Red hat enterprise linux
This hub aggregates every CVE we track for Red hat enterprise linux, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
10,915
CVEs tracked
906
Critical
4,260
High
112
In CISA KEV
Severity distribution
MEDIUM5,259HIGH4,260CRITICAL906LOW490
Monthly trend
184
128
183
107
288
149
127
254
259
282
69
377
346
75
199
107
45
118
88
58
98
94
100
38
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat enterprise linux.
- CVE-2026-74860Libxml2: double-free/uaf in libxml2 python bindings8.5
- CVE-2026-74859Gnome-tweaks: path traversal in theme installer6.8
- CVE-2026-76561Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint)7.2
- CVE-2026-86469Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path5.3
- CVE-2026-19843389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor8.4
- CVE-2026-18922389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property9.8
- CVE-2026-18453389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results and use_one_backend control in op_shared_search7.5
- CVE-2026-18355389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound underflow in sasl_io_start_packet()7.5
- CVE-2026-76560389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empty bind dn7.5
- CVE-2026-79678Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service8.1
- CVE-2026-76578Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci9.8
- CVE-2026-76925Flatpak: flatpak: toctou race condition allows symlink redirection5.8
- CVE-2026-85769Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize6.5
- CVE-2026-85534Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read5.9
- CVE-2026-81666Corosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems6.5
Product normalization is registry-driven with AI assist and human review. How it works