Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5821 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.5Red Hat

Medium [CVE-2026-74658] Prevent robust futex exit race some more

In the Linux kernel, the following vulnerability has been resolved: futex: Prevent robust futex exit race some more A robust futex unlock stores 0 over the whole futex value - wiping FUTEX_WAITERS - and wakes a single waiter. That wakeup is a one-shot notification: the protocol relies on its recipient to either acquire the futex (and eventually unlock while aware of the remaining contention) or re-arm FUTEX_WAITERS before sleeping again. If the woken waiter is killed before it can do either, the kernel must jump in and wake the next task down the line. This is a known complication of the futex protocol with a previous partial fix in commit ca16d5bee598 ("futex: Prevent robust futex exit race"). Unfortunately, that fix is insufficient. If a third task re-acquired the futex through the uncontended fast path in the meantime, the notification is lost: robust exit processing sees that it is owned by another task and does nothing, while the new owner sees no FUTEX_WAITERS when it unlocks and wakes nobody. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74658
Linux Kernel
Aug 22, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-74636] Fix race between update_event_fields and, event_define_fields

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix race between update_event_fields and, event_define_fields The following sequence may leads race between event_define_fields() and update_event_fields(): CPU0 (loads module A) CPU1 (loads module B) =============================== =============================== load_module(A) load_module(B) notifier_call_chain notifier_call_chain trace_module_notify trace_module_notify mutex_lock(&event_mutex) trace_event_update_all() trace_module_add_events(A) down_write(&trace_event_sem) __register_event(call_A) __add_event_to_tracers(call_A) event_define_fields(call_A) for each f: list_for_each_entry(field, list_add(&f->link, &class->fields, link) &class->fields) field = class->fields->next; Where access to the class->fields is not protected by the event_mutex in trace_event_update_all(). This produces the following panic: Unable to handle kernel access... at virtual address 0000000000000018 pc: update_event_fields+0xf8/0x368 Call trace: update_event_fields+0xf8/0x368 trace_event_update_all+0x7c/0x2b4 trace_module_notify+0x4c/0x1dc notifier_call_chain+0x84/0x168 blocking_notifier_call_chain_robust+0x64/0xd4 load_module+0x10c8/0x123c __arm64_sys_finit_module+0x230/0x31c Fix by taking event_mutex in trace_event_update_all() before trace_event_sem.

CVE-2026-74636
Linux Kernel
Aug 22, 2026
Medium5.5Red Hat

Medium [CVE-2026-74627] prevent net-iov / page mixing

In the Linux kernel, the following vulnerability has been resolved: net: devmem: prevent net-iov / page mixing We should either have net_iov or page backed frags in a single skb, otherwise it blows up down the stack. Don't allow mixing in zerocopy_fill_skb_from_devmem(). This vulnerability occurs when `net_iov` and page-backed fragments are improperly mixed within a single `skb` (socket buffer) in the `zerocopy_fill_skb_from_devmem()` function. This improper handling can lead to a system crash, resulting in a Denial of Service (DoS). Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-843. Affected Red Hat products: Red Hat Enterprise Linux 6. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel.

CVE-2026-74627
Linux Kernel
Aug 22, 2026
Medium5.5Red Hat

Medium [CVE-2026-74687] prevent timer rearm during teardown

In the Linux kernel, the following vulnerability has been resolved: watchdog: at91sam9_wdt: prevent timer rearm during teardown at91_ping() rearms the watchdog timer from its callback. timer_delete() neither waits for a running callback nor prevents it from rearming the timer, so probe failure or driver removal can leave the timer accessing the devm-allocated at91wdt after it has been freed. Use timer_shutdown_sync() on both teardown paths. However, the `timer_delete()` function does not prevent this, resulting in a use-after-free vulnerability where the timer attempts to access memory that has already been released. This flaw could be triggered by a local attacker or specific system conditions, potentially leading to system instability or a denial of service. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-825. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-74687
Unclassified
Aug 22, 2026
Medium5.3Red Hat

Medium [CVE-2026-76905] Denial of Service via malformed multipart/form-data body

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A malformed non-string scalar field in a multipart/form-data request body produces a nested ParseError with a nil RequestError. Parameter, and applications that render the validation error through openapi3filter. ConvertErrors or ValidationErrorEncoder panic. An unauthenticated client can repeatedly send such requests to deny service when the application lacks a recovery boundary. JSON request bodies and applications that do not use these error-rendering helpers are not affected. This issue is fixed in version 0.141.0. This can cause applications that render validation errors through specific error-rendering helpers to panic, leading to a Denial of Service (DoS). Red Hat scores A:L because the panic occurs inside an HTTP handler goroutine where Go's net/http automatically recovers it. Only the individual request fails; the server continues serving. The CNA scores A:H based on the theoretical case of no recovery boundary. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-476.

