprise Linux
Jul 15, 2026
Medium5.8Vendor: LowRed Hat

Medium [CVE-2026-15811] encryption key exposure in memory after cryptographic configuration changes

A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability. Red Hat Product Security rates this flaw's impact as Moderate. While kronosnet is a critical core networking component within the Red Hat Enterprise Linux High Availability (RHEL HA) ecosystem, exploiting this vulnerability requires a high degree of complexity. An attacker must already possess local access to the host machine and successfully pair this flaw with a distinct memory disclosure mechanism to extract the key fragments post-free(). Red Hat severity: Low — CVSS 5.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L). Weakness: CWE-212. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-15811
Red Hat Enterprise Linux
Jul 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-38755] Denial of Service via heap overflow in evalcommand function

A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. A flaw was found in Busybox. This can lead to the unavailability of the service. The vulnerability requires an attacker to supply specially crafted input, which typically implies existing local access or specific application interactions within the Busybox environment, thus limiting the direct exposure. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 6. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:42074. Affected products named by the advisory: Red Hat package: busybox.

CVE-2026-38755
Red Hat Enterprise Linux
Jul 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-38752] Denial of Service via crafted AWK script

A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script. A flaw was found in BusyBox. A Denial of Service attack can make the affected system or application unavailable to legitimate users. An attacker could provide a specially crafted AWK script, leading to a stack overflow and making the BusyBox instance unresponsive. This vulnerability primarily affects systems where BusyBox is configured to execute untrusted AWK scripts, limiting its broader impact. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 6. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:42074. Affected products named by the advisory: Red Hat package: busybox.

CVE-2026-38752
Red Hat Enterprise Linux
Jul 15, 2026
Medium5.3Red Hat

Medium [CVE-2026-48125] Denial of Service via crafted Client Hints header

UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10. A flaw was found in UAParser.js, a JavaScript library for detecting client information. This can cause excessive CPU usage due to a regular expression denial-of-service (ReDoS) issue, leading to a denial of service for the affected application. Mobile browsers send this hint to inform servers about the specific device model. Servers use the model name to tailor content, apply device-specific optimizations, or log analytics about which hardware models access a service. A single request with a ~32,000-character model value can consume over 400ms of CPU time, with parsing time growing polynomially with input length. The impact is availability only, there is no confidentiality or integrity impact. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-1333.

CVE-2026-48125
Red Hat Enterprise Linux
Jul 14, 2026
Medium5.3Red Hat

Medium [CVE-2026-49854] Information disclosure via out-of-bounds read in websocket_mask

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6. This allowed the C function to read beyond the intended buffer, potentially exposing up to three bytes of uninitialized memory. This vulnerability can be triggered when the native extension is active and Tornado's Cross-Site Request Forgery (XSRF) token decoder is in use, leading to information disclosure. This Moderate vulnerability in the Tornado web framework's optional native extension, `tornado.speedups`, could lead to information disclosure. When the native extension is active and the XSRF token decoder is in use, an out-of-bounds read of up to three bytes of uninitialized memory may occur. This limited data exposure is contingent on specific configurations and does not directly lead to broader system compromise. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-125.

CVE-2026-49854
Red Hat Enterprise Linux
Jul 14, 2026
Medium6.5Red Hat

Medium [CVE-2026-15714] Out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string

An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict or validate the size of incoming multipart boundary strings. When processing a crafted HTTP response containing a malformed or oversized boundary parameter, the internal stream reader reads past the allocated buffer bounds. A remote, unauthenticated attacker can exploit this behavior to cause a service denial (DoS) through application failure or potentially read fragments of unauthorized memory metadata. This vulnerability presents a moderate risk to confidentiality and availability for software implementations implementing libsoup for multipart payload handling. Because the memory tracking misalignment happens during the automated header ingestion phase, an attacker can seamlessly induce a crash remotely without needing local context or user interaction. Red Hat Product Security ranks this as a notable security regression within parsing utilities, though impact vectors generally manifest as localized client or server session instability rather than complete remote code execution. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-125.

CVE-2026-15714
Red Hat Enterprise Linux
Jul 14, 2026
Medium5.9Vendor: LowRed Hat

Medium [CVE-2026-15713] HTTP/2 frame window exhaustion remote denial of service via memory leak

A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote, unauthenticated attacker acting as a malicious network peer can trick the connection engine into allocating stream states that are subsequently leaked during cleanup. Over a sustained period, this flaw allows the remote attacker to consume the system's heap allocations incrementally, triggering a denial of service (DoS) through an ultimate Out-of-Memory (OOM) application crash. This flaw poses a moderate availability impact to applications leveraging libsoup for modern HTTP/2 communications. Because the memory leakage accrues iteratively over standard session handling paths, an attacker can reliably cause a service disruption without needing local system privileges or user interaction. Red Hat Product Security notes that while the impact is bounded to a local application process termination, it remains a severe reliability risk for persistent cloud daemons or desktop clients communicating over untrusted wide-area network nodes. Red Hat severity: Low — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-772.

CVE-2026-15713
Red Hat Enterprise Linux
Jul 14, 2026

← All Red Hat advisories