Red hat enterprise linux
This hub aggregates every CVE we track for Red hat enterprise linux, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
10,987
CVEs tracked
908
Critical
4,293
High
114
In CISA KEV
Severity distribution
MEDIUM5,289HIGH4,293CRITICAL908LOW497
Monthly trend
184
128
183
107
288
149
126
254
259
282
69
377
346
75
199
107
45
118
88
58
98
93
100
113
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat enterprise linux.
- CVE-2026-95521Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm7.8
- CVE-2026-95519Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows)7.8
- CVE-2026-97185Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file7.8
- CVE-2026-96889Librsvg: use-after-free when xml includes have duplicated entities7.8
- CVE-2026-96546Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader2.5
- CVE-2026-96545Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader4.4
- CVE-2026-96541Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline7.5
- CVE-2026-96276Flatpak: flatpak: arbitrary write in host context via flatpak build-init9.8
- CVE-2026-96275Flatpak: flatpak: arbitrary write access as root via extra-data extraction8.8
- CVE-2026-96512Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization7.8
- CVE-2026-96442Emacs: emacs: arbitrary code execution in flymake mode7.8
- CVE-2026-13087Kernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path...8.8
- CVE-2026-90462Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization5.4
- CVE-2026-94640Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service7.5
- CVE-2026-95619Gcc: libstdc++ integer overflow in `new` operator7.7
Product normalization is registry-driven with AI assist and human review. How it works