Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories
1165 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 771 high, 347 medium, 16 low.
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux Red Hat Enterprise Linux advisories
High [CVE-2026-42246] Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS
Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS. Red Hat rates this important (CVSS 7.4). Weakness: CWE-325. Affected package(s): ruby, ruby4, ruby4.0, ruby:3.3, ruby3, ruby:2.5. Resolved in Red Hat advisory RHSA-2026:33514 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 9 more.
High [CVE-2026-4890] NSEC bitmap parsing infinite loop
NSEC bitmap parsing infinite loop. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.19.
High [CVE-2026-4891] RRSIG rdlen underflow leading to heap OOB read
RRSIG rdlen underflow leading to heap OOB read. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; and 2 more.
High [CVE-2026-4892] DHCPv6 CLID buffer overflow in helper process
DHCPv6 CLID buffer overflow in helper process. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; and 2 more.
High [CVE-2026-5172] extract_addresses() OOB read via malformed rdlen
extract_addresses() OOB read via malformed rdlen. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:19158 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-42264] Prototype pollution allows information disclosure and request manipulation
Prototype pollution allows information disclosure and request manipulation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, advanced-cluster-security/rhacs-main-rhel8:1779371594, advanced-cluster-security/rhacs-main-rhel8:1779293013, openshift-service-mesh/kiali-rhel9:1782201812. Resolved in Red Hat advisory RHSA-2026:20889 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.11; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat OpenShift Service Mesh 3.1; and 24 more.
High [CVE-2026-43329] strictly check for maximum number of actions
strictly check for maximum number of actions. Red Hat rates this important (CVSS 7.8). Weakness: CWE-770. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:34094 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 11 more.
High [CVE-2026-39820] Go net/mail: Denial of Service via crafted email inputs
Go net/mail: Denial of Service via crafted email inputs. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected package(s): openshift-service-mesh/istio-proxyv2-rhel9:1782310747, openshift-service-mesh/istio-proxyv2-rhel9:1782303211, rhdh/rhdh-rhel9-operator:1782767215, openshift-service-mesh/istio-cni-rhel9:1782222217, openshift-service-mesh/istio-pilot-rhel9:1782223341, openshift-service-mesh/istio-pilot-rhel9:1782223138. Resolved in Red Hat advisory RHSA-2026:33120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift 6.4; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Developer Hub 1.10; and 52 more.
High [CVE-2026-33811] Go net package: Denial of Service via long CNAME response in LookupCNAME
Go net package: Denial of Service via long CNAME response in LookupCNAME. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1341. Affected package(s): golang-github-openprinting-ipp-usb, opentelemetry-collector, golang1, openshift-service-mesh/istio-proxyv2-rhel9:1782310747, openshift-service-mesh/istio-proxyv2-rhel9:1782303211, rhdh/rhdh-rhel9-operator:1782767215. Resolved in Red Hat advisory RHSA-2026:23262 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: RHEM 1.0 for RHEL 9; Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); Red Hat Enterprise Linux AppStream (v. 9); and 88 more.
High [CVE-2026-42499] Denial of Service via pathological email address parsing
Denial of Service via pathological email address parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1046. Affected package(s): openshift-service-mesh/istio-proxyv2-rhel9:1782310747, openshift-service-mesh/istio-proxyv2-rhel9:1782303211, rhdh/rhdh-rhel9-operator:1782767215, openshift-service-mesh/istio-cni-rhel9:1782222217, openshift-service-mesh/istio-pilot-rhel9:1782223341, openshift-service-mesh/istio-pilot-rhel9:1782223138. Resolved in Red Hat advisory RHSA-2026:33120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift 6.4; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Developer Hub 1.10; and 52 more.
High [CVE-2026-33814] Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected package(s): golang1, cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9:1782839981, openshift-service-mesh/istio-cni-rhel9:1782222217, cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9:1782840519, openshift-service-mesh/istio-pilot-rhel9:1782223138, openshift-service-mesh/istio-pilot-rhel9:1782222366. Resolved in Red Hat advisory RHSA-2026:23262 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Openshift Data Foundation 4.22; Red Hat OpenShift Service Mesh 3.1; Red Hat OpenShift Service Mesh 3.2; and 11 more.
High [CVE-2026-8094] Other issue in the WebRTC component
Other issue in the WebRTC component. Red Hat rates this important (CVSS 7.5). Affected package(s): firefox. Resolved in Red Hat advisory RHSA-2026:24509 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-8092] Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2
Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): firefox. Resolved in Red Hat advisory RHSA-2026:24509 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-8091] Incorrect boundary conditions in the Audio/Video: Playback component
Incorrect boundary conditions in the Audio/Video: Playback component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-8090] Use-after-free in the DOM: Networking component
Use-after-free in the DOM: Networking component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): firefox. Resolved in Red Hat advisory RHSA-2026:24509 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-42216] Information disclosure and denial of service via malformed EXR files
Information disclosure and denial of service via malformed EXR files. Red Hat rates this important (CVSS 8.1). Weakness: CWE-130. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream E4S (v.9.2); Red Hat Enterprise Linux AppStream E4S (v.9.4); and 11 more.
High [CVE-2026-41142] Arbitrary code execution via integer overflow in image resizing
Arbitrary code execution via integer overflow in image resizing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream E4S (v.9.2); Red Hat Enterprise Linux AppStream E4S (v.9.4); and 10 more.
High [CVE-2026-13601] Overly Permissive Content Security Policy in Yelp Allows Host File Disclosure from Flatpak Applications
Overly Permissive Content Security Policy in Yelp Allows Host File Disclosure from Flatpak Applications. Red Hat rates this important (CVSS 7.1). Weakness: CWE-693. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-43284] "Dirty Frag" ESP XFRM variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel
"Dirty Frag" ESP XFRM variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel. Red Hat rates this important (CVSS 7.8). Weakness: CWE-123. Affected package(s): rhcos, kernel, kernel-rt, kpatch-patch. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NVIDIA for RHEL 10; Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; and 63 more.
High [CVE-2026-43112] fix out-of-bounds read in cifs_sanitize_prepath
fix out-of-bounds read in cifs_sanitize_prepath. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:34911 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.22.