Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4669 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.1Red Hat

High [CVE-2026-73515] Memory Disclosure and Denial of Service via Malformed FlatGeobuf Buffer

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service. A flaw was found in PostGIS. This can lead to sensitive information disclosure or a denial of service. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:65899. Affected products named by the advisory: Red Hat package: postgresql16-postgis; Red Hat package: postgresql18-postgis.

CVE-2026-73515
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73556] Denial of Service via Regular Expression processing

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer. RegexParser without compile_regex_with_timeout or validation in validate_structured_output_request_lm_format_enforcer, allowing an unauthenticated /v1/completions request against the lm-format-enforcer backend to consume a CPU core and stall the structured-output engine path with a catastrophic regular expression. This issue is fixed in version 0.26.0. An unauthenticated remote attacker can exploit a Regular Expression Denial of Service (ReDoS) vulnerability in the lm-format-enforcer backend. By submitting a specially crafted regular expression through the structured_outputs.regex parameter, the attacker can cause the system to consume excessive CPU resources. This leads to a denial of service, stalling the structured-output engine and preventing legitimate requests from being processed. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1333. Affected Red Hat products: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI). Red Hat lists Red Hat OpenShift AI (RHOAI) as not affected. Will not fix / out of support: Red Hat AI Inference Server.

CVE-2026-73556
Unclassified
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-70452] rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees. A flaw was found in rsync. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-636. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6 as not affected. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462. Affected products named by the advisory: Red Hat package: rsync.

CVE-2026-70452
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-70455] Denial of Service via Zstandard compression thread exhaustion

rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources. By sending requests using the --zt Zstandard compression alias, an attacker can bypass security directives and spawn an excessive number of worker threads. RHEL 9 and older versions are unaffected. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:67463. Affected products named by the advisory: Red Hat package: rsync.

CVE-2026-70455
Red Hat Enterprise Linux
Aug 13, 2026
High8.2Red Hat

High [CVE-2026-70456] Heap Out-of-Bounds Write via crafted argument list

rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory. A flaw was found in rsync. This could lead to corruption of adjacent memory, potentially causing a denial of service or, in some cases, arbitrary code execution. This is an Important severity flaw in rsync, allowing a remote attacker to corrupt heap memory via a specially crafted argument list. The vulnerability, exploitable without authentication or user interaction, could lead to denial of service or potentially arbitrary code execution, elevating its impact beyond Moderate due to the remote, unauthenticated nature of the attack. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462. Affected products named by the advisory: Red Hat package: rsync.

CVE-2026-70456
Red Hat Enterprise Linux
Aug 13, 2026
High8.2Red Hat

High [CVE-2026-70458] Memory corruption via crafted file entries

rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing F_SUM field in the file_struct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data. A flaw was found in rsync. This can lead to denial of service or other unpredictable system behavior. This Important out-of-bounds write vulnerability in rsync can lead to memory corruption when processing specially crafted file entries, potentially resulting in a denial of service. The flaw is triggered when hard-link preservation is inactive, allowing a remote attacker to exploit it without requiring user interaction or elevated privileges. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462. Affected products named by the advisory: Red Hat package: rsync.

CVE-2026-70458
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-70460] rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink

rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent. A path traversal and symlink vulnerability in rsync allows a malicious sender with write access to write files outside the intended directory. By exploiting symbolic links in conjunction with the --partial-dir or --backup-dir options, an attacker can bypass path restrictions to modify arbitrary system files, compromising system integrity Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-59. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462. Affected products named by the advisory: Red Hat package: rsync.

CVE-2026-70460
Red Hat Enterprise Linux
Aug 13, 2026
High8.2Red Hat

High [CVE-2026-70461] Information disclosure and denial of service via crafted files-from entry

rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer. A flaw was found in rsync. This can lead to information disclosure or denial of service. This can be exploited against read-only rsync daemon modules, making it a significant risk for publicly exposed rsync services. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6 as not affected. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462. Affected products named by the advisory: Red Hat package: rsync.

CVE-2026-70461
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-70463] Authorization bypass via `auth users` directive parsing

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing. An authorization bypass flaw was found in the rsync daemon. The auth users directive parser incorrectly handles group names containing spaces due to comma-only tokenization. This flaw causes deny rules to be silently discarded, allowing an authenticated user to bypass restrictions and gain unauthorized access to restricted modules. The flaw allows an authenticated, but unauthorized, user to access restricted rsync modules due to incorrect parsing of deny rules. This bypass occurs because the rsync parser fails to properly tokenize group names with embedded spaces, silently discarding intended access restrictions. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-863.

CVE-2026-70463
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-70464] Denial of Service via handshake stall

rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients. An unauthenticated remote attacker can stall the handshake process by opening multiple concurrent connections and trickling data or stalling prior to module selection. This bypasses standard timeouts and exhausts all available connection slots, preventing legitimate clients from connecting. An unauthenticated remote attacker can exhaust available connection slots by stalling the handshake process, preventing legitimate clients from connecting. This vulnerability primarily affects systems where the rsync daemon is explicitly enabled and exposed to untrusted networks. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more.

CVE-2026-70464
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-53795] Arbitrary file write via --temp-dir or --link-dest options

rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve to paths outside the destination tree, enabling attacker-controlled values to write files to arbitrary locations accessible to the rsync process. A flaw was found in rsync. This bypasses the rename-confinement logic, allowing the attacker to write files to arbitrary locations outside the intended destination tree, potentially leading to unauthorized data modification or system disruption. This occurs when a user is tricked into executing rsync with attacker-controlled absolute paths via the `--temp-dir` or `--link-dest` options, bypassing path confinement. The requirement for user interaction to supply malicious input prevents this from being a Critical severity issue. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H). Weakness: CWE-59. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462. Affected products named by the advisory: Red Hat package: rsync.

