Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4665 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.7Red Hat

High [CVE-2026-63385] HTTP header handling bugs create risk of access control bypass.

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a path and bypass validation performed on a different representation. evhttp_header_is_valid_value also accepts obsolete line folding in header values containing carriage return or line feed characters, allowing a proxy and libevent to interpret headers differently and enabling header injection or access control bypass. The CRLF header acceptance is fixed in versions 2.1.13 and 2.2.2-alpha, but the reviewed patches do not clearly remediate the URI NUL-truncation condition. A flaw was found in libevent. The evhttp_decode_uri_internal function in http.c decodes percent-encoded %00 bytes into literal NUL characters without rejecting them, allowing an attacker to craft a URI such as /admin/secret%00.jpg where extension-based access checks see.jpg but the server processes /admin/secret, bypassing path-based access controls. Additionally, evhttp_header_is_valid_value accepts obsolete HTTP header line folding (CRLF followed by SP/HT), which RFC 9112 states new implementations should reject, creating a header injection vector in proxy chains where the frontend rejects obs-fold but libevent accepts it.

CVE-2026-63385
Red Hat Enterprise Linux
Aug 20, 2026
High8.6Red Hat

High [CVE-2026-63387] Off-by-one stack buffer overflow leading to denial of service or data corruption

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing DNS record at the end of the 64 KB stack buffer allocated by evdns_server_request_format_response. The final-label check permits j plus label_len plus one to equal buf_len, after which the terminating null byte is written to buf[buf_len]. A crafted DNS server response containing PTR, CNAME, MX, NS, or SOA data can trigger the one-byte out-of-bounds write and crash or corrupt the process. A remote attacker could send a specially crafted DNS server response, which may lead to a crash or corruption of the process, resulting in a denial of service or potential information disclosure and integrity impact. This Important vulnerability in the libevent library's DNS parsing component can lead to a denial of service or data corruption due to an off-by-one stack buffer overflow. A remote attacker can exploit this flaw with low attack complexity by providing a specially crafted DNS server response to services utilizing libevent for DNS resolution. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-787.

CVE-2026-63387
Red Hat Enterprise Linux
Aug 20, 2026
High7.5Red Hat

High [CVE-2026-63384] Denial of Service via integer conversion error in `evtag_unmarshal_header`

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode an attacker-controlled uint32 payload length and returns it as a signed int. Values above INT_MAX become negative or truncated, and evtag_unmarshal_string can use the converted value in allocation sizing, producing a wrapped large allocation request and denial of service. A flaw was found in Libevent. An incorrect integer conversion in the `evtag_unmarshal_header` function allows a remote attacker to provide a specially crafted payload length. This can lead to a wrapped large allocation request, resulting in a denial of service (DoS) for the affected system. This is an Important flaw. A remote attacker can trigger a denial of service in applications utilizing Libevent's event tagging feature by sending a specially crafted payload. The incorrect integer conversion can lead to excessive memory allocation, causing resource exhaustion. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Cert Manager support for Red Hat OpenShift release 1.20; and 6 more.

CVE-2026-63384
Red Hat Enterprise Linux
Aug 20, 2026
High7.7Red Hat

High [CVE-2026-63382] Multiple HTTP Parser Bugs Enable Request Smuggling

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, and bare line feeds in chunked framing. evhttp_find_header can select only the first header, evhttp_check_transfer_encoding_ was absent so the previous whole-string comparison fails to recognize valid lists ending in chunked, and evhttp_handle_chunked_read uses EVBUFFER_EOL_CRLF rather than EVBUFFER_EOL_CRLF_STRICT, accepting bare LF chunk terminators. When libevent is deployed behind a proxy that frames the same request differently, an unauthenticated remote attacker can desynchronize request boundaries and smuggle a second request, potentially bypassing access controls or poisoning caches. Red Hat Enterprise Linux, OpenShift (RHCOS), RHIVOS, and community products (Fedora, Hummingbird) ship affected versions of libevent. Red Hat severity: Important — CVSS 7.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L). Weakness: CWE-444. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Cert Manager support for Red Hat OpenShift release 1.20; Red Hat Hardened Images; Red Hat Update Infrastructure 5; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat OpenShift Container Platform 4.

