CVE-2026-80725
Severity: important
Released on: 29/08/2026
Advisory:
Bugzilla: 2525861
Bugzilla Description: kernel: net: gro: properly validate BIG TCP aggregation criteria
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-56854
Severity: critical
Released on: 28/08/2026
Advisory:
Bugzilla: 2525639
Bugzilla Description: golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions
CVSS Score:
CVSSv3 Score: 9.1
Vector:
CWE: CWE-346
Affected Packages:
Package States: Assisted Installer for Red Hat OpenShift Container Platform 2,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,cert-manager Operator for Red Hat OpenShift,cert-manager Operator for Red Hat OpenShift,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Cryostat 4,External Secrets Operator for Red Hat OpenShift,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift Pipelines,OpenShift Serverless,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Ceph Storage 9,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Workspaces Operator,Red Hat OpenShift Dev Workspaces Operator,Red Hat OpenShift for Windows Containers,Red Hat OpenShift for Windows Containers,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift on AWS,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Security Profiles Operator,Security Profiles Operator,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,
Full Details
CVE document


CVE-2026-82327
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525602
Bugzilla Description: libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist data
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-129
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Update Infrastructure 4 for Cloud Providers,
Full Details
CVE document


CVE-2026-80612
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525366
Bugzilla Description: kernel: net: lwtunnel: Drop skb metadata before LWT encapsulation
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80673
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525367
Bugzilla Description: kernel: ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80661
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525368
Bugzilla Description: kernel: ufs: core: tracing: Do not dereference pointers in TP_printk()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80603
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525369
Bugzilla Description: kernel: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80677
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525370
Bugzilla Description: kernel: driver core: use READ_ONCE() for dev->driver in dev_has_sync_state()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80718
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525371
Bugzilla Description: kernel: mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80697
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525372
Bugzilla Description: kernel: erofs: ensure valid f_path for page cache sharing
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80700
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525373
Bugzilla Description: kernel: drm/vmwgfx: validate external BO copy bounds for both stride paths
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80664
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525374
Bugzilla Description: kernel: netfilter: xt_nat: reject unsupported target families
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80689
Severity: low
Released on: 28/08/2026
Advisory:
Bugzilla: 2525375
Bugzilla Description: kernel: tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80694
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525376
Bugzilla Description: kernel: net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80618
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525378
Bugzilla Description: kernel: drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-832
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80599
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525379
Bugzilla Description: kernel: batman-adv: dat: ensure accessible eth_hdr proto field
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80629
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525380
Bugzilla Description: kernel: octeontx2-af: npc: Fix size of entry2cntr_map
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80667
Severity: low
Released on: 28/08/2026
Advisory:
Bugzilla: 2525381
Bugzilla Description: kernel: net/mlx5: LAG, MPESW, Fix missing complete() on devcom error
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80600
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525382
Bugzilla Description: kernel: batman-adv: dat: acquire ARP hw source only after skb realloc
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80598
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525383
Bugzilla Description: kernel: ntfs3: fix out-of-bounds read in decompress_lznt
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80610
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525384
Bugzilla Description: kernel: net: enetc: fix potential divide-by-zero when num_vsi is zero
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80655
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525385
Bugzilla Description: kernel: soc: xilinx: Fix race condition in event registration
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80682
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525386
Bugzilla Description: kernel: riscv/mm: use physical alignment for vmemmap_start_pfn
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80648
Severity: low
Released on: 28/08/2026
Advisory:
Bugzilla: 2525387
Bugzilla Description: kernel: pinctrl: spacemit: fix NULL check in spacemit_pin_set_config
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80595
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525388
Bugzilla Description: kernel: Input: ims-pcu - add response length checks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80594
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525389
Bugzilla Description: kernel: Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-606
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80654
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525390
Bugzilla Description: kernel: soc: xilinx: Shutdown and free rx mailbox channel
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80670
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525391
Bugzilla Description: kernel: perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1285
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80653
Severity: low
Released on: 28/08/2026
Advisory:
Bugzilla: 2525392
Bugzilla Description: kernel: scsi: hisi_sas: Add slave_destroy interface for v3 hw
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80712
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525393
Bugzilla Description: kernel: spi: spi-qpic-snand: write the feature value before executing SET_FEATURE
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80619
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525394
Bugzilla Description: kernel: apparmor: fix potential UAF in aa_replace_profiles
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80684
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525395
Bugzilla Description: kernel: KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80597
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525396
Bugzilla Description: kernel: mtd: maps: vmu-flash: fix NULL pointer dereference in initialization
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80591
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525397
Bugzilla Description: kernel: f2fs: fix listxattr handling of corrupted xattr entries
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80676
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525398
Bugzilla Description: kernel: Drivers: hv: vmbus: use generic driver_override infrastructure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80707
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525399
Bugzilla Description: kernel: can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80671
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525400
Bugzilla Description: kernel: perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80672
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525401
Bugzilla Description: kernel: ntfs: fix u16 truncation of restart-area length check
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80652
Severity: low
Released on: 28/08/2026
Advisory:
Bugzilla: 2525402
Bugzilla Description: kernel: crypto: ccp - Treat zero-length cert chain as query for blob lengths
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80674
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525403
Bugzilla Description: kernel: ntfs: validate resident attribute lists and harden the validator
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80620
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525404
Bugzilla Description: kernel: Revert "PCI/MSI: Unmap MSI-X region on error"
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80662
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525422
Bugzilla Description: kernel: cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80711
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525445
Bugzilla Description: kernel: power: supply: max17040: handle missing status supplier
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80639
Severity: low
Released on: 28/08/2026
Advisory:
Bugzilla: 2525497
Bugzilla Description: kernel: cxl/test: Fix __fortify_panic
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80604
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525498
Bugzilla Description: kernel: HID: core: Fix OOB read in hid_get_report for numbered reports
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80592
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525499
Bugzilla Description: kernel: samples/damon/mtier: fail early if address range parameters are invalid
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1288
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80636
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525500
Bugzilla Description: kernel: netfilter: conntrack: revert ct extension genid infrastructure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80693
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525501
Bugzilla Description: kernel: idpf: bound interrupt-vector register fill to the allocated array
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80628
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525502
Bugzilla Description: kernel: ALSA: seq: oss: Serialize readq reset state with q->lock
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-820
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80621
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525503
Bugzilla Description: kernel: PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80633
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525504
Bugzilla Description: kernel: iommufd: Take dma_resv lock before dma_buf_unpin() in release path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-414
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80678
Severity: moderate
Released on: 28/08/2026
Advisory:
Bugzilla: 2525505
Bugzilla Description: kernel: i2c: imx: Fix slave registration race and error handling
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80489
Severity: moderate
Released on: 27/08/2026
Advisory:
Bugzilla: 2524870
Bugzilla Description: glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81893
Severity: moderate
Released on: 27/08/2026
Advisory:
Bugzilla: 2524834
Bugzilla Description: gdk-pixbuf: gdk-pixbuf: invalid write in JPEG ICC profile parser on error recovery
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-81624
Severity: important
Released on: 27/08/2026
Advisory:
Bugzilla: 2524868
Bugzilla Description: undertow-core: undertow: WebSocketContainer defaults for buffers and timeouts are infinite
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat build of Apache Camel for Spring Boot 4,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-81658
Severity: moderate
Released on: 27/08/2026
Advisory:
Bugzilla: 2524899
Bugzilla Description: foreman: Cross-tenant disclosure of template revisions via unauthorized audit lookup
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-639
Affected Packages:
Package States: Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-81668
Severity: moderate
Released on: 27/08/2026
Advisory:
Bugzilla: 2524928
Bugzilla Description: rubygem-katello: Cross-tenant Content View Filter rule access and modification via unauthorized parent filter lookup
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-639
Affected Packages:
Package States: Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-38350
Severity: moderate
Released on: 27/08/2026
Advisory:
Bugzilla: 2525313
Bugzilla Description: ffmpeg: FFmpeg: Integer overflow leads to Denial of Service
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-38347
Severity: moderate
Released on: 27/08/2026
Advisory:
Bugzilla: 2525314
Bugzilla Description: ffmpeg: FFmpeg: Heap overflow vulnerability leads to Denial of Service
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-38348
Severity: moderate
Released on: 27/08/2026
Advisory:
Bugzilla: 2525315
Bugzilla Description: ffmpeg: FFmpeg: Denial of Service via crafted image file due to integer overflow
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-38343
Severity: moderate
Released on: 27/08/2026
Advisory:
Bugzilla: 2525320
Bugzilla Description: ffmpeg: FFmpeg: Denial of Service via integer overflow in video scaling
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-38345
Severity: moderate
Released on: 27/08/2026
Advisory:
Bugzilla: 2525325
Bugzilla Description: ffmpeg: FFmpeg: Denial of Service via division-by-zero vulnerability in `ff_sws_init_single_context` function.
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-38346
Severity: moderate
Released on: 27/08/2026
Advisory:
Bugzilla: 2525326
Bugzilla Description: ffmpeg: FFmpeg: Denial of Service via crafted video file due to integer overflow
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-38349
Severity: important
Released on: 27/08/2026
Advisory:
Bugzilla: 2525327
Bugzilla Description: ffmpeg: FFmpeg: Denial of Service via crafted image file due to integer overflow
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-38344
Severity: moderate
Released on: 27/08/2026
Advisory:
Bugzilla: 2525330
Bugzilla Description: ffmpeg: FFmpeg: Denial of Service via crafted video file
CVSS Score:
CVSSv3 Score: 5.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-65642
Severity: important
Released on: 26/08/2026
Advisory:
Bugzilla: 2524738
Bugzilla Description: Plesk: Plesk: Information disclosure and data modification via Insecure Direct Object Reference
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-639
Affected Packages:
Package States: Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-65646
Severity: important
Released on: 26/08/2026
Advisory:
Bugzilla: 2524740
Bugzilla Description: Plesk: Plesk: Remote Privilege Escalation and File Disclosure Vulnerability
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-78
Affected Packages:
Package States: Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-47842
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524636
Bugzilla Description: org.springframework.security/spring-security-core: Spring Security: Information disclosure via deterministic AES/CBC encryption
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1204
Affected Packages:
Package States: OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat Fuse 7,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-80206
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524336
Bugzilla Description: nltk: NLTK: Denial of Service vulnerability in tgrep module
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-1333
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-80205
Severity: important
Released on: 26/08/2026
Advisory:
Bugzilla: 2524331
Bugzilla Description: nltk: NLTK: Denial of Service via unvalidated regular expressions
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1333
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-79654
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2523348
Bugzilla Description: ketello: Katello Content View History API Cross-Organization Authorization Bypass
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-639
Affected Packages:
Package States: Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-78002
Severity: important
Released on: 26/08/2026
Advisory:
Bugzilla: 2521135
Bugzilla Description: rsyslog: rsyslog: Denial of service via heap buffer overflow in RainerScript replace() function
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80179
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524147
Bugzilla Description: jwcrypto: jwcrypto: Denial of Service via malformed JWE tokens
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,
Full Details
CVE document