CVE-2026-76905
Unclassified
Aug 21, 2026
Medium6.3Red Hat

Medium [CVE-2026-44517] Build breakout via malicious Git repository or tar archive

Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/types.go does not securely confine Git repository subdirectories to the downloaded build context, and download ToDirectory and stdinToDirectory can follow a Dockerfile symlink left by a partially extracted tar archive. A malicious server supplying a Git repository or tar archive can cause files outside the build context directory to be included in the context or copied into the build. This issue is fixed in versions 1.43.2 and 1.44.0. A flaw was found in Buildah. This could lead to a build breakout, enabling an attacker to manipulate files on the host system. Red Hat ships Buildah as a standalone package and as a bundled dependency in Podman across RHEL, OpenShift, and RHIVOS. Versions of Buildah from 1.38.1 through 1.43.1 are affected. Red Hat severity: Moderate — CVSS 6.3 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N). Weakness: CWE-22. Affected Red Hat products: Red Hat Certification Program for Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat OpenStack Platform 18.0; Red Hat Quay 3. Red Hat lists Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4 as not affected.

CVE-2026-44517
Red Hat Enterprise Linux
Aug 21, 2026
Medium5.9Red Hat

Medium [CVE-2026-59296] Line-protocol and log injection via unsanitized input allows metric and log spoofing

Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform. When such unsafe instrumentation is used, the application becomes vulnerable to injection and spoofing attacks because micrometer-registry-statsd and micrometer-core do not sanitize newline characters (\n, \r) by default prior to this fix. * For the StatsD registry in micrometer-registry-statsd (when using the Datadog or Etsy flavor), because the StatsD protocol is newline-delimited, this allows for line-protocol injection (cross-metric spoofing). * For LoggingMeterRegistry in micrometer-core, because metric output is printed line-by-line to log files, this allows for both metric spoofing (if downstream log-metrics scrapers or parsers ingest the log lines as separate metrics) and general log spoofing. Specifically, an application is vulnerable when all the following are true: * The application uses a vulnerable version of io.micrometer:micrometer-registry-statsd or io.micrometer:micrometer-core. * The application uses the Datadog or Etsy flavor of the StatsD registry, or uses LoggingMeterRegistry. * The application instruments meters using user-controlled, unvalidated input for metric names, tag keys, or tag values.

CVE-2026-59296
Unclassified
Aug 21, 2026
Medium5.8Red Hat

Medium [CVE-2026-74866] @fastify/busboy: @fastify/busboy: CRLF injection via multipart Content-Disposition filename and name

@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-return line-feed sequence, so a lone carriage return or line feed embedded in a part header is not treated as a line break and is carried verbatim into the parsed Content-Disposition filename and field name handed to the application. An attacker who uploads a file whose filename or field name contains a bare carriage return or line feed can inject control characters into consumers that trust the parser to return clean values, enabling filesystem filename pollution, log forging, or header injection when the value is forwarded to a carriage-return-sensitive sink. All versions of @fastify/busboy up to and including 3.2.1 are affected. Users should upgrade to 3.2.2, and consumers such as @fastify/multipart should bump their @fastify/busboy dependency to pull in the fix. A remote attacker could exploit this by uploading a file with a specially crafted filename or field name, leading to control character injection. An attacker can inject CRLF characters into multipart form data, which may be passed through to downstream HTTP responses or headers if the application reflects the parsed filename or name values without additional sanitization, potentially enabling HTTP response splitting or header injection.

CVE-2026-74866
Unclassified
Aug 21, 2026
Medium5.5Red Hat

Medium [CVE-2026-77679] path traversal in WebExtension XPI extraction (ZIP slip)

path traversal in WebExtension XPI extraction (ZIP slip). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-22.

CVE-2026-77679
Unclassified
Aug 21, 2026
Medium5.5Red Hat

Medium [CVE-2026-55894] Denial of Service via crafted SH2A bytecode

Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active mode-specific decode[] function-pointer table. An application using CS_ARCH_SH with CS_MODE_SH2A or CS_MODE_SH4A and CS_MODE_SHFPU can pass crafted bytecode through cs_disasm_iter() or cs_disasm(), causing the decode[idx] test to read outside the table and terminate the process with a segmentation fault. No code execution or information disclosure was demonstrated. This issue is fixed in version 6.0.0-Alpha10. The `sh_disassemble()` function incorrectly processes 16-bit instructions, leading to an attempt to read data from an unauthorized memory location (an out-of-bounds read). A remote attacker could exploit this by providing specially crafted bytecode to an application using Capstone in specific modes (SH2A or SH4A with SHFPU). This could cause the application to crash, resulting in a Denial of Service (DoS), where the service becomes unavailable. This Moderate impact flaw in Capstone's SH disassembler can lead to a denial of service. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125.

