Red Hat Enterprise Linux (RHEL)
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Red Hat Enterprise Linux (RHEL).
Recent Red Hat Enterprise Linux (RHEL) Security Advisories
| Advisory | Title | Published |
|---|---|---|
| RHSA-2026:46956 | (RHSA-2026:46956) Red Hat Enterprise Linux AI 3.3.5 | July 27, 2026 |
| RHSA-2026:43855 | (RHSA-2026:43855) Red Hat Enterprise Linux AI 3.3.5 | July 22, 2026 |
| RHSA-2026:43853 | (RHSA-2026:43853) Red Hat Enterprise Linux AI 3.3.5 | July 22, 2026 |
| RHSA-2026:43854 | (RHSA-2026:43854) Red Hat Enterprise Linux AI 3.3.5 | July 22, 2026 |
| RHSA-2026:43851 | (RHSA-2026:43851) Red Hat Enterprise Linux AI 3.3.5 | July 22, 2026 |
| RHSA-2026:43670 | (RHSA-2026:43670) Red Hat Enterprise Linux AI 3.3.5 | July 22, 2026 |
| RHSA-2026:43651 | (RHSA-2026:43651) Red Hat Enterprise Linux AI 3.3.5 | July 22, 2026 |
| RHSA-2026:33531 | (RHSA-2026:33531) Red Hat Enterprise Linux AI 3.4.1 enhancement update | June 30, 2026 |
| RHSA-2026:33524 | (RHSA-2026:33524) Red Hat Enterprise Linux AI 3.4.1 enhancement update | June 30, 2026 |
| RHSA-2026:17611 | (RHSA-2026:17611) Red Hat Enterprise Linux AI 3.3.3 | May 14, 2026 |
By the Year
In 2026 there have been 1230 vulnerabilities in Red Hat Enterprise Linux (RHEL) with an average score of 7.1 out of ten. Last year, in 2025 Enterprise Linux (RHEL) had 213 security vulnerabilities published. That is, 1017 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.54.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1230 | 7.07 |
| 2025 | 213 | 6.52 |
| 2024 | 172 | 6.36 |
| 2023 | 213 | 6.38 |
| 2022 | 176 | 6.72 |
| 2021 | 148 | 6.50 |
| 2020 | 104 | 6.35 |
| 2019 | 293 | 6.21 |
| 2018 | 113 | 7.02 |
It may take a day or so for new Enterprise Linux (RHEL) vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Red Hat Enterprise Linux (RHEL) Security Vulnerabilities
xdg-dbus-proxy <0.1.9 Bypass DBus Message Filtering, Code Exec
CVE-2026-94422
8.8 - High
- October 02, 2026
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox boundary for Flatpak, but it is released as a separate project and is sometimes used by other app frameworks such as Firejail.
Authentication Bypass by Spoofing
FreeType CID Font Loader Memory DoS via Repeated Allocations
CVE-2026-95512
5.5 - Medium
- October 02, 2026
A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.
Resource Exhaustion
389-ds-base LDAP StartTLS buffer injection allows auth bypass
CVE-2026-86345
9 - Critical
- October 01, 2026
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a client application to treat a failed authentication (bind) attempt as successful.
Improper Restriction of Communication Channel to Intended Endpoints
389-ds LDAP Thread Exhaustion DoS via Incomplete LDAPMessage
CVE-2026-86344
7.5 - High
- October 01, 2026
A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing delivery of the completed operation's result. Repeating this across a small number of connections proportional to the configured worker-thread pool size exhausts the entire pool under default configuration, denying service to all clients (anonymous and authenticated, plaintext and TLS) for as long as the attacker maintains the connections.
Resource Exhaustion
Heap Buffer Overflow in rpm via Symlink Entry Parsing
CVE-2026-95520
7.1 - High
- September 29, 2026
A heap-based buffer overflow flaw was found in rpm. Parsing a symlink entry in an untrusted RPM package whose declared RPMTAG_LONGFILESIZES value is 0xFFFFFFFFFFFFFFFF causes an integer overflow in iterReadArchiveNext() that shrinks a buffer allocation to one byte, after which the payload's independently-controlled cpio filesize field is used to write attacker-controlled data past the end of that allocation. This is reachable via rpm2cpio, rpm2archive, and rpm -qlvp on an untrusted package.
