Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1662 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 33 critical, 636 high, 821 medium, 170 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

Medium5.5Red Hat

Medium [CVE-2026-59089] Gimp: gimp: denial of service via integer overflow in playstation tim loader

A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color Look-Up Table (CLUT) due to an integer overflow. This occurs when multiplying num_colors and num_cluts, both 16-bit unsigned short integers, resulting in a value exceeding the maximum integer limit. An attacker could exploit this by providing a specially crafted image file, leading to undefined behavior and causing the GIMP plug-in to abort, effectively resulting in a denial of service. Conditions for Exploitation: Successful exploitation requires user interaction. An attacker must trick a user into manually opening a specially crafted, malicious PlayStation TIM image file within the GIMP application. Impact Limitations: The vulnerability is strictly limited to a localized Denial of Service (DoS) where the specific file loader plug-in aborts. It does not allow for remote code execution, data exfiltration, or privilege escalation, and it does not compromise the broader system or network security. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-59089
Red Hat Enterprise Linux
Jul 6, 2026
Medium5.0Vendor: LowRed Hat

Medium [CVE-2026-14684] Denial of Service via uncontrolled memory allocation in decodeFromByteBuffer

A flaw has been found in HdrHistogram up to 2.2.2. This affects the function org. AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This manipulation of the argument numberOfSignificantValueDigits causes uncontrolled memory allocation. The attack can only be executed locally. The exploit has been published and may be used. The actual existence of this vulnerability is currently in question. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack. A local attacker can exploit a vulnerability in the `decodeFromByteBuffer` function by manipulating the `numberOfSignificantValueDigits` argument. Successful exploitation requires local access, as an attacker must be able to supply specially crafted, manipulated input directly to an application that is actively utilizing the affected HdrHistogram library. The vulnerability is strictly limited to causing a Denial of Service (DoS) via uncontrolled memory allocation. It does not allow an attacker to execute arbitrary code, escalate privileges, or access unauthorized data. Furthermore, the impact is localized to the specific application processing the malicious input, rather than causing a broader, system-wide compromise. Red Hat severity: Low — CVSS 5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).

CVE-2026-14684
Red Hat Enterprise Linux
Jul 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-14604] Denial of Service vulnerability in PLY Model Handler

A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporter::ExportToBlob of the file code/AssetLib/Ply/PlyLoader.cpp of the component PLY Model Handler. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report. This vulnerability, a double free, exists within the PLY Model Handler component. A remote attacker could exploit this flaw by manipulating PLY model files, leading to a denial of service and making the application unavailable. This double free vulnerability can be triggered by processing a specially crafted PLY model file, potentially leading to application unavailability. While remote, exploitation typically requires user interaction to open a malicious file. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-1341. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: qt6-qtquick3d.

CVE-2026-14604
Red Hat Enterprise Linux
Jul 3, 2026
Medium4.7Red Hat

Medium [CVE-2026-14620] Arbitrary file opening and denial of service via exposed developer endpoints

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page. Any website a developer visits while the dev server is running can trigger these endpoints cross-origin with no interaction beyond the An attacker can open an arbitrary existing local file in the developer's editor, including files outside the project root, and repeated requests can spawn editor processes and force recompilations that degrade the developer's machine. Patches: upgrade to webpack-dev-server 5.2.6. Workarounds: none. This vulnerability allows a remote attacker to exploit exposed internal developer endpoints, `/webpack-dev-server/open-editor` and `/webpack-dev-server/invalidate`, through cross-origin requests. Repeated exploitation can lead to a denial of service by spawning numerous editor processes and forcing recompilations, degrading the developer's system performance. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L). Weakness: CWE-940. Affected products named by the advisory: Cryostat 4; Gatekeeper 3; Migration Toolkit for Containers; Node HealthCheck Operator; and 24 more.

CVE-2026-14620
Red Hat Enterprise Linux
Jul 3, 2026
Medium4.2Vendor: LowRed Hat

Medium [CVE-2026-14612] off-by-one buffer overflows in ipa-otpd oauth2.c during OAuth2 device authorization

Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon. Red Hat rates this issue as Low impact. We have not identified a path to arbitrary code execution, privilege escalation, or disclosure of Kerberos keys or other IdM secrets. The practical outcome is limited to instability or crash of the ipa-otpd service handling that authentication attempt. Red Hat severity: Low — CVSS 4.2 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: ipa.