CVE-2026-55894
Red Hat Enterprise Linux
Aug 20, 2026
Medium4.4Red Hat

Medium [CVE-2026-77643] Xapian xapian-core: Arbitrary code execution via incomplete HTML escaping

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499. A remote attacker could exploit this by injecting malicious script, leading to arbitrary code execution in the user's browser context. This could result in information disclosure or session hijacking. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-79. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: xapian-core.

CVE-2026-77643
Red Hat Enterprise Linux
Aug 20, 2026
Medium4.4Red Hat

Medium [CVE-2026-70654] Heap buffer overflow allows memory corruption and denial of service.

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in vips_source_read_to_memory in libvips/iofuncs/source.c. The function uses VIPS_MAX instead of VIPS_MIN when selecting the remaining read size, allowing up to 4032 bytes to be written beyond the allocated heap buffer and causing memory corruption or a process crash. This issue is fixed in version 8.18.3. This vulnerability, located in the vips_source_read_to_memory function, allows a local attacker to write beyond an allocated memory buffer. This can lead to memory corruption or cause the application to crash, resulting in a denial of service. This Moderate impact flaw in libvips involves a heap buffer overflow when processing untrusted uncompressed PPM images through applications configured with unusual custom libvips sources. Exploitation requires a specific, non-default application setup and user interaction, which reduces the overall risk in typical Red Hat environments. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787.

CVE-2026-70654
Unclassified
Aug 20, 2026
Medium6.1Red Hat

Medium [CVE-2026-70651] Denial of Service via integer overflow in multi-page TIFF image processing

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The vulnerable calculations in libvips/foreign/magick6load.c and libvips/foreign/magick7load.c multiply the per-page Ysize by n_frames without a checked bound, which can cause a heap buffer over-read and process crash. Most package-manager builds include libtiff and do not use this affected fallback path. This issue is fixed in version 8.18.3. This overflow, caused by unchecked calculations of image frame height, can lead to a heap buffer over-read and result in a process crash, causing a Denial of Service (DoS). This Moderate impact flaw in libvips occurs when the library is built without libtiff support but with ImageMagick, allowing a local attacker to trigger a denial of service by providing a crafted multi-page TIFF image. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H). Weakness: CWE-190.

CVE-2026-70651
Unclassified
Aug 20, 2026
Medium5.0Red Hat

Medium [CVE-2026-70652] Information disclosure or denial of service via heap buffer over-read when processing JPEGs with gain maps

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3. Moderate: This flaw in libvips, when built with libultrahdr support, could lead to information disclosure or a denial of service. Exploitation requires processing a specially crafted JPEG with gain map data, which may not be a default or common operation in all Red Hat environments. The impact is limited to the application processing the malicious image. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125.

CVE-2026-70652
Unclassified
Aug 20, 2026
Medium6.5Red Hat

Medium [CVE-2026-53586] Information disclosure via HTTP redirect allows credential leakage

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP transport in src/libgit2/transports/http.c follows an offsite initial redirect, and handle_remote_auth and handle_auth pass transport->owner->url instead of transport->server.url to the credential callback when the redirected host returns 401 Unauthorized. A callback that scopes credentials to the original trusted URL can therefore return GIT_CREDENTIAL_USERPASS_PLAINTEXT credentials that libgit2 stores in transport->server.cred and sends as an Authorization header to the redirected host. An attacker who controls a trusted Git host or an open redirect on that host can disclose HTTP Basic credentials, personal access tokens, or equivalent credentials. This issue is fixed in versions 1.8.6 and 1.9.5. A flaw was found in libgit2. The built-in HTTP transport component incorrectly handles offsite redirects, leading to the disclosure of sensitive information. This vulnerability results in the leakage of user authentication credentials. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-201.