CVE-2026-63382
Red Hat Enterprise Linux
Aug 20, 2026
High7.5Red Hat

High [CVE-2026-63495] Remote denial of service via unbounded memory accumulation in WebSocket server

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenticated remote client can repeatedly send fragmented WebSocket frames below WS_MAX_RECV_FRAME_SZ with FIN=0, causing the evbuffer to grow without bound until the process or host exhausts memory. This issue is fixed in version 2.2.2-alpha. A flaw was found in Libevent. Due to a lack of a total message-size limit, these fragmented frames accumulate in memory without bound, leading to memory exhaustion and a denial of service (DoS) for the process or host. Important: A remote denial of service flaw exists in the libevent WebSocket server due to unbounded memory accumulation. An unauthenticated attacker can exploit this by sending fragmented WebSocket frames, leading to memory exhaustion and service unavailability. This is rated Important because it allows a remote attacker to cause a complete denial of service without authentication or user interaction, impacting the availability of affected systems. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 6; Red Hat OpenShift Container Platform 4.

CVE-2026-63495
Red Hat Enterprise Linux
Aug 20, 2026
High7.5Red Hat

High [CVE-2026-63383] Denial of Service via malformed RPC data

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at most five bytes from evbuffer_pullup but iterates using the full logical buffer length. A fragmented evbuffer containing a six-byte malformed tag can therefore advance past the pullup window and trigger an out-of-bounds read, which can crash a process that decodes attacker-controlled tagged RPC data. A remote attacker could exploit an out-of-bounds read vulnerability in the `decode_tag_internal()` function by sending specially crafted, attacker-controlled tagged RPC (Remote Procedure Call) data. This could lead to a denial of service, causing the process that decodes the data to crash. This Important flaw in libevent can lead to a denial of service. An attacker could send specially crafted RPC data to a service utilizing libevent, causing an out-of-bounds read and crashing the application. This vulnerability primarily affects applications that process untrusted RPC data using libevent. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Cert Manager support for Red Hat OpenShift release 1.20; and 6 more.

CVE-2026-63383
Red Hat Enterprise Linux
Aug 20, 2026
High8.4Red Hat

High [CVE-2026-63388] Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX peer address into bufferevent_private.conn_address. Release builds compiled with NDEBUG disable the EVUTIL_ASSERT length guard, and the evhttp accept path can pass a 110-byte sockaddr from accept() into the 28-byte field. An unauthenticated local peer able to connect to an AF_UNIX listener can overwrite the adjacent dns_request pointer and heap data, causing memory corruption with confidentiality, integrity, and availability impact. A flaw was found in Libevent. A heap out-of-bounds write vulnerability in the `bufferevent_socket_set_conn_address_` function allows an unauthenticated local peer to achieve arbitrary code execution. By connecting to an AF_UNIX listener, an attacker can overwrite critical heap data, leading to memory corruption and potentially full control over the affected system. By connecting to an AF_UNIX listener, an attacker can trigger a heap out-of-bounds write, leading to memory corruption and high impact on system confidentiality, integrity, and availability. The local attack vector limits the immediate threat, but the unauthenticated nature and severe consequences elevate its importance.

CVE-2026-63388
Red Hat Enterprise Linux
Aug 20, 2026
High7.4Red Hat

High [CVE-2026-54770] Open redirect vulnerability leading to phishing and token theft

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An attacker-controlled value such as a space followed by a protocol-relative or absolute URL can therefore bypass SCHEME_RE and startswith("//") checks and be normalized to an off-host redirect. Request.relative_url() and webob.exc._HTTPMove subclasses, including HTTPFound, are also affected because they use the same unsafe URL joining behavior or bypass the earlier normalization path. An unauthenticated attacker who can influence an application's redirect target can send users to an attacker-controlled host for phishing or OAuth and SSO token theft, but exploitation requires the user to follow the redirect. This issue is fixed in version 1.8.11. This vulnerability allows an unauthenticated attacker to bypass URL validation checks by injecting leading control characters or spaces into a redirect target. This can lead to an open redirect, enabling attackers to send users to malicious websites for phishing or to steal OAuth and Single Sign-On (SSO) tokens. This is an open redirect vulnerability in the WebOb library.

