Red Hat Enterprise Linux

322 known vulnerabilities in Red Hat Enterprise Linux, 26 critical, 5 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-31431 CVSS 7.8 high · actively exploited Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
  • CVE-2026-34486 CVSS 7.5 high · actively exploited Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
  • CVE-2026-34197 CVSS 8.8 high · actively exploited Apache ActiveMQ Improper Input Validation Vulnerability
  • CVE-2025-31277 CVSS 8.8 high · actively exploited Apple Multiple Products Buffer Overflow Vulnerability
  • CVE-2023-4911 CVSS 7.8 high · actively exploited GNU C Library Buffer Overflow Vulnerability

Latest vulnerabilities

  • CVE-2026-105326 CVSS 2.5 low An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription…
  • CVE-2026-104988 CVSS 8.1 high A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is…
  • CVE-2026-94422 CVSS 8.7 high An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message…
  • CVE-2026-95512 CVSS 5.5 medium A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a…
  • CVE-2026-86345 CVSS 9.0 critical A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating…
  • CVE-2026-86344 CVSS 7.5 high A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an…
  • CVE-2026-103641 CVSS 5.5 medium A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter…
  • CVE-2026-103399 CVSS 5.3 medium A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue and a request body, and…
  • CVE-2026-103242 CVSS 7.1 high A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared…
  • CVE-2026-102560 CVSS 8.6 high A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size…
  • CVE-2026-102559 CVSS 8.6 high A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to…
  • CVE-2026-102558 CVSS 8.6 high A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray…
  • CVE-2026-102555 CVSS 8.2 high A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated…
  • CVE-2026-102557 CVSS 8.6 high A flaw was found in libsoup. When reassembling fragmented WebSocket messages into a GByteArray, libsoup did not adequately cap total…
  • CVE-2026-102556 CVSS 8.6 high A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a…
  • CVE-2026-95520 CVSS 7.1 high A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared…
  • CVE-2026-102474 CVSS 4.0 medium A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \u or \U escape, but the multi-byte token can…
  • CVE-2026-102473 CVSS 5.5 medium A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over…
  • CVE-2026-97029 CVSS 5.7 medium Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching…
  • CVE-2026-97024 CVSS 7.1 high A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to…
  • CVE-2026-97027 CVSS 3.6 low Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus…
  • CVE-2026-97026 CVSS 3.9 low Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems…
  • CVE-2026-97025 CVSS 3.2 low Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory…
  • CVE-2026-97023 CVSS 7.1 high A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to…
  • CVE-2026-102010 CVSS 7.0 high A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library…
  • CVE-2026-96284 CVSS 2.5 low A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the…
  • CVE-2026-96283 CVSS 3.3 low By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from…
  • CVE-2026-96282 CVSS 3.1 low A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host…
  • CVE-2026-96281 CVSS 6.2 medium On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by…
  • CVE-2026-96280 CVSS 7.5 high The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit…