Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1635 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 619 high, 814 medium, 169 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
High [CVE-2026-47528] arbitrary code execution via uninitialized pointer access
arbitrary code execution via uninitialized pointer access. Red Hat rates this important (CVSS 7.8). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47514] arbitrary code execution via kernel stack disclosure
arbitrary code execution via kernel stack disclosure. Red Hat rates this important (CVSS 7.8). Weakness: CWE-497. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47513] arbitrary code execution via kernel heap out-of-bounds read
arbitrary code execution via kernel heap out-of-bounds read. Red Hat rates this important (CVSS 7.8). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47512] privilege escalation via out-of-bounds read in kernel mode layer
privilege escalation via out-of-bounds read in kernel mode layer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47511] Arbitrary code execution via kernel-mode out-of-bounds write
Arbitrary code execution via kernel-mode out-of-bounds write. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47510] Arbitrary code execution via integer overflow in kernel mode layer
Arbitrary code execution via integer overflow in kernel mode layer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47508] Code execution via incorrect numeric type conversion
Code execution via incorrect numeric type conversion. Red Hat rates this important (CVSS 7.8). Weakness: CWE-681. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47507] Privilege escalation via out-of-bounds array access in the kernel mode layer
Privilege escalation via out-of-bounds array access in the kernel mode layer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47504] Arbitrary code execution via type confusion in the NGX updater
Arbitrary code execution via type confusion in the NGX updater. Red Hat rates this important (CVSS 7.8). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47501] Privilege escalation via out-of-bounds write during event buffer setup
Privilege escalation via out-of-bounds write during event buffer setup. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47494] Arbitrary code execution via format string flaw
Arbitrary code execution via format string flaw. Red Hat rates this important (CVSS 7.8). Weakness: CWE-134. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47491] Privilege escalation via improper memory release
Privilege escalation via improper memory release. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47489] Privilege escalation via unpreserved read-only memory permissions
Privilege escalation via unpreserved read-only memory permissions. Red Hat rates this important (CVSS 7.8). Weakness: CWE-281. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-103226] stack-based buffer overflow in pdfwrite via crafted font data
stack-based buffer overflow in pdfwrite via crafted font data. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ghostscript.
High [CVE-2026-15815] PLUGIN ARCHIVE EXTRACTION ESCAPES THE PLUGIN DIRECTORY, ALLOWING CODE EXECUTION
PLUGIN ARCHIVE EXTRACTION ESCAPES THE PLUGIN DIRECTORY, ALLOWING CODE EXECUTION. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22. Affected products named by the advisory: Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: grafana.
High [CVE-2026-76154] Stored cross-site scripting in the Geomap panel allows privilege escalation
Stored cross-site scripting in the Geomap panel allows privilege escalation. Red Hat rates this important (CVSS 7.3). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:74164 with package grafana13-1-main-13.1.6-0.5.hum1, grafana12-4-main-12.4.12-0.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Enterprise Linux 10; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: grafana.
High [CVE-2026-103242] Heap-based buffer overflow write in hex2binv via a mistyped RPMTAG_FILESIGNATURES header tag
Heap-based buffer overflow write in hex2binv() via a mistyped RPMTAG_FILESIGNATURES header tag. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 16 more. Affected products named by the advisory: Red Hat package: python3-rpm; Red Hat package: rpm-apidocs; Red Hat package: rpm-build-libs; Red Hat package: rpm-cron; and 12 more.
High [CVE-2026-93994] Authentication bypass via duplicate public key presentation
Authentication bypass via duplicate public key presentation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:71541 with package maven3-9-main-3.9.16-0.3.hum1. Affected products named by the advisory: OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Enterprise Linux 10; and 10 more. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 6 more.
High [CVE-2026-103111] Out-of-bounds write via crafted regular expression
Out-of-bounds write via crafted regular expression. Red Hat rates this important (CVSS 7.6). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:74972 with package pcre2-main-10.49-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: mariadb10.11; Red Hat package: mariadb11.8; and 2 more.
High [CVE-2026-102253] Denial of Service via UDP receive worker infinite loop
Denial of Service via UDP receive worker infinite loop. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: iperf3.