Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4620 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-84124] Use-after-free in the DOM: Core & HTML component

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2026:67129, RHSA-2026:68549, RHSA-2026:67133, RHSA-2026:70642. Affected products named by the advisory: Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-84124
Red Hat Enterprise Linux
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84123] Privilege escalation due to use-after-free in the Graphics: WebGPU component

Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-84123
Unclassified
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84122] Use-after-free in the Audio/Video component

Use-after-free in the Audio/Video component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-84122
Red Hat Enterprise Linux
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84118] Use-after-free in the JavaScript: GC component

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-84118
Unclassified
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84117] Privilege escalation in Firefox for Android

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-266. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-84117
Unclassified
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84145] Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40

Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-84145
Red Hat Enterprise Linux
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84121] Sandbox escape due to use-after-free in the DOM: Security component

Sandbox escape due to use-after-free in the DOM: Security component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-84121
Red Hat Enterprise Linux
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84120] Use-after-free in the Audio/Video component

Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-84120
Red Hat Enterprise Linux
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-84119] Sandbox escape due to use-after-free in the DOM: Navigation component

Sandbox escape due to use-after-free in the DOM: Navigation component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-84119
Red Hat Enterprise Linux
Sep 1, 2026
High7.7Red Hat

High [CVE-2026-84196] Server-Side Request Forgery via apiCall.service.url allows information disclosure.

Server-Side Request Forgery via apiCall.service.url allows information disclosure. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918.

CVE-2026-84196
Unclassified
Sep 1, 2026
High7.7Red Hat

High [CVE-2026-84199] Information Disclosure via Server-Side Request Forgery in APICall Feature

Information Disclosure via Server-Side Request Forgery in APICall Feature. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918.

CVE-2026-84199
Unclassified
Sep 1, 2026
High7.7Red Hat

High [CVE-2026-84195] Credential leak via apiCall leads to unauthorized cluster resource control

Credential leak via apiCall leads to unauthorized cluster resource control. Red Hat rates this important (CVSS 7.7). Weakness: CWE-497.

CVE-2026-84195
Unclassified
Sep 1, 2026
High8.1Red Hat

High [CVE-2018-1000130 +1] Incomplete JNDI Denylist in Jolokia JSR-160 Proxy (Bypass of CVE-2018-1000130 Fix)

A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using alternative valid JMX service URL forms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host component. These URLs are accepted as valid `JMXServiceURL` objects and can cause the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. This can result in server-side request forgery (SSRF), forwarding of supplied JMX credentials to the remote endpoint, and potentially remote code execution depending on the classes and configuration available in the target JVM. The incomplete denylist permits specially crafted JMX service URLs to trigger JNDI lookups against attacker-controlled endpoints, potentially leading to remote code execution. This risk is elevated in deployments where the Jolokia JSR-160 proxy is exposed to untrusted input. This vulnerability is an incomplete fix for CVE-2018-1000130. ``` Red Hat Satellite is not affected by this vulnerability.

CVE-2018-1000130CVE-2026-84218
Unclassified
Sep 1, 2026
High7.5Red Hat

High [CVE-2026-82393] Arbitrary file write and code execution via path traversal in tarball dependency manifest

pnpm is a package manager. The overwrite can replace shell startup files, Git hooks, or installed package code and lead to code execution. This issue is fixed in versions 10.34.5, and 11.11.0. A flaw was found in pnpm. This vulnerability allows a remote attacker to perform a path traversal by crafting a malicious tarball dependency's manifest name. This can result in attacker-controlled files overwriting arbitrary filesystem paths, potentially leading to arbitrary code execution on the affected system. This Important vulnerability in pnpm allows arbitrary file write and code execution through a path traversal flaw during tarball dependency installation. An attacker can craft a malicious package.json manifest with a scoped path traversal to overwrite arbitrary files outside the `node_modules` directory, even when `--ignore-scripts` is used. This could lead to system compromise by replacing critical files like shell startup scripts or Git hooks in Red Hat environments where pnpm is used to manage untrusted packages. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-22. Red Hat lists Red Hat AMQ Broker 7; Red Hat Build of Keycloak; Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack as not affected.

CVE-2026-82393
Unclassified
Aug 31, 2026
High7.1Red Hat

High [CVE-2026-82392] Arbitrary Code Execution via Path Traversal

pnpm is a package manager. When dangerouslyAllowAllBuilds or a matching allowBuilds entry permits lifecycle scripts, the escaped package can execute code with the user's privileges. This issue is fixed in versions 10.34.5 and 11.11.0. If the system is configured to allow lifecycle scripts, this path traversal vulnerability can lead to arbitrary code execution with the user's privileges. This is an Important path traversal vulnerability in pnpm that allows an attacker to write arbitrary files outside the intended `node_modules` directory when a user executes `pnpm install` with a specially crafted `pnpm-lock.yaml`. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L). Weakness: CWE-22. Red Hat lists Red Hat AMQ Broker 7; Red Hat Build of Keycloak; Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack as not affected.

