Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1635 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 619 high, 814 medium, 169 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
High [CVE-2026-102010] Denial of Service via use-after-free in binary heap erase_if
Denial of Service via use-after-free in binary heap erase_if. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:74569 with package gcc-main-16.2.1-3.hum1, gcc13-main-13.5.0-0.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 13 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: gcc-toolset-15-gcc; and 9 more.
High [CVE-2026-97023] CVE-2026-97023
CVE-2026-97023. Red Hat rates this important (CVSS 7.1). Weakness: CWE-61. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.
High [CVE-2026-85644] Denial of Service via improper array reference validation
Denial of Service via improper array reference validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: perl-xs-parse-keyword.
High [CVE-2026-88815] Denial of Service via invalid memory read during numeric type casting
Denial of Service via invalid memory read during numeric type casting. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: perl-dbi.
High [CVE-2026-94286] Denial of Service via out-of-bounds read in RECORD reply parser
Denial of Service via out-of-bounds read in RECORD reply parser. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: libxtst.
High [CVE-2026-96280] Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems
The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems. Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H. The malicious stream is served over the network (AV:N), and the attacker needs only control over the OCI registry content (PR:N). This overflow only manifests on 32-bit targets — on 64-bit systems gsize and guint64 are the same width and truncation does not occur, so exploitability depends on a target configuration outside the attacker's control (AC:H). Meaningful user interaction is required (UI:R). The vulnerable and impacted components remain within the same flatpak client/helper security authority (S:U). Because this is a heap buffer overflow with a stated path to code execution in the Flatpak client process, a successful exploit is treated as a full compromise of that process's privileges (C:H/I:H/A:H). Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-197.
High [CVE-2026-100700] Denial of Service via regular expression backtracking in addressparser
Denial of Service via regular expression backtracking in addressparser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Self-service automation portal 2; Red Hat package: grafana.
High [CVE-2026-100419] Arbitrary code execution via symlink manipulation during checkout
Arbitrary code execution via symlink manipulation during checkout. Red Hat rates this moderate (CVSS 7). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: igvm; and 1 more. Affected products named by the advisory: Red Hat package: rust.
High [CVE-2026-91765] Denial of Service via unbounded recursion in SOAP parser
Denial of Service via unbounded recursion in SOAP parser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-674. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.
High [CVE-2026-93834] use-after-free race in Tlcreate/Twalk allows VM guest escape
use-after-free race in Tlcreate/Twalk allows VM guest escape. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: qemu-kvm.
High [CVE-2026-95521] shell command injection via macro expansion of source/spec file basenames when installing a source RPM
shell command injection via macro expansion of source/spec file basenames when installing a source RPM. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: rpm.
High [CVE-2026-95519] Code Execution via Macro Expansion of Manifest Entries in `rpmgi` (`-q -p` / verify manifest flows)
Code Execution via Macro Expansion of Manifest Entries in `rpmgi` (`-q -p` / verify manifest flows). Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: rpm.
High [CVE-2026-96889] Use-after-free when XML includes have duplicated entities
Use-after-free when XML includes have duplicated entities. Red Hat rates this important (CVSS 7.8). Weakness: CWE-416. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: glycin-loaders; Red Hat package: librsvg2.
High [CVE-2026-96541] Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline
A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is closed. By holding open unauthenticated RDP sockets indefinitely, an attacker can exhaust the default global connection limit. Exploitation requires connecting from at least two distinct source IP addresses to fully utilize the default per-source and global connection limits. Existing authenticated RDP sessions remain unaffected. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-400. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gnome-remote-desktop.
High [CVE-2026-96808] Local privilege escalation via symlink traversal in revokefs writer
Local privilege escalation via symlink traversal in revokefs writer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.
High [CVE-2026-96275] Flatpak: flatpak: arbitrary write access as root via extra-data extraction
A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal. Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Exploitation requires a user or administrator to add or trust a malicious or compromised Flatpak repository and then install or update an application from it. The malicious content is served over the network (AV:N), and the attacker needs only control over the repository content (PR:N). Meaningful user interaction is required, since a user/admin must actively configure the remote and initiate an install or update from it (UI:R). Because this is an unconstrained, attacker-controlled write as root, it is treated as equivalent to full system compromise: an attacker can overwrite files such as SSH authorized_keys, systemd units, cron entries, or setuid binaries, yielding full loss of confidentiality, integrity, and availability (C:H/I:H/A:H). Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-22.
High [CVE-2026-94422] message filtering bypass via reply serial allows sandbox escape
message filtering bypass via reply serial allows sandbox escape. Red Hat rates this important (CVSS 8.8). Weakness: CWE-290. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: xdg-dbus-proxy.
High [CVE-2026-86350] HTTP/2 request smuggling due to header mix-up
HTTP/2 request smuggling due to header mix-up. Red Hat rates this important (CVSS 7.2). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat package: tomcat9.
High [CVE-2026-78383] Denial of Service via AJP request
Denial of Service via AJP request. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; and 4 more.
High [CVE-2026-77791] Denial of Service via busy wait during WebSocket close
Denial of Service via busy wait during WebSocket close. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat package: tomcat9.