Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories
1166 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 771 high, 348 medium, 16 low.
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux Red Hat Enterprise Linux advisories
High [CVE-2026-22029] @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects
@remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects. Red Hat rates this important (CVSS 8). Weakness: CWE-79. Affected package(s): odf4/odf-csi-addons-sidecar-rhel9:1781550957, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, multicluster-engine/console-mce-rhel9:1776223790, odf4/odf-cli-rhel9:1781557189, odf4/rook-ceph-rhel9-operator:1781557496. Resolved in Red Hat advisory RHSA-2026:2456 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.12; and 44 more.
High [CVE-2026-21884] @remix-run/react: React Router SSR XSS in ScrollRestoration
@remix-run/react: React Router SSR XSS in ScrollRestoration. Red Hat rates this important (CVSS 8.2). Weakness: CWE-79. Affected package(s): rhoai/odh-mod-arch-model-registry-rhel9:1778666987, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, ansible-automation-platform, automation-platform-ui, rhoai/odh-dashboard-rhel9:1772093424. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3.
High [CVE-2025-59057] @remix-run/router: React Router XSS Vulnerability
@remix-run/router: React Router XSS Vulnerability. Red Hat rates this important (CVSS 7.6). Weakness: CWE-79. Affected package(s): rhoai/odh-mod-arch-model-registry-rhel9:1778666987, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, ansible-automation-platform, automation-platform-ui, rhoai/odh-dashboard-rhel9:1772093424. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3.
High [CVE-2025-14459] Unauthorized PVC Cloning via DataImportCron
Unauthorized PVC Cloning via DataImportCron. Red Hat rates this important (CVSS 8.5). Weakness: CWE-639. Affected package(s): container-native-virtualization/ovs-cni-plugin-rhel9:v4.19.17, container-native-virtualization/vm-network-latency-checkup-rhel9:v4.19.17, container-native-virtualization/kubesecondarydns-rhel9:v4.19.17, container-native-virtualization/aaq-controller-rhel9:v4.19.17, container-native-virtualization/kubevirt-template-validator-rhel9:v4.19.17, container-native-virtualization/virt-handler-rhel9:v4.19.17. Resolved in Red Hat advisory RHSA-2026:0950 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: RHEL-9-CNV-4.19.
High [CVE-2026-0719] Signed to Unsigned Conversion Error Leading to Stack-Based Buffer Overflow in libsoup NTLM Authentication
Signed to Unsigned Conversion Error Leading to Stack-Based Buffer Overflow in libsoup NTLM Authentication. Red Hat rates this important (CVSS 8.6). Weakness: CWE-121. Affected package(s): libsoup, spice-client-win, devspaces/pluginregistry-rhel9:1770918006, devspaces/openvsx-rhel9:1770851052, devspaces/udi-rhel9:1770913862, libsoup3. Resolved in Red Hat advisory RHSA-2026:2513 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 11 more.
High [CVE-2026-21441] urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API). Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected package(s): rhacm2/submariner-globalnet-rhel9:1774550347, oadp/oadp-velero-rhel9:1770421082, rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1771502845, rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9:1770103255, python3.12-urllib3, rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1771502910. Resolved in Red Hat advisory RHSA-2026:2456 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 68 more.
High [CVE-2026-22184] Arbitrary code execution via buffer overflow in untgz utility
Arbitrary code execution via buffer overflow in untgz utility. Red Hat rates this important (CVSS 8.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2025-69223] AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): automation-controller, rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1771502844, ansible-automation-platform, rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1770053721, rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1770055428, rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1771502845. Resolved in Red Hat advisory RHSA-2026:2106 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 11 more.
High [CVE-2025-67269] Denial of Service due to malformed NAVCOM packet parsing
Denial of Service due to malformed NAVCOM packet parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Affected package(s): gpsd-minimal, gpsd. Resolved in Red Hat advisory RHSA-2026:0770 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
High [CVE-2025-67268] Arbitrary code execution via heap-based out-of-bounds write in NMEA2000 packet handling
Arbitrary code execution via heap-based out-of-bounds write in NMEA2000 packet handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. Affected package(s): gpsd-minimal, gpsd. Resolved in Red Hat advisory RHSA-2026:1621 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.
High [CVE-2024-3884] Undertow: outofmemory when parsing form data encoding with application/x-www-form-urlencoded
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform; Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; and 7 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9; and 2 more.
High [CVE-2025-9784] Undertow: undertow madeyoureset http/2 ddos vulnerability
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform; Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; and 12 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9; and 7 more.
High [CVE-2025-7425] Libxslt: libxml2: heap use-after-free in libxslt caused by atype corruption in xmlattrptr
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 29 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; and 26 more.
High [CVE-2025-32462] Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines. A privilege escalation vulnerability was found in Sudo. In certain configurations, unauthorized users can gain elevated system privileges via the Sudo host option (`-h` or `--host`). When using the default sudo security policy plugin (sudoers), the host option is intended to be used in conjunction with the list option (`-l` or `--list`) to determine what permissions a user has on a different system. However, this restriction can be bypassed, allowing a user to elevate their privileges on one system to the privileges they may have on a different system, effectively ignoring the host identifier in any sudoers rules. This vulnerability is particularly impactful for systems that share a single sudoers configuration file across multiple computers or use network-based user directories, such as LDAP, to provide sudoers rules on a system. This vulnerability is classified as a Local Privilege Escalation (LPE), meaning an attacker needs an authenticated account before they could exploit it. Due to this restriction, the severity is rated Important. Additionally, for a system to be vulnerable, it must already be in a non-default configuration.
High [CVE-2025-5318] Libssh: out-of-bounds read in sftp_handle
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 21 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; and 17 more.
High [CVE-2025-6020] Linux-pam: linux-pam directory traversal
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; and 21 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; and 17 more.
High [CVE-2025-5914] Libarchive: double free at archive_read_format_rar_seek_data in archive_read_support_format_rar.c
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 28 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; and 25 more.
High [CVE-2025-5222] Icu: stack buffer overflow in the srbroot::addtag function
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4.
High [CVE-2025-48798] Gimp: multiple use after free in xcf parser
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing use-after-free issues. Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 4 more.
High [CVE-2025-48797] Gimp: multiple heap buffer overflows in tga parser
A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and causing a heap buffer overflow. Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 4 more.