CVE-2026-80524
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524417
Bugzilla Description: kernel: optee: ffa: Add NULL check in optee_ffa_lend_protmem
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80554
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524419
Bugzilla Description: kernel: s390/vfio_ccw: Limit the number of channel program segments
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80547
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524420
Bugzilla Description: kernel: s390/vfio_ccw: Implement a crw lock
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74749
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524421
Bugzilla Description: kernel: rseq: Prevent hard lockup on granted time slice extension
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74752
Severity: important
Released on: 26/08/2026
Advisory:
Bugzilla: 2524422
Bugzilla Description: kernel: sctp: validate cookie AUTH state before use
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80522
Severity: important
Released on: 26/08/2026
Advisory:
Bugzilla: 2524423
Bugzilla Description: kernel: crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74734
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524424
Bugzilla Description: kernel: firewire: ohci: fix NULL pointer dereference in ar_context_release
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74751
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524425
Bugzilla Description: kernel: riscv: lib: Fix ZBB strnlen reading past count boundary
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74739
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524426
Bugzilla Description: kernel: net/sched: cls_u32: skip hash tables in u32_bind_class()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80575
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524427
Bugzilla Description: kernel: Input: cs40l50-vibra - validate custom data from user space
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80576
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524428
Bugzilla Description: kernel: drm/amdgpu: reject oversized IBs with per-ring packet limits
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74754
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524429
Bugzilla Description: kernel: scsi: core: pair EH runtime PM get and put
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74748
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524430
Bugzilla Description: kernel: netfilter: ipset: fix refcount race between list:set GC and swap
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74744
Severity: important
Released on: 26/08/2026
Advisory:
Bugzilla: 2524431
Bugzilla Description: kernel: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-124
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80537
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524432
Bugzilla Description: kernel: xfs: fix off-by-one in rtrefcount btree root level validation
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80546
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524433
Bugzilla Description: kernel: s390/zcrypt: Improve CCA CPRB length and overflow checks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74753
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524434
Bugzilla Description: kernel: perf: Reject exited events as group leaders
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80585
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524435
Bugzilla Description: kernel: mptcp: fastopen: only mark MPTFO subflows with SYN data
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74743
Severity: important
Released on: 26/08/2026
Advisory:
Bugzilla: 2524436
Bugzilla Description: kernel: macvlan: inherit needed_headroom and needed_tailroom from lowerdev
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-124
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80557
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524437
Bugzilla Description: kernel: libceph: fix OOB read in decode_watchers() via missing bounds check
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80586
Severity: important
Released on: 26/08/2026
Advisory:
Bugzilla: 2524438
Bugzilla Description: kernel: mptcp: options: reset DSS fields in case of unexpected size
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80562
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524439
Bugzilla Description: kernel: gpio: ml-ioh: use raw_spinlock_t for the register lock
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80545
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524440
Bugzilla Description: kernel: s390/zcrypt: Improve EP11 CPRB length and overflow checks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80541
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524441
Bugzilla Description: kernel: drm/amdgpu: validate GEM_CREATE domain combinations
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80553
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524442
Bugzilla Description: kernel: s390/vfio_ccw: Cancel existing workqueues
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80581
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524443
Bugzilla Description: kernel: ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-390
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80529
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524444
Bugzilla Description: kernel: xfs: don't swallow dquot recovery verification errors
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-252
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80523
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524445
Bugzilla Description: kernel: clk: spacemit: k3: set hdma clock as critical
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-909
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74738
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524446
Bugzilla Description: kernel: regmap: sdw-mbq: don't call an unset readable_reg callback
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80527
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524447
Bugzilla Description: kernel: ceph: fix hanging __ceph_get_caps() with stale mds_wanted
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80567
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524449
Bugzilla Description: kernel: Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74750
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524450
Bugzilla Description: kernel: ovpn: defer key slot crypto freeing to workqueue
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80531
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524451
Bugzilla Description: kernel: xfs: avoid UAF on sc->tempip in xrep_tempfile_create
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80539
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524452
Bugzilla Description: kernel: drm/amdgpu: disallow multiple FENCE chunks in one submit
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80538
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524453
Bugzilla Description: kernel: xfs: propagate errors from xfs_rtginode_load
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-253
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80543
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524454
Bugzilla Description: kernel: s390/zcrypt: Pad trailing CCA or EP11 message with zeros
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74736
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524455
Bugzilla Description: kernel: net/sched: cls_bpf: reject dev-bound programs bound to a different device
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-346
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80558
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524456
Bugzilla Description: kernel: libceph: Avoid using invalid osd indices from primary_temp
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80559
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524457
Bugzilla Description: kernel: Input: sur40 - fix input device registration ordering
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80571
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524458
Bugzilla Description: kernel: powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80577
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524459
Bugzilla Description: kernel: drm/panthor: skip zero-sized firmware sections
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74742
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524460
Bugzilla Description: kernel: veth: fix queue index used to wake the peer txq in veth_poll
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1285
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80566
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524461
Bugzilla Description: kernel: Input: hynitron_cstxxx - validate touch count and finger IDs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80580
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524462
Bugzilla Description: kernel: fbdev: bound mode sysfs output to the sysfs buffer
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80550
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524463
Bugzilla Description: kernel: s390/vfio_ccw: Fix out of bounds check on CCW array
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80525
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524464
Bugzilla Description: kernel: ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80569
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524465
Bugzilla Description: kernel: Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80535
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524467
Bugzilla Description: kernel: xfs: don't double-lock when deleting a self-referential directory
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-764
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80572
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524468
Bugzilla Description: kernel: Input: byd - synchronize timer deletion before freeing private data
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80582
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524469
Bugzilla Description: kernel: drm/shmem_helper: Check VMA boundaries for PMD mappings
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74740
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524470
Bugzilla Description: kernel: net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80565
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524471
Bugzilla Description: kernel: crypto: qce - fix error path in devm_qce_register_algs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80520
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524472
Bugzilla Description: kernel: ovpn: fix NULL dereference when killing missing key
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74737
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524473
Bugzilla Description: kernel: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80584
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524475
Bugzilla Description: kernel: s390/qeth: validate user buffer length in SNMP and ARP query ioctls
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74741
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524476
Bugzilla Description: kernel: net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80578
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524477
Bugzilla Description: kernel: fbdev: core: Fix pointer desynchronization in fb_io_read()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80521
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524478
Bugzilla Description: kernel: af_unix: Unlink scc_entry in unix_del_edge()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80573
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524479
Bugzilla Description: kernel: Input: iforce - validate input packet lengths
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80583
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524480
Bugzilla Description: kernel: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74747
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524481
Bugzilla Description: kernel: ipvs: revalidate ihl to prevent out-of-bounds access
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80563
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524482
Bugzilla Description: kernel: gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74746
Severity: important
Released on: 26/08/2026
Advisory:
Bugzilla: 2524483
Bugzilla Description: kernel: netfilter: flowtable: publish GC-visible tuple last
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74735
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524484
Bugzilla Description: kernel: l2tp: fix tunnel and session refcount leak on seq_file release
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80533
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524486
Bugzilla Description: kernel: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80540
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524487
Bugzilla Description: kernel: drm/amdgpu: Fix UVD decode image min size calculation
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-190
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-80564
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524488
Bugzilla Description: kernel: gve: fix NULL dereference due to missing ptp adjfine
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-80532
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524489
Bugzilla Description: kernel: xfs: fix another iunlink infinite loop bug in online fsck
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80568
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524490
Bugzilla Description: kernel: Input: synaptics-rmi4 - block s_input when F54 queue is busy
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-131
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-80519
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524491
Bugzilla Description: kernel: ovpn: finish crypto callback cleanup before peer release
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80530
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524492
Bugzilla Description: kernel: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80542
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524493
Bugzilla Description: kernel: drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80587
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524494
Bugzilla Description: kernel: mptcp: avoid combining some incoming suboptions
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1288
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80544
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524495
Bugzilla Description: kernel: s390/zcrypt: Improve EP11 CPRB domain handling with ASN.1 parsing
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80589
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524496
Bugzilla Description: kernel: block: stop the timeout timer when releasing a never added disk
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80526
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524498
Bugzilla Description: kernel: ASoC: tas2562: Validate values for volume writes
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80570
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524499
Bugzilla Description: kernel: Input: synaptics-rmi4 - zero report size on F54 work error
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80556
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524500
Bugzilla Description: kernel: mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80536
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524501
Bugzilla Description: kernel: xfs: bounds-check buffer log item's dirty bitmap
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80528
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524502
Bugzilla Description: kernel: ceph: avoid fs reclaim while using current->journal_info
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80574
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524503
Bugzilla Description: kernel: Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80548
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524504
Bugzilla Description: kernel: s390/vfio_ccw: Selectively expand io_mutex
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80551
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524505
Bugzilla Description: kernel: s390/vfio_ccw: Ensure first IDAW remains constant
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80579
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524506
Bugzilla Description: kernel: fbdev: clear fb_info->mode before deleting a videomode
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80549
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524507
Bugzilla Description: kernel: s390/vfio_ccw: Move cp cleanup out of not operational
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74745
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524508
Bugzilla Description: kernel: eth: bnxt: avoid deadlock when canceling IRQ affinity notifier
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80552
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524509
Bugzilla Description: kernel: s390/vfio_ccw: Ensure index for read/write regions are within range
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80588
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524510
Bugzilla Description: kernel: mptcp: reclaim forward-allocated memory on RX path errors
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80561
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524511
Bugzilla Description: kernel: libceph: fix multiple unsafe decodes in decode_locker()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80560
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524512
Bugzilla Description: kernel: openrisc: signal: do not restore privileged SR bits on sigreturn
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-15
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80534
Severity: low
Released on: 26/08/2026
Advisory:
Bugzilla: 2524514
Bugzilla Description: kernel: xfs: fix ilock leak on error in xfs_dq_get_next_id
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-667
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80158
Severity: moderate
Released on: 26/08/2026
Advisory:
Bugzilla: 2524651
Bugzilla Description: ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the IPA bind password in logs and process listings
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-214
Affected Packages:
Package States: Red Hat Ceph Storage 5,Red Hat Ceph Storage 9,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-57171
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2524216
Bugzilla Description: compliance-trestle: Trestle: Arbitrary file write via path traversal in author generate commands
CVSS Score:
CVSSv3 Score: 7.7
Vector:
CWE: CWE-22
Affected Packages:
Package States: File Integrity Operator,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-57170
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2524207
Bugzilla Description: compliance-trestle: Trestle: Arbitrary code execution via Server-Side Template Injection
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-917
Affected Packages:
Package States: File Integrity Operator,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-52776
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2524202
Bugzilla Description: compliance-trestle: Trestle: Server-Side Request Forgery (SSRF) bypass via IPv4-mapped IPv6 and 0.0.0.0
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-1289
Affected Packages:
Package States: File Integrity Operator,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-54757
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2524199
Bugzilla Description: compliance-trestle: Trestle: Remote Code Execution via Server-Side Template Injection
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-917
Affected Packages:
Package States: File Integrity Operator,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-16645
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2524176
Bugzilla Description: photoswipe: PhotoSwipe: Unauthorized access due to missing authorization
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-425
Affected Packages:
Package States: Red Hat Developer Hub,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-72924
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2524130
Bugzilla Description: github.com/cli/cli: GitHub CLI: Forwarded services exposed on all network interfaces by default
CVSS Score:
CVSSv3 Score: 4.6
Vector:
CWE: CWE-1327
Affected Packages:
Package States: Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-68515
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2523747
Bugzilla Description: OpenEXR: OpenEXR: Heap out-of-bounds write in exrmultiview via crafted EXR files
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-19913
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2523656
Bugzilla Description: mwEmbed: html5lib: Kaltura HTML5 Player: Information disclosure via improper validation of ServiceUrl parameter
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-55553
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2523609
Bugzilla Description: urllib: urllib: Credential leakage via cross-origin redirects
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-201
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-63075
Severity: low
Released on: 25/08/2026
Advisory: RHSA-2026:59641, RHSA-2026:59635,
Bugzilla: 2517570
Bugzilla Description: openssl: QUIC ACK-only packet retention can cause memory exhaustion
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages: openssl3-main-3.5.8-0.1.hum1,openssl-main-3.5.8-0.1.hum1,
Package States: Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat JBoss Core Services,Red Hat JBoss Core Services,Red Hat JBoss Web Server 6,Red Hat JBoss Web Server 7,Red Hat OpenShift Container Platform 4,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite Client,Red Hat Satellite Client,
Full Details
CVE document


