Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1635 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 619 high, 814 medium, 169 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
High [CVE-2026-102313] Information disclosure via uninitialized resource in ANGLE
Information disclosure via uninitialized resource in ANGLE. Red Hat rates this important (CVSS 7.4). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-102826] simple-git allows command execution through unblocked Git configuration includes
simple-git allows command execution through unblocked Git configuration includes. Red Hat rates this important (CVSS 8.1). Weakness: CWE-78. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat package: grafana-pcp.
High [CVE-2026-95325] Use after free in ANGLE
Use after free in ANGLE. Red Hat rates this moderate (CVSS 8.8). Weakness: CWE-416. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-102560] Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth
A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated buffer and resulting in a heap buffer overflow. This issue is rated Important. Applications that enable WebSocket deflate with untrusted or unbounded message sizes are affected. Impact is heap corruption or denial of service. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-102559] Libsoup: libsoup: heap buffer overflow during websocket client-frame masking
A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow. This issue is rated Important. Triggering requires causing a libsoup WebSocket client (or client-role connection) to send an extremely large message. That may be reachable when application-level message size is attacker-influenced. Impact is heap corruption or denial of service in the sending process. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-102558] Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth
A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data. This issue is rated Important. A remote WebSocket peer can cause heap corruption or denial of service, especially when applications leave incoming payload size unlimited. Default configurations that set a finite max-incoming-payload-size reduce exposure but the vulnerable code path remains relevant for applications that disable the limit. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-102555] Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding
A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI. This issue is rated Important. Impact depends on how the application consumes the returned GBytes. Red Hat Enterprise Linux ships libsoup/libsoup3 widely used by GNOME and other HTTP clients; applications that decode untrusted data URIs are in scope. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-102676] Privilege escalation via unauthorized Node.js integration in web workers
Privilege escalation via unauthorized Node.js integration in web workers. Red Hat rates this important (CVSS 8.3). Weakness: CWE-266. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 10; Red Hat package: podman-desktop; Red Hat package: rh-podman-desktop.
High [CVE-2026-102675] Cross-origin information disclosure via improper CORS enforcement in custom protocol handlers
Cross-origin information disclosure via improper CORS enforcement in custom protocol handlers. Red Hat rates this important (CVSS 7.4). Weakness: CWE-346. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 10; Red Hat package: podman-desktop; Red Hat package: rh-podman-desktop.
High [CVE-2026-102674] Sandbox bypass via popup window creation
Sandbox bypass via popup window creation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-281. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 10; Red Hat package: podman-desktop; Red Hat package: rh-podman-desktop.
High [CVE-2026-102673] Sandbox bypass via popups opened from sandboxed iframes
Sandbox bypass via popups opened from sandboxed iframes. Red Hat rates this important (CVSS 8.2). Weakness: CWE-281. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 10; Red Hat package: podman-desktop; Red Hat package: rh-podman-desktop.
High [CVE-2026-102557] Libsoup: libsoup: heap buffer overflow during websocket message reassembly
A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total message size against the limits of the underlying buffer type. A remote peer could send fragments that caused size truncation while the implementation still used the full length, leading to heap corruption or a crash. This issue is rated Important. A remote, unauthenticated WebSocket peer can trigger heap corruption or denial of service during message reassembly. Any Red Hat product or application exposing or consuming libsoup WebSockets with untrusted peers is affected until updated. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-102556] Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion
A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong. This issue is rated Important. A remote peer can send a WebSocket Pong that reaches receive_pong(). Exploitation requires an application to connect a::pong handler that expects GBytes; many keep-alive users do. Successful triggering can crash the process or corrupt heap state. libsoup WebSocket support is used by client and server applications on Red Hat platforms. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-843. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.
High [CVE-2026-94603] The `podman run` command can be instructed to disable almost all sandboxing - including user-requested sandboxing - by image annotation
The `podman run` command can be instructed to disable almost all sandboxing - including user-requested sandboxing - by image annotation. Red Hat rates this important (CVSS 8.6). Weakness: CWE-15. Red Hat lists fixing advisory RHSA-2026:74861 with package podman-main-6.1.3-1.hum1, podman-main-6.1.2-1.1.hum1. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat OpenShift Virtualization 4; and 2 more.
High [CVE-2026-75804] Denial of Service via unenforced QUIC connection flow control
Denial of Service via unenforced QUIC connection flow control. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:74162 with package openssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 15 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat JBoss Core Services; and 11 more.
High [CVE-2026-95520] integer overflow in iterReadArchiveNext leads to heap-based buffer overflow when parsing untrusted RPM packages
integer overflow in iterReadArchiveNext() leads to heap-based buffer overflow when parsing untrusted RPM packages. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 1 more. Affected products named by the advisory: Red Hat package: rpm.
High [CVE-2026-95389] Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
High [CVE-2026-95387] Denial of Service via heap-based buffer overflow in SPDY dissector
Denial of Service via heap-based buffer overflow in SPDY dissector. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: wireshark.
High [CVE-2026-97024] Arbitrary write in root context via path traversal in deploy directory files/etc
Arbitrary write in root context via path traversal in deploy directory files/etc. Red Hat rates this important (CVSS 7.1). Weakness: CWE-61. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.
High [CVE-2026-84782] Information disclosure via DTLS handshake retransmission
Information disclosure via DTLS handshake retransmission. Red Hat rates this important (CVSS 7.4). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:74162 with package ruby3-4-main-3.4.10-31.7.hum1, rust-bootupd-main-0.3.2-1.hum1, openssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Ansible Automation Orchestrator 2026; Confidential Cluster Operator; Confidential Compute Attestation; and 53 more. Affected products named by the advisory: Lightspeed Core; Logging Subsystem for Red Hat OpenShift; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 49 more.