Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1229 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 799 high, 376 medium, 20 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High7.5Linux

High [CVE-2026-44488] Denial of Service due to unenforced request and response size limits

Denial of Service due to unenforced request and response size limits. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, satellite/iop-host-inventory-frontend-rhel9:1782253070, openshift-service-mesh/kiali-ossmc-rhel9:1782201894. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 42 more.

CVE-2026-44488
Red Hat Enterprise Linux
Jun 11, 2026
High7.5Linux

High [CVE-2026-44496] Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name

Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, quay/quay-rhel8:1782487717, quay/quay-rhel8:1781878070, advanced-cluster-security/rhacs-main-rhel8:1779293013. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 40 more.

CVE-2026-44496
Red Hat Enterprise Linux
Jun 11, 2026
High7.0Linux

High [CVE-2026-44495] Information disclosure due to prototype pollution vulnerability

Information disclosure due to prototype pollution vulnerability. Red Hat rates this important (CVSS 7). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, advanced-cluster-security/rhacs-main-rhel8:1779293013, discovery/discovery-ui-rhel9:1782166952, openshift4/ose-monitoring-plugin-rhel9:1781731914. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 44 more.

CVE-2026-44495
Red Hat Enterprise Linux
Jun 11, 2026
High8.7Linux

High [CVE-2026-44494] Man-in-the-Middle (MITM) attack via Prototype Pollution

Man-in-the-Middle (MITM) attack via Prototype Pollution. Red Hat rates this important (CVSS 8.7). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, satellite/iop-advisor-frontend-rhel9:1782243376, openshift4/ose-monitoring-plugin-rhel9:1782243791, openshift4/ose-monitoring-plugin-rhel9:1782313844. Resolved in Red Hat advisory RHSA-2026:29864 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 44 more.

CVE-2026-44494
Red Hat Enterprise Linux
Jun 11, 2026
High8.6Linux

High [CVE-2026-44492] Proxy bypass via IPv4-mapped IPv6 address non-normalization

Proxy bypass via IPv4-mapped IPv6 address non-normalization. Red Hat rates this important (CVSS 8.6). Weakness: CWE-289. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift4/ose-console-rhel9:1782244020, advanced-cluster-security/rhacs-main-rhel8:1779293013, discovery/discovery-ui-rhel9:1782166952, openshift4/ose-monitoring-plugin-rhel9:1781731914. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 42 more.

CVE-2026-44492
Red Hat Enterprise Linux
Jun 11, 2026
High7.5Linux

High [CVE-2026-5497] Denial of Service via unbounded video frame processing

Denial of Service via unbounded video frame processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-5497
Red Hat Enterprise Linux
Jun 11, 2026
High7.5Linux

High [CVE-2026-53460] Denial of Service via missing memory request check

Denial of Service via missing memory request check. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-53460
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-49218] Denial of Service via crafted DCM image with invalid dimensions

Denial of Service via crafted DCM image with invalid dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-49218
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-46520] Denial of Service via out-of-bounds write when processing multiple images

Denial of Service via out-of-bounds write when processing multiple images. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-46520
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-45664] Denial of Service due to excessive resource use in MNG coder

Denial of Service due to excessive resource use in MNG coder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-45664
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-46522] Denial of Service via crafted MIFF file

Denial of Service via crafted MIFF file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-46522
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-45031] Denial of Service due to resource policy bypass in PSD decoder

Denial of Service due to resource policy bypass in PSD decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-45031
Red Hat Enterprise Linux
Jun 10, 2026
High7.8Linux

High [CVE-2026-2049] Remote Code Execution via HDR File Parsing Heap-based Buffer Overflow

Remote Code Execution via HDR File Parsing Heap-based Buffer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-2049
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-46523] Denial of Service via crafted MSL image leading to heap-use-after-free

Denial of Service via crafted MSL image leading to heap-use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-46523
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-46625] Cookie attribute manipulation via prototype pollution

Cookie attribute manipulation via prototype pollution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift-service-mesh/kiali-rhel9:1782201466. Resolved in Red Hat advisory RHSA-2026:33183 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat OpenShift Service Mesh 3.3; OpenShift Lightspeed; Red Hat 3scale API Management Platform 2; and 4 more.

CVE-2026-46625
Red Hat Enterprise Linux
Jun 10, 2026
High7.8Linux

High [CVE-2026-46529] PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen

PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen. Red Hat rates this important (CVSS 7.8). Weakness: CWE-77. Affected package(s): evince. Resolved in Red Hat advisory RHSA-2026:33416 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 8); Red Hat Enterprise Linux AppStream E4S (v.9.2); Red Hat Enterprise Linux AppStream E4S (v.9.4); Red Hat Enterprise Linux AppStream EUS (v.9.6); and 13 more.

CVE-2026-46529
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-6893] Root code execution via DHCP options command injection

Root code execution via DHCP options command injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Affected package(s): dracut, dracut-main. Resolved in Red Hat advisory RHSA-2026:26713 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more.

CVE-2026-6893
Red Hat Enterprise Linux
Jun 10, 2026
High7.3Linux

High [CVE-2026-11837] ansible.posix authorized_key: local privilege escalation via symlink-following chown

ansible.posix authorized_key: local privilege escalation via symlink-following chown. Red Hat rates this important (CVSS 7.3). Weakness: CWE-59. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

CVE-2026-11837
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2025-71319] Denial of Service due to infinite loop when processing specially crafted images.

Denial of Service due to infinite loop when processing specially crafted images.. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): discovery/discovery-ui-rhel9:1782756541. Resolved in Red Hat advisory RHSA-2026:33313 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Discovery 2; Red Hat Trusted Artifact Signer 1.4; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.

CVE-2025-71319
Red Hat Enterprise Linux
Jun 9, 2026
High7.5Linux

High [CVE-2026-45591] Denial of Service via uncontrolled resource consumption

Denial of Service via uncontrolled resource consumption. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dotnet8, dotnet8.0, dotnet9.0, dotnet9, dotnet10.0, dotnet10. Resolved in Red Hat advisory RHSA-2026:25110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2026-45591
Red Hat Enterprise Linux
Jun 9, 2026

← All Linux advisories