CVE-2026-79781
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523572
Bugzilla Description: github.com/rclone/rclone: rclone: Path Traversal allows unauthorized file access
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-22
Affected Packages:
Package States: Cryostat 4,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-79779
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523550
Bugzilla Description: github.com/rclone/rclone: rclone: Credential exposure via HTTPS-to-HTTP redirect downgrade.
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-523
Affected Packages:
Package States: Cryostat 4,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-79780
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523578
Bugzilla Description: github.com/rclone/rclone: rclone: Information disclosure via S3 redirect callbacks
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-201
Affected Packages:
Package States: Cryostat 4,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-79776
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2523573
Bugzilla Description: github.com/rclone/rclone: rclone: Authentication bypass leads to backend credential disclosure
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-305
Affected Packages:
Package States: Cryostat 4,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-79772
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523567
Bugzilla Description: nokogiri: Nokogiri: Signature validation bypass via unchecked return value
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-252
Affected Packages:
Package States: Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-79770
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2523562
Bugzilla Description: nokogiri: Nokogiri: Denial of Service via crafted CSS selectors
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1333
Affected Packages:
Package States: Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-79771
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523571
Bugzilla Description: nokogiri: Nokogiri: Denial of Service via XSLT transform memory leak
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-79769
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523563
Bugzilla Description: nokogiri: Nokogiri: Process crash due to invalid memory read via programming error in internal method
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-79676
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523560
Bugzilla Description: nltk: NLTK: Information disclosure via path traversal with symlink bypass
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-22
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-79674
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2523576
Bugzilla Description: nltk: NLTK: Information disclosure via path traversal in corpus-reader constructors
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-22
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2025-71406
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2523577
Bugzilla Description: nokogiri: libxslt: Nokogiri: Memory corruption via crafted XSLT
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2025-71346
Severity: low
Released on: 25/08/2026
Advisory:
Bugzilla: 2523552
Bugzilla Description: nokogiri: libxml2: Nokogiri: Heap buffer under-read in XML Schema validation
CVSS Score:
CVSSv3 Score: 2.9
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2023-54354
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523569
Bugzilla Description: nokogiri: libxml2: Nokogiri: Denial of Service via crafted XML schema
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2022-50999
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2523554
Bugzilla Description: nokogiri: libxml2: Nokogiri: Integer overflow in libxml2 leads to information disclosure, data modification, or denial of service
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2021-47996
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2523549
Bugzilla Description: nokogiri: libxml2: Nokogiri: Memory Corruption via Crafted XML Documents
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2022-50998
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2523558
Bugzilla Description: nokogiri: libxml2: Nokogiri: Denial of Service and Memory Corruption via Crafted XML Input
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-80182
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2517801
Bugzilla Description: keystone: keystone: Delegated token scope restrictions not consistently enforced across trust, OAuth1, and application credential endpoints
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-80184
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2517802
Bugzilla Description: keystone: keystone: Application credential tokens can escape project scope via token-method reauthentication
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-16599
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523509
Bugzilla Description: wget: wget: Denial of Service via crafted FTP OPIE/S-KEY authentication challenge
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-78360
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2521819
Bugzilla Description: anitya: anitya: missing authorization check in delete_user allows any authenticated user to delete arbitrary users
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-862
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-79717
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523431
Bugzilla Description: galaxy_ng: galaxy_ng: blind SSRF via namespace avatar_url with no private-address restriction
CVSS Score:
CVSSv3 Score: 6.4
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,
Full Details
CVE document