CVE-2026-82392
Unclassified
Aug 31, 2026
High8.8Red Hat

High [CVE-2026-83596] Validate the full FeatureList array once in OpenTypeVerticalData findFeature

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. To exploit this issue, an attacker needs to trick a user into processing or loading malicious web content. For this reason, this flaw has been rated with an important severity. Additionally, this issue can cause memory corruption and the possibility of remote code execution is not discarded. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:74084, RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.

CVE-2026-83596
Red Hat Enterprise Linux
Aug 31, 2026
High7.0Red Hat

High [CVE-2026-13732] Gdb: gdb: out-of-bounds write in stabs parser read_member_functions via crafted elf

A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the list length counter is decremented, resulting in an out-of-bounds write when the function list is copied to its final allocated array. An attacker can craft an ELF binary with malicious.stab and.stabstr sections that triggers this out-of-bounds write when a user opens the file in GDB and performs any symbol-inspection operation such as setting a breakpoint. The inferior process does not need to be executed. Under controlled conditions, this was demonstrated to achieve execution of arbitrary commands within the GDB process. While GCC removed STABS emitting support in GCC 13 and GDB deprecated STABS parsing in GDB 17, all deployed GDB versions parse STABS data without user opt-in. An attacker can embed STABS sections in any ELF binary, including one compiled with DWARF debug information, and GDB will parse both. The vulnerability requires the user to open the crafted binary in GDB and issue a symbol-inspection command, which is normal GDB usage. Red Hat severity: Important — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-13732
Red Hat Enterprise Linux
Aug 31, 2026
High7.5Red Hat

High [CVE-2026-17615] RESTeasy SourceProvider remote unauthenticated file read

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted XML body with a DOCTYPE declaration referencing external entities to an endpoint that accepts application/xml and returns Source or StreamSource, the server can be tricked into resolving the entity and including sensitive file contents in the HTTP response. This is due to the SourceProvider.writeTo() method creating a SAXParser without disabling external entity resolution, leading to an XML External Entity (XXE) vulnerability. An attacker can exploit this by sending a crafted XML request to an exposed endpoint that processes `application/xml` and returns `Source` or `StreamSource` types, leading to the disclosure of sensitive server-side files. This affects applications utilizing RESTEasy where endpoints are configured to accept XML input and return `Source` or `StreamSource` objects, potentially exposing sensitive data on Red Hat supported products. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-611. Affected products named by the advisory: Red Hat build of Keycloak 26.6.7; Red Hat Enterprise Linux 9; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apicurio Registry 3; and 5 more.

CVE-2026-17615
Red Hat Enterprise Linux
Aug 31, 2026
High7.0Red Hat

High [CVE-2026-78422] Privilege escalation via PID reuse due to incorrect D-Bus type handling

Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit subject as an unsigned 32-bit integer (D-Bus type u), whereas the org.freedesktop. PolicyKit1.Authority interface specifies a signed 32-bit integer (D-Bus type i). Because of this type mismatch, polkit silently discards the caller-supplied UID and instead determines the subject's owner itself by looking up the PID in /proc, a lookup that is inherently subject to a time-of-check/time-of-use race. Consequently, an application that passes a UID obtained from a trustworthy source — for example SO_PEERCRED Unix socket peer credentials — in order to defend against PID reuse receives no protection, and the supplied UID has no effect on the authorization decision. A local unprivileged attacker who can cause an authorized process to terminate and then win the race to have their own process assigned the same PID can be authorized under the identity of the terminated process, bypassing the polkit authorization check and performing actions the attacker is not entitled to. This issue affects zbus_polkit before 5.1.0. A flaw was found in zbus_polkit. The `Subject::new_for_owner()` function incorrectly encodes the user ID (UID) as an unsigned 32-bit integer instead of a signed 32-bit integer when communicating with the PolicyKit (polkit) authorization framework.

CVE-2026-78422
Unclassified
Aug 31, 2026
High7.5Red Hat

High [CVE-2026-76763] Unauthenticated Denial of Service via large exponent float literals

A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An unauthenticated remote attacker can exploit this by sending a GraphQL query containing a large exponent float literal. This can lead to the allocation of extremely large BigInteger objects, causing CPU exhaustion or an OutOfMemoryError, resulting in a denial of service. This flaw is rated as Important. This can lead to CPU exhaustion or an OutOfMemoryError, as the parsing occurs before authorization and affects commonly used data types like Long or BigInteger. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1284.

CVE-2026-76763
Unclassified
Aug 31, 2026

← All vendors