Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1641 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 621 high, 814 medium, 169 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

Medium5.3Red Hat

Medium [CVE-2026-85501] Denial of Service via algorithmic complexity attacks on DNSSEC

Denial of Service via algorithmic complexity attacks on DNSSEC. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:68590 with package unbound-main-1.26.1-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: unbound.

CVE-2026-85501
Red Hat Enterprise Linux
Sep 16, 2026
Medium5.9Red Hat

Medium [CVE-2026-82720] Denial of Service via use-after-free in DoH stream cleanup

Denial of Service via use-after-free in DoH stream cleanup. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:68590 with package unbound-main-1.26.1-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: unbound.

CVE-2026-82720
Red Hat Enterprise Linux
Sep 16, 2026
Medium5.3Red Hat

Medium [CVE-2026-80225] Denial of Service via continuous queries on TCP/DoT connection

Denial of Service via continuous queries on TCP/DoT connection. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:68590 with package unbound-main-1.26.1-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: unbound.

CVE-2026-80225
Red Hat Enterprise Linux
Sep 16, 2026
Medium4.4Red Hat

Medium [CVE-2026-77955] ZONEMD verification bypass due to asynchronous DNSSEC resolution

ZONEMD verification bypass due to asynchronous DNSSEC resolution. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-345. Red Hat lists fixing advisory RHSA-2026:68590 with package unbound-main-1.26.1-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: unbound.

CVE-2026-77955
Red Hat Enterprise Linux
Sep 16, 2026
Medium5.9Red Hat

Medium [CVE-2026-92091] denial of service via O(n^2) duplicate check on unbounded JWK key_ops array

denial of service via O(n^2) duplicate check on unbounded JWK key_ops array. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-407. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more.

CVE-2026-92091
Red Hat Enterprise Linux
Sep 16, 2026
Medium6.5Red Hat

Medium [CVE-2026-19248] Denial of Service vulnerability in XML parsing

Denial of Service vulnerability in XML parsing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59393 with package qt6-qtbase-main-6.11.2-2.hum1, qt5-qtbase-main-5.15.18-5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: qt6-qtbase; Red Hat package: qt5-qtbase.

CVE-2026-19248
Red Hat Enterprise Linux
Sep 16, 2026
Medium5.5Red Hat

Medium [CVE-2025-11395] Podman: arbitrary file write when importing oci archive

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman. This flaw in Podman allows an attacker to achieve arbitrary file write on the host system. Exploitation requires the attacker to supply a specially crafted OCI archive to the `podman load` command, which then executes with the privileges of the user invoking Podman. This risk is primarily relevant in environments where untrusted OCI archives are routinely processed by Podman users. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L). Weakness: CWE-277. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: buildah; Red Hat package: podman; Red Hat package: skopeo.

CVE-2025-11395
Red Hat Enterprise Linux
Sep 15, 2026
Medium5.9Red Hat

Medium [CVE-2026-91992] Credential leak via HTTP client handle reuse

Credential leak via HTTP client handle reuse. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-524. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 11 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more.

CVE-2026-91992
Red Hat Enterprise Linux
Sep 15, 2026
Medium5.4Red Hat

Medium [CVE-2026-91986] Information disclosure and virtual host spoofing via control character injection

Information disclosure and virtual host spoofing via control character injection. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 2 more. Affected products named by the advisory: Red Hat package: igvm; Red Hat package: rust.

CVE-2026-91986
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.3Red Hat

Medium [CVE-2026-91962] Remote out-of-bounds access via integer overflow in audin Apple backends

Remote out-of-bounds access via integer overflow in audin Apple backends. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-91962
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91961] Denial of Service via URBDRC control-transfer request with invalid OutputBufferSize

Denial of Service via URBDRC control-transfer request with invalid OutputBufferSize. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-91961
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.6Red Hat

Medium [CVE-2026-91958] Denial of service and potential code execution via malicious RDP file

Denial of service and potential code execution via malicious RDP file. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.

CVE-2026-91958
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91952] Denial of Service via crafted AVC444 graphics updates

Denial of Service via crafted AVC444 graphics updates. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-91952
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91951] Denial of Service via out-of-bounds write in urbdrc client channel

Denial of Service via out-of-bounds write in urbdrc client channel. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.

CVE-2026-91951
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91945] Denial of Service due to out-of-bounds read in smartcard response processing

Denial of Service due to out-of-bounds read in smartcard response processing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.

CVE-2026-91945
Red Hat Enterprise Linux
Sep 15, 2026
Medium5.4Red Hat

Medium [CVE-2024-58384] CRLF injection in CurlAsyncHTTPClient allows arbitrary header injection or new HTTP requests.

CRLF injection in CurlAsyncHTTPClient allows arbitrary header injection or new HTTP requests. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-93. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 11 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more.

CVE-2024-58384
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.1Red Hat

Medium [CVE-2026-91786] out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size

out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gnome-shell.

CVE-2026-91786
Red Hat Enterprise Linux
Sep 15, 2026
Medium4.8Red Hat

Medium [CVE-2026-86472] Security bypass due to inconsistent host case normalization

Security bypass due to inconsistent host case normalization. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-178. Red Hat lists fixing advisory RHSA-2026:71040 with package grafana12-4-main-12.4.10-0.4.hum1, grafana13-2-main-13.2.1-0.7.hum1, grafana13-1-main-13.1.6-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cost Management On Premise; Migration Toolkit for Applications 8; Migration Toolkit for Containers; and 32 more. Affected products named by the advisory: Multicluster Engine for Kubernetes; Network Observability Operator; OpenShift Lightspeed; OpenShift Pipelines; and 28 more.

CVE-2026-86472
Red Hat Enterprise Linux
Sep 15, 2026
Medium5.9Red Hat

Medium [CVE-2026-17495] Path Traversal via crafted non-string input to locale function

Path Traversal via crafted non-string input to locale function. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22. Affected products named by the advisory: Multicluster Engine for Kubernetes; OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat 3scale API Management Platform 2; and 31 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel for Spring Boot 4; and 27 more.

CVE-2026-17495
Red Hat Enterprise Linux
Sep 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-53495] Denial of Service via CRI ExecSync goroutine leak

Denial of Service via CRI ExecSync goroutine leak. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; AWS Load Balancer Operator; Compliance Operator; Confidential Compute Attestation; and 42 more. Affected products named by the advisory: Custom Metric Autoscaler operator for Red Hat Openshift; Deployment Validation Operator; Gatekeeper 3; Logging Subsystem for Red Hat OpenShift; and 38 more.

CVE-2026-53495
Red Hat Enterprise Linux
Sep 14, 2026

← All Red Hat advisories