Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1261 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 806 high, 399 medium, 25 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High8.2Linux

High [CVE-2026-39979] out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers

out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, jq, rhcos, rhaiis/model-opt-cuda-rhel9:1780681984, rhaiis/vllm-rocm-rhel9:1782353093. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 21 more.

CVE-2026-39979
Red Hat Enterprise Linux
Apr 13, 2026
High7.1Linux

High [CVE-2026-4786] Arbitrary code execution via command injection in webbrowser.open() API

Arbitrary code execution via command injection in webbrowser.open() API. Red Hat rates this important (CVSS 7.1). Weakness: CWE-88. Affected package(s): python3.11, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, rhpam, python3.9, python3.12. Resolved in Red Hat advisory RHSA-2026:35838 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 16 more.

CVE-2026-4786
Red Hat Enterprise Linux
Apr 13, 2026
High8.1Linux

High [CVE-2026-6100] Arbitrary code execution or information disclosure via use-after-free in decompression modules

Arbitrary code execution or information disclosure via use-after-free in decompression modules. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825. Affected package(s): python3.11, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, rhpam, python3.9, python3.12. Resolved in Red Hat advisory RHSA-2026:26187 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 16 more.

CVE-2026-6100
Red Hat Enterprise Linux
Apr 13, 2026
High8.6Linux

High [CVE-2026-5367] Information disclosure via crafted DHCPv6 packets

Information disclosure via crafted DHCPv6 packets. Red Hat rates this important (CVSS 8.6). Weakness: CWE-130. Affected package(s): ovn25.03, ovn25.09, ovn, ovn23.09, ovn24.03, ovn23.06. Resolved in Red Hat advisory RHSA-2026:11702 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Fast Datapath for Red Hat Enterprise Linux 10; Fast Datapath for Red Hat Enterprise Linux 8; Fast Datapath for Red Hat Enterprise Linux 9; Fast Datapath for RHEL 8; and 2 more.

CVE-2026-5367
Red Hat Enterprise Linux
Apr 13, 2026
High7.0Linux

High [CVE-2026-31419] Linux kernel: Use-after-free in bonding driver leads to denial of service

Linux kernel: Use-after-free in bonding driver leads to denial of service. Red Hat rates this important (CVSS 7). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 2 more.

CVE-2026-31419
Red Hat Enterprise Linux
Apr 13, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-35469] Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code. Red Hat rates this important (CVSS 6.5). Weakness: CWE-770. Affected package(s): openshift4/ose-node-feature-discovery-rhel9:1779252023, openshift4/ose-sriov-network-config-daemon:1780955979, container-native-virtualization/virt-exportserver-rhel9:1782358244, openshift4/ose-sriov-network-webhook-rhel9:1779249801, advanced-cluster-security/rhacs-roxctl-rhel8:1777986630, multicluster-engine/assisted-service. Resolved in Red Hat advisory RHSA-2026:29795 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: RHEM 1.0 for RHEL 9; Red Hat OpenShift Container Platform 4.19; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 29 more.

CVE-2026-35469
Red Hat Enterprise Linux
Apr 13, 2026
Medium5.0Linux

Medium [CVE-2026-6845] Denial of Service via crafted ELF file

Denial of Service via crafted ELF file. Red Hat rates this moderate (CVSS 5). Weakness: CWE-476. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:34924 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more.

CVE-2026-6845
Red Hat Enterprise Linux
Apr 13, 2026
High7.8Linux

High [CVE-2026-4154] Remote Code Execution via XPM File Parsing Integer Overflow

Remote Code Execution via XPM File Parsing Integer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:17533 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-4154
Red Hat Enterprise Linux
Apr 11, 2026
High7.8Linux

High [CVE-2026-4153] Remote Code Execution via PSP file parsing

Remote Code Execution via PSP file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:17533 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-4153
Red Hat Enterprise Linux
Apr 11, 2026
High7.8Linux

High [CVE-2026-4152] Remote Code Execution via malicious JP2 file parsing

Remote Code Execution via malicious JP2 file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Affected package(s): gimp. Resolved in Red Hat advisory RHSA-2026:25907 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2026-4152
Red Hat Enterprise Linux
Apr 11, 2026
High7.8Linux

High [CVE-2026-4151] Remote Code Execution via ANI File Parsing Integer Overflow

Remote Code Execution via ANI File Parsing Integer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): gimp. Resolved in Red Hat advisory RHSA-2026:16484 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-4151
Red Hat Enterprise Linux
Apr 11, 2026
High7.8Linux

High [CVE-2026-4150] Arbitrary code execution via specially crafted PSD file

Arbitrary code execution via specially crafted PSD file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:17533 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 9 more.

