Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4662 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.1Red Hat

High [CVE-2026-77682] JavaScript code injection in autofill via unsanitized CSS selector from element id

JavaScript code injection in autofill via unsanitized CSS selector from element id. Red Hat rates this important (CVSS 7.1). Weakness: CWE-94.

CVE-2026-77682
Unclassified
Aug 21, 2026
High7.8Red Hat

High [CVE-2026-74581] use-after-free in fib6_rule_suppress due to stale res->rt6 pointer

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info. If no later rule supplies a replacement, fib6_rule_lookup() still sees res.rt6 and returns that stale dst to its caller. A suppressing rule can therefore leak a released route back to rt6_lookup(), and the next put hits rcuref_put_slowpath() from dst_release(). Clear res->rt6 when suppressing the route so suppressed lookups fall through to the null dst instead of reusing the released one. A use-after-free vulnerability was found in the Linux kernel's IPv6 FIB rule lookup path. The subsequent dst_release() then operates on freed memory, hitting rcuref_put_slowpath(). A local attacker who can configure IPv6 routing/FIB rules could trigger this to cause a denial of service (kernel crash) or potentially escalate privileges. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-416. Affected products named by the advisory: NVIDIA for RHEL 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-74581
Linux Kernel
Aug 21, 2026
High7.8Red Hat

High [CVE-2026-74583] fix fastmap use-after-free on filter

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_route: fix fastmap use-after-free on filter The route4 classifier maintains a 16-slot fastmap cache that stores raw struct route4_filter pointers indexed by (id, iif). The reader (route4_classify) populates this cache via route4_set_fastmap() for every classified packet that hits a filter. The writer (route4_delete, route4_change) clears the cache via route4_reset_fastmap() before RCU-deferred kfree of the filter. This creates a UAF race: 1. Reader walks the RCU-protected bucket chain, finds filter f 2. Writer unlinks f, calls route4_reset_fastmap(), then tcf_queue_work() 3. Reader calls route4_set_fastmap() and writes f into the cache *after* the writer's reset, caching a pointer about to be freed 4. After the RCU grace period, kfree(f) executes 5. Next classified packet on the same (id, iif) tuple hits the stale fastmap entry and reads f->res from freed memory Reproduced with an mdelay(100) accelerator in route4_set_fastmap() and a concurrent add/delete stress test (provided by both zdi and Santosh). Both triggered KASAN slab-use-after-free reports in the route4 fastmap paths. Fix: Introduce a per-filter boolean dying flag to suppress stale fastmap republishing by in-flight readers.

CVE-2026-74583
Linux Kernel
Aug 21, 2026
High7.3Red Hat

High [CVE-2026-74580] reset the vring metadata cache on vring reconfiguration

In the Linux kernel, the following vulnerability has been resolved: vhost: reset the vring metadata cache on vring reconfiguration vq->meta_iotlb[] caches the vhost_iotlb_map that backs each vring metadata region, and iotlb_access_ok() returns early on a cache hit, taking the hit as proof that the region has already been validated: if (vhost_vq_meta_fetch(vq, addr, len, type)) return true; The cache is reset on VHOST_IOTLB_UPDATE and VHOST_IOTLB_INVALIDATE, on device IOTLB (re)initialisation and on vq reset, but not when VHOST_SET_VRING_ADDR replaces vq->desc, vq->avail and vq->used, nor when VHOST_SET_VRING_NUM changes the region sizes. With a device IOTLB attached both ioctls are accepted while the vq is live, and neither validates the addresses at ioctl time: vq_access_ok() and vq_log_used_access_ok() return true early because the addresses are GIOVAs, deferring validation to prefetch time. Affected products named by the advisory: Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 2 more.

CVE-2026-74580
Linux Kernel
Aug 21, 2026
High7.8Red Hat

High [CVE-2026-74582] use consistent hard_header_len in non-ring send paths

In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in non-ring send paths packet_snd() reads dev->hard_header_len multiple times while allocating and constructing an skb. Device reconfiguration can change this value concurrently, for example through bonding device type changes. For SOCK_RAW, packet_snd() can save a larger value in reserve and later allocate headroom using a smaller value. Moving skb->data back by reserve then places it before skb->head, and the following copy from userspace can attempt an out-of-bounds write. packet_sendmsg_spkt() has the same issue because it calculates its reservation and header offset from separate reads before dropping the RCU read lock to allocate the skb. Add LL_RESERVED_SPACE_EX() for callers that already saved a header length. Read hard_header_len once in packet_snd() and use it for allocation and construction. In packet_sendmsg_spkt(), preserve the allocation-time value through the device lookup retry. The separate SOCK_DGRAM consistency problem between hard_header_len and header_ops->create is not addressed here. An out-of-bounds write problem was observed in packet_sendmsg_spkt in net/packet/af_packet.c in the Linux Kernel. In this flaw, AF_PACKET hard_header_len race may allow local privilege escalation.

