Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories
1158 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 770 high, 341 medium, 16 low.
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux Red Hat Enterprise Linux advisories
High [CVE-2026-42006] Denial of Service via excessive IMAP bracing
Denial of Service via excessive IMAP bracing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; and 7 more.
High [CVE-2026-8391] Other issue in the JavaScript Engine component
Other issue in the JavaScript Engine component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-475. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-8388] Incorrect boundary conditions in the JavaScript Engine: JIT component
Incorrect boundary conditions in the JavaScript Engine: JIT component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-4802] Arbitrary command execution via crafted links in system logs UI
Arbitrary command execution via crafted links in system logs UI. Red Hat rates this important (CVSS 8). Weakness: CWE-78. Affected package(s): cockpit. Resolved in Red Hat advisory RHSA-2026:21390 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; and 6 more.
High [CVE-2026-8177] XML::LibXML: Denial of Service via truncated UTF-8 in XML node names
XML::LibXML: Denial of Service via truncated UTF-8 in XML node names. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-45186] denial of service via crafted XML input
denial of service via crafted XML input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-407. Affected package(s): expat, rhui5/haproxy-rhel9:1781525671, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, libexpat, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:22715 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 9); Red Hat Enterprise Linux BaseOS (v. 10); Red Hat Enterprise Linux BaseOS (v. 8); and 9 more.
High [CVE-2026-7263] denial of service via DOMNode::C14N()
denial of service via DOMNode::C14N(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): php8.4. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-6104] global buffer over-read in mb_convert_encoding() with attacker-supplied encoding
global buffer over-read in mb_convert_encoding() with attacker-supplied encoding. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected package(s): php8.4. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-6722] PHP SOAP extension: Remote Code Execution via use-after-free vulnerability
PHP SOAP extension: Remote Code Execution via use-after-free vulnerability. Red Hat rates this important (CVSS 7.7). Weakness: CWE-825. Affected package(s): php, php:7.4. Resolved in Red Hat advisory RHSA-2026:33449 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7.
High [CVE-2026-7262] NULL pointer dereference in SOAP apache:Map decoder with missing <value>
NULL pointer dereference in SOAP apache:Map decoder with missing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Affected package(s): php, php8.4, php:8.2, php:7.4, php:8.3. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2025-14179] SQL injection in pdo_firebird via NUL bytes in quoted strings
SQL injection in pdo_firebird via NUL bytes in quoted strings. Red Hat rates this important (CVSS 8.1). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-7568] signed integer overflow in metaphone()
signed integer overflow in metaphone(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): php, php8.4, php:8.2, php:7.4, php:8.3. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-42258] Net::IMAP: IMAP Command Injection via Symbol Arguments
Net::IMAP: IMAP Command Injection via Symbol Arguments. Red Hat rates this important (CVSS 7.1). Weakness: CWE-93. Affected package(s): ruby, ruby4.0, ruby:3.3, ruby:2.5, ruby:4.0. Resolved in Red Hat advisory RHSA-2026:33514 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.
High [CVE-2026-42246] Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS
Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS. Red Hat rates this important (CVSS 7.4). Weakness: CWE-325. Affected package(s): ruby, ruby4, ruby4.0, ruby:3.3, ruby3, ruby:2.5. Resolved in Red Hat advisory RHSA-2026:33514 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 9 more.
High [CVE-2026-4890] NSEC bitmap parsing infinite loop
NSEC bitmap parsing infinite loop. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.19.
High [CVE-2026-4891] RRSIG rdlen underflow leading to heap OOB read
RRSIG rdlen underflow leading to heap OOB read. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; and 2 more.
High [CVE-2026-4892] DHCPv6 CLID buffer overflow in helper process
DHCPv6 CLID buffer overflow in helper process. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; and 2 more.
High [CVE-2026-5172] extract_addresses() OOB read via malformed rdlen
extract_addresses() OOB read via malformed rdlen. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:19158 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-42264] Prototype pollution allows information disclosure and request manipulation
Prototype pollution allows information disclosure and request manipulation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, advanced-cluster-security/rhacs-main-rhel8:1779371594, advanced-cluster-security/rhacs-main-rhel8:1779293013, openshift-service-mesh/kiali-rhel9:1782201812. Resolved in Red Hat advisory RHSA-2026:20889 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.11; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat OpenShift Service Mesh 3.1; and 24 more.
High [CVE-2026-43329] strictly check for maximum number of actions
strictly check for maximum number of actions. Red Hat rates this important (CVSS 7.8). Weakness: CWE-770. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:34094 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 11 more.