Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories
1229 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 799 high, 376 medium, 20 low.
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux Red Hat Enterprise Linux advisories
High [CVE-2026-44488] Denial of Service due to unenforced request and response size limits
Denial of Service due to unenforced request and response size limits. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, satellite/iop-host-inventory-frontend-rhel9:1782253070, openshift-service-mesh/kiali-ossmc-rhel9:1782201894. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 42 more.
High [CVE-2026-44496] Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, quay/quay-rhel8:1782487717, quay/quay-rhel8:1781878070, advanced-cluster-security/rhacs-main-rhel8:1779293013. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 40 more.
High [CVE-2026-44495] Information disclosure due to prototype pollution vulnerability
Information disclosure due to prototype pollution vulnerability. Red Hat rates this important (CVSS 7). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, advanced-cluster-security/rhacs-main-rhel8:1779293013, discovery/discovery-ui-rhel9:1782166952, openshift4/ose-monitoring-plugin-rhel9:1781731914. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 44 more.
High [CVE-2026-44494] Man-in-the-Middle (MITM) attack via Prototype Pollution
Man-in-the-Middle (MITM) attack via Prototype Pollution. Red Hat rates this important (CVSS 8.7). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, openshift4/ose-monitoring-plugin-rhel9:1782243791, openshift4/ose-monitoring-plugin-rhel9:1782313844. Resolved in Red Hat advisory RHSA-2026:29864 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 44 more.
High [CVE-2026-44492] Proxy bypass via IPv4-mapped IPv6 address non-normalization
Proxy bypass via IPv4-mapped IPv6 address non-normalization. Red Hat rates this important (CVSS 8.6). Weakness: CWE-289. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, advanced-cluster-security/rhacs-main-rhel8:1779293013, discovery/discovery-ui-rhel9:1782166952, openshift4/ose-monitoring-plugin-rhel9:1781731914. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 42 more.
High [CVE-2026-5497] Denial of Service via unbounded video frame processing
Denial of Service via unbounded video frame processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-53460] Denial of Service via missing memory request check
Denial of Service via missing memory request check. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-49218] Denial of Service via crafted DCM image with invalid dimensions
Denial of Service via crafted DCM image with invalid dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-46520] Denial of Service via out-of-bounds write when processing multiple images
Denial of Service via out-of-bounds write when processing multiple images. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-45664] Denial of Service due to excessive resource use in MNG coder
Denial of Service due to excessive resource use in MNG coder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-46522] Denial of Service via crafted MIFF file
Denial of Service via crafted MIFF file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-45031] Denial of Service due to resource policy bypass in PSD decoder
Denial of Service due to resource policy bypass in PSD decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-2049] Remote Code Execution via HDR File Parsing Heap-based Buffer Overflow
Remote Code Execution via HDR File Parsing Heap-based Buffer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-46523] Denial of Service via crafted MSL image leading to heap-use-after-free
Denial of Service via crafted MSL image leading to heap-use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-46625] Cookie attribute manipulation via prototype pollution
Cookie attribute manipulation via prototype pollution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift-service-mesh/kiali-rhel9:1782201466. Resolved in Red Hat advisory RHSA-2026:33183 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat OpenShift Service Mesh 3.3; OpenShift Lightspeed; Red Hat 3scale API Management Platform 2; and 4 more.
High [CVE-2026-46529] PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen. Red Hat rates this important (CVSS 7.8). Weakness: CWE-77. Affected package(s): evince. Resolved in Red Hat advisory RHSA-2026:33416 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 8); Red Hat Enterprise Linux AppStream E4S (v.9.2); Red Hat Enterprise Linux AppStream E4S (v.9.4); Red Hat Enterprise Linux AppStream EUS (v.9.6); and 13 more.
High [CVE-2026-6893] Root code execution via DHCP options command injection
Root code execution via DHCP options command injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Affected package(s): dracut, dracut-main. Resolved in Red Hat advisory RHSA-2026:26713 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more.
High [CVE-2026-11837] ansible.posix authorized_key: local privilege escalation via symlink-following chown
ansible.posix authorized_key: local privilege escalation via symlink-following chown. Red Hat rates this important (CVSS 7.3). Weakness: CWE-59. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
High [CVE-2025-71319] Denial of Service due to infinite loop when processing specially crafted images.
Denial of Service due to infinite loop when processing specially crafted images.. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): discovery/discovery-ui-rhel9:1782756541. Resolved in Red Hat advisory RHSA-2026:33313 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Discovery 2; Red Hat Trusted Artifact Signer 1.4; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.
High [CVE-2026-45591] Denial of Service via uncontrolled resource consumption
Denial of Service via uncontrolled resource consumption. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dotnet8, dotnet8.0, dotnet9.0, dotnet9, dotnet10.0, dotnet10. Resolved in Red Hat advisory RHSA-2026:25110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.