Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11898 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-85396] Arbitrary file write via path traversal

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix. A flaw was found in rubyzip. This path traversal vulnerability in the Zip::Entry#extract function allows a remote attacker to craft malicious archive entries. By failing to properly validate extraction paths, the vulnerability enables an attacker to write files outside the intended extraction directory, potentially leading to arbitrary file write. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-22. Red Hat lists Red Hat 3scale API Management Platform 2 as not affected.

CVE-2026-85396
Unclassified
Sep 3, 2026
High7.5Red Hat

High [CVE-2026-85393] Signature forgery vulnerability in RSA PKCS#1 v1.5 verification

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitrary messages using low-exponent RSA keys. This is an incomplete fix for CVE-2026-33894. By embedding specially crafted data, an attacker can bypass signature validation, leading to potential integrity compromise. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-1284. Affected Red Hat products: Red Hat Ansible Automation Platform 2.5; Red Hat Ansible Automation Platform 2.6; Node HealthCheck Operator; OpenShift Pipelines; Red Hat Ansible Automation Platform 2; Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift GitOps; Self-service automation portal 2. Red Hat lists Gatekeeper 3; OpenShift Service Mesh 3; Red Hat 3scale API Management Platform 2; Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Connectivity Link 1; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat Quay 3 as not affected.

CVE-2026-85393
Unclassified
Sep 3, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-71221] stack out-of-bounds write via unchecked height in savemeta

A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images. This vulnerability is assessed as Moderate impact because the unchecked height field enables a stack buffer overflow in savemeta, similar to the di_height OOB write in gfs2_edit. The attacker can overwrite stack memory beyond the fixed-size array, potentially achieving code execution. While RHEL compiler hardening provides partial mitigation, the controlled out-of-bounds write makes exploitation plausible. Exploitation requires local access and user interaction (an administrator must run savemeta on the crafted image). The vulnerability does not affect the kernel GFS2 driver, which validates i_height. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gfs2-utils.

CVE-2026-71221
Red Hat Enterprise Linux
Sep 3, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-71220] stack out-of-bounds write via unchecked di_height in gfs2_edit

A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images. This vulnerability is assessed as Moderate impact because the unchecked di_height field enables a controlled stack buffer overflow in gfs2_edit. The attacker controls the array index and can overwrite the return address on the stack, potentially achieving code execution. While RHEL compiler hardening (-fstack-protector-strong, PIE, ASLR) provides partial mitigation, the controlled nature of the out-of-bounds write makes exploitation plausible. Exploitation requires local access and user interaction (an administrator must run gfs2_edit on the crafted image). The vulnerability does not affect the kernel GFS2 driver, which validates di_height against sd_max_height. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gfs2-utils.

CVE-2026-71220
Red Hat Enterprise Linux
Sep 3, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-71223] integer overflow in resource group allocation size on 32-bit platforms

An integer overflow vulnerability was found in gfs2-utils. The resource group allocation size computation on 32-bit platforms causes an undersized buffer allocation followed by heap out-of-bounds writes when processing crafted GFS2 filesystem images. This vulnerability does not affect 64-bit builds. This vulnerability is assessed as Moderate impact because it requires a 32-bit platform to trigger. All standard RHEL 8+ architectures (x86_64, aarch64, ppc64le, s390x) are 64-bit and not affected. The vulnerability is applicable only to legacy 32-bit builds or embedded environments. On affected 32-bit platforms, the integer overflow leads to heap corruption with controlled writes, which could potentially enable code execution. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Red Hat lists Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-71223
Unclassified
Sep 3, 2026
High7.5Red Hat

High [CVE-2026-85124] @fastify/http-proxy: @fastify/http-proxy: Information disclosure via path traversal with backslash dot-segments

@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects forward-slash traversal, so a request containing backslash dot-segments can escape the boundary set by the prefix and rewritePrefix options. An unauthenticated network attacker can use this to reach upstream paths that were meant to stay hidden behind the proxy, resulting in disclosure of internal endpoints. Users should upgrade to @fastify/http-proxy 11.6.2 or later. This component, designed to proxy HTTP requests, does not correctly validate incoming request paths, specifically failing to account for backslash-based dot-segments. This allows them to access internal network endpoints that should be protected, leading to the disclosure of sensitive information. This Important flaw in `@fastify/http-proxy` allows an unauthenticated network attacker to bypass proxy path validation using backslash dot-segments. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-22. Affected Red Hat products: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-85124
Unclassified
Sep 3, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-85150] NULL/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials when parsing a crafted Digest Authorization/WWW-Authenticate header

A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity. Analysis of which Red Hat products ship the affected gst-plugins-base RTSP library and/or gst-rtsp-server is still pending component mapping; this statement will be updated once that mapping is complete. The vulnerable code path is only reachable in gst-rtsp-server based RTSP servers when the application has explicitly configured a GstRTSPAuth object (Basic or Digest authentication enabled) -- gst_rtsp_auth_check() short-circuits and never calls the vulnerable parser when no auth object is configured, so RTSP servers/media servers run without authentication are not affected by the server-side attack path.

