Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1635 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 619 high, 814 medium, 169 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

Low3.5Red Hat

Low [CVE-2026-53584] Submodule path traversal allows arbitrary directory creation

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 does not reject traversal components in a submodule path loaded from.gitmodules. The affected src/libgit2/submodule.c paths include git_submodule_lookup and git_submodule_add_setup. A crafted repository can specify a path such as../escape-target, and applications that initialize the submodule can create directories outside the repository working tree. This issue is fixed in versions 1.8.6 and 1.9.5. A flaw was found in libgit2. By crafting a malicious repository that specifies traversal components in a submodule path, applications initializing the submodule can be tricked into creating directories in arbitrary locations on the file system. This could lead to unintended file system modifications or potentially further compromise. Red Hat severity: Low — CVSS 3.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N). Weakness: CWE-22. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3. Red Hat fixing advisory: RHSA-2026:59361. Affected products named by the advisory: Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-53584
Red Hat Enterprise Linux
Aug 20, 2026
Low2.8Red Hat

Low [CVE-2026-64846] Arbitrary file truncation via time-of-check/time-of-use race

Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the LocalStore restore path. The race can cause writeFile to follow a substituted final symlink when opening a path with O_TRUNC instead of enforcing FinalSymlink::DontFollow, allowing the Nix process or nix-daemon to create or truncate an empty file outside the build sandbox with the daemon user's permissions. The primitive does not provide arbitrary-content writes and requires winning the race. This issue is fixed in version 2.35.0. A flaw was found in Nix. Red Hat severity: Low — CVSS 2.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N). Weakness: CWE-367. Affected products named by the advisory: Confidential Compute Attestation; Logging Subsystem for Red Hat OpenShift; OpenShift Lightspeed; OpenShift Service Mesh 3; and 41 more.

CVE-2026-64846
Red Hat Enterprise Linux
Aug 20, 2026
Low3.1Red Hat

Low [CVE-2026-76891] Denial of Service via sharkd crash

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in the sharkd component of Wireshark. A remote attacker could exploit this vulnerability, which requires user interaction and has high attack complexity, by triggering a crash. Red Hat Enterprise Linux 10 and Red Hat In-Vehicle OS ship Wireshark 4.4.2, which is within the affected range (4.4.0–4.4.17). Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-248. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: wireshark.

CVE-2026-76891
Red Hat Enterprise Linux
Aug 19, 2026
Low3.1Red Hat

Low [CVE-2026-76885] Denial of Service via Tektronix K12xx file parsing

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. This vulnerability, a buffer over-read, occurs when the Tektronix K12xx file parser processes a specially crafted file. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-125. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76885
Red Hat Enterprise Linux
Aug 19, 2026
Low3.1Red Hat

Low [CVE-2026-76888] Heap-based Buffer Overflow in RDP dissector leads to Denial of Service

RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. A remote attacker could exploit a heap-based buffer overflow vulnerability within the RDP (Remote Desktop Protocol) dissector. By crafting a malicious RDP packet, an attacker could cause the Wireshark application to crash, leading to a denial of service. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-120. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76888
Red Hat Enterprise Linux
Aug 19, 2026
Low3.1Red Hat

Low [CVE-2026-76887] Denial of service via heap-based buffer overflow in dissection engine

Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. Exploitation requires a user to process a specially crafted network packet, leading to a crash of the application. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat severity: Low — CVSS 3.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-120. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76887
Red Hat Enterprise Linux
Aug 19, 2026
Low3.3Red Hat

Low [CVE-2026-76884] Denial of Service via ERF file parser crash

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. A remote attacker could exploit a buffer over-read vulnerability in the ERF (Extensible Record Format) file parser. This could lead to a denial of service, making the application unavailable to legitimate users. Red Hat Enterprise Linux 6 through 9 ship Wireshark versions 1.x through 3.x, which predate the introduction of the vulnerable code in version 4.4.0 and are therefore not affected by this flaw. Red Hat severity: Low — CVSS 3.3 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-130. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76884
Red Hat Enterprise Linux
Aug 19, 2026
Low3.4Red Hat

