Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11898 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Vendor: MediumRed Hat

High [CVE-2026-85504] Arbitrary code execution via malformed Fujitsu System Event Log responses

FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses. A flaw was found in FreeIPMI. This vulnerability, a stack-based buffer overflow, occurs when the software processes malformed Fujitsu System Event Log (SEL) responses. An attacker could exploit this by providing specially crafted SEL data, potentially requiring user interaction, to achieve arbitrary code execution. This vulnerability is restricted to a Moderate severity rating due to its elevated attack complexity: successful exploitation requires an attacker to successfully inject specially crafted SEL data and relies on active user interaction to trigger the vulnerable code path, significantly lowering the likelihood of an automated or widespread attack. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-121. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: freeipmi.

CVE-2026-85504
Red Hat Enterprise Linux
Sep 4, 2026
High7.3Vendor: MediumRed Hat

High [CVE-2026-80863] Fix OOB in free_rd_atomic_resources

Fix OOB in free_rd_atomic_resources(). Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-80863
Linux Kernel
Sep 4, 2026
High8.3Red Hat

High [CVE-2026-80844] validate routing header segments_left

In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of addresses described by the routing header's hdrlen field. That assumption does not hold for raw IPv6 HDRINCL packets. A packet with hdrlen equal to 2 describes one address, but can carry an arbitrary segments_left value. With segments_left equal to 255, the function moves its address pointer 4,064 bytes backwards and passes a 4,064-byte length to memmove(), resulting in an out-of-bounds access. Validate the invariant locally before modifying the routing header or performing any address-pointer arithmetic, and propagate malformed-header errors to the existing AH6 input and output error paths. A flaw was found in the Linux kernel's xfrm subsystem, specifically within the AH6 (Authentication Header for IPv6) module. This oversight allows an attacker to craft a malicious packet that can cause an out-of-bounds memory access, potentially leading to memory corruption. This issue is classified as Important severity because exploitation can be achieved by a local attacker with unprivileged user access.

CVE-2026-80844
Linux Kernel
Sep 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-53769] Unauthorized attachment modification via authorization bypass

Unauthorized attachment modification via authorization bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-639. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift GitOps; and 2 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat package: golang.

CVE-2026-53769
Red Hat Enterprise Linux
Sep 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-85769] heap out-of-bounds read in TPM2 state unmarshalling via unchecked block_skip_read blocksize

A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized skip-block length that is not validated against the remaining size of the input buffer. This can drive an internal size counter negative, which bypasses a subsequent bounds check due to an unsafe signed-to-unsigned conversion, causing the parser to read memory outside the bounds of the heap buffer holding the state data. Successful exploitation can crash the process hosting libtpms (such as swtpm), resulting in a denial of service of the emulated TPM device and the virtual machine that depends on it. No data corruption or information disclosure was confirmed. This vulnerability is rated as Moderate because exploitation results in a denial of service (crash or forced TPM failure mode) via a heap out-of-bounds read, with no confirmed information disclosure or code execution path. The flaw affects builds of libtpms compiled with TPM 2.0 support (--with-tpm2, the default). The vulnerable code is in the TPM 2.0 state (de)serializer and is not present in TPM 1.2-only builds. Products that ship libtpms with TPM 2.0 support (used to provide virtual TPM 2.0 devices to guests via swtpm/QEMU) are affected.

CVE-2026-85769
Red Hat Enterprise Linux
Sep 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-18149] Denial of Service due to orphaned response body in retry handler

Denial of Service due to orphaned response body in retry handler. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-911. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; OpenShift Pipelines; Red Hat Build of Podman Desktop; Red Hat Developer Hub; and 6 more. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; and 2 more.

CVE-2026-18149
Red Hat Enterprise Linux
Sep 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-84890] Denial of Service via unbounded decompression of compressed responses

Denial of Service via unbounded decompression of compressed responses. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.

CVE-2026-84890
Red Hat Enterprise Linux
Sep 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-84933] Cross-user cookie disclosure via Set-Cookie caching

undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example one marked with a public and max-age directive, is stored and then re-served to a later caller that matches the same cache key. As a result one caller's cookie is disclosed to a different caller, and an untrusted server can inject cookies into cached responses served to all subsequent callers. This violates the requirement that a shared cache must not store cookies. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2. A flaw was found in undici. The software's caching mechanism, when operating in shared cache mode, improperly stores responses that include 'Set-Cookie' headers. Consequently, sensitive cookie information from one user can be inadvertently disclosed to another user accessing the same cached content. Applications that only use undici as an HTTP client without enabling the shared cache interceptor, or that only use the private cache mode, are not affected. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N). Weakness: CWE-524.

