Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1638 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 34 critical, 619 high, 814 medium, 169 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
Medium [CVE-2026-86248] OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:68257 with package tomcat11-main-11.0.26-0.1.hum1, tomcat10-main-10.1.60-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: tomcat9.
Medium [CVE-2026-79616] Denial of Service due to out-of-bounds read in SVG path parsing.
Denial of Service due to out-of-bounds read in SVG path parsing. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: qt6-qtdeclarative; Red Hat package: qt5-qtdeclarative.
Medium [CVE-2026-90462] Fail-open in LDAP ppolicy access check allows continued authorization
Fail-open in LDAP ppolicy access check allows continued authorization. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-280. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: sssd.
Medium [CVE-2026-89407] Denial of Service via regular expression backtracking
Denial of Service via regular expression backtracking. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-1333. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 32 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 28 more.
Medium [CVE-2026-88340] Memory corruption and denial of service via specially crafted rule files
Memory corruption and denial of service via specially crafted rule files. Red Hat rates this moderate (CVSS 5). Weakness: CWE-763. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: yara.
Medium [CVE-2026-88341] Denial of Service via crafted compiled rule file
Denial of Service via crafted compiled rule file. Red Hat rates this moderate (CVSS 5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: yara.
Medium [CVE-2026-93433] Denial of Service via stack buffer overflow in SCSI VPD page parsing
Denial of Service via stack buffer overflow in SCSI VPD page parsing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: libstoragemgmt.
Medium [CVE-2026-93981] Cross-Site Scripting via Unescaped Strings
Cross-Site Scripting via Unescaped Strings. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:71906 with package grafana13-1-main-13.1.6-0.6.hum1, grafana12-4-main-12.4.10-0.10.hum1, grafana13-2-main-13.2.1-0.7.hum1, grafana13-1-main-13.1.6-0.5.hum1. Affected products named by the advisory: Red Hat Hardened Images; Migration Toolkit for Applications 8; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; and 3 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces; Red Hat package: grafana.
Medium [CVE-2026-91202] Arbitrary file ownership change via symlink following in privileged paste
Arbitrary file ownership change via symlink following in privileged paste. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-61. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: cockpit-files.
Medium [CVE-2026-91203] Arbitrary file ownership and permission modification via symlink race condition
Arbitrary file ownership and permission modification via symlink race condition. Red Hat rates this moderate (CVSS 6). Weakness: CWE-363. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: cockpit-files.
Medium [CVE-2026-91205] Local attacker can hijack file ownership via symlink race
Local attacker can hijack file ownership via symlink race. Red Hat rates this moderate (CVSS 6). Weakness: CWE-363. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: cockpit-files.
Medium [CVE-2026-92768] Sensitive data exposure via command-line arguments
Sensitive data exposure via command-line arguments. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-214. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: cockpit-machines.
Medium [CVE-2026-92747] Sensitive Data Exposure of guest credentials via JSON argument in process list
Sensitive Data Exposure of guest credentials via JSON argument in process list. Red Hat rates this moderate (CVSS 5). Weakness: CWE-214. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: cockpit-machines.
Medium [CVE-2026-92745] Information Disclosure of RHSM Offline Token via Process Arguments
Information Disclosure of RHSM Offline Token via Process Arguments. Red Hat rates this moderate (CVSS 5). Weakness: CWE-214. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: cockpit-machines.
Medium [CVE-2026-91147] Denial of Service in `cockpit-ws` due to URL-root handling without a trailing slash
Denial of Service in `cockpit-ws` due to URL-root handling without a trailing slash. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Dev Spaces; Red Hat package: cockpit.
Medium [CVE-2026-77301] Denial of Service via uncontrolled memory allocation
Denial of Service via uncontrolled memory allocation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Developer Hub; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Self-service automation portal 2; and 2 more.
Medium [CVE-2026-93653] unbounded CPU loop in SplashOutputDev::tilingPatternFill via unvalidated tiling-pattern repeat count (denial of service)
unbounded CPU loop in SplashOutputDev::tilingPatternFill via unvalidated tiling-pattern repeat count (denial of service). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: poppler; Red Hat package: compat-poppler022.
Medium [CVE-2026-93602] Certificate Revocation Check Bypass via Faulty CRL Logic
Certificate Revocation Check Bypass via Faulty CRL Logic. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-295. Affected products named by the advisory: Ansible Automation Orchestrator 2026; Confidential Cluster Operator; Confidential Compute Attestation; Logging Subsystem for Red Hat OpenShift; and 32 more. Affected products named by the advisory: Migration Toolkit for Applications 8; OpenShift Lightspeed; OpenShift Service Mesh 3; Pen Drive Powered by Red Hat Lightspeed; and 28 more.
Medium [CVE-2026-93589] Denial of Service via division by zero in FLIF encoder
Denial of Service via division by zero in FLIF encoder. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-369. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: imagemagick.
Medium [CVE-2026-93387] Cross-origin data disclosure via improper state validation
Cross-origin data disclosure via improper state validation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-346. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.