Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories
1225 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 799 high, 375 medium, 17 low.
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux Red Hat Enterprise Linux advisories
High [CVE-2026-45832] Authorization bypass in V1 collection-level endpoints
Authorization bypass in V1 collection-level endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-551. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-50010] Improper trust manager handling leads to hostname verification bypass
Improper trust manager handling leads to hostname verification bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-347. Affected package(s): netty-handler, offline-knowledge-portal/rhokp-rhel9:1782239370. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Offline Knowledge Portal 1.2.7; OpenShift Serverless; Red Hat AMQ Broker 7; Red Hat AMQ Clients; and 16 more.
High [CVE-2026-45830] Unauthorized data manipulation due to improper authorization validation
Unauthorized data manipulation due to improper authorization validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-48059] Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): netty-codec-haproxy. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 14 more.
High [CVE-2026-48043] Denial of Service due to resource leak
Denial of Service due to resource leak. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected package(s): netty-codec-http2. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 15 more.
High [CVE-2026-47691] Netty has Insufficient Bailiwick Validation for NS Records
Netty has Insufficient Bailiwick Validation for NS Records. Red Hat rates this important (CVSS 8.7). Weakness: CWE-346. Affected package(s): netty-resolver-dns. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 14 more.
High [CVE-2026-45674] Information disclosure and data manipulation due to improper CNAME record validation
Information disclosure and data manipulation due to improper CNAME record validation. Red Hat rates this important (CVSS 8.7). Weakness: CWE-346. Affected package(s): netty-resolver-dns. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 14 more.
High [CVE-2026-45416] Denial of Service due to eager buffer allocation in TLS handshake
Denial of Service due to eager buffer allocation in TLS handshake. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): netty-handler, offline-knowledge-portal/rhokp-rhel9:1782239370. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Offline Knowledge Portal 1.2.7; OpenShift Serverless; Red Hat AMQ Broker 7; Red Hat AMQ Clients; and 16 more.
High [CVE-2026-44893] Denial of Service via malformed HAProxy message
Denial of Service via malformed HAProxy message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. Affected package(s): netty-codec-haproxy. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1; Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat build of Quarkus 3.27.4.SP1; Red Hat build of Quarkus 3.33.2.SP1; and 14 more.
High [CVE-2026-53705] Heap buffer overflow in WavPack decoder via integer overflow
Heap buffer overflow in WavPack decoder via integer overflow. Red Hat rates this important (CVSS 7.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; and 3 more.
Medium [CVE-2026-48914] Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling
A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux for NVIDIA 26; and 1 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.
Critical [CVE-2026-49261] Arbitrary code execution via wsrep_notify_cmd
Arbitrary code execution via wsrep_notify_cmd. Red Hat rates this important (CVSS 9). Weakness: CWE-78. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images.
High [CVE-2026-44249] IPv6 subnet rule bypass due to incorrect masking operation
IPv6 subnet rule bypass due to incorrect masking operation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1287. Affected package(s): netty-handler, offline-knowledge-portal/rhokp-rhel9:1782239370. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Offline Knowledge Portal 1.2.7; Red Hat OpenShift Dev Spaces 3.29; OpenShift Serverless; Red Hat AMQ Broker 7; and 17 more.
High [CVE-2026-47162] Arbitrary Code Execution via crafted directory names
Arbitrary Code Execution via crafted directory names. Red Hat rates this important (CVSS 7.3). Weakness: CWE-140. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more.
High [CVE-2026-44486] Information disclosure of proxy credentials via HTTP redirects
Information disclosure of proxy credentials via HTTP redirects. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, advanced-cluster-security/rhacs-main-rhel8:1779293013, discovery/discovery-ui-rhel9:1782166952, openshift4/ose-monitoring-plugin-rhel9:1781731914. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 40 more.
High [CVE-2026-44487] Information disclosure of proxy credentials via redirect flows
Information disclosure of proxy credentials via redirect flows. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, openshift4/ose-monitoring-plugin-rhel9:1782171032, satellite/iop-host-inventory-frontend-rhel9:1782253070. Resolved in Red Hat advisory RHSA-2026:29864 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 42 more.
High [CVE-2026-44488] Denial of Service due to unenforced request and response size limits
Denial of Service due to unenforced request and response size limits. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, satellite/iop-host-inventory-frontend-rhel9:1782253070, openshift-service-mesh/kiali-ossmc-rhel9:1782201894. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 42 more.
High [CVE-2026-44496] Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, quay/quay-rhel8:1782487717, quay/quay-rhel8:1781878070, advanced-cluster-security/rhacs-main-rhel8:1779293013. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 40 more.
High [CVE-2026-44495] Information disclosure due to prototype pollution vulnerability
Information disclosure due to prototype pollution vulnerability. Red Hat rates this important (CVSS 7). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, advanced-cluster-security/rhacs-main-rhel8:1779293013, discovery/discovery-ui-rhel9:1782166952, openshift4/ose-monitoring-plugin-rhel9:1781731914. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 44 more.
High [CVE-2026-44494] Man-in-the-Middle (MITM) attack via Prototype Pollution
Man-in-the-Middle (MITM) attack via Prototype Pollution. Red Hat rates this important (CVSS 8.7). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, openshift4/ose-monitoring-plugin-rhel9:1782243791, openshift4/ose-monitoring-plugin-rhel9:1782313844. Resolved in Red Hat advisory RHSA-2026:29864 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 44 more.