Red Hat Red Hat Linux OS and other open source products

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Red Hat product.

RSS Feeds for Red Hat security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Red Hat Sorted by Most Security Vulnerabilities since 2018

Red Hat Enterprise Linux (RHEL)2600 vulnerabilities

Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.

Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.

Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop

Red Hat Enterprise Linux Eus1093 vulnerabilities

Red Hat Openshift569 vulnerabilities

Red Hat Rhel Eus552 vulnerabilities

Red Hat Rhel E4s453 vulnerabilities

Red Hat Rhel Tus404 vulnerabilities

Red Hat Rhel Aus400 vulnerabilities

Red Hat Satellite360 vulnerabilities

Red Hat Rhel Eus Long Life315 vulnerabilities

Red Hat Rhel Els308 vulnerabilities

Red Hat Openshift Ai305 vulnerabilities

Red Hat Openstack275 vulnerabilities

Red Hat Hummingbird263 vulnerabilities

Red Hat Jboss Fuse203 vulnerabilities

Red Hat Rhivos199 vulnerabilities

Red Hat Jbosseapxp195 vulnerabilities

Red Hat Build Keycloak190 vulnerabilities

Red Hat Jboss Data Grid171 vulnerabilities

Red Hat Enterprise Linux Ai154 vulnerabilities

Red Hat Openshift Devspaces149 vulnerabilities

Red Hat Quay143 vulnerabilities

Red Hat Single Sign On141 vulnerabilities

Red Hat Rhdh123 vulnerabilities

Red Hat Keycloak123 vulnerabilities

Red Hat Software Collections123 vulnerabilities

Red Hat Cryostat119 vulnerabilities

Red Hat Acm117 vulnerabilities

Red Hat Virtualization115 vulnerabilities

Red Hat Discovery111 vulnerabilities

Red Hat Ai Inference Server104 vulnerabilities

Red Hat Single Sign On95 vulnerabilities

Red Hat Openshift Pipelines93 vulnerabilities

Red Hat Ceph Storage92 vulnerabilities

Red Hat Apache Camel Hawtio91 vulnerabilities

Red Hat Multicluster Engine86 vulnerabilities

Red Hat Amq Streams84 vulnerabilities

Red Hat Service Mesh84 vulnerabilities

Red Hat Logging81 vulnerabilities

Red Hat Camel Spring Boot80 vulnerabilities

Red Hat Amq Broker77 vulnerabilities

Red Hat Ansible Portal77 vulnerabilities

Red Hat Openshift Lightspeed74 vulnerabilities

Red Hat Rhui74 vulnerabilities

Red Hat Serverless74 vulnerabilities

Red Hat Ansible Tower69 vulnerabilities

Red Hat Openshift Gitops67 vulnerabilities

Red Hat Kafka66 vulnerabilities

Red Hat Quarkus63 vulnerabilities

Red Hat 3scale Amp61 vulnerabilities

Red Hat Podman Desktop58 vulnerabilities

Red Hat Apicurio Registry55 vulnerabilities

Red Hat Libvirt55 vulnerabilities

Red Hat Camel Quarkus54 vulnerabilities

Red Hat Service Registry54 vulnerabilities

Red Hat Rhmt54 vulnerabilities

Red Hat Virtualization Host53 vulnerabilities

Red Hat Network Observ Optr50 vulnerabilities

Red Hat Multicluster Globalhub50 vulnerabilities

Red Hat Satellite Capsule49 vulnerabilities

Red Hat Jboss Core Services44 vulnerabilities

Red Hat Directory Server42 vulnerabilities

Red Hat Ansible42 vulnerabilities

Red Hat Http Server42 vulnerabilities

Red Hat Enterprise Linux Aus41 vulnerabilities

Red Hat Gatekeeper40 vulnerabilities

Recent Red Hat Security Advisories

Advisory Title Published
RHSA-2026:47633 (RHSA-2026:47633) Important: kernel security, bug fix, and enhancement update July 29, 2026
RHSA-2026:47632 (RHSA-2026:47632) Important: kernel-rt security, bug fix, and enhancement update July 29, 2026
RHSA-2026:47451 (RHSA-2026:47451) Important: Red Hat Advanced Cluster Management for Kubernetes v2.15.4 security update July 28, 2026
RHSA-2026:47388 (RHSA-2026:47388) Critical: multicluster engine for Kubernetes v2.10.4 security update July 28, 2026
RHSA-2026:47248 (RHSA-2026:47248) Important: kernel security update July 28, 2026
RHSA-2026:47236 (RHSA-2026:47236) Red Hat Hardened Images RPMs Security Update July 28, 2026
RHSA-2026:47231 (RHSA-2026:47231) Red Hat Hardened Images RPMs Security Update July 28, 2026
RHSA-2026:47201 (RHSA-2026:47201) Important: freerdp security update July 28, 2026
RHSA-2026:47184 (RHSA-2026:47184) Important: libtiff security update July 28, 2026
RHSA-2026:46197 (RHSA-2026:46197) Red Hat Hardened Images RPMs bug fix and enhancement update July 28, 2026

By the Year

In 2026 there have been 2349 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1166 security vulnerabilities published. That is, 1183 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.64.




Year Vulnerabilities Average Score
2026 2349 7.23
2025 1166 6.59
2024 1690 6.57
2023 1206 6.75
2022 1362 6.97
2021 1123 6.61
2020 664 6.39
2019 772 6.98
2018 760 7.16

It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Red Hat Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-18107 Jul 28, 2026
CRIU rseq Credential Spo via Checkpoint/Restore A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, allowing it to spoof the process credentials saved in the checkpoint image. On restore, the container process gains elevated capabilities and zeroed UIDs/GIDs. The practical impact on Red Hat products is limited by several factors: checkpoint/restore requires root privileges (podman) or cluster-admin RBAC (OpenShift) to trigger and cannot be initiated from within the container itself; on OpenShift prior to 4.17 the feature required explicit opt-in, and on 4.17+ the kubelet checkpoint API RBAC is not configured by default; OpenShift enforces user namespaces by default for regular workloads (hostUsers is gated behind admin-only SCCs), which makes the spoofed capabilities namespace-scoped and ineffective for privilege escalation; SELinux type enforcement (container_t) blocks privilege transitions independently of capabilities; seccomp filters persist through checkpoint/restore and cannot be corrupted via the parasite; and kernel mount namespace ownership checks on RHEL 9/10 kernels prevent mount-based container escape even with spoofed capabilities.
Enterprise Linux (RHEL)
Openshift
CVE-2026-16313 Jul 28, 2026
Red Hat sg3_utils: sg_inq --export Control Characters Leak A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.
Enterprise Linux (RHEL)
Openshift
CVE-2026-18047 Jul 28, 2026
Dogtag PKI ACME Responder Admin Bypass via URL Trailing Slash A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service.
Certificate System
Enterprise Linux (RHEL)
CVE-2026-49332 Jul 28, 2026
OpenShift OAuth-Proxy Header Injection via Underscore-variant A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.
Openshift
CVE-2026-17072 Jul 28, 2026
gstreamer gst-plugins-good FLAC-Matroska OOB heap read A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a boundary check that does not account for the full size of the data being copied, allowing a small read past the end of the allocated buffer. An attacker could exploit this by crafting a malicious Matroska or WebM file and tricking a user into opening it, potentially leaking a small amount of adjacent heap memory.
Enterprise Linux (RHEL)
CVE-2026-65624 Jul 28, 2026
Cowboy 2.02.18.0 Mem Exhaust via unlimited HTTP headers Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the max_headers limit by counting the number of distinct header names in a map (maps:size(Headers)). When a request contains multiple header lines with the same name, the values are concatenated into a single ever-growing binary stored under that one map key (", " for regular headers, "; " for cookies), so the map size stays at one and the max_headers cap (default 100) is never reached. Because no accumulator bounds the total number of header lines or the total byte size of the header block (only per-line max_header_name_length and max_header_value_length apply), an unauthenticated client can send an arbitrary number of header lines with the same name and grow the connection process's binary memory to arbitrary size within the request window. The impact per connection is bounded by request_timeout (default 5 seconds, not reset by header data), and by max_heap_size when set (the offending connection process is killed once its heap grows past the limit). When max_heap_size is left at the default (unset), sustained abuse can drive the Erlang VM into out-of-memory conditions. This issue affects cowboy from 2.0.0-pre.4 before 2.18.0.
CVE-2026-59248 Jul 28, 2026
cowlib <=2.18.0: unbounded int decode in HPACK/QPACK causes DoS Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and QPACK prefixed-integer decoder cow_hpack_common:dec_big_int/3 in src/cow_hpack_common.hrl (invoked from cow_hpack:decode/2 in src/cow_hpack.erl and from cow_qpack:decode_field_section/3 in src/cow_qpack.erl) reads continuation octets until it sees one whose high bit is clear, evaluating Int + (Value bsl M) at each step with the shift M growing by seven per octet. No limit is enforced on the number of continuation octets, on the resulting bit width, or on the value; the decoder consumes whatever encoded length the peer supplies. Because Erlang integers are immutable, each intermediate Value bsl M and each accumulator update allocates a fresh bignum whose digit width grows linearly with the number of octets processed so far. Summed across the whole decode, the transient bignum digit materialization is on the order of the square of the encoded length. A single maximal HPACK indexed representation carried inside one HTTP/2 HEADERS plus one CONTINUATION frame at Cowboy's default max_frame_size_received can force hundreds of megabytes of transient allocation and garbage-collection churn before the resulting header-table index is rejected as invalid. Repeated or concurrent connections multiply the pressure and can drive the Erlang VM to memory exhaustion. Cowlib is the HTTP parser used by Cowboy, RabbitMQ's management plugin, and other Erlang and Elixir HTTP/2 and HTTP/3 servers and clients, so any exposed endpoint that accepts HPACK or QPACK from an untrusted peer is reachable. This issue affects cowlib: from 2.0.0 before 2.19.0.
CVE-2026-12383 Jul 27, 2026
EDA Server Permissive Access Allows Event Injection via Spoofed Header A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP header value for mTLS authentication without verifying that the header originated from a trusted proxy. Additionally, the expected certificate Distinguished Name is leaked in the 403 error response body. An attacker who can reach the EDA API endpoint with a spoofed Subject header can inject arbitrary events into mTLS-protected event streams, triggering downstream automation actions.
Ansible Automation Platform
CVE-2026-66759 Jul 27, 2026
GIMP icns_plugin OOB Read leaks heap via truncated mask A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed.
Enterprise Linux (RHEL)
CVE-2026-66758 Jul 27, 2026
GIMP file-fits plugin int32 overflow -> heap BO A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service.
Enterprise Linux (RHEL)
CVE-2026-66757 Jul 27, 2026
GIMP file-sgi Plugin: RLE Header Integer Overflows DoS A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize * zsize overflows the standard 32-bit int boundary before being passed to calloc. This integer overflow issue results in undefined behavior, aborting the plugin and causing a denial of service.
Enterprise Linux (RHEL)
CVE-2026-59251 Jul 27, 2026
Erlang OTP public_key Policy Tree DoS via X509 chain (M^K) Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the TLS handshake. During RFC 5280 policy processing in public_key:pkix_path_validation/3, the certificate policy tree maintained by pubkey_policy_tree grows without an upper bound. When a certificate chain contains M policies per certificate and K certificates, the tree grows on the order of M^K nodes because pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2 extend the tree per policy per certificate. A modest chain with many policies per certificate is enough to pin BEAM schedulers and exhaust the node's memory, taking down the entire VM. The attacker only needs to be able to present a certificate chain to the victim, which is the normal precondition for a TLS handshake, so exploitation succeeds against any incoming or outgoing TLS connection that validates the peer's chain (the default for SSL/TLS clients and mutual-TLS servers). This is the same vulnerability class as OpenSSL's X509_verify_cert policy tree DoS. This vulnerability is associated with program files lib/public_key/src/pubkey_policy_tree.erl and program routines pubkey_policy_tree:add_leaves/2 and pubkey_policy_tree:add_leaf_siblings/2. This issue affects OTP from OTP 26.2 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to public_key from 1.15 before 1.21.4, 1.20.3.4 and 1.17.1.5.
CVE-2026-55953 Jul 27, 2026
Erlang OTP SSL TLS1.2/DTLS Client Ignores Server Cipher Suite Before 27.3.4.15 The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5 handler validates the negotiated protocol version and the downgrade sentinel but hands the server-chosen suite directly to ssl_handshake:handle_server_hello_extensions/9, which installs it without a membership check. The TLS 1.3 client path performs this check (per RFC 8446), so it is not affected. An on-path attacker between the client and the intended server can respond with a ServerHello selecting an anonymous key exchange suite such as TLS_DH_anon_* or TLS_ECDH_anon_* that the client never offered. Anonymous suites do not require the server to present a certificate, so the entire verify_peer and cacerts configuration is bypassed: the attacker completes the handshake with its own ephemeral parameters, no certificate is validated, no hostname is checked, and ssl:connect returns {ok, Socket}. All subsequent application traffic is readable and modifiable by the attacker. This issue affects OTP from OTP 17.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to ssl from 5.3.4 before 11.7.4, 11.6.0.4 and 11.2.12.11.
CVE-2026-42792 Jul 27, 2026
Erlang OTP epmd DoS via FD exhaustion (before 27.3.4.15) Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connection slot exhaustion. The do_accept function in erts/epmd/src/epmd_srv.c calls epmd_cleanup_exit() when accept(2) returns EMFILE (per-process file descriptor limit reached) or ENFILE (system-wide file descriptor limit reached), rather than treating these as recoverable conditions. An attacker can exhaust epmd's file descriptor slots by holding many TCP connections open while periodically sending a single byte to reset the idle timeout, then causing accept(2) to return EMFILE, which kills the daemon. epmd has no per-source-IP connection cap, making the attack feasible from a single source. On Debian/Ubuntu default packaging the impact is amplified: the systemd unit inherits a low file descriptor soft limit, and repeated daemon deaths trigger systemd's start-rate-limit, permanently failing both epmd.service and epmd.socket and requiring manual operator intervention to recover. This issue affects OTP from OTP 17.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15.
CVE-2026-15003 Jul 27, 2026
GNU Binutils Linker Heap Buffer Overflow in XCOFF A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-55969 Jul 27, 2026
Apache Thrift <0.24.0 Integer Overflow Vulnerability Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
CVE-2026-48586 Jul 27, 2026
Apache Thrift <0.24: Improper Data Amplification Vulnerability Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
CVE-2026-17527 Jul 27, 2026
CDI view role create on datavolumes/source enables unauthorized PVC clone In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source namespace. A user or service account bound to the view role, commonly granted cluster-wide via ClusterRoleBinding, who also has ordinary write access (edit/admin) to any single namespace, can use this to exfiltrate the contents of any PVC in the cluster into a namespace they control, bypassing namespace isolation and the read-only guarantee of the view role.
Container Native Virtualization
CVE-2026-17523 Jul 27, 2026
Red Hat Kernel Local Privilege Escalation CVE-2026-17523 A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.
Enterprise Linux (RHEL)
CVE-2026-66338 Jul 24, 2026
libsoup Chunked Encoding Parser Permissive RFT Exploit A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests.
Enterprise Linux (RHEL)
CVE-2026-66337 Jul 24, 2026
Heap Over-Read in Libsoup via Unsigned Underflow A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory.
Enterprise Linux (RHEL)
CVE-2026-66339 Jul 24, 2026
libsoup Proxy-Auth Header leakage via CONNECT tunnel A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.
Enterprise Linux (RHEL)
CVE-2026-17107 Jul 24, 2026
RHACM/MCE Service-Proxy Group Impersonation Escalation A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.
Multicluster Engine
CVE-2026-66035 Jul 24, 2026
libssh2 Pre-auth Heap Buffer Overflow via ETM Negotiation (<1.11.1) libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication.
CVE-2026-66034 Jul 24, 2026
libssh2 <=1.11.1 PublicKey OOB Read & Uninit Ptr Free libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region.
CVE-2026-66033 Jul 24, 2026
libssh2 <=1.11.1 AES-GCM Cipher Integer Underflow Crash libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs.
CVE-2026-66032 Jul 24, 2026
Double-Free vulnerability in libssh2 sftp_open() (1.11.1) libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites.
CVE-2026-17039 Jul 24, 2026
Red Hat pki-core Missing Realm Auth on CA Renewal (CVE202617039) A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.
Certificate System
Enterprise Linux (RHEL)
CVE-2026-17059 Jul 24, 2026
Keycloak role-users endpoint leaks user info due to missing admin permission A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-17048 Jul 24, 2026
Keycloak Admin REST API: View-Only Admins Can Leak Client Secrets A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. Due to improper boundary enforcement, a delegated administrator with view-only permissions can retrieve the actual resolved secret instead of the vault placeholder, leading to the exposure of sensitive credentials.
Build Keycloak
Jboss Data Grid
Jbosseapxp
And others...
CVE-2026-16743 Jul 24, 2026
Local File Read via systemd-homed in accountsservice A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the classic handler. A local attacker with a systemd-homed-managed account can read arbitrary files accessible to the accounts-daemon process.