CVE-2026-84933
Red Hat Enterprise Linux
Sep 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-84947] Response truncation and connection termination

undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the interceptor aborts cleanly, but when a response has no Content-Length and is chunked, the interceptor instead signals completion early once the accumulated size reaches the maximum, without pausing or aborting the request. Because the underlying parser keeps delivering body bytes, a second completion signal fires and trips an internal assertion, which aborts the request and tears down the connection. The application is left observing a misleading successful status with an empty or truncated body while the connection has actually been disconnected. Users should upgrade to undici 7.29.1 or 8.10.2. A flaw was found in undici, a Node.js HTTP/1.1 client. When the dump interceptor processes oversized chunked responses that do not declare a Content-Length, it prematurely signals completion. This causes the application to receive an incomplete or empty response body, while the network connection is unexpectedly closed. This issue can lead to applications processing partial data or encountering unexpected connection disruptions. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more.

CVE-2026-84947
Red Hat Enterprise Linux
Sep 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-85014] Denial of Service via WebSocketStream unclean close

Denial of Service via WebSocketStream unclean close. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-390. Red Hat lists fixing advisory RHSA-2026:54389 with package nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, grafana12-4-main-12.4.10-0.2.hum1, nodejs26-main-26.7.0-1.5.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; and 13 more.

CVE-2026-85014
Red Hat Enterprise Linux
Sep 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-85024] Denial of Service via unhandled error in WebSocket permessage-deflate decompression

undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2. A flaw was found in undici. A remote, unauthenticated attacker can trigger a Denial of Service (DoS) by sending a specially crafted compressed WebSocket payload. This unhandled error leads to the termination of the entire Node.js process, making the service unavailable. A denial of service flaw exists in the undici WebSocket client, which is used by Node.js. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat AMQ Broker 7; and 17 more.

CVE-2026-85024
Red Hat Enterprise Linux
Sep 4, 2026
Medium5.9Red Hat

Medium [CVE-2026-85534] HTTP/2 client crash in on_data_source_read_callback when SETTINGS INITIAL_WINDOW_SIZE shrinks during deferred body read

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session. A libsoup 3 HTTP/2 client can abort or drop the session when it uploads a request body from a non-pollable stream (for example GFileInputStream) to a malicious server that shrinks SETTINGS_INITIAL_WINDOW_SIZE during the deferred read. Red Hat builds keep GLib assertions enabled, so the usual result is a client process abort rather than memory corruption. Exploitation requires the client to connect to an attacker-controlled HTTP/2 endpoint and use that request-body path. Version affected: libsoup >= 3.0.0 Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-617. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3.

CVE-2026-85534
Red Hat Enterprise Linux
Sep 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-81666] integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems

An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory access that crashes the Corosync daemon. This results in a denial of service for the affected cluster node. The overflow does not occur on 64-bit systems, where the length calculation is correctly performed in 64-bit arithmetic. This vulnerability is rated as Moderate. The published Red Hat CVSS score is 6.5 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), matching the unmitigated upstream baseline for 32-bit deployments. The integer overflow described only affects 32-bit builds, because C integer-promotion rules cause the vulnerable multiplication to be evaluated in 64-bit arithmetic on 64-bit systems, which prevents the overflow entirely. Red Hat Enterprise Linux 8, 9, and 10 ship primarily 64-bit architectures (x86_64, aarch64), so this specific overflow mechanism does not apply to the vast majority of Red Hat deployments; this remains true regardless of the encryption scoring decision below.