CVE-2026-14612
Red Hat Enterprise Linux
Jul 3, 2026
Medium4.8Red Hat

Medium [CVE-2026-8926] Information disclosure via incorrect.netrc password lookup

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user. A flaw was found in curl. This could lead to unauthorized information disclosure, as curl might connect using unintended credentials. Red Hat severity: Moderate — CVSS 4.8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-289. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Trusted Profile Analyzer. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:69125, RHSA-2026:29017, RHSA-2026:34975. Affected products named by the advisory: Red Hat package: curl.

CVE-2026-8926
Red Hat Enterprise Linux
Jul 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-8924] Cookie injection via malicious HTTP server using super cookies

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. Moderate: Red Hat rates this flaw Moderate (CVSS 6.5) compared to CISA's Critical (9.1). The scoring difference is due to two factors: first, exploitation requires the victim's curl to connect using a trailing-dot hostname (e.g.,.), a format that is uncommon in practice and incompatible with TLS SNI; second, the direct impact is cookie injection into outbound requests — not exfiltration of victim data to the attacker. The curl project itself rates this flaw Low severity. Red Hat products that use curl for HTTP communication are affected, but the trailing-dot precondition significantly limits real-world exploitability. This flaw has not been shown to enable impacts beyond session integrity modification. Weakness: CWE-565. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Hardened Images; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6. Affected products named by the advisory: Red Hat package: curl.

CVE-2026-8924
Red Hat Enterprise Linux
Jul 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-11856] Information disclosure via incorrect Digest authentication header reuse

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`. A flaw was found in curl. This could lead to unintended information disclosure, potentially allowing an attacker to gain unauthorized access to sensitive data. This Moderate-severity flaw in `libcurl` can lead to information disclosure when an application reuses a `libcurl` handle for transfers to different HTTP origins while using Digest authentication. The vulnerability arises from `libcurl` incorrectly sending the authentication header intended for the initial origin to a subsequent, different origin. This could expose sensitive authentication data to an unintended recipient, potentially compromising user credentials or session information. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Hardened Images; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more.

CVE-2026-11856
Red Hat Enterprise Linux
Jul 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-11564] Certificate validation bypass due to incorrect connection reuse

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer. A flaw was found in curl. When libcurl reuses a connection from its connection pool, an easy handle that initially used default native Certificate Authority (CA) trust may continue to trust the native platform store. This occurs even after the application has switched that same handle to custom CA material for a subsequent transfer, potentially bypassing intended certificate validation. This Moderate flaw in curl allows a certificate validation bypass. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-295. Affected Red Hat products: Red Hat Hardened Images; Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Core Services; Red Hat OpenShift Dev Spaces; Red Hat Trusted Profile Analyzer as not affected.

CVE-2026-11564
Red Hat Enterprise Linux
Jul 3, 2026
Medium4.7Red Hat

Medium [CVE-2026-10536] Use-after-free vulnerability leading to Denial of Service

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation. This can lead to application crashes, resulting in a Denial of Service (DoS). It occurs when an application specifically configures an HTTP/2 stream-dependency tree and then performs a precise sequence of `curl_easy_reset()` and `curl_easy_cleanup()` operations, attempting to access already freed memory. This vulnerability requires a specific application programming pattern, limiting its exploitability in typical Red Hat deployments. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:41240. Affected products named by the advisory: Red Hat package: curl; Red Hat package: igvm; Red Hat package: snphost.

CVE-2026-10536
Red Hat Enterprise Linux
Jul 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-38969] Request smuggling via re-parsing of Content-Length header

ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling. NOTE: the Supplier reports that "The project README states that it is suitable for testing and development, and that its developers do not encourage its use to serve production web applications that may be subject to hostile input. It is not a production web server and is not intended to receive traffic from untrusted sources. Request smuggling is only reachable when WEBrick sits behind a proxy and receives hostile traffic in a production deployment, which is the configuration the project documents as discouraged." This CVE has been marked as Rejected by the assigning CNA. Red Hat severity: not rated. Weakness: CWE-444. Affected Red Hat products: Red Hat Hardened Images; Red Hat 3scale API Management Platform 2; Red Hat Enterprise Linux 9; Red Hat Satellite 6. Red Hat fixing advisory: RHSA-2026:34975. Affected products named by the advisory: Red Hat package: pcs.

