Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1637 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 33 critical, 619 high, 814 medium, 169 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
High [CVE-2026-89059] IIOImageProvider Unbounded Image Decode (Decompression-Bomb DoS)
IIOImageProvider Unbounded Image Decode (Decompression-Bomb DoS). Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; and 15 more. Affected products named by the advisory: Red Hat build of Quarkus; Red Hat Certificate System 10; Red Hat Certificate System 11; Red Hat Enterprise Linux 10; and 11 more.
High [CVE-2026-86320] Flatpak-builder: host code execution via `git am` hook execution in patch source extraction (`use-git-am`)
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder. Red Hat Product Security has rated this flaw as having an Important security impact. Exploitation requires the target build process to process an attacker-controlled or otherwise untrusted source using this option. In typical interactive builds, user interaction is required to initiate the build, while automated build services that process untrusted manifests may be exposed without additional user interaction. Successful exploitation provides code execution with the privileges of the flatpak-builder process and may allow access to or modification of data available to that process. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-94. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: flatpak-builder.
High [CVE-2026-92599] Denial of Service via `isoDate` validation regular expression
Denial of Service via `isoDate` validation regular expression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:68778 with package grafana13-2-main-13.2.1-0.5.hum1, grafana13-1-main-13.1.6-0.2.hum1, grafana12-4-main-12.4.10-0.6.hum1. Affected products named by the advisory: Red Hat Hardened Images; Gatekeeper 3; Migration Toolkit for Containers; Red Hat Data Grid 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 1 more.
High [CVE-2026-91106] heap-based buffer overflow can lead to remote code execution
heap-based buffer overflow can lead to remote code execution. Red Hat rates this important (CVSS 8.4). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
High [CVE-2026-91105] Remote code execution and privilege escalation vulnerabilities
Remote code execution and privilege escalation vulnerabilities. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
High [CVE-2026-91102] Multiple vulnerabilities could lead to remote code execution
Multiple vulnerabilities could lead to remote code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-494. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
High [CVE-2026-91098] Multiple vulnerabilities allow remote code execution and privilege escalation
Multiple vulnerabilities allow remote code execution and privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-494. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
High [CVE-2026-91097] Multiple vulnerabilities enable remote code execution and privilege escalation
Multiple vulnerabilities enable remote code execution and privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
High [CVE-2026-42784] Cryptographic integrity compromise via key flag confusion
Cryptographic integrity compromise via key flag confusion. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:42902 with package rust-podman-sequoia-main-0.3.2-4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Confidential Compute Attestation; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat Satellite 6; Red Hat Trusted Profile Analyzer; and 4 more.
High [CVE-2026-63127] Token impersonation via missing OAuth resource field validation
Token impersonation via missing OAuth resource field validation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-289. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: goose.
High [CVE-2026-63128] Denial of Service via unauthenticated session table leak
Denial of Service via unauthenticated session table leak. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: goose.
High [CVE-2026-92000] Denial of Service via crafted ZIP archives with zero declared uncompressed size
Denial of Service via crafted ZIP archives with zero declared uncompressed size. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:74609 with package cluster-observability-operator/monitoring-console-plugin-rhel9:1790854525, cluster-observability-operator/distributed-tracing-console-plugin-rhel9:1790854443, cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1790854528, cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1790854526. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 5 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Self-service automation portal 2; Red Hat package: mozjs60; and 1 more.
High [CVE-2026-19774] Arbitrary Code Execution via A2DP Stack-based Buffer Overflow
Arbitrary Code Execution via A2DP Stack-based Buffer Overflow. Red Hat rates this important (CVSS 8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: bluez.
High [CVE-2026-85234] Denial of Service due to out-of-bounds read/write in remap engine
Denial of Service due to out-of-bounds read/write in remap engine. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: tftp.
High [CVE-2026-91990] Denial of Service via memory amplification in multipart parsing
Denial of Service via memory amplification in multipart parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 9 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 5 more.
High [CVE-2026-91955] Denial of Service via crafted desktop dimensions
Denial of Service via crafted desktop dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-369. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
High [CVE-2026-91948] Arbitrary code execution via oversized channel messages in SHOW_PROTOCOL
Arbitrary code execution via oversized channel messages in SHOW_PROTOCOL. Red Hat rates this important (CVSS 7.5). Weakness: CWE-124. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
High [CVE-2024-14029] Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding
Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-444. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat package: python-tornado.
High [CVE-2023-54397] Tornado before 6.3.3 HTTP Request Smuggling via Content-Length
Tornado before 6.3.3 HTTP Request Smuggling via Content-Length. Red Hat rates this critical (CVSS 7.5). Weakness: CWE-444. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat package: python-tornado.
High [CVE-2026-85013] Command injection in environment-modules Bash completion via malicious module names containing shell metacharacters
Command injection in environment-modules Bash completion via malicious module names containing shell metacharacters. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:64766 with package environment-modules-main-5.6.2-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: environment-modules.