CVE-2026-78684
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523362
Bugzilla Description: vllm: vLLM: Denial of Service via DeepStream backend resource control bypass.
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-77117
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523274
Bugzilla Description: glibc: Non-progress DoS in SHIFT_JISX0213 ->
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-19499
Severity: moderate
Released on: 25/08/2026
Advisory: RHSA-2026:60865,
Bugzilla: 2523258
Bugzilla Description: glibc: Buffer Overflow in strfmon right-justification padding
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-787
Affected Packages: glibc-main-2.43-8.3.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-19542
Severity: moderate
Released on: 25/08/2026
Advisory: RHSA-2026:59721,
Bugzilla: 2523249
Bugzilla Description: glibc: Fix out-of-bounds array write in tdelete
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-787
Affected Packages: glibc-main-2.43-8.2.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-59183
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523187
Bugzilla Description: openexr: OpenEXR: Integer Overflow Vulnerability Leading to Application Crash
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-55373
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523181
Bugzilla Description: openexr: OpenEXR: Denial of Service via infinite loop in sample count processing.
CVSS Score:
CVSSv3 Score: 6.2
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-55371
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523180
Bugzilla Description: openexr: OpenEXR: Denial of Service via NULL pointer dereference in exr_attr_set_bytes()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-55059
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523179
Bugzilla Description: OpenEXR: OpenEXR: Heap out-of-bounds write leads to denial of service
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-124
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-54920
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2523178
Bugzilla Description: openexr: OpenEXR: Denial of Service via crafted HTJ2K-compressed EXR file
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18798
Severity: moderate
Released on: 25/08/2026
Advisory: RHSA-2026:59641, RHSA-2026:59635,
Bugzilla: 2517559
Bugzilla Description: openssl: QUIC server may trigger double free when processing INITIAL packet
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-415
Affected Packages: openssl3-main-3.5.8-0.1.hum1,openssl-main-3.5.8-0.1.hum1,
Package States: Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat JBoss Core Services,Red Hat JBoss Core Services,Red Hat JBoss Web Server 6,Red Hat JBoss Web Server 7,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite Client,Red Hat Satellite Client,
Full Details
CVE document


CVE-2026-63072
Severity: moderate
Released on: 25/08/2026
Advisory: RHSA-2026:59641, RHSA-2026:59635,
Bugzilla: 2517560
Bugzilla Description: openssl: heap buffer overflow in CMS key unwrapping
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages: openssl3-main-3.5.8-0.1.hum1,openssl-main-3.5.8-0.1.hum1,
Package States: Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat JBoss Core Services,Red Hat JBoss Core Services,Red Hat JBoss Web Server 6,Red Hat JBoss Web Server 7,Red Hat OpenShift Container Platform 4,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite Client,Red Hat Satellite Client,
Full Details
CVE document


CVE-2026-63076
Severity: moderate
Released on: 25/08/2026
Advisory: RHSA-2026:59641, RHSA-2026:59635,
Bugzilla: 2517561
Bugzilla Description: openssl: invalid pointer dereference in CMP server via crafted protectionAlg
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-476
Affected Packages: openssl3-main-3.5.8-0.1.hum1,openssl-main-3.5.8-0.1.hum1,
Package States: Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat JBoss Core Services,Red Hat JBoss Core Services,Red Hat JBoss Web Server 6,Red Hat JBoss Web Server 7,Red Hat OpenShift Container Platform 4,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite Client,Red Hat Satellite Client,
Full Details
CVE document


CVE-2026-14457
Severity: low
Released on: 25/08/2026
Advisory: RHSA-2026:59641, RHSA-2026:59635,
Bugzilla: 2517562
Bugzilla Description: openssl: RPK server signature algorithm selection can dereference a missing certificate
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-476
Affected Packages: openssl3-main-3.5.8-0.1.hum1,openssl-main-3.5.8-0.1.hum1,
Package States: Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat JBoss Core Services,Red Hat JBoss Core Services,Red Hat JBoss Web Server 6,Red Hat JBoss Web Server 7,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite Client,Red Hat Satellite Client,
Full Details
CVE document


CVE-2026-54874
Severity: low
Released on: 25/08/2026
Advisory: RHSA-2026:59641, RHSA-2026:59635,
Bugzilla: 2517564
Bugzilla Description: openssl: excessive memory use buffering DTLS records for a future epoch
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-405
Affected Packages: openssl3-main-3.5.8-0.1.hum1,openssl-main-3.5.8-0.1.hum1,
Package States: Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat JBoss Core Services,Red Hat JBoss Core Services,Red Hat JBoss Web Server 6,Red Hat JBoss Web Server 7,Red Hat OpenShift Container Platform 4,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite Client,Red Hat Satellite Client,
Full Details
CVE document


CVE-2026-63073
Severity: low
Released on: 25/08/2026
Advisory: RHSA-2026:59641, RHSA-2026:59635,
Bugzilla: 2517565
Bugzilla Description: openssl: untrusted sender DN used as format string in CMP response validation
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-134
Affected Packages: openssl3-main-3.5.8-0.1.hum1,openssl-main-3.5.8-0.1.hum1,
Package States: Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat JBoss Core Services,Red Hat JBoss Core Services,Red Hat JBoss Web Server 6,Red Hat JBoss Web Server 7,Red Hat OpenShift Container Platform 4,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite Client,Red Hat Satellite Client,
Full Details
CVE document


CVE-2026-63074
Severity: low
Released on: 25/08/2026
Advisory: RHSA-2026:59641, RHSA-2026:59635,
Bugzilla: 2517566
Bugzilla Description: openssl: CMP indefinite cache growth of ExtraCerts
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages: openssl3-main-3.5.8-0.1.hum1,openssl-main-3.5.8-0.1.hum1,
Package States: Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat JBoss Core Services,Red Hat JBoss Core Services,Red Hat JBoss Web Server 6,Red Hat JBoss Web Server 7,Red Hat OpenShift Container Platform 4,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite Client,Red Hat Satellite Client,
Full Details
CVE document


CVE-2026-52491
Severity: important
Released on: 25/08/2026
Advisory: RHSA-2026:53467,
Bugzilla: 2524131
Bugzilla Description: libtiff: libtiff: Arbitrary code execution via thumbnail.c: main() component
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-120
Affected Packages: libtiff-main-4.7.2-2.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80186
Severity: important
Released on: 25/08/2026
Advisory:
Bugzilla: 2524132
Bugzilla Description: bluez: Stack Overflow in name2utf8 causes DoS and potential code execution
CVSS Score:
CVSSv3 Score: 7.6
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-80185
Severity: moderate
Released on: 25/08/2026
Advisory:
Bugzilla: 2524139
Bugzilla Description: bluez: sdp-xml: BlueZ 5.86: unprivileged-local and adjacent-LE-peer leads to arbitrary code execution as root
CVSS Score:
CVSSv3 Score: 5.7
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-53532
Severity: moderate
Released on: 24/08/2026
Advisory:
Bugzilla: 2523172
Bugzilla Description: OpenEXR: OpenEXR: Denial of Service via crafted HTJ2K-compressed EXR file
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68516
Severity: moderate
Released on: 24/08/2026
Advisory:
Bugzilla: 2523170
Bugzilla Description: OpenEXR: OpenEXR: Denial of service via crafted HTJ2K-compressed EXR with invalid image-offset
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-17113
Severity: moderate
Released on: 24/08/2026
Advisory:
Bugzilla: 2506872
Bugzilla Description: cri-o: CRI-O: unvalidated image env var causes daemon crash
CVSS Score:
CVSSv3 Score: 6.0
Vector:
CWE: CWE-1287
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-75509
Severity: moderate
Released on: 24/08/2026
Advisory:
Bugzilla: 2523102
Bugzilla Description: joserfc: joserfc: Issuer-validation bypass via array-valued claims
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-480
Affected Packages:
Package States: Lightspeed Core,Migration Toolkit for Applications 8,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux command line assistant,Red Hat Hardened Images,Red Hat OpenShift Virtualization 4,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-76098
Severity: important
Released on: 24/08/2026
Advisory:
Bugzilla: 2523100
Bugzilla Description: mistune: Mistune: Denial of Service via excessive emphasis markers in Markdown
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Migration Toolkit for Applications 8,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-63621
Severity: important
Released on: 24/08/2026
Advisory:
Bugzilla: 2522066
Bugzilla Description: org.apache.camel/camel-knative: Apache Camel Knative: Header injection vulnerability allows server-side request forgery
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-791
Affected Packages:
Package States: OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat build of Apache Camel for Spring Boot 4,
Full Details
CVE document


CVE-2026-66908
Severity: important
Released on: 24/08/2026
Advisory:
Bugzilla: 2522058
Bugzilla Description: org.apache.camel/camel-platform-http-main: org.apache.camel/camel-main: Apache Camel: Improper authentication allows JWT bypass in Platform HTTP Main component
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-305
Affected Packages:
Package States: OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat Fuse 7,
Full Details
CVE document


CVE-2026-19685
Severity: important
Released on: 24/08/2026
Advisory:
Bugzilla: 2515042
Bugzilla Description: NetworkManager: NetworkManager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing WPA-Enterprise server validation bypass (incomplete fix for CVE-2025-9615)
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-71366
Severity: important
Released on: 24/08/2026
Advisory: RHSA-2026:59153, RHSA-2026:59155, RHSA-2026:59135, RHSA-2026:59136,
Bugzilla: 2511902
Bugzilla Description: awx: notification backends allow SSRF and credential leakage
CVSS Score:
CVSSv3 Score: 7.7
Vector:
CWE: CWE-918
Affected Packages: automation-controller-0:4.7.16-1.el9ap,ansible-automation-platform-26/controller-rhel9:1787244009,automation-controller-0:4.6.32-1.el8ap,ansible-automation-platform-27/controller-rhel9:1787220257,automation-controller-0:4.6.32-1.el9ap,
Package States:
Full Details
CVE document


CVE-2026-71364
Severity: important
Released on: 24/08/2026
Advisory: RHSA-2026:59153, RHSA-2026:59155, RHSA-2026:59135, RHSA-2026:59136,
Bugzilla: 2511900
Bugzilla Description: awx: project archive extraction allows path traversal file writes
CVSS Score:
CVSSv3 Score: 7.2
Vector:
CWE: CWE-22
Affected Packages: automation-controller-0:4.7.16-1.el9ap,ansible-automation-platform-26/controller-rhel9:1787244009,automation-controller-0:4.6.32-1.el8ap,ansible-automation-platform-27/controller-rhel9:1787220257,automation-controller-0:4.6.32-1.el9ap,
Package States:
Full Details
CVE document


CVE-2026-76848
Severity: important
Released on: 24/08/2026
Advisory:
Bugzilla: 2521891
Bugzilla Description: typeorm: TypeORM: Information disclosure via SQL injection in SelectQueryBuilder.distinctOn
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-89
Affected Packages:
Package States: Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-76845
Severity: moderate
Released on: 24/08/2026
Advisory:
Bugzilla: 2521870
Bugzilla Description: adm-zip: adm-zip: Arbitrary File Overwrite via Symlink Following
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-59
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-76844
Severity: important
Released on: 24/08/2026
Advisory:
Bugzilla: 2521896
Bugzilla Description: webpack-dev-middleware: webpack-dev-middleware: Information Disclosure via Path Traversal
CVSS Score:
CVSSv3 Score: 8.6
Vector:
CWE: CWE-22
Affected Packages:
Package States: Gatekeeper 3,Migration Toolkit for Containers,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat 3scale API Management Platform 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 4,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat Quay 3,Red Hat Satellite 6,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-78701
Severity: moderate
Released on: 24/08/2026
Advisory:
Bugzilla: 2523232
Bugzilla Description: 389-ds-base: 389-ds-base: CVE-2026-11610 incomplete fix may introduce a connection-stall DoS
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Directory Server 11,Red Hat Directory Server 12,Red Hat Directory Server 13,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-10582
Severity: important
Released on: 24/08/2026
Advisory:
Bugzilla: 2521803
Bugzilla Description: hugo: github.com/gohugoio/hugo: Hugo: Server-Side Request Forgery (SSRF) leading to information disclosure.
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-59295
Severity: moderate
Released on: 24/08/2026
Advisory:
Bugzilla: 2521797
Bugzilla Description: io.micrometer/micrometer-core: Micrometer Instrumentation for Apache HttpAsyncClient: Denial of Service via asynchronous request failures
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Exploit Intelligence,Red Hat AMQ Broker 7,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-76172
Severity: important
Released on: 24/08/2026
Advisory: RHSA-2026:60856, RHSA-2026:60855, RHSA-2026:60866,
Bugzilla: 2521798
Bugzilla Description: fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-76
Affected Packages: grafana13-1-main-13.1.3-0.3.hum1,grafana13-2-main-13.2.0-0.1.2.hum1,grafana12-4-main-12.4.9-0.4.hum1,
Package States: Migration Toolkit for Applications 8,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apicurio Registry 3,Red Hat Build of Podman Desktop,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-75975
Severity: important
Released on: 24/08/2026
Advisory: RHSA-2026:60856, RHSA-2026:60855, RHSA-2026:60866,
Bugzilla: 2521779
Bugzilla Description: fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-918
Affected Packages: grafana13-1-main-13.1.3-0.3.hum1,grafana13-2-main-13.2.0-0.1.2.hum1,grafana12-4-main-12.4.9-0.4.hum1,
Package States: Migration Toolkit for Applications 8,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apicurio Registry 3,Red Hat Build of Podman Desktop,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-75899
Severity: important
Released on: 24/08/2026
Advisory: RHSA-2026:60856, RHSA-2026:60855, RHSA-2026:60866,
Bugzilla: 2521778
Bugzilla Description: fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-140
Affected Packages: grafana13-1-main-13.1.3-0.3.hum1,grafana13-2-main-13.2.0-0.1.2.hum1,grafana12-4-main-12.4.9-0.4.hum1,
Package States: Migration Toolkit for Applications 8,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apicurio Registry 3,Red Hat Build of Podman Desktop,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-75931
Severity: important
Released on: 24/08/2026
Advisory: RHSA-2026:60856, RHSA-2026:60855, RHSA-2026:60866,
Bugzilla: 2521777
Bugzilla Description: fast-uri: fast-uri: Host confusion via skipped IDN canonicalization
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-444
Affected Packages: grafana13-1-main-13.1.3-0.3.hum1,grafana13-2-main-13.2.0-0.1.2.hum1,grafana12-4-main-12.4.9-0.4.hum1,
Package States: Migration Toolkit for Applications 8,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apicurio Registry 3,Red Hat Build of Podman Desktop,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-78323
Severity: moderate
Released on: 24/08/2026
Advisory:
Bugzilla: 2521775
Bugzilla Description: jss: jss: JSSTrustManager does not verify NSS trust flags on CA certificates
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-295
Affected Packages:
Package States: Red Hat Certificate System 10,Red Hat Certificate System 11,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-78161
Severity: important
Released on: 24/08/2026
Advisory:
Bugzilla: 2521703
Bugzilla Description: libwebsockets: libwebsockets: Out-of-bounds write in LECP CBOR Recording
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-787
Affected Packages:
Package States: A-MQ Interconnect 1,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat Satellite 6,Red Hat Service Interconnect 2,
Full Details
CVE document