CVE-2026-53586
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat

Medium [CVE-2026-53583] Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/openssl.c uses an inverted!!memcmp result in the GEN_IPADD branch when comparing an IP-literal host with a certificate IP SubjectAltName. OpenSSL builds reject matching IP addresses and accept mismatched IP addresses, allowing a network attacker with a CA-trusted certificate containing any IP SubjectAltName to intercept libgit2 connections to IP-literal HTTPS URLs. DNS SubjectAltName validation and non-OpenSSL TLS backends are not affected. This issue is fixed in versions 1.8.6 and 1.9.5. An inverted comparison in the OpenSSL backend's certificate verification logic, specifically when handling IP-literal hosts and certificate IP SubjectAltNames, allows a network attacker to intercept HTTPS connections. By presenting a CA-trusted certificate with any IP SubjectAltName, an attacker can trick libgit2 into accepting a mismatched IP address, leading to the interception of sensitive communication. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-295.

CVE-2026-53583
Red Hat Enterprise Linux
Aug 20, 2026
Medium6.5Red Hat

Medium [CVE-2026-53585] Denial of Service via Unbounded Memory Allocation

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, git_delta_apply in src/libgit2/delta.c trusts the attacker-controlled res_sz value parsed by hdr_sz from a delta object header and passes that amount to git__malloc before validating delta instructions. Malicious pack data supplied through git_clone, git_fetch, git_remote_fetch, git_indexer_append, or a local attacker-supplied repository can use a very small multi-level OFS_DELTA chain to retain extremely large allocations and exhaust memory. This issue is fixed in versions 1.8.6 and 1.9.5. A flaw was found in libgit2. The `git_delta_apply` function incorrectly trusts an attacker-controlled size value from a delta object header, which is used for memory allocation before proper validation of delta instructions. This can lead to the exhaustion of system memory, resulting in a Denial of Service (DoS). Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3. Red Hat fixing advisory: RHSA-2026:59361.

CVE-2026-53585
Red Hat Enterprise Linux
Aug 20, 2026
Medium5.4Vendor: HighRed Hat

Medium [CVE-2026-66787] Go pprof profiling endpoint enabled unconditionally on lighthouse-agent:8082

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malicious endpoints. This enables a remote attacker to conduct transparent Man-in-the-Middle (MITM) attacks on cross-cluster service communications, potentially leading to unauthorized information disclosure and data manipulation. By creating unvalidated EndpointSlice objects with attacker-controlled IP addresses, a malicious actor can redirect legitimate service traffic between clusters, enabling transparent Man-in-the-Middle attacks without altering the target service. Red Hat severity: Important — CVSS 5.4 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-489. Red Hat fixing advisory: RHSA-2026:63016. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-66787
Unclassified
Aug 20, 2026
Medium6.5Red Hat

Medium [CVE-2026-63379] HTTP header smuggling allows authorization bypass or cache poisoning

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces evhttp_parse_headers_impl_ and a temporary trailer header list. An unauthenticated remote attacker can place security-sensitive fields in trailers so that an upstream proxy and the libevent application interpret different effective headers, enabling header smuggling, authorization bypass, proxy-header spoofing, or cache poisoning. An unauthenticated remote attacker can exploit a vulnerability where chunked HTTP (Hypertext Transfer Protocol) trailers are incorrectly merged into request headers. Red Hat ships libevent in multiple products including Red Hat Enterprise Linux, RHIVOS, and as part of RHCOS in OpenShift. All shipped versions are prior to the fix in 2.1.13 and are affected by this vulnerability. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-444. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Cert Manager support for Red Hat OpenShift release 1.20; Red Hat Hardened Images; Red Hat Update Infrastructure 5; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4.

CVE-2026-63379
Red Hat Enterprise Linux
Aug 20, 2026
Medium4.7Red Hat

Medium [CVE-2026-63380] Denial of Service via Null Pointer Dereference

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. evws_connection_free sees a non-null http_server and unconditionally calls TAILQ_REMOVE even though the session was never inserted into http_server->ws_sessions. A local caller able to induce this allocation or locking failure can crash the process. This issue is fixed in version 2.2.2-alpha. This vulnerability allows a local attacker to trigger a null pointer dereference during specific error handling within the `evws_new_session` function. By inducing an allocation or locking failure, an attacker can cause the application to crash, leading to a denial of service. Moderate impact. This flaw allows a local caller to induce specific allocation or locking failures during websocket session creation, leading to a denial of service. Exploitation is limited to applications utilizing Libevent's websocket functionality and exposed to untrusted local input. The vulnerable code module has only ever shipped as part of the 2.2.x development/alpha line, culminating in the 2.2.2-alpha release that fixes this issue. It was never backported into the 2.1.x stable series. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2026-63380
Red Hat Enterprise Linux
Aug 20, 2026

← All vendors