Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1225 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 785 high, 384 medium, 25 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High7.5Linux Updated

High [CVE-2026-47302] .NET: Denial of Service vulnerability due to uncontrolled resource allocation

.NET: Denial of Service vulnerability due to uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-47302
Red Hat Enterprise Linux
Jul 14, 2026
High8.8Linux Updated

High [CVE-2026-47300] Privilege Escalation via Incorrect Authentication Algorithm

Privilege Escalation via Incorrect Authentication Algorithm. Red Hat rates this important (CVSS 8.8). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet9-0-main-9.0.119-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-47300
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux Updated

High [CVE-2026-57108] .NET Core: Denial of Service via type confusion

.NET Core: Denial of Service via type confusion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-57108
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux Updated

High [CVE-2026-56170] Denial of Service via uncontrolled resource allocation

Denial of Service via uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet9-0-main-9.0.119-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-56170
Red Hat Enterprise Linux
Jul 14, 2026
High8.2Linux Updated

High [CVE-2026-59197] Native heap out-of-bounds write

Native heap out-of-bounds write. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:48021 with package quay/quay-rhel8:1785261506, python-pillow-0:5.1.1-23.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-59197
Red Hat Enterprise Linux
Jul 14, 2026
High8.8Linux Updated

High [CVE-2026-15719] Site isolation issue in the DOM: Navigation component

Site isolation issue in the DOM: Navigation component. Red Hat rates this important (CVSS 8.8). Weakness: CWE-501. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-15719
Red Hat Enterprise Linux
Jul 14, 2026
High8.8Vendor: MediumLinux Updated

High [CVE-2026-15718] Invalid pointer in the JavaScript: WebAssembly component

Invalid pointer in the JavaScript: WebAssembly component. Red Hat rates this moderate (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-15718
Red Hat Enterprise Linux
Jul 14, 2026
High7.8Linux Updated

High [CVE-2026-64600] XFS data corruption using reflink

XFS data corruption using reflink. Red Hat rates this important (CVSS 7.8). Weakness: CWE-362. Red Hat lists fixing advisory RHSA-2026:47981 with package kernel-0:6.12.0-55.89.1.el10_0, kernel-0:4.18.0-553.144.1.el8_10, kpatch-patch, kernel-0:5.14.0-284.182.1.el9_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-64600
Red Hat Enterprise Linux
Jul 14, 2026
High7.1Linux Updated

High [CVE-2026-43701] A malicious website may process restricted web content outside the sandbox

A malicious website may process restricted web content outside the sandbox. Red Hat rates this important (CVSS 7.1). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43701
Red Hat Enterprise Linux
Jul 10, 2026
High8.8Linux Updated

High [CVE-2026-43705] Maliciously crafted web content may lead to memory corruption

Maliciously crafted web content may lead to memory corruption. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43705
Red Hat Enterprise Linux
Jul 10, 2026
High8.8Linux Updated

High [CVE-2026-43715] Maliciously crafted web content may lead to memory corruption

Maliciously crafted web content may lead to memory corruption. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43715
Red Hat Enterprise Linux
Jul 10, 2026
High7.1Linux Updated

High [CVE-2026-43725] A malicious website may process restricted web content outside the sandbox

A malicious website may process restricted web content outside the sandbox. Red Hat rates this important (CVSS 7.1). Weakness: CWE-20. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-43725
Red Hat Enterprise Linux
Jul 10, 2026
High7.5Linux Updated

High [CVE-2026-15308] CPU Denial of Service in HTML parser via repeated unterminated markup declarations

CPU Denial of Service in HTML parser via repeated unterminated markup declarations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:44481 with package discovery/discovery-ui-rhel9:1784821750, python3-12-main-3.12.13-3.5.hum1, python3.12-0:3.12.13-3.el8_10, python3.12-0:3.12.13-3.el9_8.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-15308
Red Hat Enterprise Linux
Jul 9, 2026
High7.5Linux Updated

High [CVE-2026-59899] Memory exhaustion in netty-codec-http (decompression bomb)

A flaw was found in the Netty netty-codec-http component. A remote attacker can send HTTP requests containing highly compressed data. This can lead to memory exhaustion and a denial of service (DoS), making the service unavailable to legitimate users. This is an Important vulnerability in Netty's HTTP decoder, which could lead to a denial of service. Red Hat products utilizing `netty-codec-http` are susceptible to memory exhaustion when processing specially crafted, highly compressed HTTP payloads. This allows a remote attacker to trigger excessive memory allocation, impacting system availability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-409. Affected products named by the advisory: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33; Red Hat build of Quarkus 3.27.4.SP3; Red Hat build of Quarkus 3.33.2.SP3; Cryostat 4; and 19 more.

CVE-2026-59899
Red Hat Enterprise Linux
Jul 9, 2026
High7.8Linux

High [CVE-2026-39822] Go os.Root: Symlink following vulnerability allows directory traversal

Go os.Root: Symlink following vulnerability allows directory traversal. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:44624 with package podman-6:5.8.2-5.el9_8, rhosdt/tempo-query-rhel9:1784775793, golang-0:1.26.5-1.el10_2, buildah-2:1.43.1-4.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-39822
Red Hat Enterprise Linux
Jul 8, 2026
High7.5Linux

High [CVE-2026-55999] glamor Font Atlas Heap Buffer Overflow

glamor Font Atlas Heap Buffer Overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:38486 with package xorg-x11-server-0:1.20.11-34.el9_8.3, xorg-x11-server-Xwayland-0:21.1.3-20.el8_10.3, xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.3, xorg-x11-server-0:1.20.11-28.el8_10.3. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-55999
Red Hat Enterprise Linux
Jul 8, 2026
High7.3Linux

High [CVE-2026-56001] BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow

BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow. Red Hat rates this important (CVSS 7.3). Red Hat lists fixing advisory RHSA-2026:47079 with package libXfont2-0:2.0.3-2.el8_10.1, libXfont2-0:2.0.6-5.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-56001
Red Hat Enterprise Linux
Jul 8, 2026
High7.3Linux

High [CVE-2026-56002] PCF Font Parsing Heap Buffer Overflow

PCF Font Parsing Heap Buffer Overflow. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47079 with package libXfont2-0:2.0.3-2.el8_10.1, libXfont2-0:2.0.6-5.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-56002
Red Hat Enterprise Linux
Jul 8, 2026
High7.1Linux

High [CVE-2026-59691] rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer

rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer. Red Hat rates this important (CVSS 7.1). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47180 with package gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2.6. Affected product named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-59691
Red Hat Enterprise Linux
Jul 8, 2026
High7.5Linux

High [CVE-2026-59692] DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback

DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback. Red Hat rates this important (CVSS 7.5). Weakness: CWE-121. Red Hat lists fixing advisory RHSA-2026:47180 with package gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2.6. Affected product named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-59692
Red Hat Enterprise Linux
Jul 8, 2026

← All Linux advisories