Red hat enterprise linux
This hub aggregates every CVE we track for Red hat enterprise linux, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
938
CVEs tracked
19
Critical
327
High
1
In CISA KEV
Severity distribution
MEDIUM516HIGH327LOW76CRITICAL19
Monthly trend
15
11
19
1
11
25
18
29
18
29
19
8
13
10
17
8
18
20
38
45
25
86
94
46
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat enterprise linux.
- CVE-2026-19548Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing5.5
- CVE-2026-18663389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext() via critical session tracking control5.9
- CVE-2026-19550Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes4.3
- CVE-2026-14180Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap5.3
- CVE-2026-19546Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via caller-influenced profile attribute8.8
- CVE-2026-71218Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated remote memory exhaustion5.3
- CVE-2026-71217Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabling remote denial of service via resource exhaustion7.5
- CVE-2026-72693Kbd: local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login7.8
- CVE-2026-72694Mrtg: mrtg daemon symlink-following chown allows local privilege escalation via pid file path manipulation7.1
- CVE-2026-19391Insights-core: insights-core: incomplete credential redaction exposes sssd bind passwords and pacemaker fence credentials in uploaded archives6.5
- CVE-2026-6426Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access4.4
- CVE-2026-19411Shim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns null3.9
- CVE-2026-63622Libvirt: swtpm privilege escalation via symlink following7.8
- CVE-2026-59091Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image file7.3
- CVE-2026-63623Libvirt: information disclosure via world-readable storage volume images during clone/convert5.5
Product normalization is registry-driven with AI assist and human review. How it works