Low [CVE-2026-74983] Mitigation bypass in the Data Loss Prevention component

Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-807. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-74983
Red Hat Enterprise Linux
Aug 18, 2026
Low3.4Red Hat

Low [CVE-2026-74976] JIT miscompilation in the JavaScript Engine: JIT component

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-733. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-74976
Red Hat Enterprise Linux
Aug 18, 2026
Low3.7Vendor: MediumRed Hat

Low [CVE-2026-60589] Improve Resource Resolving (2026-08 Security Update)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Red Hat severity: Moderate — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 18 more.

CVE-2026-60589
Red Hat Enterprise Linux
Aug 18, 2026
Low3.8Red Hat

Low [CVE-2026-6469] Incorrect ownership assignment allows unauthorized statistics modification

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. The overall impact is limited, as standard DROP TABLE operations still correctly remove the affected objects. This flaw has a Low impact on Red Hat products. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-708. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-6469
Red Hat Enterprise Linux
Aug 13, 2026
Low3.8Red Hat

Low [CVE-2026-16241] Denial of Service via integer underflow

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. This vulnerability causes the client to overwrite a large memory region, leading to a temporary denial of service (DoS). This Low impact flaw in PostgreSQL ECPG affects client applications. The limited scope to client-side disruption and the prerequisite of elevated server privileges contribute to its lower severity. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-191. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.

CVE-2026-16241
Red Hat Enterprise Linux
Aug 13, 2026
Low3.8Red Hat

Low [CVE-2026-14673] PostgreSQL amcheck: Privilege escalation via untrusted search path

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.5, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected. By setting a malicious search path before invoking an amcheck function, an attacker can hijack execution to run arbitrary SQL functions with the elevated permissions of the expression index owner. This vulnerability is rated as Low impact because exploitation requires an attacker to already possess EXECUTE privileges on amcheck functions. The necessity of having this pre-existing, elevated database access to manipulate the search path significantly limits the likelihood of successful privilege escalation. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-426. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7 as not affected. Red Hat fixing advisory: RHSA-2026:54751, RHSA-2026:57198.

CVE-2026-14673
Red Hat Enterprise Linux
Aug 13, 2026
Low3.5Red Hat

Low [CVE-2026-73281] ssh-agent allows remote execution of local operations

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension. This could enable a remote attacker to add PKCS#11 tokens or utilize keys with destination restrictions, bypassing intended security controls. Red Hat has determined that this vulnerability has limited impact. Exploitation requires an authenticated SSH session with agent forwarding enabled and the agent in a locked state. Red Hat Enterprise Linux 6, 7, 8, and RHEL 9 through 9.6 ship OpenSSH versions prior to 8.9 and are not affected. Red Hat may apply this fix in a future update for affected products. Red Hat severity: Low — CVSS 3.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N). Weakness: CWE-266. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: openssh.

CVE-2026-73281
Red Hat Enterprise Linux
Aug 11, 2026
Low2.8Red Hat

Low [CVE-2026-18503] Denial of Service via super-linear regular expression work in csv.Sniffer.sniff

Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv. Sniffer.sniff(). A flaw was found in the `csv. This excessive processing consumes significant CPU resources, potentially leading to a Denial of Service (DoS) for applications that process unbounded input using this function. Red Hat has evaluated this issue and determined it has a Low security impact. Most applications are not affected as they use csv.reader() or csv. DictReader() directly without invoking the sniffing functionality. Red Hat severity: Low — CVSS 2.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-1333. Affected Red Hat products: Red Hat Hardened Images; Exploit Intelligence; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Enterprise Linux command line assistant; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces; Red Hat OpenShift Virtualization 4; Self-service automation portal 2. Red Hat fixing advisory: RHSA-2026:54534, RHSA-2026:54554, RHSA-2026:57010, RHSA-2026:57660, RHSA-2026:58420. Affected products named by the advisory: Red Hat package: python3.12; Red Hat package: python36; Red Hat package: python3.9.

