Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5822 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.5Red Hat

Medium [CVE-2026-76217] Arbitrary File Read via Crafted Parameters

GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with full file contents returned in GitCommandError.stderr. A remote attacker with low privileges could exploit this by supplying crafted parameters, such as --pathspec-from-file and --pathspec-file-nul. This vulnerability allows for arbitrary file disclosure, enabling the attacker to read any file accessible to the GitPython process. Exploitation requires an application to pass untrusted, attacker-controlled input directly as the path/pathspec argument to these GitPython methods; in normal use these arguments are supplied by the application or developer rather than by a remote adversary. Red Hat products that bundle GitPython use it as an internal build and automation helper with developer-controlled arguments and do not expose these parameters to untrusted input, so the vulnerable code cannot be controlled by an adversary in those products, which are therefore not affected. The GitPython library packages shipped in Red Hat OpenStack Platform contain the vulnerable code; those affected streams are out of support scope for this fix. Red Hat rates the impact of this flaw as Moderate.

CVE-2026-76217
Unclassified
Aug 19, 2026
Medium5.7Red Hat

Medium [CVE-2026-16440] Denial of Service via crafted.class file

Denial of Service via crafted.class file. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: java-1.8.0-ibm.

CVE-2026-16440
Red Hat Enterprise Linux
Aug 19, 2026
Medium4.3Red Hat

Medium [CVE-2026-76166] mod_cluster Advertise Listener: unauthenticated DoS via crafted multicast datagram

A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" header but without the "Date:", "Digest:", and "Sequence:" headers triggers a NullPointerException in verifyDigest() that is not caught by the worker thread's exception handler. This causes the advertise listener thread to terminate permanently. The failure is silent (isListening() continues to return true) and persists until the node is restarted. The crash occurs before the AdvertiseSecurityKey comparison, so deployments with a configured security key are still affected. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-476. Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 5; Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat Single Sign-On 7. Will not fix / out of support: Red Hat JBoss Web Server 5. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-76166
Unclassified
Aug 19, 2026
Medium6.1Red Hat

Medium [CVE-2026-75900] Out-of-bounds read in SWTPM_NVRAM_CheckHeader due to sizeof(pointer) vs sizeof(struct) mismatch

An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead of sizeof(*bh), the actual struct size. This allows an undersized buffer to pass validation, causing a 2-byte heap overread on 64-bit systems (6 bytes on 32-bit) when accessing the totlen field. This may cause daemon termination on some platforms and leaks heap data to the log. Red Hat rates this issue as Moderate impact. An attacker with access to the control channel can send an 8-byte state blob that passes this guard; the subsequent read of bh->totlen at offset 6 overreads the heap allocation by 2 bytes. The out-of-bounds value is then printed to the swtpm log, leaking a small amount of adjacent heap data. This is distinct from CVE-2022-23645, which added validation on the hdrsize field below this guard but did not fix the entry length check. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: swtpm.

CVE-2026-75900
Red Hat Enterprise Linux
Aug 19, 2026
Medium5.5Red Hat

Medium [CVE-2026-76014] Denial of Service via null pointer dereference in wget.c

A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/wget.c of the component FEATURE_WGET_TIMEOUT Handler. Such manipulation of the argument -T leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is 83a40bf7a93c8ac093d33ab452222dd5b9eb57ff. A patch should be applied to remediate this issue. A flaw was found in BusyBox. This occurs when the attacker manipulates the -T argument, leading to a denial of service. This vulnerability, which affects BusyBox versions up to 1.30.1, leads to a denial of service as the wget process crashes. Red Hat products shipping BusyBox versions above 1.30.1 are not affected by this vulnerability. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476. Affected Red Hat products: Red Hat Enterprise Linux 6. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: busybox.

CVE-2026-76014
Red Hat Enterprise Linux
Aug 19, 2026
Medium5.8Red Hat

Medium [CVE-2026-76925] TOCTOU race condition allows symlink redirection

A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop. SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure. Red Hat severity: Moderate — CVSS 5.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L). Weakness: CWE-367. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: flatpak.

