Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1635 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 619 high, 814 medium, 169 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
Medium [CVE-2026-72897] Denial of Service via out-of-bounds write during TLS context switch
Denial of Service via out-of-bounds write during TLS context switch. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:74162 with package openssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 15 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat JBoss Core Services; and 11 more.
Medium [CVE-2026-54875] information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V
information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-208. Red Hat lists fixing advisory RHSA-2026:74162 with package openssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 15 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat JBoss Core Services; and 11 more.
Medium [CVE-2026-54873] Denial of Service via excessive QUIC packet buffer retention
Denial of Service via excessive QUIC packet buffer retention. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:74162 with package openssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 15 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat JBoss Core Services; and 11 more.
Medium [CVE-2026-54872] Private key recovery via timing side-channel in generic elliptic curve operations
Private key recovery via timing side-channel in generic elliptic curve operations. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-208. Red Hat lists fixing advisory RHSA-2026:74162 with package openssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 15 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat JBoss Core Services; and 11 more.
Medium [CVE-2026-42772] Denial of Service via inefficient QUIC stream reassembly
Denial of Service via inefficient QUIC stream reassembly. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:74162 with package openssl-main-3.5.9-0.1.hum1, openssl3-main-3.5.9-0.1.hum1. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 15 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat JBoss Core Services; and 11 more.
Medium [CVE-2026-95395] Denial of Service via memory leak in IEEE C37.118 Synchrophasor dissector
Denial of Service via memory leak in IEEE C37.118 Synchrophasor dissector. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-95393] Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-95392] Buffer Over-read in Wireshark
Buffer Over-read in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-126. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-95388] Denial of Service via heap-based buffer overflow in sharkd
Denial of Service via heap-based buffer overflow in sharkd. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96422] Reachable Assertion in Wireshark
Reachable Assertion in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96421] Denial of Service via USB HID dissector infinite loop
Denial of Service via USB HID dissector infinite loop. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96417] Denial of Service via malformed RF4CE packet
Denial of Service via malformed RF4CE packet. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96418] Denial of Service via infinite loop in TIFF protocol dissector
Denial of Service via infinite loop in TIFF protocol dissector. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96419] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-22. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96420] Buffer Over-read in Wireshark
Buffer Over-read in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96423] Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96416] Denial of Service via malformed IEEE 802.11 packet processing
Denial of Service via malformed IEEE 802.11 packet processing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1286. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96415] Stack-based Buffer Overflow in Wireshark
Stack-based Buffer Overflow in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-97029] Sandboxed app can signal unsandboxed processes in the same process group
Sandboxed app can signal unsandboxed processes in the same process group. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-653. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.
Medium [CVE-2026-102474] Heap out-of-bounds write in conv_escape via undersized Unicode escape reservation
Heap out-of-bounds write in conv_escape via undersized Unicode escape reservation. Red Hat rates this moderate (CVSS 4). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: dash.