Skip to content
VulniPulse

Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories

1635 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 619 high, 814 medium, 169 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat RHEL & SELinux advisories

Critical9.6Vendor: HighRed Hat Updated

Critical [CVE-2026-102331] arbitrary code execution via buffer overflow in ANGLE

arbitrary code execution via buffer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-102331
Red Hat Enterprise Linux
Sep 29, 2026
Critical9.6Vendor: MediumRed Hat Updated

Critical [CVE-2026-95331] Out of bounds write in ANGLE

Out of bounds write in ANGLE. Red Hat rates this moderate (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-95331
Red Hat Enterprise Linux
Sep 29, 2026
Critical9.6Vendor: HighRed Hat Updated

Critical [CVE-2026-95284] Buffer overflow in ANGLE

Buffer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-95284
Red Hat Enterprise Linux
Sep 29, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-100811] Sandbox escape via use-after-free in DOM component

Sandbox escape via use-after-free in DOM component. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: firefox.

CVE-2026-100811
Red Hat Enterprise Linux
Sep 29, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-100786] Sandbox escape via use-after-free in Graphics component

Sandbox escape via use-after-free in Graphics component. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: firefox.

CVE-2026-100786
Red Hat Enterprise Linux
Sep 29, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-87648] Arbitrary code execution in Google Chrome due to use-after-free

Arbitrary code execution in Google Chrome due to use-after-free. Red Hat rates this important (CVSS 9). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-87648
Red Hat Enterprise Linux
Sep 9, 2026
Critical9.6Red Hat

Critical [CVE-2026-87500] ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page

ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: webkitgtk4; and 1 more. Affected products named by the advisory: Red Hat package: webkit2gtk3.

CVE-2026-87500
Red Hat Enterprise Linux
Sep 9, 2026
Critical9.6Red Hat

Critical [CVE-2026-87654] Arbitrary code execution via buffer overflow in ANGLE

Arbitrary code execution via buffer overflow in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-87654
Red Hat Enterprise Linux
Sep 9, 2026
Critical9.6Red Hat

Critical [CVE-2026-87621] Google Chrome (ANGLE): Arbitrary Code Execution vulnerability

Google Chrome (ANGLE): Arbitrary Code Execution vulnerability. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-87621
Red Hat Enterprise Linux
Sep 9, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-87604] ANGLE in Google Chrome: Arbitrary code execution via out-of-bounds read

ANGLE in Google Chrome: Arbitrary code execution via out-of-bounds read. Red Hat rates this important (CVSS 9). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-87604
Red Hat Enterprise Linux
Sep 9, 2026
Critical9.6Red Hat

Critical [CVE-2026-87512] Arbitrary code execution via use-after-free vulnerability in ANGLE

Arbitrary code execution via use-after-free vulnerability in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-87512
Red Hat Enterprise Linux
Sep 9, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-42007] Arbitrary Code Execution via Sieve editheader use-after-free

Arbitrary Code Execution via Sieve editheader use-after-free. Red Hat rates this important (CVSS 9.1). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-42007
Red Hat Enterprise Linux
Aug 28, 2026
Critical9.3Red Hat

Critical [CVE-2026-79269] Web origin policy bypass via uninitialized resource in ANGLE

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) A flaw was found in ANGLE, a component of Chromium. This could potentially allow the attacker to bypass the web origin policy, leading to unauthorized access to sensitive information or actions. Red Hat severity: Critical — CVSS 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-824. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-79269
Red Hat Enterprise Linux
Aug 25, 2026
Critical9.6Vendor: MediumRed Hat

Critical [CVE-2026-11861] Obtaining TGS with impersonating cname through trust relationships

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain. This vulnerability is rated as Moderate because practical exploitation is significantly constrained by conditions that are unlikely to be met in most production environments. The attack requires a cross-realm trust to be configured between FreeIPA and Active Directory, the attacker must already hold a valid Active Directory account, and the impersonation technique depends on the ability to register a duplicate or conflicting Service Principal Name (SPN) in the Active Directory forest. Microsoft addressed this prerequisite by enforcing SPN and UPN uniqueness constraints on Windows Server 2012 R2 domain controllers with MSKB-3070083 applied, and by default on Windows 11 version 22H2 and later.

CVE-2026-11861
Red Hat Enterprise Linux
Aug 20, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-73501] ValidationHandler.Load Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler. Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on ValidationHandler as its enforcement middleware. The no-op callback prevents the fail-closed ErrAuthenticationServiceMissing path from being reached and forwards the request to protected handlers that may require an API key, OAuth token, or another security scheme. This issue is fixed in version 0.144.0. This vulnerability allows a remote attacker to bypass authentication checks. Specifically, the system incorrectly handles missing authentication configurations, substituting them with a function that does not verify user credentials. This enables unauthorized access to protected resources that should require proper authentication, compromising the application's security. Red Hat rates this as Important rather than Critical because exploitation requires the target application to explicitly instantiate and load the ValidationHandler middleware instead of ValidateRequest() or the Validator middleware.

CVE-2026-73501
Red Hat Enterprise Linux
Aug 12, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-19173] Sandbox escape via out-of-bounds write in Chromium

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-19173
Red Hat Enterprise Linux
Aug 6, 2026
Critical9.0Vendor: MediumRed Hat

Critical [CVE-2026-17832] Use after free in ANGLE

Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:74084, RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.

CVE-2026-17832
Red Hat Enterprise Linux
Jul 30, 2026
Critical9.6Vendor: MediumRed Hat

Critical [CVE-2026-17801] Out of bounds memory access in ANGLE

Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) An out of bounds memory access flaw was found in the ANGLE component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:74084, RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.

CVE-2026-17801
Red Hat Enterprise Linux
Jul 30, 2026
Critical9.6Vendor: MediumRed Hat

Critical [CVE-2026-17750] Use after free in ANGLE

Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) An use after free flaw was found in the ANGLE component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:74084, RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.

CVE-2026-17750
Red Hat Enterprise Linux
Jul 30, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-17718] Use after free in ANGLE

Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) An use after free flaw was found in the ANGLE component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:74084, RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.

CVE-2026-17718
Red Hat Enterprise Linux
Jul 30, 2026

← All Red Hat advisories