CVE-2026-76925
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.8Red Hat

Medium [CVE-2026-71084] Denial of Service via unauthenticated local access

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H). This can lead to a complete denial of service (DoS) by causing the component to crash repeatedly. This Moderate severity flaw in `mysql-connector-odbc` allows an unauthenticated attacker with local logon access to the system to cause a complete denial of service and gain unauthorized read access to a subset of data. The local attack vector limits the immediate remote exploitability, but successful exploitation can significantly impact system availability and data confidentiality. Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-71084
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.5Red Hat

Medium [CVE-2026-71079] Denial of Service via network access by a low privileged attacker

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). This vulnerability allows a low privileged attacker with network access to cause a complete denial of service (DoS) by triggering a hang or frequently repeatable crash of the component. The attacker can exploit this flaw through multiple protocols. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: mysql-connector-odbc.

CVE-2026-71079
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.8Red Hat

Medium [CVE-2026-76042] Information disclosure via uninitialized resource in GPU

Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) A flaw was found in Google Chrome, specifically within its GPU component, where an uninitialized resource could be used. This Moderate impact information disclosure flaw in Chromium and QtWebEngine, affecting community projects, requires a prior renderer process compromise and user interaction with a specially crafted HTML page. The need for these preconditions reduces the overall risk in typical Red Hat desktop deployments. Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N). Weakness: CWE-824.

CVE-2026-76042
Unclassified
Aug 18, 2026
Medium6.1Red Hat

Medium [CVE-2026-16732] Request spoofing via numeric trustProxy configuration

fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to derive the request host, protocol, hostname, ip, and ips values, checking the connecting address. That guard closes the IP, CIDR, and custom-function forms of trustProxy correctly, because those forms compile to predicates that inspect the connecting address. The hop-count form, where trustProxy is set to a number, compiles to a predicate that structurally ignores the address, so the guard is always satisfied for any hop count of one or more. Applications configured with a numeric trustProxy value, such as trustProxy set to 1 for a single reverse proxy, remain vulnerable: an attacker who can reach the Fastify origin directly, bypassing the front-facing proxy, can spoof the forwarded request fields exactly as in the unpatched version. The impact class matches the parent CVE-2026-3635, including host injection in generated URLs, HTTPS-enforcement bypass, secure-cookie and CSRF-origin bypass, and host-based routing and cache poisoning. Affected versions are fastify from 5.8.3 up to but not including 5.12.1. Patches: patched in fastify 5.12.1, where the numeric form of trustProxy is disabled at runtime and removed from the TypeScript type union. Affected product named by the advisory: Red Hat OpenShift Dev Spaces.

CVE-2026-16732
Unclassified
Aug 18, 2026
Medium5.4Red Hat

Medium [CVE-2026-18504] Schema validation bypass via root primitive coercion mismatch

fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a request body schema targets a root primitive value. As a result, a request that should have failed validation can reach application logic with a value that does not satisfy the schema, which can undermine integrity and access-control checks that rely on the validated type. Users should upgrade to fastify 5.12.1, which fixes the mismatch. No known workarounds are available. A flaw was found in fastify. This occurs because the validation process may coerce a JSON string into an expected type, but the original unvalidated string is then passed to the application logic. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-843. Affected Red Hat products: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-18504
Unclassified
Aug 18, 2026
Medium6.5Red Hat

Medium [CVE-2026-49452] CSS Injection via Presentational Hints

WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background attribute is inserted into a background-image:url() declaration and parsed by tinycss2.parse_blocks_contents(), allowing untrusted HTML to inject additional CSS declarations. Applications that render untrusted HTML with presentational hints enabled can be affected by CSS injection and server-side requests through injected url() values. This issue is fixed in version 69.0. This vulnerability allows a remote attacker to inject arbitrary CSS, potentially leading to information disclosure or the initiation of server-side requests through specially crafted url() values. Red Hat Ansible Automation Platform 2.5 ships WeasyPrint 69.0, which already includes the fix for this vulnerability, and is therefore not affected. The WeasyPrint package in EPEL ships a version within the vulnerable range. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-79.