CVE-2026-4150
Red Hat Enterprise Linux
Apr 11, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-40175] Remote Code Execution via Prototype Pollution escalation

Remote Code Execution via Prototype Pollution escalation. Red Hat rates this important (CVSS 9). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1776149682, openshift-service-mesh/kiali-ossmc-rhel9:1776151134, rhtas/rhtas-console-rhel9:1776672801, devspaces/dashboard-rhel9:1776795511, openshift-service-mesh/kiali-ossmc-rhel8:1776202125, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 29 more.

CVE-2026-40175
Red Hat Enterprise Linux
Apr 10, 2026
High7.5Linux

High [CVE-2026-34486] Missing Encryption of Sensitive Data due to EncryptInterceptor bypass

Missing Encryption of Sensitive Data due to EncryptInterceptor bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-807. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; and 8 more.

CVE-2026-34486
Red Hat Enterprise Linux
Apr 9, 2026
High7.5Linux

High [CVE-2026-29146] Information disclosure via Padding Oracle vulnerability in EncryptInterceptor

Information disclosure via Padding Oracle vulnerability in EncryptInterceptor. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1240. Affected package(s): jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; and 10 more.

CVE-2026-29146
Red Hat Enterprise Linux
Apr 9, 2026
High7.8Linux

High [CVE-2026-34734] HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file

HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-34734
Red Hat Enterprise Linux
Apr 9, 2026
High7.0Linux

High [CVE-2025-62718] Server-Side Request Forgery and proxy bypass due to improper hostname normalization

Server-Side Request Forgery and proxy bypass due to improper hostname normalization. Red Hat rates this important (CVSS 7). Weakness: CWE-1289. Affected package(s): openshift-service-mesh/kiali-rhel9:1776149682, openshift-service-mesh/kiali-ossmc-rhel9:1776151134, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, devspaces/dashboard-rhel9:1776795511, openshift-service-mesh/kiali-ossmc-rhel8:1776202125, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 35 more.

CVE-2025-62718
Red Hat Enterprise Linux
Apr 9, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-27140] Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names

Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names. Red Hat rates this important (CVSS 9). Weakness: CWE-641. Affected package(s): openshift4/cloud-network-config-controller-rhel9:1780040126, openshift4/ose-agent-installer-utils-rhel9:1780044523, openshift4/ose-vsphere-csi-driver-rhel9-operator:1780040095, openshift4/ose-aws-cloud-controller-manager-rhel9:1780040386, openshift4/ose-aws-cluster-api-controllers-rhel9:1780040551, openshift4/ose-ironic-machine-os-downloader-rhel9:1780365576. Resolved in Red Hat advisory RHSA-2026:10704 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 12 more.

CVE-2026-27140
Red Hat Enterprise Linux
Apr 8, 2026
High7.3Linux

High [CVE-2026-39892] Buffer overflow via non-contiguous buffer in API

Buffer overflow via non-contiguous buffer in API. Red Hat rates this important (CVSS 7.3). Weakness: CWE-131. Affected package(s): ansible-automation-platform, quay/quay-rhel8:1779811473, quay/quay-rhel8:1779689392, ansible-automation-platform-tech-preview/metrics-service-rhel9:1779760844, automation-controller, python3.12-cryptography. Resolved in Red Hat advisory RHSA-2026:23361 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat AI Inference Server 3.3; and 20 more.

CVE-2026-39892
Red Hat Enterprise Linux
Apr 8, 2026
High7.5Linux

High [CVE-2026-32280] Denial of Service vulnerability in certificate chain building

Denial of Service vulnerability in certificate chain building. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): rhc, openshift-service-mesh/pilot-rhel8:1777319850, openshift-service-mesh/istio-rhel9-operator:1778149657, grafana-pcp, openshift-service-mesh/istio-cni-rhel8:1777374598, rhtas/client-server-rhel9:1780399582. Resolved in Red Hat advisory RHSA-2026:11507 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 10; Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat OpenShift Container Platform 4.14; and 114 more.

CVE-2026-32280
Red Hat Enterprise Linux
Apr 8, 2026

← All Linux advisories