CVE-2026-85150
Red Hat Enterprise Linux
Sep 3, 2026
High7.1Red Hat

High [CVE-2026-85218] AVRCP ListPlayerAttributes double stack overflow in avrcp_list_player_attributes_rsp/avrcp_get_current_player_value

A double stack-based buffer overflow was found in the BlueZ AVRCP controller implementation. A nearby BR/EDR peripheral can send a crafted AVRCP player-settings response that supplies an attacker-controlled attribute count, causing avrcp_list_player_attributes_rsp() and avrcp_get_current_player_value() in profiles/audio/avrcp.c to write attacker-controlled data past fixed-size stack buffers, potentially leading to a crash or code execution in the bluetoothd daemon. Red Hat CVSSv3 score is an estimate from CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N. This vulnerability requires user interaction and does not have any impact on the subsequent system, thus the scope is unchanged. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-121. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: bluez.

CVE-2026-85218
Red Hat Enterprise Linux
Sep 3, 2026
High8.8Red Hat

High [CVE-2026-80726] WARN and clear role.invalid when creating a child shadow page

WARN and clear role.invalid when creating a child shadow page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80726
Linux Kernel
Sep 3, 2026
Medium5.9Red Hat

Medium [CVE-2026-84185] General JSON JWS kid binding bypass during JWKSet verification

A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid) and may instead accept a signature made by any valid key in the set. This can allow an attacker with a valid key to bypass authorization checks in applications that rely on the key ID to identify specific tenants or users. The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires the attacker to already possess a valid signing key within the trusted JWKSet. Successful exploitation allows an attacker to bypass key binding and potentially impersonate other identities or tenants. The vulnerability's root cause is an incorrect type check in the JWS verification logic when handling General JSON Serialization. Weakness: CWE-347. Affected Red Hat products: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat lists Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 16.2 as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-84185
Red Hat Enterprise Linux
Sep 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-85063] Prototype pollution via malicious CSV header

node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-parse with the columns and group_columns_by_name options enabled treats a duplicate __proto__ header as an existing property in packages/csv-parse/lib/api/index.js, assigns an attacker-controlled array through obj['__proto__'], and replaces the parsed record object's prototype. A malicious CSV header can therefore inject inherited array values into the returned record, hide those inherited values from JSON serialization, and affect property enumeration and type or shape checks in applications that process the record. This issue is fixed in version 7.0.2. A flaw was found in node-csv, specifically within its csv-parse component. This allows the injection of attacker-controlled values into the parsed record's prototype, leading to information disclosure. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-915. Affected Red Hat products: Red Hat Fuse 7; Self-service automation portal 2. Red Hat lists Red Hat Developer Hub; Red Hat Hardened Images as not affected. Will not fix / out of support: Red Hat Fuse 7. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-85063
Unclassified
Sep 3, 2026
Medium5.3Red Hat

Medium [CVE-2026-85062] Denial of Service via oversized malformed color strings

Denial of Service via oversized malformed color strings. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 5 more. Affected products named by the advisory: Self-service automation portal 2; Red Hat package: grafana-pcp; Red Hat package: dotnet6.0; Red Hat package: dotnet7.0; and 1 more.

CVE-2026-85062
Red Hat Enterprise Linux
Sep 3, 2026
Medium6.2Red Hat

Medium [CVE-2026-71429] Denial of Service due to inefficient processing of deeply nested JSON

stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.5.0, the path filters pick, ignore, filter, and replace in src/core/filters/filter-base.js recompute the full path string from the nesting stack for every checkable token. Because the stack length equals the current nesting depth and a checkable token is emitted at every level, a depth D document costs O(D²) rather than O(D) to process. The issue is triggered by nesting depth rather than byte volume, including the documented pick({filter: 'data'}) traversal-until-match path, so an application that sends untrusted JSON through a string or RegExp filter can block the Node.js event loop and cause denial of service with a small deeply nested document. The streamArray, streamObject, and streamValues streamers are not affected because they use the constant-time asm.depth getter. This issue is fixed in version 3.5.0. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted, deeply nested JSON document. The library's path filters, such as pick and ignore, inefficiently process these structures, leading to excessive resource consumption and blocking the Node.js event loop. Red Hat severity: Moderate — CVSS 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1046.