Enterprise Linux (RHEL)
CVE-2026-16730 Jul 24, 2026
dbus-broker DoS via FD exhaustion causing fatal broker exit A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-56391 Jul 24, 2026
OOB Read in GNU coreutils uniq via -w option GNU coreutils uniq is vulnerable to an outofbounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.
CVE-2026-16910 Jul 24, 2026
Red Hat Quay SSRF via Unvalidated URLs in Webhook Notification A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should not be reachable from the application.
Openshift Update Service
Quay
CVE-2026-12353 Jul 23, 2026
Out-of-Memory Crash via TLS Endpoint in RHCS (Java) An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.
Certificate System
Enterprise Linux (RHEL)
CVE-2026-16768 Jul 23, 2026
OOB Read in gdk-pixbuf ICO Parsing A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.
Enterprise Linux (RHEL)
CVE-2026-43823 Jul 23, 2026
swift-crypto 4.5.1: Double-Free in RSA Public Key Init (BoringSSL) When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This vulnerability is addressed in swift-crypto version 4.5.1.
CVE-2026-14257 Jul 23, 2026
brace-expansion 5.0.7 DoS via brace chain memory exhaustion brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays.
CVE-2026-64611 Jul 23, 2026
libcupsfilters Infinite Loop DoS via IEEE-1284 Printer ID A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.
Enterprise Linux (RHEL)
CVE-2026-16745 Jul 23, 2026
Auth Bypass in Red Hat ODH-Dashboard via Network Binding A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
Openshift Ai
CVE-2026-59677 Jul 23, 2026
SELinux Policycoreutils 3.10 Unconfined Kill Auth Bypass A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.
CVE-2026-59676 Jul 23, 2026
seunshare TOCTOU Race in Selinux Policycoreutils 3.10 Arbitrary File Deletion A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.
CVE-2026-64600 Jul 23, 2026
Linux Kernel XFS: Stale Data Mappings Post ILOCK Reacquire Causing DirectIO Race In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and returns an inaccurate value in *shared. If *shared is now false, the directio write proceeds with a stale data fork mapping. Fix this by querying the data fork mapping if the sequence counter changes across the ILOCK cycle.
CVE-2026-6390 Jul 23, 2026
GNU nano multi-buffer format string vulnerability A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may allow an attacker to achieve stack information disclosure, cause a denial of service (crash), or potentially perform arbitrary memory writes.
Enterprise Linux (RHEL)
Openshift
CVE-2026-16615 Jul 22, 2026
Red Hat librest PKCE GRand PRNG flaw A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow.
Enterprise Linux (RHEL)
CVE-2026-16552 Jul 22, 2026
CVE-2026-16552: systemdtmpfiles Symlink Spoofing (Integrity)
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-11605 Jul 22, 2026
Resource Exhaustion via DNSSEC RRSIG Validation in BIND 9 9.20.x-9.21.x The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.
CVE-2026-53910 Jul 22, 2026
Diffutils diff3 Heap Buffer Overflow via Signed Integer Overflows diff3 tool from GNU diffutils is vulnerable to a heapbased buffer overflow due to multiple signed integer overflows in linemapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. When processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform outofbounds writes during internal processing.  An attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment. This issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815  NOTE: The project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges.
CVE-2026-40691 Jul 22, 2026
Unbound 1.9.01.25.1 DNSCrypt TCP DoS In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. The size clamp that protects the UDP path is not applied on the TCP path, so a reply larger than 65504 bytes is shifted forward by 48 bytes inside a buffer of capacity equal to 'msg-buffer-size', writing past the end of the heap allocation. A single malicious encrypted query crashes the resolver and lead to denial of service. This vulnerability needs Unbound to be compiled with DNSCrypt support ('--enable-dnscrypt') and the 'dnscrypt:' clause to be configured and enabled for the listening interfaces.
CVE-2026-16560 Jul 22, 2026
Heap-Ovfl in 389 Directory Server via Legacy-Quoted DN A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation.
Directory Server
Enterprise Linux (RHEL)
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.