CVE-2026-74582
Linux Kernel
Aug 21, 2026
High7.8Red Hat

High [CVE-2026-77652] heap buffer overflow in WPG colormap parser via out-of-bounds palette index

heap buffer overflow in WPG colormap parser via out-of-bounds palette index. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122.

CVE-2026-77652
Unclassified
Aug 21, 2026
High7.8Red Hat

High [CVE-2026-77658] stack buffer overflow in Bus object via unvalidated handle count in project files

stack buffer overflow in Bus object via unvalidated handle count in project files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-121.

CVE-2026-77658
Unclassified
Aug 21, 2026
High8.6Red Hat

High [CVE-2026-72848] Server-Side Request Forgery and Information Disclosure via nested sitemap entries

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to self.scrape_all([loc.text], "xml"), which reaches WebBaseLoader.scrape_all and an aiohttp GET, with no domain comparison and no check for private, loopback or link-local destinations. An attacker who controls or influences an ingested sitemap can therefore point a nested sitemap entry at an internal address and make the server fetch it even when the deploying application set restrict_to_same_domain to True specifically to confine outbound requests. The fetched content is parsed and surfaces in the returned Documents, so internal responses are disclosed to the caller rather than merely requested. A flaw was found in langchain-community. This leads to Server-Side Request Forgery (SSRF) and information disclosure, as internal server responses are parsed and returned to the attacker. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N). Weakness: CWE-918. Affected Red Hat products: Exploit Intelligence; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-72848
Unclassified
Aug 20, 2026
High7.5Red Hat

High [CVE-2026-72818] Denial of Service via crafted URL input

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label separators can be partitioned in exponentially many ways, and because the branch also requires a trailing top-level domain that such input never supplies, the engine explores those partitions before failing at each offset. A few kilobytes of input therefore consumes seconds to minutes of single-threaded CPU, and the HANG_RE substitution performed before matching does not collapse the pattern. TweetTokenizer is intended for tokenizing untrusted social-media text, so any service that applies it, or the module-level casual_tokenize, to submitted text can be stalled per request without authentication. Version 3.10.1 bounds the label repetition. A flaw was found in NLTK. The `TweetTokenizer` component, used for processing social media text, contains a regular expression vulnerability. A remote unauthenticated attacker can provide specially crafted input containing many alternating label separators, causing the regular expression to backtrack catastrophically. This can lead to a Denial of Service (DoS) by consuming significant CPU resources and stalling the application.

CVE-2026-72818
Unclassified
Aug 20, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-55893] Heap buffer overflow with potential code execution

Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking the fixed-size operands[] array. Repeated crafted instructions processed through cs_disasm_iter() or cs_disasm() with CS_ARCH_SH, CS_MODE_SH2A or CS_MODE_SH4A, CS_MODE_SHFPU, and CS_OPT_DETAIL can increment the operand count beyond the 176-byte sh_info allocation and perform a four-byte heap buffer overflow write. The corruption can crash the process and may enable code execution depending on heap layout. This issue is fixed in version 6.0.0-Alpha10. This vulnerability allows a local attacker to provide specially crafted SH2A FPU bytecode, leading to a heap buffer overflow. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-805. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:59419. Affected products named by the advisory: Red Hat package: capstone.

CVE-2026-55893
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-69242] Integer overflow leads to heap buffer overflow and arbitrary memory access

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflow in vips_image_sanity. The resulting buffer-region calculation can access attacker-controlled negative offsets in mmap-resident allocations, allowing reads or writes of other image data, possible data disclosure through uncompressed.v output, and likely process crashes. Remote code execution has not been demonstrated but cannot be ruled out. This issue is fixed in version 8.18.3. A flaw was found in libvips. This overflow leads to a heap buffer overflow, allowing an attacker to access arbitrary memory locations with negative offsets. This is an Important flaw in libvips, where a specially crafted TIFF image can trigger an integer overflow, leading to a heap buffer overflow. This could allow an attacker to achieve arbitrary memory access, potentially resulting in data disclosure, denial of service, or remote code execution. The vulnerability requires local access or user interaction to process the malicious file. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-69242
Unclassified
Aug 20, 2026
High8.8Red Hat

High [CVE-2026-76020] Race condition in V8

Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) A race condition flaw was found in the V8 component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-368.

CVE-2026-76020
Unclassified
Aug 20, 2026
High8.2Red Hat

High [CVE-2026-76023] Improper resource control in Linux Toolkit Theming

Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-708.

