Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1639 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 34 critical, 620 high, 814 medium, 169 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
High [CVE-2026-90852] luben zstd-jni: Remote use-after-free vulnerability in dictionary sharing
luben zstd-jni: Remote use-after-free vulnerability in dictionary sharing. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 10 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 6 more.
High [CVE-2026-90616] Arbitrary code execution via missing symlink protection
Arbitrary code execution via missing symlink protection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.
High [CVE-2026-90560] Denial of Service via out-of-bounds read in ZstdDictDecompress
Denial of Service via out-of-bounds read in ZstdDictDecompress. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 10 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 6 more.
High [CVE-2026-68497] com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: CPU Denial of Service via unbounded numeric parsing
com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: CPU Denial of Service via unbounded numeric parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:73521 with package jackson-databind, rh-lightspeed-runtimes/runtimes-agent-init-rhel9:1790202798. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 31 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; and 27 more.
High [CVE-2026-87776] Denial of Service via memory leak on premature response close
Denial of Service via memory leak on premature response close. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Red Hat lists fixing advisory RHSA-2026:69289 with package discovery/discovery-ui-rhel9:1789677459, ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Gatekeeper 3; Migration Toolkit for Containers; Node HealthCheck Operator; OpenShift Lightspeed; and 25 more. Affected products named by the advisory: OpenShift Pipelines; Red Hat 3scale API Management Platform 2; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel for Spring Boot 4; and 21 more.
High [CVE-2026-89161] Memory corruption vulnerability in pcre2_jit_match
Memory corruption vulnerability in pcre2_jit_match. Red Hat rates this important (CVSS 7.4). Weakness: CWE-1341. Red Hat lists fixing advisory RHSA-2026:67534 with package pcre2-main-10.48-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: bootc; Red Hat package: mariadb10.11; and 3 more.
High [CVE-2026-78807] Security bypass via missing PMKSA validation
Security bypass via missing PMKSA validation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-322. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: wpa_supplicant.
High [CVE-2026-88031] Data deletion via query-operator injection in GridFS file IDs
Data deletion via query-operator injection in GridFS file IDs. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1287. Red Hat lists fixing advisory RHSA-2026:72849 with package multicluster-engine/maestro-rhel9:1790134239, multicluster-engine/hive-rhel9:1790286311. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Compliance Operator; Confidential Compute Attestation; Cryostat 4; and 38 more. Affected products named by the advisory: ExternalDNS Operator; File Integrity Operator; Lightspeed Core; Logging Subsystem for Red Hat OpenShift; and 34 more.
High [CVE-2026-89046] Information disclosure or denial of service via out-of-bounds read
Information disclosure or denial of service via out-of-bounds read. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 11 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 7 more.
High [CVE-2026-88053] Heap out-of-bounds write leads to heap corruption via crafted data file
Heap out-of-bounds write leads to heap corruption via crafted data file. Red Hat rates this important (CVSS 8.4). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-88052] Heap out-of-bounds write can lead to arbitrary code execution
Heap out-of-bounds write can lead to arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-88051] Heap out-of-bounds write via crafted.traineddata model
Heap out-of-bounds write via crafted.traineddata model. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-88049] Heap out-of-bounds write allows arbitrary code execution or denial of service
Heap out-of-bounds write allows arbitrary code execution or denial of service. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-88048] Heap out-of-bounds write/read leading to information disclosure via crafted data
Heap out-of-bounds write/read leading to information disclosure via crafted data. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-88047] Stack buffer overflow via crafted.traineddata file
Stack buffer overflow via crafted.traineddata file. Red Hat rates this important (CVSS 8.4). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-87877] Use-After-Free vulnerability allows memory corruption and denial of service
Use-After-Free vulnerability allows memory corruption and denial of service. Red Hat rates this important (CVSS 7.7). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 5 more.
High [CVE-2026-87824] Denial of Service (DoS) via out-of-bounds read in Zstd.trainFromBufferDirect
Denial of Service (DoS) via out-of-bounds read in Zstd.trainFromBufferDirect. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 5 more.
High [CVE-2026-87825] Data corruption or denial of service via use-after-free vulnerability
Data corruption or denial of service via use-after-free vulnerability. Red Hat rates this important (CVSS 7.7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 5 more.
High [CVE-2026-87853] IdP authentication prefix comparison allows cross-user impersonation
IdP authentication prefix comparison allows cross-user impersonation. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-187. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: sssd.
High [CVE-2026-87795] Out-of-bounds read in ZstdDictCompress constructor leads to denial of service
Out-of-bounds read in ZstdDictCompress constructor leads to denial of service. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 5 more.