CVE-2026-78322
Severity: moderate
Released on: 24/08/2026
Advisory:
Bugzilla: 2521767
Bugzilla Description: file-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and RAR handlers
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-78367
Severity: moderate
Released on: 24/08/2026
Advisory:
Bugzilla: 2521857
Bugzilla Description: rpm: rpmbuild getTarSpec() crafted tar member name → macro injection
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-94
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-78376
Severity: important
Released on: 24/08/2026
Advisory:
Bugzilla: 2521858
Bugzilla Description: webkitgtk: use-after-free of JSCValue function parameters
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-416
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-52492
Severity: important
Released on: 24/08/2026
Advisory: RHSA-2026:53467,
Bugzilla: 2523134
Bugzilla Description: libtiff: libtiff: Arbitrary code execution via crafted TIFF image
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-787
Affected Packages: libtiff-main-4.7.2-2.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-52490
Severity: important
Released on: 24/08/2026
Advisory: RHSA-2026:53467,
Bugzilla: 2523148
Bugzilla Description: libtiff: libtiff: Arbitrary code execution via process_command_opts() function
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-78
Affected Packages: libtiff-main-4.7.2-2.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-70626
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521338
Bugzilla Description: nltk: NLTK: Information disclosure via symlink escape in CorpusReader.open()
CVSS Score:
CVSSv3 Score: 6.2
Vector:
CWE: CWE-22
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-66393
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521342
Bugzilla Description: nltk: NLTK: Denial of Service via unbounded recursion in JSONTaggedDecoder
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-606
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-65915
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521343
Bugzilla Description: nltk: NLTK: Arbitrary file read due to logic bug in FileSystemPathPointer
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-22
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-63311
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521348
Bugzilla Description: nltk: NLTK: Server-Side Request Forgery bypass via DNS resolution failures
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-918
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-62388
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521328
Bugzilla Description: NLTK: NLTK: Bypass of path traversal and pickle deserialization protections due to insecure default configuration
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1188
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-62385
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521333
Bugzilla Description: nltk: NLTK: Information disclosure through path traversal
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-22
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-62384
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521349
Bugzilla Description: nltk: NLTK: Information Disclosure via Symlink Sandbox Bypass
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-41
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-62383
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521332
Bugzilla Description: nltk: nltk: Information disclosure via symlink in IPIPANCorpusReader
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-22
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-71514
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521318
Bugzilla Description: nltk: NLTK: Information disclosure via path traversal in CrubadanCorpusReader
CVSS Score:
CVSSv3 Score: 2.5
Vector:
CWE: CWE-22
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-71513
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521317
Bugzilla Description: nltk: NLTK: Remote Code Execution via AllowlistUnpickler dotted-name bypass
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-502
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-62243
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521309
Bugzilla Description: io.netty/netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-295
Affected Packages:
Package States: Exploit Intelligence,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat AMQ Broker 7,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Data Grid 8,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Offline Knowledge Portal,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Satellite 6,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-74584
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521352
Bugzilla Description: kernel: RDMA/bnxt_re: zero shared page before exposing to userspace
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74595
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521355
Bugzilla Description: kernel: fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-628
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74607
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521356
Bugzilla Description: kernel: KVM: SVM: Serialize accesses to the owner and mirror list with separate lock
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74625
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521357
Bugzilla Description: kernel: netfilter: bridge: release template ct on non-IP path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74638
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521358
Bugzilla Description: kernel: drm/v3d: Serialize the scheduler timeout handlers
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74729
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521359
Bugzilla Description: kernel: soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74730
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521360
Bugzilla Description: kernel: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74664
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521361
Bugzilla Description: kernel: net: openvswitch: reallocate update replies for mismatched IDs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74677
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521362
Bugzilla Description: kernel: net: usb: ipheth: fix carrier_work UAF on disconnect
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74666
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521363
Bugzilla Description: kernel: packet: synchronize pressure clearing with ring reconfiguration
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74683
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521364
Bugzilla Description: kernel: Input: evdev - sanitize event type index when fetching event masks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74624
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521365
Bugzilla Description: kernel: netfilter: nf_conntrack: defer invalid log until after unlock
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74700
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521366
Bugzilla Description: kernel: net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74668
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521367
Bugzilla Description: kernel: packet: use consistent hard_header_len in TX_RING send path
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74712
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521368
Bugzilla Description: kernel: vdpa/mlx5: Fix buffer length in create_direct_keys()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74715
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521369
Bugzilla Description: kernel: bpf: Fix netns reference imbalance in conntrack kfuncs
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74599
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521370
Bugzilla Description: kernel: mm/ptdump: always stabilise against page table freeing using init_mm
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74632
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521371
Bugzilla Description: kernel: mm/huge_memory: fix huge_zero_pfn race
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74606
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521372
Bugzilla Description: kernel: eventfs: Fix use-after-free in eventfs_remove_rec()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74621
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521373
Bugzilla Description: kernel: net/sched: act_ct: fix sk_buff leak when the header checks reject a packet
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74648
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521374
Bugzilla Description: kernel: staging: rtl8723bs: validate monitor transmit frame lengths
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74669
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521375
Bugzilla Description: kernel: ipvs: clear IPv4 options after rebasing tunnel ICMP errors
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74675
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521376
Bugzilla Description: kernel: vt: stabilize tty reference in kbd_keycode with tty_port_tty_get
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74654
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521377
Bugzilla Description: kernel: serial: 8250_dma: Clear stale RX state on shutdown
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74714
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521378
Bugzilla Description: kernel: bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74727
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521379
Bugzilla Description: kernel: ovpn: skip rehash for peers already removed from by_id
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74643
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521380
Bugzilla Description: kernel: samples/damon/mtier: error out for zero quota goal target values
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74673
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521381
Bugzilla Description: kernel: Input: evdev - fix information leak in evdev_pass_values()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-201
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74695
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521382
Bugzilla Description: kernel: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74649
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521383
Bugzilla Description: kernel: staging: rtl8723bs: fix missing shared-key auth challenge length check
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74588
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521384
Bugzilla Description: kernel: sctp: keep chunk->transport in step with the list it is queued on
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74650
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521385
Bugzilla Description: kernel: staging: rtl8723bs: fix OOB read in WMM_param_handler()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-74646
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521386
Bugzilla Description: kernel: misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-414
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74717
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521387
Bugzilla Description: kernel: net/mlx5: fw_tracer, return NULL on create error
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74661
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521388
Bugzilla Description: kernel: mac802154: fix netdev use-after-free in beacon worker
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74663
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521389
Bugzilla Description: kernel: net/sched: reject overly deep qdisc hierarchies
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74680
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521390
Bugzilla Description: kernel: usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74699
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521391
Bugzilla Description: kernel: drm/xe: Fix memory leak in exec_queue_set_hang_replay_state()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74719
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521392
Bugzilla Description: kernel: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74657
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521393
Bugzilla Description: kernel: ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74679
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521394
Bugzilla Description: kernel: usb: gadget: f_ncm: Use unsigned int for ndp_index
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-74591
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521395
Bugzilla Description: kernel: mm/filemap: __filemap_add_folio() restore index before retrying
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74656
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521396
Bugzilla Description: kernel: ipv4: fix use-after-free in fib_nhc_update_mtu()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74671
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521397
Bugzilla Description: kernel: ima: fix out-of-bounds read in xattr_verify()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74703
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521398
Bugzilla Description: kernel: vhost-scsi: Validate T10 PI scatterlist counts
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74585
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521399
Bugzilla Description: kernel: thunderbolt: Bound the DROM dual link port number before indexing sw->ports
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-823
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74589
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521400
Bugzilla Description: kernel: bpf, sockmap: Fix sk_redir use-after-free in send verdict
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74701
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521401
Bugzilla Description: kernel: net/openvswitch: check Ethernet header length in key_extract()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74614
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521402
Bugzilla Description: kernel: vsock/virtio: read virtqueues under worker locks
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-820
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74593
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521403
Bugzilla Description: kernel: sched_ext: Take cgroup_lock() first in scx_cgroup_lock()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74711
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521404
Bugzilla Description: kernel: hwmon: (pmbus) Fix type confusion in notification logic
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74726
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521405
Bugzilla Description: kernel: bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74615
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521406
Bugzilla Description: kernel: vxlan: do not arm the ageing timer on a device that is down
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74693
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521407
Bugzilla Description: kernel: net: prestera: validate firmware header length
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74733
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521408
Bugzilla Description: kernel: gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74597
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521409
Bugzilla Description: kernel: ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74651
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521410
Bugzilla Description: kernel: staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74629
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521411
Bugzilla Description: kernel: net/dibs: Correct freeing of dmb_clientid_arr
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74718
