Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5812 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.4Red Hat

Medium [CVE-2026-56128] pfSense Plus: CE: pfSense Plus and CE: Stored Cross-Site Scripting (XSS) via firewall schedule description.

pfSense Plus: CE: pfSense Plus and CE: Stored Cross-Site Scripting (XSS) via firewall schedule description. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79.

CVE-2026-56128
Unclassified
Sep 3, 2026
Medium4.7Red Hat

Medium [CVE-2026-71224] stack overflow via alloca(i_height) in metadata walk

stack overflow via alloca(i_height) in metadata walk. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: gfs2-utils.

CVE-2026-71224
Red Hat Enterprise Linux
Sep 3, 2026
Medium5.3Red Hat

Medium [CVE-2026-71222] heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing

heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: gfs2-utils.

CVE-2026-71222
Red Hat Enterprise Linux
Sep 3, 2026
Medium4.7Red Hat

Medium [CVE-2026-71219] stack overflow via alloca(1<<di_depth) in hash table traversal

A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta. This vulnerability is assessed as Moderate impact because the alloca-based stack exhaustion results in a process crash (SIGSEGV) rather than controlled memory corruption. Exploitation requires local access and user interaction: an administrator must run a gfs2-utils tool (fsck.gfs2, gfs2_edit, or savemeta) on a crafted GFS2 filesystem image. The vulnerability does not affect the kernel GFS2 driver, which validates di_depth in gfs2_dinode_in(). Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gfs2-utils.

CVE-2026-71219
Red Hat Enterprise Linux
Sep 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-85089] Information disclosure via uninitialized heap memory in Save Session Info PDU

FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) use Stream_Seek instead of Stream_Zero for reserved pad bytes (up to 576 bytes), leaving previously freed heap contents in the outgoing PDU. Because the send buffer is allocated with malloc (not zeroed), stale heap data — which may include cleartext credentials from prior sessions — can be sent to the receiving peer. FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy (which forwards these PDUs) are affected, allowing disclosure of server/proxy process memory to a downstream client. A flaw was found in FreeRDP. This vulnerability allows a remote attacker with low privileges to disclose sensitive information from the server or proxy process memory to a downstream client. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-908. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:75570. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-85089
Red Hat Enterprise Linux
Sep 3, 2026
Medium5.4Red Hat

Medium [CVE-2026-85090] Heap Out-of-Bounds Read in AVC444 Chroma Combine

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane. A flaw was found in FreeRDP. A remote attacker, acting as a malicious Remote Desktop Protocol (RDP) server, can exploit this by sending a specially crafted `RFX_AVC444_BITMAP_STREAM` with specific frame geometry. This can lead to an out-of-bounds memory read, potentially disclosing sensitive heap data to the client or causing a client crash, resulting in a denial of service. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-85090
Red Hat Enterprise Linux
Sep 3, 2026
Medium5.3Red Hat

Medium [CVE-2026-78662] Denial of Service via channel request flooding

Denial of Service via channel request flooding. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-833. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; Confidential Compute Attestation; and 34 more. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Multicluster Engine for Kubernetes; OpenShift API for Data Protection; and 30 more.

CVE-2026-78662
Red Hat Enterprise Linux
Sep 2, 2026
Medium5.3Red Hat

Medium [CVE-2026-56855] Denial of Service via crafted messages

Denial of Service via crafted messages. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-833. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; Confidential Compute Attestation; and 34 more. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Multicluster Engine for Kubernetes; OpenShift API for Data Protection; and 30 more.

CVE-2026-56855
Red Hat Enterprise Linux
Sep 2, 2026
Medium5.6Red Hat

Medium [CVE-2026-84380] Request Smuggling and Connection Desynchronization via Conflicting HTTP Headers

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding header because its setdefault() processing checks each default header independently rather than treating the two framing headers as mutually exclusive. Fixed-size byte, JSON, form, and known-length multipart bodies can therefore be serialized over HTTP/1.1 with both headers, allowing request smuggling or connection desynchronization when downstream intermediaries disagree about which framing header takes precedence. This could allow an attacker to bypass security controls or interfere with network traffic. This vulnerability is rated Moderate. Exploitation requires a high attack complexity, as it depends on how downstream intermediaries process these conflicting headers, leading to limited impact on confidentiality, integrity, and availability. Red Hat severity: Moderate — CVSS 5.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L). Weakness: CWE-444. Affected Red Hat products: Lightspeed Core; Red Hat OpenShift AI (RHOAI). Red Hat lists Migration Toolkit for Applications 8; Red Hat Enterprise Linux command line assistant as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-84380
Unclassified
Sep 2, 2026
Medium5.3Red Hat

Medium [CVE-2026-84379] Multipart header injection via unvalidated input

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-element (filename, content, content_type) tuple and the files= four-element (filename, content, content_type, headers) tuple into multipart/form-data part headers without validating header names or values. CR or LF characters can terminate a part header, inject additional part headers, or end the part header block early, allowing a downstream multipart parser to treat attacker-supplied lines as genuine headers and potentially alter part semantics or bypass header-based checks. This issue is fixed in version 2.11.0. A remote attacker could exploit this vulnerability by sending specially crafted multipart/form-data requests. The `FileField.render_headers()` function fails to validate `Content-Type` values and custom headers, allowing the injection of Carriage Return (CR) or Line Feed (LF) characters. This could lead to the injection of arbitrary part headers, potentially altering the interpretation of multipart data or bypassing security checks by a downstream parser. This Moderate severity flaw in the `httpx2` Python library allows for multipart header injection.

CVE-2026-84379
Unclassified
Sep 2, 2026
Medium5.9Red Hat

Medium [CVE-2026-84378] Denial of Service via crafted Server-Sent Events stream

HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an attacker-controlled or compromised SSE endpoint splits one unterminated line across many response chunks. The behavior affects httpx2.Client.sse() and httpx2.AsyncClient.sse(), and the total processing work grows quadratically with the line length, allowing a crafted stream to consume excessive CPU and block a synchronous worker or asynchronous event loop. This issue is fixed in version 2.10.0. This quadratic processing work consumes excessive CPU resources, leading to a Denial of Service (DoS) by blocking synchronous workers or asynchronous event loops. Moderate: A denial of service vulnerability exists in the HTTPX2 Python client library, affecting Red Hat products such as Lightspeed Core and Red Hat OpenShift AI. This flaw allows a remote attacker to consume excessive CPU resources by sending a specially crafted Server-Sent Events (SSE) stream, leading to resource exhaustion. The impact is limited to availability and requires interaction with a malicious or compromised SSE endpoint. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-606.

CVE-2026-84378
Unclassified
Sep 2, 2026
Medium6.5Red Hat

Medium [CVE-2026-84377] Authenticated Server-Side Request Forgery and credential exposure

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and cause the proxy to send its configured provider credentials to that destination. Request validation in litellm/proxy/auth/auth_utils.py, litellm/proxy/common_request_processing.py, litellm/proxy/health_endpoints/_health_endpoints.py, litellm/proxy/image_endpoints/endpoints.py, and litellm/proxy/litellm_pre_call_utils.py used incomplete checks that did not cover every sensitive parameter or inspect equivalent values across nested request fields, path values, and bracket-notation form data. Routing and credential parameters including api_base, base_url, model_list, fallbacks, and litellm_credential_name could therefore be applied without clearing the operator's stored key, exposing upstream provider credentials and other configured secrets and permitting server-side requests to internal services reachable by the proxy. This issue is fixed in versions 1.88.6 and 1.96.2. A flaw was found in LiteLLM, a proxy server for Large Language Model (LLM) APIs. An authenticated remote attacker could exploit incomplete request validation to redirect outbound provider calls to an attacker-controlled destination.

CVE-2026-84377
Unclassified
Sep 2, 2026
Medium5.3Red Hat

Medium [CVE-2026-53600] Tar entry/content smuggling via PAX extension-header desynchronization

async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension header (a GNU longname L, a GNU longlink K, or a PAX x/g header) instead of to the next file entry. POSIX requires a PAX extended-header record set to describe the next file entry, never an intervening extension header. Because poll_next_raw (src/archive.rs) threads the buffered PAX records into the size computation of whatever raw header it reads next — and that header can be an intermediary L — the stream cursor is advanced by an attacker-chosen amount when the L body is consumed. The parser then desyncs relative to a POSIX-correct tar parser (e.g. GNU tar), reading subsequent bytes at the wrong block boundary. This issue has been patched in version 0.6.1. This allows an attacker to craft a malicious tar archive that manipulates the stream cursor, causing the parser to desynchronize. This desynchronization can lead to differential extraction or tar entry/content smuggling, where async-tar extracts different files or contents than a POSIX-compliant tar parser, potentially allowing an attacker to hide malicious payloads or alter expected file contents. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-1286.

CVE-2026-53600
Unclassified
Sep 2, 2026
Medium4.3Red Hat

Medium [CVE-2026-84646] Unauthorized creation of user objects via deserialization vulnerability

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML. A flaw was found in Jenkins. While these created user objects are not actual Jenkins accounts and cannot be used for login, their unauthorized creation could lead to unexpected behavior or resource manipulation within the Jenkins environment. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-502. Affected Red Hat products: OpenShift Developer Tools and Services. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-84646
Unclassified
Sep 2, 2026
Medium4.3Red Hat

Medium [CVE-2026-53683] IdM/FreeIPA Web UI - Client-side open redirect in reset_password.html

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow. Rated Moderate because exploitation requires a victim to follow a crafted link, and the direct technical impact is limited to a client-side redirect with no data disclosure or modification. The practical risk is phishing/social-engineering enablement rather than a direct technical compromise. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N). Weakness: CWE-601. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: ipa.

CVE-2026-53683
Red Hat Enterprise Linux
Sep 2, 2026
Medium6.4Red Hat

Medium [CVE-2026-82968] Cross-session email verification proof not bound to upstream identity for social providers

A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different account on the same social provider to intercept the process and link their own account to the victim's local profile, gaining unauthorized access. The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires specific timing and user interaction during an active account-linking process. The vulnerability's root cause is the failure to bind the cross-session verification proof to the specific upstream identity for social providers. Weakness: CWE-639. Affected Red Hat products: Red Hat Build of Keycloak; Red Hat Single Sign-On 7. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-82968
Unclassified
Sep 2, 2026
Medium6.8Red Hat

Medium [CVE-2026-12704] SAML assertion replay via skipped InResponseTo validation

SAML assertion replay via skipped InResponseTo validation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-294.

CVE-2026-12704
Unclassified
Sep 2, 2026
Medium4.3Vendor: LowRed Hat

Medium [CVE-2026-84356] UI misrepresentation in FullScreen

UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low) An ui misrepresentation flaw was found in the FullScreen component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Low — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N). Weakness: CWE-1021.

CVE-2026-84356
Unclassified
Sep 1, 2026
Medium4.3Red Hat

Medium [CVE-2026-84327] Incorrect authorization in Autofill

Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) An incorrect authorization flaw was found in the Autofill component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N). Weakness: CWE-551.

CVE-2026-84327
Unclassified
Sep 1, 2026
Medium5.7Red Hat

Medium [CVE-2026-84323] Missing authorization in FileSystem

Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 5.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-425.

CVE-2026-84323
Unclassified
Sep 1, 2026

← All vendors