Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories
1225 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 785 high, 384 medium, 25 low.
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux Red Hat Enterprise Linux advisories
High [CVE-2026-56003] computeProps Property Buffer Heap Buffer Overflow
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:47103.
High [CVE-2026-11610] Heap buffer overflow in sasl_io_recv via padded SASL UNBIND
Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:36209 with package redhat-ds:11-8060020260702180044.0ca98e7e, 389-ds:1.4-8060020260626130540.824efc52, redhat-ds:12-9040020260703055735.1674d574, redhat-ds:11-8100020260702145313.37ed7c03. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.
High [CVE-2026-14474] sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation
sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1188. Red Hat lists fixing advisory RHSA-2026:42122 with package sssd-0:2.9.4-5.el8_10.5, sssd-0:2.9.8-4.el9_8.1, sssd-0:2.12.0-3.el10_2.1, sssd-0:2.10.2-3.el10_0.5. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-14476] GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass
GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass. Red Hat rates this moderate (CVSS 8). Weakness: CWE-23. Red Hat lists fixing advisory RHSA-2026:42122 with package sssd-0:2.9.4-5.el8_10.5, sssd-0:2.9.8-4.el9_8.1, sssd-0:2.12.0-3.el10_2.1, sssd-0:2.10.2-3.el10_0.5. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-58384] Gimp: gimp: integer overflow in read_rle_channel
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-33630] Use-after-free / double-free in query-completion handling
Use-after-free / double-free in query-completion handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42096 with package c-ares-0:1.34.6-2.el10_2, c-ares-main-1.34.7-1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-55379] Denial of Service via crafted BDF font file
Denial of Service via crafted BDF font file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:39127 with package python-pillow-0:5.1.1-22.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-55380] Denial of Service via crafted GD 2.x image file
Denial of Service via crafted GD 2.x image file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. Red Hat lists fixing advisory RHSA-2026:39127 with package python-pillow-0:5.1.1-22.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-54060] Denial of Service via excessive memory allocation when processing font files
Denial of Service via excessive memory allocation when processing font files. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:39127 with package python-pillow-0:5.1.1-22.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-54059] Denial of Service via crafted PCF font data
Denial of Service via crafted PCF font data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:39127 with package python-pillow-0:5.1.1-22.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-58380] Gimp: gimp: stack buffer overflow in pnmscanner_gettoken
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.
High [CVE-2026-53359] Fix shadow paging use-after-free due to unexpected role
Fix shadow paging use-after-free due to unexpected role. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:36957 with package rhcos-4.22.9.8.202607152026-0, kernel-0:5.14.0-570.127.1.el9_6, kernel-0:4.18.0-477.154.1.el8_8, kernel-0:5.14.0-427.137.1.el9_4. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-5136] Privilege escalation to administrator-level access via usergroup role assignment manipulation
Privilege escalation to administrator-level access via usergroup role assignment manipulation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:34366 with package foreman-0:3.14.0.17-1.el9sat, foreman-0:3.18.0.7-1.el9sat, foreman-0:3.12.0.17-1.el9sat, foreman-0:3.12.0.17-1.el8sat. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-58050] Heap buffer overflow via integer overflow in publickey attribute allocation
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. A flaw in libssh2 allows a malicious SSH server to trigger a memory overflow by sending a manipulated attribute count. This can cause the connecting client to crash or allow unauthorized code execution. By manipulating the publickey-subsystem response, an attacker could cause an integer overflow, potentially leading to denial of service or arbitrary code execution on Red Hat systems using libssh2 to establish SSH connections. Note: Red Hat Enterprise Linux (RHEL) 8 and newer are not affected by this flaw, as they do not ship the libssh2 package. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Hardened Images. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-57231] Information disclosure via malicious container image environment variables
Information disclosure via malicious container image environment variables. Red Hat rates this important (CVSS 7.5). Weakness: CWE-914. Red Hat lists fixing advisory RHSA-2026:37123 with package podman-7:5.8.2-4.el10_2, podman-6:5.8.2-4.el9_8, podman-main-6.0.0-1.hum1, container-tools:rhel8-8100020260709093628.afee755d. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-48618] Authentication bypass due to TLS hostname handling and unicode dot separator mismatch
Authentication bypass due to TLS hostname handling and unicode dot separator mismatch. Red Hat rates this important (CVSS 7.7). Weakness: CWE-289. Red Hat lists fixing advisory RHSA-2026:39246 with package nodejs20-main-20.20.2-1.hum1, nodejs22-main-22.23.1-1.hum1, nodejs24-main-24.18.0-0.1.hum1, nodejs26-main-26.4.0-1.2.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-48933] Denial of Service via large input to subtle.encrypt
Denial of Service via large input to subtle.encrypt(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:39246 with package nodejs20-main-20.20.2-1.hum1, nodejs22-main-22.23.1-1.hum1, nodejs24-main-24.18.0-0.1.hum1, nodejs26-main-26.4.0-1.2.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-53290] Fix drm_dev_put called before stream disable in close
In the Linux kernel, the following vulnerability has been resolved: drm/xe/eustall: Fix drm_dev_put called before stream disable in close In xe_eu_stall_stream_close(), drm_dev_put() is called before the stream is disabled and its resources are freed. If this drops the last reference, the device structures could be freed while the subsequent cleanup code still accesses them, leading to a use-after-free. Fix this by moving drm_dev_put() after all device accesses are complete. This matches the ordering in xe_oa_release(). (cherry picked from commit 35aff528f7297e949e5e19c9cd7fd748cf1cf21c) This timing issue can lead to a use-after-free condition, where device structures might be accessed after they have been deallocated. A local attacker could potentially exploit this to cause system instability or a denial of service (DoS). Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-55693] Out-of-bounds Write in Spell File Word Count
Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted.spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653. Red Hat severity: Moderate — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H). Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:30267.
High [CVE-2026-53168] reject fuse_notify pagecache ops on directories
In the Linux kernel, the following vulnerability has been resolved: fuse: reject fuse_notify() pagecache ops on directories The operations FUSE_NOTIFY_STORE and FUSE_NOTIFY_RETRIEVE allow the FUSE daemon to actively write/read pagecache contents. For directories with FOPEN_CACHE_DIR, the pagecache is used as kernel-internal cache storage, and userspace is not supposed to have direct access to this cache - in particular, fuse_parse_cache() will hit WARN_ON() if the cache contains bogus data. Reject FUSE_NOTIFY_STORE and FUSE_NOTIFY_RETRIEVE on anything other than regular files with -EINVAL. A flaw was found in the Linux kernel's Filesystem in Userspace (FUSE) component. When these operations are performed on directories configured with `FOPEN_CACHE_DIR`, userspace can improperly access and manipulate kernel-internal cache storage. This could lead to system instability or a denial of service if the cache contains invalid data, potentially triggering a kernel warning. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-266. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.