CVE-2026-49452
Unclassified
Aug 18, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-66780] Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an attacker can redirect inter-cluster tunnel traffic, enabling a Man-in-the-Middle (MITM) attack across the entire cluster mesh. Red Hat severity: Important — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-532. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.17; Red Hat Advanced Cluster Management for Kubernetes 2. Red Hat fixing advisory: RHSA-2026:63016.

CVE-2026-66780
Unclassified
Aug 18, 2026
Medium4.4Vendor: HighRed Hat

Medium [CVE-2026-66783] Release workflow consumes same-org composite action via mutable @devel branch ref

A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image. This is due to a lack of image validation when overriding component images, enabling the deployment of malicious images with extensive privileges. Red Hat severity: Important — CVSS 4.4 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N). Weakness: CWE-1357. Red Hat fixing advisory: RHSA-2026:63016. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-66783
Unclassified
Aug 18, 2026
Medium5.8Vendor: HighRed Hat

Medium [CVE-2026-66782] Operator ClusterRole grants cluster-wide create/update on all ConfigMaps

A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token within the Submariner Custom Resource (CR) specification. An attacker with access to the cluster's etcd database or through `kubectl get` commands could obtain this token. The possession of this token grants full control over the mesh network, enabling unauthorized management of network resources such as endpoints and secrets. This configuration exposes the token to cluster administrators or any entity with read access to the CR, potentially granting full mesh control over the Submariner network. This risk is heightened by the token's long-lived nature and its exposure through standard Kubernetes tools like `kubectl get` and `must-gather`. Red Hat severity: Important — CVSS 5.8 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N). Weakness: CWE-269. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.17; Red Hat Advanced Cluster Management for Kubernetes 2. Red Hat fixing advisory: RHSA-2026:63016.

CVE-2026-66782
Unclassified
Aug 18, 2026
Medium5.4Vendor: HighRed Hat

Medium [CVE-2026-66781] pprof debug endpoint enabled by default on 0.0.0.0:8082 without authentication

A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthorized parties. Such access enables an attacker to passively decrypt network traffic flowing between any two clusters in the mesh, resulting in sensitive information disclosure. As Custom Resources are not encrypted by default in etcd on OpenShift, and the PSK is identical across all clusters in a mesh, its disclosure via `kubectl get submariner -o yaml` or through must-gather bundles allows an attacker with appropriate permissions to passively decrypt traffic between any two connected clusters. Red Hat severity: Important — CVSS 5.4 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-749. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66781
Unclassified
Aug 18, 2026
Medium5.5Red Hat

Medium [CVE-2026-75485] /tmp/kubeconfig retention

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially disclosing sensitive authentication information to anyone with access to the archive. This flaw in the ACM must-gather tool causes the cluster Proxy object to be collected without redaction, bypassing the sanitization provided by oc inspect. Proxy basic-auth credentials are exposed in the resulting archive, which may be shared with support teams or stored externally. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-532. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-75485
Unclassified
Aug 18, 2026
Medium5.5Red Hat

Medium [CVE-2026-73834] embedded Secret data in ACM wrapper CRs collected without redaction

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive, potentially exposing sensitive information to anyone with access to the archive. The must-gather archive may be shared with support teams or stored externally, creating an information disclosure risk for credentials embedded in these resources. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-312. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-73834
Unclassified
Aug 18, 2026
Medium6.3Red Hat

Medium [CVE-2026-75032] Out-of-bounds read in AVRCP parse_media_element and parse_media_folder

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability, affecting the parse_media_element() and parse_media_folder() functions, can lead to a crash of the bluetoothd daemon, resulting in a Denial of Service (DoS). It could also potentially expose sensitive heap memory contents. Exploitation requires user interaction to pair with the malicious device. Red Hat ships BlueZ in Red Hat Enterprise Linux and related products. Red Hat severity: Moderate — CVSS 6.3 (CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125. Red Hat lists Red Hat Enterprise Linux 6 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: bluez.

CVE-2026-75032
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.1Red Hat

Medium [CVE-2026-74989] Internally found bugs fixed in Firefox 154

Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-825. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-74989
Unclassified
Aug 18, 2026

← All vendors