CVE-2026-54770
Unclassified
Aug 20, 2026
High8.8Red Hat

High [CVE-2026-15679] Hugging Face PyTorch Image Models: Remote Code Execution via Deserialization of Untrusted Data

Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27987. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-502. Affected Red Hat products: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI). Will not fix / out of support: Red Hat AI Inference Server. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-15679
Unclassified
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18309] Remote Code Execution via APNG file parsing integer overflow

GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of APNG files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29401. A flaw was found in GIMP. Successful exploitation requires user interaction, such as opening a malicious file. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18309
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18308] Remote Code Execution via TIF File Parsing Integer Overflow

GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29405. A flaw was found in GIMP. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18308
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18307] Remote code execution via TIF file parsing heap-based buffer overflow

GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29404. A flaw was found in GIMP. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-131. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:62507, RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18307
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18306] Remote Code Execution via SGI File Parsing Integer Overflow

GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SGI files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29396. A flaw was found in GIMP. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:62507, RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18306
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18305] Remote Code Execution via TIF file parsing integer overflow

GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29406. A flaw was found in GIMP, an image manipulation program. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:62507, RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18305
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18304] Arbitrary code execution via crafted TIF file parsing

GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29403. A flaw was found in GIMP. This vulnerability allows a remote attacker to execute arbitrary code by tricking a user into opening a specially crafted TIF file. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:62507, RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18304
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18303] Remote code execution via TIF file parsing vulnerability

GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29399. A flaw was found in GIMP. The issue stems from insufficient validation of user-supplied data length before copying it to a buffer, leading to potential code execution in the context of the current process. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:62507, RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18303
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18302] Remote code execution via TIF file parsing heap-based buffer overflow

GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29398. A flaw was found in GIMP. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18302
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18301] Remote code execution via PSD file parsing integer overflow

GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PSD files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29395. A flaw was found in GIMP. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:62507, RHSA-2026:61587. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-18301
Red Hat Enterprise Linux
Aug 20, 2026
High7.8Red Hat

High [CVE-2026-18300] Remote code execution via integer overflow in HDR file parsing

GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29289. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:62420, RHSA-2026:62425, RHSA-2026:62170. Affected products named by the advisory: Red Hat package: gegl04; Red Hat package: gimp.

CVE-2026-18300
Red Hat Enterprise Linux
Aug 20, 2026
High8.8Red Hat

High [CVE-2026-18299] Remote Code Execution via Use-After-Free in rtpsbcdepay

A flaw was found in GStreamer. This use-after-free vulnerability in the rtpsbcdepay element, specifically during the processing of Real-time Transport Protocol (RTP) payload elements, allows a remote attacker to execute arbitrary code. The issue arises from a lack of validation for an object's existence before operations are performed on it. Successful exploitation can lead to arbitrary code execution within the context of the current process. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-386. Affected Red Hat products: Red Hat Enterprise Linux AppStream EUS (v. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7 as not affected. Red Hat fixing advisory: RHSA-2026:71650, RHSA-2026:59972, RHSA-2026:59179, RHSA-2026:71646, RHSA-2026:71647, RHSA-2026:71648, RHSA-2026:59152. 8); Red Hat Enterprise Linux AppStream E4S (v.9.2); and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 8); Red Hat Enterprise Linux AppStream E4S (v.9.4); and 7 more.

CVE-2026-18299
Red Hat Enterprise Linux
Aug 20, 2026

← All vendors