CVE-2026-38969
Red Hat Enterprise Linux
Jul 2, 2026
Medium6.5Red Hat

Medium [CVE-2026-48816] Insufficient verification of data authenticity allows timestamp manipulation

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify derives a transparency-log timestamp from tlogEntries[].integratedTime for bundle v0.2 inclusionProof-only entries even though the inclusion proof path does not cryptographically bind integratedTime, allowing an attacker who can supply an untrusted bundle to influence certificate validity and timestampThreshold verification decisions. This issue is fixed in version 3.1.1. A flaw was found in sigstore-js. This could lead to incorrect validation of certificate validity. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-345. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; Self-service automation portal 2. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: sigstore.

CVE-2026-48816
Red Hat Enterprise Linux
Jul 1, 2026
Medium5.5Red Hat

Medium [CVE-2026-55597] Heap buffer overwrite via incorrect argument handling in JP2 encoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder. This issue has been fixed in version7.1.2-26. This vulnerability could allow an attacker to cause a denial of service (DoS) by providing a specially crafted image, leading to an application crash. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-55597
Red Hat Enterprise Linux
Jul 1, 2026
Medium4.7Red Hat

Medium [CVE-2026-55595] Denial of Service via invalid arguments to connected-components option

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. Successful exploitation of this flaw can lead to a Denial of Service (DoS), making the software unresponsive. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-55595
Red Hat Enterprise Linux
Jul 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-55594] Denial of Service via crafted image in MVG decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. This vulnerability could result in a Denial of Service (DoS), making the application unavailable. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-55594
Red Hat Enterprise Linux
Jul 1, 2026
Medium5.9Red Hat

Medium [CVE-2026-55577] Heap buffer overflow in MVG decoder allows out-of-bounds write

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. This vulnerability could allow an attacker to cause an out-of-bounds write, potentially leading to a denial of service or other impacts. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-55577
Red Hat Enterprise Linux
Jul 1, 2026
Medium5.5Red Hat

Medium [CVE-2026-55510] Denial of Service via crafted 8BIM profile

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. This could lead to a denial of service, making the software unavailable. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-55510
Red Hat Enterprise Linux
Jul 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-53467] Information disclosure vulnerability in MNG decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. A flaw was found in ImageMagick. This flaw could allow an attacker to potentially access sensitive information from memory due to parts of image pixels being left unchanged during processing. This could lead to unauthorized disclosure of data. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-908. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-53467
Red Hat Enterprise Linux
Jul 1, 2026
Medium5.5Red Hat

Medium [CVE-2026-13769] Information disclosure via overly permissive file permissions

Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) may allow other local users on the same host to read credentials written by certain CLI subcommands (aws codeartifact login, aws iam create-virtual-mfa-device, aws deploy register). To remediate this issue, users should upgrade to AWS CLI 1.44.78 (v1) or 2.34.29 (v2) or later. This vulnerability can lead to information disclosure, potentially exposing sensitive user credentials to unauthorized local attackers. Successful exploitation requires an attacker to already have local access to the same Unix-like host as the targeted user. Additionally, the vulnerability relies on the system having an unrestricted umask configuration and requires the victim to manually execute specific AWS CLI subcommands (such as codeartifact login or iam create-virtual-mfa-device) that write credentials to the filesystem. Impact Limitations: The direct impact is strictly limited to localized information disclosure. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: awscli2.

CVE-2026-13769
Red Hat Enterprise Linux
Jul 1, 2026
Medium6.5Red Hat

Medium [CVE-2026-53466] Denial of Service via integer overflow in XCF decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. An attacker could craft a malicious image file that, when processed by the XCF decoder, triggers an integer overflow. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: imagemagick.

CVE-2026-53466
Red Hat Enterprise Linux
Jul 1, 2026

← All Red Hat advisories