Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories
1225 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 785 high, 384 medium, 25 low.
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux Red Hat Enterprise Linux advisories
High [CVE-2026-55831] Denial of Service via SPDY SETTINGS frame processing
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a syntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map entries and amplifies network input into heap growth and ordered-map insertion work. A remote attacker, by sending a specially crafted SPDY/3.1 SETTINGS frame, could cause the SPDY SETTINGS decoder to create a large number of map entries. This excessive processing and memory allocation can lead to a denial of service (DoS) due to heap growth and increased CPU usage. This is an Important denial of service flaw in Netty's SPDY SETTINGS decoder, allowing a remote unauthenticated attacker to exhaust system resources. By sending a specially crafted SPDY/3.1 SETTINGS frame, an attacker can cause excessive memory allocation and CPU usage, leading to a denial of service. This vulnerability has a low attack complexity and requires no user interaction or privileges. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.
High [CVE-2026-64612] Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malformed png
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-248. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-63807] Ensure hugepage is in by slot before checking max mapping level
Ensure hugepage is in by slot before checking max mapping level. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:49030 with package kernel-0:6.12.0-55.94.1.el10_0. Affected product named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-64017] pop cached request if it is usable
pop cached request if it is usable. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:47040 with package kernel-0:5.14.0-687.31.1.el9_8. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-53366] account for fraggap on the paged allocation path
account for fraggap on the paged allocation path. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:34911 with package kernel-0:6.12.0-211.30.1.el10_2, kernel-0:6.12.0-55.86.1.el10_0. Affected product named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-12382] missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing
missing requestHeadersToRemove allows mTLS bypass via Subject header spoofing. Red Hat rates this important (CVSS 8.2). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:42078 with package automation-gateway-0:2.6.20260422-1.el9ap, automation-gateway-0:2.5.20260715-1.el8ap, automation-gateway-0:2.5.20260715-1.el9ap, ansible-automation-platform-26/gateway-rhel9:1777311120. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-60005] Memory disclosure and denial of service in ngx_http_slice_module
A vulnerability in the NGINX ngx_http_slice_module allows remote, unauthenticated attackers to access uninitialized memory via crafted requests. If configured with unnamed regex captures or background cache updates, this flaw can result in limited memory disclosure or a denial-of-service crash. Important: This vulnerability in NGINX's `ngx_http_slice_module` could lead to memory disclosure or denial of service. The impact on Red Hat products is reduced because the `ngx_http_slice_module` is not enabled by default. Exploitation requires explicit configuration of the module with the `slice` directive and unnamed regex captures, or during a background cache update, limiting exposure in typical deployments. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H). Weakness: CWE-824. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Lightspeed proxy 1. Red Hat lists Red Hat Hardened Images as not affected. Red Hat fixing advisory: RHSA-2026:46012.
High [CVE-2026-14957] badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process
badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-617. Red Hat lists fixing advisory RHSA-2026:46397 with package libreswan-0:5.3.2-1.el9fdp, libreswan-0:5.3.2-1.el10_2, libreswan-0:4.15-10.el9_8, libreswan-0:4.12-2.el8_10.6. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.
High [CVE-2026-50651] SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM
SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-50650] .NET Framework: Privilege escalation via code injection
.NET Framework: Privilege escalation via code injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-50649] .NET: Local code execution via deserialization of untrusted data
.NET: Local code execution via deserialization of untrusted data. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-50648] .NET Framework: Remote Denial of Service due to uncontrolled resource allocation
.NET Framework: Remote Denial of Service due to uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-50528] .NET: Security feature bypass due to incorrect authorization
.NET: Security feature bypass due to incorrect authorization. Red Hat rates this important (CVSS 8.2). Weakness: CWE-551. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-50646] .NET Framework: Local Code Execution via Protection Mechanism Failure
.NET Framework: Local Code Execution via Protection Mechanism Failure. Red Hat rates this important (CVSS 7.8). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-50527] .NET Framework: Denial of Service via network-based buffer overflow
.NET Framework: Denial of Service via network-based buffer overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-50526] .NET: Local tampering via improper link resolution
.NET: Local tampering via improper link resolution. Red Hat rates this moderate (CVSS 7). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-50525] .NET: Denial of Service due to uncontrolled resource allocation
.NET: Denial of Service due to uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41894 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-50524] .NET Framework: Denial of Service via improper input validation
.NET Framework: Denial of Service via improper input validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-47303] Privilege Elevation via Authentication Bypass
Privilege Elevation via Authentication Bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-472. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet9-0-main-9.0.119-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-47304] .NET Security Feature Bypass Vulnerability
.NET Security Feature Bypass Vulnerability. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet9-0-main-9.0.119-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.