Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1225 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 785 high, 384 medium, 25 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High7.5Linux Updated

High [CVE-2026-55831] Denial of Service via SPDY SETTINGS frame processing

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. A remote attacker, by sending a specially crafted SPDY/3.1 SETTINGS frame, could cause the SPDY SETTINGS decoder to create a large number of map entries. This excessive processing and memory allocation can lead to a denial of service (DoS) due to heap growth and increased CPU usage. This is an Important denial of service flaw in Netty's SPDY SETTINGS decoder, allowing a remote unauthenticated attacker to exhaust system resources. By sending a specially crafted SPDY/3.1 SETTINGS frame, an attacker can cause excessive memory allocation and CPU usage, leading to a denial of service. This vulnerability has a low attack complexity and requires no user interaction or privileges. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.

CVE-2026-55831
Red Hat Enterprise Linux
Jul 20, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-64612] Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malformed png

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-248. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-64612
Red Hat Enterprise Linux
Jul 20, 2026
High7.0Vendor: MediumLinux Updated

High [CVE-2026-63807] Ensure hugepage is in by slot before checking max mapping level

Ensure hugepage is in by slot before checking max mapping level. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:49030 with package kernel-0:6.12.0-55.94.1.el10_0. Affected product named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-63807
Red Hat Enterprise Linux
Jul 19, 2026
High7.0Linux Updated

High [CVE-2026-64017] pop cached request if it is usable

pop cached request if it is usable. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:47040 with package kernel-0:5.14.0-687.31.1.el9_8. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-64017
Red Hat Enterprise Linux
Jul 19, 2026
High7.8Linux Updated

High [CVE-2026-53366] account for fraggap on the paged allocation path

account for fraggap on the paged allocation path. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:34911 with package kernel-0:6.12.0-211.30.1.el10_2, kernel-0:6.12.0-55.86.1.el10_0. Affected product named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-53366
Red Hat Enterprise Linux
Jul 16, 2026
High8.2Linux Updated

High [CVE-2026-12382] missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing

missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing. Red Hat rates this important (CVSS 8.2). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:42078 with package automation-gateway-0:2.6.20260422-1.el9ap, automation-gateway-0:2.5.20260715-1.el8ap, automation-gateway-0:2.5.20260715-1.el9ap, ansible-automation-platform-26/gateway-rhel9:1777311120. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-12382
Red Hat Enterprise Linux
Jul 15, 2026
High8.2Linux Updated

High [CVE-2026-60005] Memory disclosure and denial of service in ngx_http_slice_module

A vulnerability in the NGINX ngx_http_slice_module allows remote, unauthenticated attackers to access uninitialized memory via crafted requests. If configured with unnamed regex captures or background cache updates, this flaw can result in limited memory disclosure or a denial-of-service crash. Important: This vulnerability in NGINX's `ngx_http_slice_module` could lead to memory disclosure or denial of service. The impact on Red Hat products is reduced because the `ngx_http_slice_module` is not enabled by default. Exploitation requires explicit configuration of the module with the `slice` directive and unnamed regex captures, or during a background cache update, limiting exposure in typical deployments. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H). Weakness: CWE-824. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Lightspeed proxy 1. Red Hat lists Red Hat Hardened Images as not affected. Red Hat fixing advisory: RHSA-2026:46012.

CVE-2026-60005
Red Hat Enterprise Linux
Jul 15, 2026
High7.5Vendor: MediumLinux Updated

High [CVE-2026-14957] badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process

badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-617. Red Hat lists fixing advisory RHSA-2026:46397 with package libreswan-0:5.3.2-1.el9fdp, libreswan-0:5.3.2-1.el10_2, libreswan-0:4.15-10.el9_8, libreswan-0:4.12-2.el8_10.6. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-14957
Red Hat Enterprise Linux
Jul 15, 2026
High7.5Linux Updated

High [CVE-2026-50651] SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM

SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50651
Red Hat Enterprise Linux
Jul 14, 2026
High7.8Linux Updated

High [CVE-2026-50650] .NET Framework: Privilege escalation via code injection

.NET Framework: Privilege escalation via code injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50650
Red Hat Enterprise Linux
Jul 14, 2026
High7.8Linux Updated

High [CVE-2026-50649] .NET: Local code execution via deserialization of untrusted data

.NET: Local code execution via deserialization of untrusted data. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50649
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux Updated

High [CVE-2026-50648] .NET Framework: Remote Denial of Service due to uncontrolled resource allocation

.NET Framework: Remote Denial of Service due to uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50648
Red Hat Enterprise Linux
Jul 14, 2026
High8.2Linux Updated

High [CVE-2026-50528] .NET: Security feature bypass due to incorrect authorization

.NET: Security feature bypass due to incorrect authorization. Red Hat rates this important (CVSS 8.2). Weakness: CWE-551. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50528
Red Hat Enterprise Linux
Jul 14, 2026
High7.8Linux Updated

High [CVE-2026-50646] .NET Framework: Local Code Execution via Protection Mechanism Failure

.NET Framework: Local Code Execution via Protection Mechanism Failure. Red Hat rates this important (CVSS 7.8). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50646
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux Updated

High [CVE-2026-50527] .NET Framework: Denial of Service via network-based buffer overflow

.NET Framework: Denial of Service via network-based buffer overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50527
Red Hat Enterprise Linux
Jul 14, 2026
High7.0Vendor: MediumLinux Updated

High [CVE-2026-50526] .NET: Local tampering via improper link resolution

.NET: Local tampering via improper link resolution. Red Hat rates this moderate (CVSS 7). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50526
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux Updated

High [CVE-2026-50525] .NET: Denial of Service due to uncontrolled resource allocation

.NET: Denial of Service due to uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41894 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50525
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux Updated

High [CVE-2026-50524] .NET Framework: Denial of Service via improper input validation

.NET Framework: Denial of Service via improper input validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50524
Red Hat Enterprise Linux
Jul 14, 2026
High8.8Linux Updated

High [CVE-2026-47303] Privilege Elevation via Authentication Bypass

Privilege Elevation via Authentication Bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-472. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet9-0-main-9.0.119-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-47303
Red Hat Enterprise Linux
Jul 14, 2026
High8.1Linux Updated

High [CVE-2026-47304] .NET Security Feature Bypass Vulnerability

.NET Security Feature Bypass Vulnerability. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet9-0-main-9.0.119-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-47304
Red Hat Enterprise Linux
Jul 14, 2026

← All Linux advisories