Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11898 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.4Red Hat

High [CVE-2026-86140] Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements

Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements. Red Hat rates this important (CVSS 7.4). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-0:2.12.5-10.el10_2.4, libxml2-0:2.9.13-14.el9_8.5, libxml2-0:2.9.7-21.el8_10.9, libxml2-main-2.15.4-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-86140
Unclassified
Sep 5, 2026
Medium5.0Red Hat

Medium [CVE-2026-18238] Information disclosure via out-of-bounds read in rpcap client

Information disclosure via out-of-bounds read in rpcap client. Red Hat rates this moderate (CVSS 5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.

CVE-2026-18238
Red Hat Enterprise Linux
Sep 5, 2026
Medium4.3Red Hat

Medium [CVE-2026-18313] Denial of Service via memory leak in rpcapd

Denial of Service via memory leak in rpcapd. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.

CVE-2026-18313
Red Hat Enterprise Linux
Sep 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-6554] Denial of Service via infinite loop in BPF interpreter

Denial of Service via infinite loop in BPF interpreter. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.

CVE-2026-6554
Red Hat Enterprise Linux
Sep 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-6244] Denial of Service via crafted BPF filter program

Denial of Service via crafted BPF filter program. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-369. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.

CVE-2026-6244
Red Hat Enterprise Linux
Sep 5, 2026
Medium5.5Red Hat

Medium [CVE-2026-31911] Denial of Service via crafted BPF opcode

Denial of Service via crafted BPF opcode. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.

CVE-2026-31911
Red Hat Enterprise Linux
Sep 5, 2026
Medium6.1Red Hat

Medium [CVE-2026-31912] Denial of service via crafted BPF filter program

Denial of service via crafted BPF filter program. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.

CVE-2026-31912
Red Hat Enterprise Linux
Sep 5, 2026
Medium5.6Red Hat

Medium [CVE-2026-86144] Information disclosure, SSRF, or denial of service due to improper parseFlags propagation.

Information disclosure, SSRF, or denial of service due to improper parseFlags propagation. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-669. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-0:2.12.5-10.el10_2.4, libxml2-0:2.9.13-14.el9_8.5, libxml2-0:2.9.7-21.el8_10.9, libxml2-main-2.15.4-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-86144
Unclassified
Sep 5, 2026
Medium6.9Red Hat

Medium [CVE-2026-86143] Data integrity issues due to integer overflow in write callbacks

Data integrity issues due to integer overflow in write callbacks. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-192. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-0:2.12.5-10.el10_2.4, libxml2-0:2.9.13-14.el9_8.5, libxml2-0:2.9.7-21.el8_10.9, libxml2-main-2.15.4-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-86143
Unclassified
Sep 5, 2026
Medium6.9Red Hat

Medium [CVE-2026-86142] Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturation

Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturation. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-0:2.12.5-10.el10_2.4, libxml2-0:2.9.13-14.el9_8.5, libxml2-main-2.15.4-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-86142
Unclassified
Sep 5, 2026
Medium6.9Red Hat

Medium [CVE-2026-86139] Integer overflow in xmlURIEscapeStr may lead to arbitrary code execution

Integer overflow in xmlURIEscapeStr may lead to arbitrary code execution. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-main-2.15.4-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-86139
Unclassified
Sep 5, 2026
Medium6.9Red Hat

Medium [CVE-2026-86138] Arbitrary code execution via heap-based buffer overflow

Arbitrary code execution via heap-based buffer overflow. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-0:2.12.5-10.el10_2.4, libxml2-0:2.9.13-14.el9_8.5, libxml2-0:2.9.7-21.el8_10.9, libxml2-main-2.15.4-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-86138
Unclassified
Sep 5, 2026
Low2.9Red Hat

Low [CVE-2026-86141] Denial of Service due to NULL pointer dereference in xmlRegNewParserCtxt

Denial of Service due to NULL pointer dereference in xmlRegNewParserCtxt. Red Hat rates this low (CVSS 2.9). Weakness: CWE-252. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-main-2.15.4-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-86141
Unclassified
Sep 5, 2026
Low2.9Red Hat

Low [CVE-2026-86137] Denial of Service via out-of-bounds read in xmlFAParsePosCharGroup

Denial of Service via out-of-bounds read in xmlFAParsePosCharGroup. Red Hat rates this low (CVSS 2.9). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-main-2.15.4-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-86137
Unclassified
Sep 5, 2026
Critical9.1Red Hat

Critical [CVE-2026-85595] Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth

Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-305. Affected product named by the advisory: Red Hat OpenShift Dev Spaces.

CVE-2026-85595
Unclassified
Sep 4, 2026
High7.7Red Hat

High [CVE-2026-85781] github.com/kubernetes-sigs/aws-efs-csi-driver: Amazon EFS CSI Driver: Unauthorized directory deletion via unverified access point ownership

github.com/kubernetes-sigs/aws-efs-csi-driver: Amazon EFS CSI Driver: Unauthorized directory deletion via unverified access point ownership. Red Hat rates this important (CVSS 7.7). Weakness: CWE-639. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-85781
Unclassified
Sep 4, 2026
High7.5Red Hat

High [CVE-2026-19534] Denial of Service via unrequested WebSocket subprotocol

Denial of Service via unrequested WebSocket subprotocol. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:69248 with package nodejs26-main-26.8.2-0.1.hum1, grafana12-4-main-12.4.10-0.2.hum1, rhdh/rhdh-hub-rhel9:1789554285. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat Build of Podman Desktop; and 14 more. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 10 more.

CVE-2026-19534
Red Hat Enterprise Linux
Sep 4, 2026
High7.4Red Hat

High [CVE-2026-84961] TLS certificate validation bypass in BalancedPool via dropped connect options

undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2. A flaw was found in undici's BalancedPool component. This vulnerability allows a remote attacker to bypass Transport Layer Security (TLS) certificate validation. The BalancedPool constructor incorrectly processes its options, silently discarding custom certificate validation functions. Consequently, a peer with an otherwise untrusted certificate may be accepted, potentially compromising the integrity of secure communication.

CVE-2026-84961
Red Hat Enterprise Linux
Sep 4, 2026
High7.4Red Hat

High [CVE-2026-85152] Authentication bypass via cross-origin cache poisoning due to missing origin isolation

undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2. A flaw was found in undici. This allows a remote attacker to perform cross-origin cache poisoning, leading to information disclosure and potentially a full authentication bypass. An attacker could exploit this by having a trusted origin accept a malicious token, without contacting the legitimate trusted origin. This flaw is present in the undici HTTP client library used by Node.js.

CVE-2026-85152
Red Hat Enterprise Linux
Sep 4, 2026
High7.5Red Hat

High [CVE-2026-85730] Denial of Service via malformed TOML documents

smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is followed by a comment with no trailing newline. In src/util.ts, skipUntil() calls indexOfNewline(), receives -1 at the end of input, and resets the cursor to the beginning of the string instead of leaving the structure scan. The parser then hangs indefinitely and can consume a service's processing capacity when an application parses attacker-controlled TOML. This issue is fixed in version 1.7.1. A remote attacker could exploit an infinite loop in the `parse()` function by providing a specially crafted TOML document. Successful exploitation leads to a Denial of Service (DoS), causing the parser to hang indefinitely and consume service processing capacity. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 10; Red Hat OpenShift AI (RHOAI). Red Hat lists Red Hat Ansible Automation Platform 2; Red Hat Developer Hub; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cockpit-image-builder.

CVE-2026-85730
Red Hat Enterprise Linux
Sep 4, 2026

← All vendors