Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1639 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 34 critical, 620 high, 814 medium, 169 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

High7.3Red Hat

High [CVE-2026-90852] luben zstd-jni: Remote use-after-free vulnerability in dictionary sharing

luben zstd-jni: Remote use-after-free vulnerability in dictionary sharing. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 10 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 6 more.

CVE-2026-90852
Red Hat Enterprise Linux
Sep 15, 2026
High7.8Red Hat

High [CVE-2026-90616] Arbitrary code execution via missing symlink protection

Arbitrary code execution via missing symlink protection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.

CVE-2026-90616
Red Hat Enterprise Linux
Sep 12, 2026
High8.2Red Hat

High [CVE-2026-90560] Denial of Service via out-of-bounds read in ZstdDictDecompress

Denial of Service via out-of-bounds read in ZstdDictDecompress. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 10 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 6 more.

CVE-2026-90560
Red Hat Enterprise Linux
Sep 12, 2026
High7.5Red Hat

High [CVE-2026-68497] com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: CPU Denial of Service via unbounded numeric parsing

com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: CPU Denial of Service via unbounded numeric parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:73521 with package jackson-databind, rh-lightspeed-runtimes/runtimes-agent-init-rhel9:1790202798. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 31 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; and 27 more.

CVE-2026-68497
Red Hat Enterprise Linux
Sep 11, 2026
High7.5Red Hat

High [CVE-2026-87776] Denial of Service via memory leak on premature response close

Denial of Service via memory leak on premature response close. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Red Hat lists fixing advisory RHSA-2026:69289 with package discovery/discovery-ui-rhel9:1789677459, ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Gatekeeper 3; Migration Toolkit for Containers; Node HealthCheck Operator; OpenShift Lightspeed; and 25 more. Affected products named by the advisory: OpenShift Pipelines; Red Hat 3scale API Management Platform 2; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel for Spring Boot 4; and 21 more.

CVE-2026-87776
Red Hat Enterprise Linux
Sep 11, 2026
High7.4Red Hat

High [CVE-2026-89161] Memory corruption vulnerability in pcre2_jit_match

Memory corruption vulnerability in pcre2_jit_match. Red Hat rates this important (CVSS 7.4). Weakness: CWE-1341. Red Hat lists fixing advisory RHSA-2026:67534 with package pcre2-main-10.48-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: bootc; Red Hat package: mariadb10.11; and 3 more.

CVE-2026-89161
Red Hat Enterprise Linux
Sep 11, 2026
High7.1Red Hat

High [CVE-2026-78807] Security bypass via missing PMKSA validation

Security bypass via missing PMKSA validation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-322. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: wpa_supplicant.

CVE-2026-78807
Red Hat Enterprise Linux
Sep 11, 2026
High8.1Red Hat

High [CVE-2026-88031] Data deletion via query-operator injection in GridFS file IDs

Data deletion via query-operator injection in GridFS file IDs. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1287. Red Hat lists fixing advisory RHSA-2026:72849 with package multicluster-engine/maestro-rhel9:1790134239, multicluster-engine/hive-rhel9:1790286311. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Compliance Operator; Confidential Compute Attestation; Cryostat 4; and 38 more. Affected products named by the advisory: ExternalDNS Operator; File Integrity Operator; Lightspeed Core; Logging Subsystem for Red Hat OpenShift; and 34 more.

CVE-2026-88031
Red Hat Enterprise Linux
Sep 10, 2026
High8.2Red Hat

High [CVE-2026-89046] Information disclosure or denial of service via out-of-bounds read

Information disclosure or denial of service via out-of-bounds read. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 11 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 7 more.

CVE-2026-89046
Red Hat Enterprise Linux
Sep 10, 2026
High8.4Red Hat

High [CVE-2026-88053] Heap out-of-bounds write leads to heap corruption via crafted data file

Heap out-of-bounds write leads to heap corruption via crafted data file. Red Hat rates this important (CVSS 8.4). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.

CVE-2026-88053
Red Hat Enterprise Linux
Sep 10, 2026
High7.8Red Hat

High [CVE-2026-88052] Heap out-of-bounds write can lead to arbitrary code execution

Heap out-of-bounds write can lead to arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.

CVE-2026-88052
Red Hat Enterprise Linux
Sep 10, 2026
High7.8Red Hat

High [CVE-2026-88051] Heap out-of-bounds write via crafted.traineddata model

Heap out-of-bounds write via crafted.traineddata model. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.

CVE-2026-88051
Red Hat Enterprise Linux
Sep 10, 2026
High7.8Red Hat

High [CVE-2026-88049] Heap out-of-bounds write allows arbitrary code execution or denial of service

Heap out-of-bounds write allows arbitrary code execution or denial of service. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.

CVE-2026-88049
Red Hat Enterprise Linux
Sep 10, 2026
High7.8Red Hat

High [CVE-2026-88048] Heap out-of-bounds write/read leading to information disclosure via crafted data

Heap out-of-bounds write/read leading to information disclosure via crafted data. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.

CVE-2026-88048
Red Hat Enterprise Linux
Sep 10, 2026
High8.4Red Hat

High [CVE-2026-88047] Stack buffer overflow via crafted.traineddata file

Stack buffer overflow via crafted.traineddata file. Red Hat rates this important (CVSS 8.4). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.

CVE-2026-88047
Red Hat Enterprise Linux
Sep 10, 2026
High7.7Red Hat

High [CVE-2026-87877] Use-After-Free vulnerability allows memory corruption and denial of service

Use-After-Free vulnerability allows memory corruption and denial of service. Red Hat rates this important (CVSS 7.7). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 5 more.

CVE-2026-87877
Red Hat Enterprise Linux
Sep 9, 2026
High7.5Red Hat

High [CVE-2026-87824] Denial of Service (DoS) via out-of-bounds read in Zstd.trainFromBufferDirect

Denial of Service (DoS) via out-of-bounds read in Zstd.trainFromBufferDirect. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 5 more.

CVE-2026-87824
Red Hat Enterprise Linux
Sep 9, 2026
High7.7Red Hat

High [CVE-2026-87825] Data corruption or denial of service via use-after-free vulnerability

Data corruption or denial of service via use-after-free vulnerability. Red Hat rates this important (CVSS 7.7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 5 more.

CVE-2026-87825
Red Hat Enterprise Linux
Sep 9, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-87853] IdP authentication prefix comparison allows cross-user impersonation

IdP authentication prefix comparison allows cross-user impersonation. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-187. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: sssd.

CVE-2026-87853
Red Hat Enterprise Linux
Sep 9, 2026
High8.2Red Hat

High [CVE-2026-87795] Out-of-bounds read in ZstdDictCompress constructor leads to denial of service

Out-of-bounds read in ZstdDictCompress constructor leads to denial of service. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 5 more.

CVE-2026-87795
Red Hat Enterprise Linux
Sep 9, 2026

← All Red Hat advisories