Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1635 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 619 high, 814 medium, 169 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-102010] Denial of Service via use-after-free in binary heap erase_if

Denial of Service via use-after-free in binary heap erase_if. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:74569 with package gcc-main-16.2.1-3.hum1, gcc13-main-13.5.0-0.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 13 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: gcc-toolset-15-gcc; and 9 more.

CVE-2026-102010
Red Hat Enterprise Linux
Sep 28, 2026
High7.1Red Hat Updated

High [CVE-2026-97023] CVE-2026-97023

CVE-2026-97023. Red Hat rates this important (CVSS 7.1). Weakness: CWE-61. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.

CVE-2026-97023
Red Hat Enterprise Linux
Sep 28, 2026
High7.5Red Hat Updated

High [CVE-2026-85644] Denial of Service via improper array reference validation

Denial of Service via improper array reference validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: perl-xs-parse-keyword.

CVE-2026-85644
Red Hat Enterprise Linux
Sep 28, 2026
High7.5Red Hat Updated

High [CVE-2026-88815] Denial of Service via invalid memory read during numeric type casting

Denial of Service via invalid memory read during numeric type casting. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: perl-dbi.

CVE-2026-88815
Red Hat Enterprise Linux
Sep 28, 2026
High7.1Red Hat Updated

High [CVE-2026-94286] Denial of Service via out-of-bounds read in RECORD reply parser

Denial of Service via out-of-bounds read in RECORD reply parser. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: libxtst.

CVE-2026-94286
Red Hat Enterprise Linux
Sep 28, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-96280] Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems

The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems. Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H. The malicious stream is served over the network (AV:N), and the attacker needs only control over the OCI registry content (PR:N). This overflow only manifests on 32-bit targets — on 64-bit systems gsize and guint64 are the same width and truncation does not occur, so exploitability depends on a target configuration outside the attacker's control (AC:H). Meaningful user interaction is required (UI:R). The vulnerable and impacted components remain within the same flatpak client/helper security authority (S:U). Because this is a heap buffer overflow with a stated path to code execution in the Flatpak client process, a successful exploit is treated as a full compromise of that process's privileges (C:H/I:H/A:H). Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-197.

CVE-2026-96280
Red Hat Enterprise Linux
Sep 27, 2026
High7.5Red Hat

High [CVE-2026-100700] Denial of Service via regular expression backtracking in addressparser

Denial of Service via regular expression backtracking in addressparser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Self-service automation portal 2; Red Hat package: grafana.

CVE-2026-100700
Red Hat Enterprise Linux
Sep 26, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-100419] Arbitrary code execution via symlink manipulation during checkout

Arbitrary code execution via symlink manipulation during checkout. Red Hat rates this moderate (CVSS 7). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: igvm; and 1 more. Affected products named by the advisory: Red Hat package: rust.

CVE-2026-100419
Red Hat Enterprise Linux
Sep 25, 2026
High7.5Red Hat

High [CVE-2026-91765] Denial of Service via unbounded recursion in SOAP parser

Denial of Service via unbounded recursion in SOAP parser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-674. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.

CVE-2026-91765
Red Hat Enterprise Linux
Sep 25, 2026
High8.8Red Hat

High [CVE-2026-93834] use-after-free race in Tlcreate/Twalk allows VM guest escape

use-after-free race in Tlcreate/Twalk allows VM guest escape. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: qemu-kvm.

CVE-2026-93834
Red Hat Enterprise Linux
Sep 25, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-95521] shell command injection via macro expansion of source/spec file basenames when installing a source RPM

shell command injection via macro expansion of source/spec file basenames when installing a source RPM. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: rpm.

CVE-2026-95521
Red Hat Enterprise Linux
Sep 24, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-95519] Code Execution via Macro Expansion of Manifest Entries in `rpmgi` (`-q -p` / verify manifest flows)

Code Execution via Macro Expansion of Manifest Entries in `rpmgi` (`-q -p` / verify manifest flows). Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: rpm.

CVE-2026-95519
Red Hat Enterprise Linux
Sep 24, 2026
High7.8Red Hat

High [CVE-2026-96889] Use-after-free when XML includes have duplicated entities

Use-after-free when XML includes have duplicated entities. Red Hat rates this important (CVSS 7.8). Weakness: CWE-416. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: glycin-loaders; Red Hat package: librsvg2.

CVE-2026-96889
Red Hat Enterprise Linux
Sep 23, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-96541] Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline

A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is closed. By holding open unauthenticated RDP sockets indefinitely, an attacker can exhaust the default global connection limit. Exploitation requires connecting from at least two distinct source IP addresses to fully utilize the default per-source and global connection limits. Existing authenticated RDP sessions remain unaffected. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-400. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gnome-remote-desktop.

CVE-2026-96541
Red Hat Enterprise Linux
Sep 23, 2026
High7.8Red Hat

High [CVE-2026-96808] Local privilege escalation via symlink traversal in revokefs writer

Local privilege escalation via symlink traversal in revokefs writer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.

CVE-2026-96808
Red Hat Enterprise Linux
Sep 23, 2026
High8.8Red Hat

High [CVE-2026-96275] Flatpak: flatpak: arbitrary write access as root via extra-data extraction

A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal. Red Hat estimates the CVSSv3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Exploitation requires a user or administrator to add or trust a malicious or compromised Flatpak repository and then install or update an application from it. The malicious content is served over the network (AV:N), and the attacker needs only control over the repository content (PR:N). Meaningful user interaction is required, since a user/admin must actively configure the remote and initiate an install or update from it (UI:R). Because this is an unconstrained, attacker-controlled write as root, it is treated as equivalent to full system compromise: an attacker can overwrite files such as SSH authorized_keys, systemd units, cron entries, or setuid binaries, yielding full loss of confidentiality, integrity, and availability (C:H/I:H/A:H). Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-22.

CVE-2026-96275
Red Hat Enterprise Linux
Sep 23, 2026
High8.8Red Hat Updated

High [CVE-2026-94422] message filtering bypass via reply serial allows sandbox escape

message filtering bypass via reply serial allows sandbox escape. Red Hat rates this important (CVSS 8.8). Weakness: CWE-290. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: xdg-dbus-proxy.

CVE-2026-94422
Red Hat Enterprise Linux
Sep 23, 2026
High7.2Red Hat

High [CVE-2026-86350] HTTP/2 request smuggling due to header mix-up

HTTP/2 request smuggling due to header mix-up. Red Hat rates this important (CVSS 7.2). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat package: tomcat9.

CVE-2026-86350
Red Hat Enterprise Linux
Sep 23, 2026
High7.5Red Hat

High [CVE-2026-78383] Denial of Service via AJP request

Denial of Service via AJP request. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; and 4 more.

CVE-2026-78383
Red Hat Enterprise Linux
Sep 23, 2026
High7.5Red Hat

High [CVE-2026-77791] Denial of Service via busy wait during WebSocket close

Denial of Service via busy wait during WebSocket close. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat package: tomcat9.

CVE-2026-77791
Red Hat Enterprise Linux
Sep 23, 2026

← All Red Hat advisories