CVE-2026-81666
Red Hat Enterprise Linux
Sep 4, 2026
Medium4.3Red Hat

Medium [CVE-2026-71197] SSRF blocklist bypass via hostname-to-IP resolution gap in web-download

A flaw was found in OpenStack Glance. The web-download image import method can bypass host-based blocklist filtering. When an operator configures disallowed_hosts with IP addresses to block access to internal services, an attacker can circumvent this protection by using a hostname that resolves to the blocked IP address. The hostname-to-IP resolution result is not used for blocklist comparison, allowing an authenticated user to force the Glance server to make requests to internal network services that were intended to be blocked. This vulnerability is rated as Moderate because it requires an authenticated OpenStack user with image import permissions, and it is a bypass of an optional IP blocklist rather than a default-open SSRF. Default disallowed_hosts is empty, so this specific bypass only matters on deployments that already configured host filtering. Deployments that do not use web-download are not affected by this bypass. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-918. Affected Red Hat products: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-71197
Unclassified
Sep 4, 2026
Medium6.5Red Hat

Medium [CVE-2026-85505] Denial of Service via stack-based buffer over-read in ipmi-oem

ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions). A stack-based out-of-bounds read vulnerability was found in the FreeIPMI ipmi-oem utility. When processing an abnormally short response from a Baseboard Management Controller (BMC), the application over-reads the buffer. A malicious BMC could exploit this to crash the client application (Denial of Service) or potentially leak stack memory. Red Hat compiler safeguards further restrict the impact primarily to a process crash. If a BMC returns an unexpectedly truncated System Event Log (SEL) response, the client fails to validate the data length before reading. This causes the application to read past the allocated stack buffer boundaries, leading to a crash or potential memory disclosure. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-85505
Red Hat Enterprise Linux
Sep 4, 2026
Medium6.2Red Hat

Medium [CVE-2026-80788] Do not WARN on remotely-controlled oversized SGL allocations

Do not WARN on remotely-controlled oversized SGL allocations. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-80788
Linux Kernel
Sep 4, 2026
Low3.7Red Hat

Low [CVE-2026-18540] HTTP response splitting via retry interceptor

undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. This happens when an upstream server delivers part of a body without a trustworthy resume checkpoint, for example a non-success response whose headers were already sent or a partial-content response with an unusable content range, then closes the connection and answers the resumed range request with more bytes. As a result the response body can be longer than the Content-Length that the application observes. Exploitation requires an attacker-controlled upstream server and an application that forwards the response through a framing-sensitive path. This affects undici versions before 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2. A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in the retry interceptor, which incorrectly appends data to a ranged retry response. Consequently, an application relaying such a response to a downstream HTTP/1.1 peer without proper framing normalization may enable HTTP response splitting or desynchronization, allowing an attacker to inject arbitrary content into subsequent responses.

CVE-2026-18540
Red Hat Enterprise Linux
Sep 4, 2026
Low3.7Red Hat

Low [CVE-2026-85008] Integrity failure due to caching of unsafe HTTP method responses

undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is never placed in the skip list and instead falls through to the full cache-read path. The response-storage gate also lacked a method check, so a response to an unsafe request that is heuristically cacheable or carries an explicit Cache-Control directive is stored and later replayed from cache. Because response headers from a remote origin are untrusted, an origin can answer once with a cacheable status and then have the client's own subsequent state-changing requests to that path served from the stale cache entry without ever reaching the origin, an integrity failure that occurs under the interceptor's default configuration. Users should upgrade to undici 7.29.1 or 8.10.2. A flaw was found in undici. This can result in an integrity failure, where the client's application state is not updated as expected. This Low impact vulnerability in undici's cache interceptor can lead to integrity issues by caching responses for unsafe HTTP methods. Under certain default configurations, a malicious remote origin could cause stale or manipulated responses to be served from the cache, bypassing intended state changes.

CVE-2026-85008
Red Hat Enterprise Linux
Sep 4, 2026
Low3.5Red Hat

Low [CVE-2026-4897 +1] Regression in CVE-2026-4897 fix (polkit read_cookie) - stack buffer underflow

No description is available for this CVE. This issue is classified as Low severity because there is no observable effect of the one byte out-of-bounds read. No information disclosure or affect to integrity has been demonstrated. Red Hat severity: Low — CVSS 3.5 (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:66287. Affected products named by the advisory: Red Hat package: polkit-pkla-compat; Red Hat package: polkit-gnome; Red Hat package: polkit-kde; Red Hat package: polkit-qt.

CVE-2026-4897CVE-2026-85498
Red Hat Enterprise Linux
Sep 4, 2026
High8.8Red Hat

High [CVE-2026-85049] Use after free in Skia

Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-85049
Red Hat Enterprise Linux
Sep 3, 2026

← All vendors