Memory Corruption
Flatpak PID NS Leak: kill(0) Kills Unsandboxed Processes
CVE-2026-97029
5.7 - Medium
- September 29, 2026
Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause denial of service by terminating processes outside its sandbox, such as the desktop shell.
Separation of Privilege
Flatpak Path Traversal Vulnerability Evicts Host Files via App Deployment
CVE-2026-97024
7.1 - High
- September 29, 2026
A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files (such as passwd, group, machine-id, or resolv.conf) to be emptied or replaced with a symlink when the app is installed or upgraded. In system-wide installations, the write is performed as root.
Symlink following
Flatpak Vendor-Extension Key Injection in Desktop Entry Export
CVE-2026-97027
3.6 - Low
- September 28, 2026
Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.desktop) and D-Bus Service (.service) files, instead of validating against an allowlist. A malicious Flatpak app can use this to cause denial of service (e.g. forced application restart loops) or to influence host D-Bus/systemd activation behavior beyond what the sandbox is intended to permit.
Improper Input Validation
Flatpak Temp Dir 0777 Permission (CVE-2026-97026)
CVE-2026-97026
3.9 - Low
- September 28, 2026
Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation failures (denial of service); tampered content would fail signature/digest verification rather than being trusted.
Creation of Temporary File With Insecure Permissions
World-Readable OCI Auth Token Exposure in Flatpak System-Helper
CVE-2026-97025
3.2 - Low
- September 28, 2026
Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not.
Creation of Temporary File With Insecure Permissions
Flatpak Export/bin Path Traversal Enables File Deletion
CVE-2026-97023
7.1 - High
- September 28, 2026
A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files outside the deployment directory when the app is installed or upgraded. In system-wide installations, the deletion is performed as root.
Symlink following
Flatpak System-Helper Symlink Traversal Grants File Read
CVE-2026-96284
2.5 - Low
- September 27, 2026
A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
insecure temporary file
Flatpak Extension Host FS Enumeration & Unvalidated Metadata Mount
CVE-2026-96282
3.1 - Low
- September 27, 2026
A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally, unvalidated extension metadata can cause extension content to be mounted at unintended locations inside the sandbox.
insecure temporary file
Flatpak SystemHelper: CancelPull Abuse
CVE-2026-96283
3.3 - Low
- September 27, 2026
By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.
AuthZ
Flatpak Downgrade via Unprivileged RemoveLocalRef on Multi-user Linux
CVE-2026-96281
6.2 - Medium
- September 27, 2026
On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the app's remote ref via the unprivileged system-helper RemoveLocalRef method, causing the anti-downgrade check to fail to find a reference date. A malicious local user could use this to expose other users of the same system to an app version with unfixed vulnerabilities.
Authorization
Flatpak OCI Delta Stream Parser Heap Overflow on 32-bit Systems
CVE-2026-96280
7.5 - High
- September 27, 2026
The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially achieving code execution on 32-bit systems.
Numeric Truncation Error
Flatpak Host File Disclosure via Hardlinking from Malicious OCI Registry
CVE-2026-96279
6.5 - Medium
- September 27, 2026
A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak application from an OCI remote, allowing disclosure of arbitrary host file contents. For system-wide installs running as root, this includes sensitive files such as /etc/shadow.
insecure temporary file
Use-after-Free in QEMU 9pfs Enables VM Escape
CVE-2026-93834
8.8 - High
- September 25, 2026
A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and code execution (VM escape) as the QEMU process user.
Dangling pointer
Command Injection via %() Macro in rpm SRPM
CVE-2026-95521
7.8 - High
- September 24, 2026
A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm.
Shell injection
CVE-2026-95519: rpm manifest macro exp. allows RCE
CVE-2026-95519
7.8 - High
- September 24, 2026
A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account.
Shell injection
GIMP OOB Write via Malicious GIMPressionist Preset
CVE-2026-97185
7.8 - High
- September 24, 2026
A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
Memory Corruption
Use-After-Free in librsvg via nested XInclude duplicate entities
CVE-2026-96889
7.8 - High
- September 23, 2026
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
Dangling pointer
GIMP DDS Plugin Heap OutofBounds Read
CVE-2026-96546
2.5 - Low
- September 23, 2026
A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.
Out-of-bounds Read
GIMP TIM Loader OOB Heap Read via Crafted 4bpp TIM Image
CVE-2026-96545
4.4 - Medium
- September 23, 2026
An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it using the larger RGBA row size. This can copy adjacent heap contents into the decoded image and may crash the plug-in.
Out-of-bounds Read
DDoS via RDP keepalive in gnome-remote-desktop
CVE-2026-96541
7.5 - High
- September 23, 2026
A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is closed.
Resource Exhaustion
Flatpak build-init Path Traversal via SDK Extension
CVE-2026-96276
9.8 - Critical
- September 23, 2026
If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.
Directory traversal
Flatpak repo ROOT write via unsanitized extra-data-sources
CVE-2026-96275
8.8 - High
- September 23, 2026
A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.
Directory traversal
sudo Time Window Bypass via TZ in NOTBEFORE/NOTAFTER
CVE-2026-96512
7.8 - High
- September 23, 2026
A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected.
AuthZ
Emacs <31.2 Flymake Arbitrary Code Exec
CVE-2026-96442
7.8 - High
- September 23, 2026
A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary code from the edited file while performing syntax checking. Viewing or editing untrusted files using Emacs could lead to arbitrary code execution with the privileges of the user running Emacs.
Code Injection
Kernel Heap OOB Write via RPC-over-RDMA in Linux
CVE-2026-13087
- September 22, 2026
SSSD LDAP ppolicy failopen: Deleted user retains access
CVE-2026-90462
5.4 - Medium
- September 22, 2026
A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache an allow decision, permitting continued authorization for a deleted or deprovisioned user. A remote attacker with prior valid account context could exploit this to maintain access to information and potentially make limited modifications to resources that should no longer be available.
Improper Handling of Insufficient Permissions or Privileges
rpcbind DoS via unbounded memory growth
CVE-2026-94640
7.5 - High
- September 22, 2026
A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedure Call) statistics in unbounded in-memory lists, leading to persistent memory growth and increased CPU usage. This can degrade or exhaust service availability.
Resource Exhaustion
Integer Overflow in libstdc++ New Operator Causing Memory Corruption
CVE-2026-95619
7.7 - High
- September 22, 2026
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.
Integer Overflow or Wraparound
Heap Overflow in libslirp DHCPv6/TFTP Builders Arbitrary Code Exec
CVE-2026-95508
7.4 - High
- September 22, 2026
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.
Memory Corruption
CUPS Privilege Escalation via cupsfilters Serial Backend Path Bypass
CVE-2026-95511
- September 22, 2026
libstoragemgmt SCSI VPD 0x80 Buffer Overflow in _sg_parse_vpd_80()
CVE-2026-93433
5.5 - Medium
- September 21, 2026
A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System Interface) Vital Product Data (VPD) page 0x80 data. This malformed data, specifically an untrusted page length field, can lead to a stack buffer overflow in the `_sg_parse_vpd_80()` function during serial number parsing. Successful exploitation could result in a denial of service by crashing or destabilizing the process querying the serial number.
Stack Overflow
USBREDIR OOB Write via usbredirhost_iso_packet() (ISO OUT stream)
CVE-2026-92382
4.1 - Medium
- September 21, 2026
An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() and allowing a usbredir peer to write past the end of the packet descriptor array on every subsequent isochronous packet.
Memory Corruption
fetchmail v5.0.86.6.6 NTLM Stack Overflow
CVE-2026-94184
8.1 - High
- September 21, 2026
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening.
Stack Overflow
Red Hat CA pki-core ACL Wildcard Permission Override CVE-2026-80110
CVE-2026-80110
8.1 - High
- September 21, 2026
A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's profile-management REST API this allows a request to POST /v2/profiles/raw -- intended to require Administrator-level profiles.create permission -- to instead be authorized under the lower-privileged profiles.approve permission held by the default Certificate Manager Agents group. The highest threat from this vulnerability is to confidentiality and integrity of the certificate authority's issuance policy.
