Red hat enterprise linux
This hub aggregates every CVE we track for Red hat enterprise linux, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
10,805
CVEs tracked
903
Critical
4,210
High
110
In CISA KEV
Severity distribution
MEDIUM5,204HIGH4,210CRITICAL903LOW488
Monthly trend
150
184
128
183
107
288
149
127
254
259
282
69
377
346
75
199
107
45
117
89
57
96
94
31
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat enterprise linux.
- CVE-2026-59090Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow8.4
- CVE-2026-59088Gimp: gimp: denial of service via signed integer overflow in fli file processing5.5
- CVE-2026-59087Gimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes attacker-controlled length into undersized allocation7.8
- CVE-2026-19404389-ds-base: 389-ds-base: missing authorization allows anonymous clients to start or abort cleanallruv replication maintenance6.5
- CVE-2026-19389Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read7.1
- CVE-2026-19387Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec ima/dvi adpcm decoder7.6
- CVE-2026-42170Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_layer() (ddsread.c)7.8
- CVE-2026-61477Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection2.3
- CVE-2026-15816Dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die()7.5
- CVE-2026-18938P11-kit: integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems6.2
- CVE-2026-19079Policycoreutils: policycoreutils: toctou race condition in fixfiles allows arbitrary selinux label manipulation4.4
- CVE-2026-7867Udisks2: udisks2: local privilege escalation via as-user option spoofing7.8
- CVE-2026-18649Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders7.5
- CVE-2026-18839Popt-devel: popt-static: size_t underflow in singleoptionhelp2.2
- CVE-2026-44605Rpm: heap buffer overflow in ndb slot table parsing5.5
Product normalization is registry-driven with AI assist and human review. How it works