CVE-2026-18503
Red Hat Enterprise Linux
Aug 10, 2026
Low3.3Red Hat

Low [CVE-2026-66484] GNU cpio: Path Traversal allows creating hard links outside intended directory via malicious tar archives.

GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name function without equivalent sanitization before calling link function. A tar archive provided by an attacker, containing a hard-link entry whose linkname is set to an absolute path outside the extraction directory, can cause cpio to create a hard link to an existing file outside the intended extraction directory, breaking the expected guarantee of --no-absolute-filenames and allowing archive-controlled linkage to external files. This issue has been fixed in commit e2b9cbdd3354d2b1569b7390d1bc15c1930559ad This vulnerability, known as Path Traversal, occurs during the extraction of tar archives in copy-in mode when the `--no-absolute-filenames` option is used. An attacker could provide a specially crafted tar archive that, when extracted with this option, creates hard links pointing to files outside the intended extraction directory, potentially leading to unauthorized file modifications. Red Hat severity: Low — CVSS 3.3 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N). Weakness: CWE-22.

CVE-2026-66484
Red Hat Enterprise Linux
Aug 10, 2026
Low2.5Red Hat

Low [CVE-2026-18739] Off-by-one in poptStuffArgs

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data. Exploitation is only possible if the host application then unsafely processes the corrupted `poptContext` data, such as sinking it into `exec`, `system`, `popen`, or `dlopen`. Red Hat severity: Low — CVSS 2.5 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-787. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:56984. Affected products named by the advisory: Red Hat package: popt.

CVE-2026-18739
Red Hat Enterprise Linux
Aug 3, 2026
Low3.3Red Hat

Low [CVE-2026-68744] NSS responder uninitialized heap disclosure in initgroups reply

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached directory data and heap layout information from the sssd_nss process. This issue can only be triggered by a local attacker who can connect to the SSSD NSS responder unix socket. Credentials, hashes, and tickets reside in separate sssd_pam and sssd_be processes and are not exposed by this flaw. Much of the directory data may already be obtainable via legitimate NSS queries depending on the deployment. The primary security concern is disclosure of heap pointers that could assist ASLR bypass if chained with a separate memory-corruption vulnerability. Red Hat severity: Low — CVSS 3.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-908. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: sssd.

CVE-2026-68744
Red Hat Enterprise Linux
Aug 3, 2026
Low2.1Red Hat

Low [CVE-2026-66401] Denial of Service via out-of-bounds read in UVC H.264 parser

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigger a heap read beyond allocated bounds during camera stream setup, causing denial of service. A flaw was found in FreeRDP. This can lead to a denial of service (DoS), making the application unavailable. Red Hat severity: Low — CVSS 2.1 (CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-66401
Red Hat Enterprise Linux
Aug 1, 2026
Low3.7Red Hat

Low [CVE-2026-67316] Prototype Pollution allows unauthorized data transmission and network redirection

axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()), inherited data is read via (config || {}).data before config normalization, causing an attacker-controlled body to be sent on requests that did not set one. Additional low-level paths, only reachable when calling exported adapters/helpers (e.g. lib/adapters/http.js, unsafe/helpers/resolveConfig.js) directly with plain configs and no own proxy or paramsSerializer, can inherit polluted proxy values (routing requests through an attacker-controlled proxy) or paramsSerializer values (attacker-controlled URL serialization). These low-level gadgets do not reproduce through normal high-level axios calls on 1.15.2+. The issue is fixed in axios 1.18.0 and 0.33.0. A flaw was found in axios, a widely used JavaScript library for making web requests. This vulnerability, known as prototype pollution, allows an attacker to subtly alter how network requests are built if another part of the system has already been compromised. This could lead to an attacker injecting unauthorized data into requests that were not intended to have a body.

CVE-2026-67316
Red Hat Enterprise Linux
Aug 1, 2026

← All Red Hat advisories