AuthZ
CRI-O Privilege Escalation via Malicious Checkpoint Restore (before 1.34)
CVE-2026-92574
8.8 - High
- September 21, 2026
A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across the container security boundary. Affected upstream supported versions are CRI-O 1.34 and later. Downstream Red Hat products are affected from OCP 4.17 onward. Fixes have been applied to supported branches but are not yet released. Exploitation requires permission to create a pod from a malicious checkpoint image and checkpoint restore functionality to be available.
Execution with Unnecessary Privileges
cockpit-files symlink exploitation: lowpriv local user can change file ownership
CVE-2026-91202
6.1 - Medium
- September 18, 2026
A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged "Paste as owner" function. This allows for arbitrary file ownership changes outside the intended pasted directory, leading to a compromise of data integrity. In some cases, this could also lead to reduced confidentiality if the new ownership grants unauthorized read access. Exploitation requires user interaction to select a non-original owner during the paste operation.
Symlink following
Red Hat Cockpit-files Symlink Race Local Privilege Escalation
CVE-2026-91203
6 - Medium
- September 18, 2026
A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating directory entries and winning this race, the attacker can redirect these operations to unintended files. This could lead to unauthorized changes in file ownership and permissions on arbitrary files, potentially compromising system integrity and availability by altering system or application states or rendering services unusable.
Race Condition Enabling Link Following
Unprivileged Race Condition in cockpit-files Enables Symlink Attack
CVE-2026-91205
6 - Medium
- September 18, 2026
A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory with a symbolic link (symlink) before the ownership change operation (chown) is applied. This allows the attacker to redirect the ownership change to an arbitrary file, potentially leading to information disclosure or unauthorized modification of sensitive files.
Race Condition Enabling Link Following
cockpitmachines CLI Arg Disclosure: VM Credentials Leaked
CVE-2026-92768
5.5 - Medium
- September 18, 2026
A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or installation. The cockpit-machines component passes password values directly on the command line, making them visible to other local users on systems where process arguments are not restricted. Successful exploitation leads to information disclosure, potentially compromising VM access.
Invocation of Process Using Visible Sensitive Information
Local Inspection Disclosure in cockpit-machines install_machine JSON
CVE-2026-92747
5 - Medium
- September 18, 2026
A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.
Invocation of Process Using Visible Sensitive Information
Local Process Metadata Disclosure in cockpit-machines via RHSM Offline Token Leak
CVE-2026-92745
5 - Medium
- September 18, 2026
A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.
Invocation of Process Using Visible Sensitive Information
Cockpit ILP32 Integer Overflow Enables Unauthorized lastlog Access
CVE-2026-91142
3.6 - Low
- September 18, 2026
A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authenticated user with a specially provisioned large User ID (UID) can cause the computed offset to wrap around. This allows the user to perform unauthorized reads and writes to other users' `lastlog` records, potentially disclosing or altering sensitive login accounting information.
Memory Corruption
Red Hat cockpit-ws Remote Unauthenticated DoS via URL-Root Prefix
CVE-2026-91147
5.9 - Medium
- September 18, 2026
A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made to the exact URL-root prefix without a trailing slash, `cockpit-ws` can terminate unexpectedly. This issue leads to the unavailability of the Cockpit web service.
assertion failure
RedHat Cockpit DoS via Unbounded Thread Creation (CVE-2026-91149)
CVE-2026-91149
7.5 - High
- September 18, 2026
A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of detached threads, consuming system resources such as memory and file descriptors. The primary consequence is a denial of service (DoS), leading to degradation or complete unavailability of the Cockpit service for legitimate users.
Allocation of Resources Without Limits or Throttling
xdg-dbus-proxy D-Bus Broadcast Filter Bypass Enables Flatpak Signal Intercept
CVE-2026-93676
3.2 - Low
- September 18, 2026
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.
Authorization
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Red Hat Enterprise Linux (RHEL) or by Red Hat? Click the Watch button to subscribe.