CVE-2026-53795
Red Hat Enterprise Linux
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-53793] rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode

rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve outside the chroot boundary when the module root contains a /./ boundary marker. Attackers can exploit improper handling of the /./ notation or forge delta-basis transfers referencing xname paths that cross the /./ boundary to gain unauthorized read or write access to files outside the module's subtree. A flaw was found in rsync. This vulnerability allows remote clients to bypass path confinement, a security measure designed to restrict file access. By crafting specific paths that include a '/./' boundary marker within a chroot environment, an attacker can gain unauthorized read or write access to files outside the intended module's directory. This could lead to sensitive information disclosure or data manipulation. Successful exploitation could lead to unauthorized read and write access to files outside the intended chroot environment, though the attack complexity is high. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-59. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4.

CVE-2026-53793
Red Hat Enterprise Linux
Aug 13, 2026
High7.4Red Hat

High [CVE-2026-53791] rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header

rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address. This allows unauthorized access to restricted resources. Note: Red Hat Enterprise Linux 8 and earlier versions do not contain the vulnerable PROXY protocol implementation and are not affected. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-290. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462. Affected products named by the advisory: Red Hat package: rsync.

CVE-2026-53791
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-53790] rsync < 3.5.0 Command Injection via Multiple Code Paths

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into unsanitized user-supplied values such as hostnames and hostspecs to execute arbitrary commands under the privileges of the rsync process or the invoking user. This Important vulnerability in rsync allows for remote command injection due to insufficient sanitization of user-supplied input across multiple code paths. While the attack complexity is high, successful exploitation could lead to arbitrary command execution under the privileges of the rsync process or the invoking user, impacting confidentiality, integrity, and availability. This risk is particularly relevant in environments where rsync is used for remote synchronization with untrusted sources or destinations. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4.

CVE-2026-53790
Red Hat Enterprise Linux
Aug 13, 2026
High7.1Red Hat

High [CVE-2026-53785] Arbitrary file write via path traversal in --relative mode

rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative paths with symlink components in --relative mode. The make_path() function follows symlinks pointing outside the destination tree while creating intermediate directories without verifying that created paths remain within the destination boundary, enabling arbitrary file writes on the receiver's filesystem. This is an Important vulnerability in rsync where a malicious sender can achieve arbitrary file writes on a receiving system when the `--relative` mode is used. The risk is present in environments where rsync is configured to pull data from untrusted sources with the `--relative` option. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H). Weakness: CWE-59. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462. Affected products named by the advisory: Red Hat package: rsync.

CVE-2026-53785
Red Hat Enterprise Linux
Aug 13, 2026
High7.1Red Hat

High [CVE-2026-53784] Unauthorized File Access via Symlink Module Root

rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, causing subsequent relative-path operations to reference files relative to the symlink target rather than the intended module root, enabling unauthorized file access. A flaw was found in rsync. This is an Important flaw. The rsync daemon is vulnerable to unauthorized file access via path traversal when configured with a symlinked module root and the `use chroot` option is explicitly disabled. This configuration is not default, but if present, a local attacker with low privileges could exploit this to read or write files outside the intended module root. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-59. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462. Affected products named by the advisory: Red Hat package: rsync.

CVE-2026-53784
Red Hat Enterprise Linux
Aug 13, 2026
High8.1Red Hat

High [CVE-2026-53783] Directory escape via TOCTOU race condition in rrsync

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and --log-file through rrsync to read or write files outside the permitted directory subtree. By replacing a validated path component with a symbolic link prior to file transfer execution, an attacker can bypass intended boundary controls and read or write arbitrary files outside the designated directory. An Important TOCTOU race condition in rsync's rrsync wrapper allows authenticated users to manipulate symlinks and escape directory boundaries, granting unauthorized read and write access to files outside the intended subtree. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-59. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8. Red Hat lists Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462.

CVE-2026-53783
Red Hat Enterprise Linux
Aug 13, 2026
High7.0Red Hat

High [CVE-2026-53803] Local Privilege Escalation via Symlink Following

rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations. This Important vulnerability in rsync allows a local attacker to achieve privilege escalation by exploiting a symlink following flaw. In Red Hat environments, the risk is elevated when rsync is configured to run with elevated privileges, such as setuid or in daemon mode, enabling an attacker to overwrite arbitrary files. The requirement for local access and specific privileged configurations prevents a Critical impact. Red Hat severity: Important — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-59. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462. Affected products named by the advisory: Red Hat package: rsync.

CVE-2026-53803
Red Hat Enterprise Linux
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73508] Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns. DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns. DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf objects when IDN.toASCII() or encodeDomainName() rejected a malformed domain name, allowing unauthenticated remote DNS packets to leak direct memory incrementally until denial of service. When processing malformed domain names in DNS packets, the DNS record decoder fails to release allocated memory. An unauthenticated remote attacker who can send DNS traffic to an application using the affected DNS resolution functionality can incrementally exhaust available memory until the process becomes unresponsive, resulting in a complete denial of service. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-772. Affected products named by the advisory: Exploit Intelligence; OpenShift Serverless; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; and 9 more.

CVE-2026-73508
Unclassified
Aug 13, 2026
High7.5Red Hat

High [CVE-2026-73507] Denial of Service via CPU Exhaustion in XmlFrameDecoder

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml. XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated remote attacker could trickle-feed repeated Affected products named by the advisory: Red Hat build of Apache Camel 4.18.4 for Spring Boot 3.5.16; Red Hat Single Sign-On 7.

CVE-2026-73507
Unclassified
Aug 13, 2026

← All vendors