CVE-2026-76023
Unclassified
Aug 20, 2026
High8.8Red Hat

High [CVE-2026-76021] Use after free in DOM

Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-76021
Unclassified
Aug 20, 2026
High7.7Red Hat

High [CVE-2026-73137] cross-namespace Secret exfiltration via HelmRelease.repo.secretRef.namespace

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch sensitive credentials from any namespace, which are then sent to an attacker-controlled Helm repository. This can lead to the exfiltration of credentials from arbitrary namespace Secrets, resulting in information disclosure. This allows for unauthorized access to sensitive data across the cluster. Red Hat severity: Important — CVSS 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). Weakness: CWE-200. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17. Red Hat fixing advisory: RHSA-2026:60387, RHSA-2026:60390, RHSA-2026:60388, RHSA-2026:60389, RHSA-2026:60391, RHSA-2026:60386.

CVE-2026-73137
Unclassified
Aug 20, 2026
High7.5Red Hat

High [CVE-2026-43678] Denial of Service via specially crafted WebSocket frame

An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Red Hat lists Red Hat Hardened Images as not affected.

CVE-2026-43678
Unclassified
Aug 20, 2026
High7.5Red Hat

High [CVE-2026-53587] Denial of Service due to heap out-of-bounds read from malicious Git server

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in src/libgit2/transports/smart_pkt.c without first verifying that the smart-protocol pkt-line capability buffer contains 14 bytes. A malicious Git server can make bytes after the pkt-line complete object-format=, causing format_str to advance beyond the pkt-line and the following memchr length calculation to underflow. The resulting heap out-of-bounds walk can crash a client during the first refs-advertisement packet over HTTP, HTTPS, SSH, or the Git protocol. A flaw was found in libgit2. A fixed-size string comparison in the `set_data` function within `transports/smart_pkt.c` does not adequately verify the size of a network packet buffer. A remote attacker, operating a malicious Git server, can send a specially crafted packet-line capability buffer. This can lead to a heap out-of-bounds read, causing the client application to crash and resulting in a Denial of Service (DoS). Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125.

CVE-2026-53587
Red Hat Enterprise Linux
Aug 20, 2026
High7.7Red Hat

High [CVE-2026-63385] HTTP header handling bugs create risk of access control bypass.

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a path and bypass validation performed on a different representation. evhttp_header_is_valid_value also accepts obsolete line folding in header values containing carriage return or line feed characters, allowing a proxy and libevent to interpret headers differently and enabling header injection or access control bypass. The CRLF header acceptance is fixed in versions 2.1.13 and 2.2.2-alpha, but the reviewed patches do not clearly remediate the URI NUL-truncation condition. A flaw was found in libevent. The evhttp_decode_uri_internal function in http.c decodes percent-encoded %00 bytes into literal NUL characters without rejecting them, allowing an attacker to craft a URI such as /admin/secret%00.jpg where extension-based access checks see.jpg but the server processes /admin/secret, bypassing path-based access controls. Additionally, evhttp_header_is_valid_value accepts obsolete HTTP header line folding (CRLF followed by SP/HT), which RFC 9112 states new implementations should reject, creating a header injection vector in proxy chains where the frontend rejects obs-fold but libevent accepts it.

CVE-2026-63385
Red Hat Enterprise Linux
Aug 20, 2026
High8.6Red Hat

High [CVE-2026-63387] Off-by-one stack buffer overflow leading to denial of service or data corruption

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label check permits j plus label_len plus one to equal buf_len, after which the terminating null byte is written to buf[buf_len]. A crafted DNS server response containing PTR, CNAME, MX, NS, or SOA data can trigger the one-byte out-of-bounds write and crash or corrupt the process. A remote attacker could send a specially crafted DNS server response, which may lead to a crash or corruption of the process, resulting in a denial of service or potential information disclosure and integrity impact. This Important vulnerability in the libevent library's DNS parsing component can lead to a denial of service or data corruption due to an off-by-one stack buffer overflow. A remote attacker can exploit this flaw with low attack complexity by providing a specially crafted DNS server response to services utilizing libevent for DNS resolution. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-787.

CVE-2026-63387
Red Hat Enterprise Linux
Aug 20, 2026
High7.5Red Hat

High [CVE-2026-63384] Denial of Service via integer conversion error in `evtag_unmarshal_header`

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. A flaw was found in Libevent. An incorrect integer conversion in the `evtag_unmarshal_header` function allows a remote attacker to provide a specially crafted payload length. This can lead to a wrapped large allocation request, resulting in a denial of service (DoS) for the affected system. This is an Important flaw. A remote attacker can trigger a denial of service in applications utilizing Libevent's event tagging feature by sending a specially crafted payload. The incorrect integer conversion can lead to excessive memory allocation, causing resource exhaustion. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Cert Manager support for Red Hat OpenShift release 1.20; and 6 more.

CVE-2026-63384
Red Hat Enterprise Linux
Aug 20, 2026

← All vendors