CVE-2026-71429
Unclassified
Sep 3, 2026
Medium5.3Red Hat

Medium [CVE-2026-85242] Server-Side Request Forgery via favicon redirect

PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon URL to prevent requests to localhost, loopback, or other non-public network addresses. However, redirects followed by aiohttp were not subjected to the same validation. An attacker able to influence the content of a page processed by PlaywrightCapture could specify a publicly reachable favicon URL that responds with an HTTP redirect to a local or otherwise restricted address, such as 127.0.0.1, localhost, or an internal network service. Because aiohttp automatically followed the redirect, the resulting request could bypass the application's local-address restrictions and cause the PlaywrightCapture host to issue HTTP requests to resources that should not be externally reachable. Depending on the services reachable from the PlaywrightCapture host and how retrieved favicon data is subsequently exposed or processed, this could be used to probe internal HTTP services or potentially obtain information from otherwise inaccessible endpoints. The patch introduces an aiohttp request middleware that applies the existing local-URL validation to every request in the redirect chain. Requests resolving to restricted/local destinations are rejected before they are issued.

CVE-2026-85242
Unclassified
Sep 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-19475] OOM DoS via $__timeGroup macro

An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected. The request can be repeated once the instance restarts. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-400. Affected Red Hat products: Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat Enterprise Linux 10. Red Hat lists Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: grafana.

CVE-2026-19475
Red Hat Enterprise Linux
Sep 3, 2026
Medium5.4Red Hat

Medium [CVE-2026-56128] pfSense Plus: CE: pfSense Plus and CE: Stored Cross-Site Scripting (XSS) via firewall schedule description.

pfSense Plus: CE: pfSense Plus and CE: Stored Cross-Site Scripting (XSS) via firewall schedule description. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79.

CVE-2026-56128
Unclassified
Sep 3, 2026
Medium4.7Red Hat

Medium [CVE-2026-71224] stack overflow via alloca(i_height) in metadata walk

A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when processing crafted GFS2 filesystem images. This vulnerability is assessed as Moderate impact because the alloca-based stack exhaustion results in a process crash (SIGSEGV) rather than controlled memory corruption. RHEL stack guard pages prevent the overflow from reaching other memory regions, confining the impact to denial of service. Exploitation requires local access and user interaction (an administrator must run fsck.gfs2 or other gfs2-utils tools on a crafted GFS2 filesystem image). The vulnerability does not affect the kernel GFS2 driver, which validates i_height against sd_max_height. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gfs2-utils.

CVE-2026-71224
Red Hat Enterprise Linux
Sep 3, 2026
Medium5.3Red Hat

Medium [CVE-2026-71222] heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing

A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images. This vulnerability is assessed as Moderate impact because the ea_num_ptrs heap over-read is a read-only operation that cannot corrupt memory. The primary risk is information disclosure (heap memory contents leaked through tool output) and potential denial of service if the over-read crosses a page boundary. Exploitation requires local access and user interaction (an administrator must run a gfs2-utils tool on the crafted image). The vulnerability does not affect the kernel GFS2 driver. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gfs2-utils.src.

CVE-2026-71222
Red Hat Enterprise Linux
Sep 3, 2026
Medium4.7Red Hat

Medium [CVE-2026-71219] stack overflow via alloca(1<<di_depth) in hash table traversal

A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta. This vulnerability is assessed as Moderate impact because the alloca-based stack exhaustion results in a process crash (SIGSEGV) rather than controlled memory corruption. Exploitation requires local access and user interaction: an administrator must run a gfs2-utils tool (fsck.gfs2, gfs2_edit, or savemeta) on a crafted GFS2 filesystem image. The vulnerability does not affect the kernel GFS2 driver, which validates di_depth in gfs2_dinode_in(). Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gfs2-utils.

CVE-2026-71219
Red Hat Enterprise Linux
Sep 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-85089] Information disclosure via uninitialized heap memory in Save Session Info PDU

FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) use Stream_Seek instead of Stream_Zero for reserved pad bytes (up to 576 bytes), leaving previously freed heap contents in the outgoing PDU. Because the send buffer is allocated with malloc (not zeroed), stale heap data — which may include cleartext credentials from prior sessions — can be sent to the receiving peer. FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy (which forwards these PDUs) are affected, allowing disclosure of server/proxy process memory to a downstream client. A flaw was found in FreeRDP. This vulnerability allows a remote attacker with low privileges to disclose sensitive information from the server or proxy process memory to a downstream client. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-908. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:75570. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-85089
Red Hat Enterprise Linux
Sep 3, 2026

← All vendors