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521412
Bugzilla Description: kernel: devlink: fix net namespace reference leak in reload
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74631
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521413
Bugzilla Description: kernel: net: smc: fix splice entry lifetime imbalance in smc_rx_splice
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74642
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521414
Bugzilla Description: kernel: ALSA: usb: Fix UAF at delayed release of MIDI2 EPs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74608
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521415
Bugzilla Description: kernel: smb: client: Fix use-after-free in cifs_try_adding_channels()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74635
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521416
Bugzilla Description: kernel: fbdev: bitblit: bound-check glyph index in bit_cursor()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74617
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521417
Bugzilla Description: kernel: dibs: initialise dibs->lock in dibs_dev_alloc()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74681
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521418
Bugzilla Description: kernel: usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74586
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521419
Bugzilla Description: kernel: sctp: clear new_transport when removing a peer
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74702
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521420
Bugzilla Description: kernel: vhost-scsi: reject feature changes after endpoint
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74710
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521421
Bugzilla Description: kernel: xsk: require at least 16 bytes of TX metadata
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74603
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521422
Bugzilla Description: kernel: ptp: ocp: Fix board ID over-read
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74628
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521423
Bugzilla Description: kernel: net/x25: fix use-after-free of the socket by its timers
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74689
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521424
Bugzilla Description: kernel: net/atm: fix slab-out-of-bounds read in vcc_setsockopt()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74598
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521425
Bugzilla Description: kernel: ipv6: fix Route Information option length validation
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74609
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521427
Bugzilla Description: kernel: tipc: read le->link under the node lock in tipc_node_link_down()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74716
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521428
Bugzilla Description: kernel: accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74672
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521429
Bugzilla Description: kernel: mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74696
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521430
Bugzilla Description: kernel: tcp: fix TFO max_qlen accounting across reuseport migration
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74723
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521431
Bugzilla Description: kernel: btrfs: lzo: reject inline extents without valid headers
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74684
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521432
Bugzilla Description: kernel: net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74682
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521433
Bugzilla Description: kernel: ALSA: usb-audio: fix OOB write on Type II inbound URBs
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74587
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521434
Bugzilla Description: kernel: sctp: fix use-after-free of cached ASCONF chunk
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74594
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521435
Bugzilla Description: kernel: sched/psi: Shut down rtpoll_timer in psi_cgroup_free()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74641
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521436
Bugzilla Description: kernel: ALSA: usx2y: bound the hwdep mmap fault offset
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74596
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521437
Bugzilla Description: kernel: fs,fsverity: remove check for fsverity being enabled in setattr_prepare()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-253
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74688
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521438
Bugzilla Description: kernel: sctp: clear control chunk transport if it is being removed
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74694
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521439
Bugzilla Description: kernel: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74713
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521440
Bugzilla Description: kernel: vhost_iotlb: bound map allocation in add_range
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74731
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521441
Bugzilla Description: kernel: sched_ext: Skip sub-disable teardown for never-linked sub-schedulers
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74686
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521442
Bugzilla Description: kernel: rqspinlock: Reset tail when preserving queue on deadlock
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74706
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521443
Bugzilla Description: kernel: bnge: Fix NULL pointer dereference in aux device release
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74645
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521444
Bugzilla Description: kernel: mm/damon/lru_sort: error out for >10000 active_mem_bp
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74722
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521445
Bugzilla Description: kernel: btrfs: fix memory leak in btrfs_do_encoded_write()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74604
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521446
Bugzilla Description: kernel: Revert "thermal/drivers/hwmon: Cleanup coding style a bit"
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74619
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521447
Bugzilla Description: kernel: ovl: don't warn when the mount is completed from another user namespace
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74655
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521448
Bugzilla Description: kernel: serial: qcom-geni: fix TX DMA buffer flush
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74670
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521449
Bugzilla Description: kernel: ipvs: stop estimator after disabled calc phase
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74653
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521450
Bugzilla Description: kernel: serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74678
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521451
Bugzilla Description: kernel: net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74704
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521452
Bugzilla Description: kernel: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74707
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521453
Bugzilla Description: kernel: xsk: validate metadata when processing requests
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74590
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521454
Bugzilla Description: kernel: fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74728
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521455
Bugzilla Description: kernel: xfs: handle NULL b_addr in xfs_buf_free
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74709
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521456
Bugzilla Description: kernel: xsk: clear metadata pointer when no timestamp is requested
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74647
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521457
Bugzilla Description: kernel: misc: fastrpc: Remove buffer from list prior to unmap operation
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74721
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521458
Bugzilla Description: kernel: accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74665
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521459
Bugzilla Description: kernel: net: fix skb length accounting after generic XDP frag adjustment
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74634
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521460
Bugzilla Description: kernel: ring-buffer: Prevent subbuf order change when resizing is disabled
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74616
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521461
Bugzilla Description: kernel: xdp: reject clones that overrun skb_shared_info tailroom
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74659
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521462
Bugzilla Description: kernel: net: bridge: mrp: fix uninitialised bytes on the wire
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74662
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521463
Bugzilla Description: kernel: inet: frags: publish queues before arming timer
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74601
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521464
Bugzilla Description: kernel: ring-buffer: Use current_context for safe per-CPU buffer swap
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74633
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521465
Bugzilla Description: kernel: tracing: Fix NULL pointer dereference in module event cache removal
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74611
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521466
Bugzilla Description: kernel: tls: rx: restore msg_iter before TLS 1.3 optimistic retry
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74639
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521467
Bugzilla Description: kernel: ALSA: us144mkii: re-anchor capture URBs on resubmission
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74602
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521468
Bugzilla Description: kernel: ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74618
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521469
Bugzilla Description: kernel: binfmt_misc: don't warn when the mount is completed from another user namespace
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74687
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521470
Bugzilla Description: kernel: watchdog: at91sam9_wdt: prevent timer rearm during teardown
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74644
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521471
Bugzilla Description: kernel: mm/damon/ops-common: putback folios on invalid migrate nid
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74622
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521472
Bugzilla Description: kernel: net: atlantic: free RX pages of consumed but not refilled buffers
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74600
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521473
Bugzilla Description: kernel: mm/page_table_check: skip special zero mappings
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74676
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521474
Bugzilla Description: kernel: vt: add permission check for KDSKBMETA ioctl
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1220
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74630
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521475
Bugzilla Description: kernel: ipv6: prevent in6_dev_get() from resurrecting inet6_dev
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74623
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521476
Bugzilla Description: kernel: net: atlantic: free stranded TX buffers on ring deinit
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-771
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74720
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521477
Bugzilla Description: kernel: bpf: Preserve pointer state for commuted arithmetic
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-823
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74697
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521478
Bugzilla Description: kernel: bnxt_en: Disable EOP for TPA on all chips to prevent data corruption
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74640
Severity: important
Released on: 22/08/2026
Advisory:
Bugzilla: 2521479
Bugzilla Description: kernel: ALSA: FCP: fix OOB write in fcp_meter_ctl_get()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74674
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521480
Bugzilla Description: kernel: mm: fix incorrect flush address in direct page table reclaim
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-823
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74724
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521481
Bugzilla Description: kernel: ipvs: avoid out-of-bounds write in ip_vs_nat_icmp
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74620
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521482
Bugzilla Description: kernel: net/sched: act_gact, act_police: range check the fallback control action
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74612
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521483
Bugzilla Description: kernel: veth: fix skb length accounting after XDP frag adjustment
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74613
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521484
Bugzilla Description: kernel: vsock/virtio: avoid refilling the RX queue after teardown
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74732
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521485
Bugzilla Description: kernel: drm/amd/display: Check for tg ops in dce110_set_avmute
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74652
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521486
Bugzilla Description: kernel: serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74626
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521487
Bugzilla Description: kernel: NTB: ntb_netdev: Preserve RX queue depth on allocation failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-826
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74592
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521488
Bugzilla Description: kernel: ima: Instantiate file_truncate and path_truncate hooks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-222
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74605
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521489
Bugzilla Description: kernel: eventfs: Use children field for rcu head and add memory barriers
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74667
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521490
Bugzilla Description: kernel: net/packet: reset the MAC header on the packet-socket transmit path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74698
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521491
Bugzilla Description: kernel: net/mlx5e: fix BQL reset on SQ re-activation
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74725
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521492
Bugzilla Description: kernel: enic: fix tx_hang_reset use-after-free on device removal
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74685
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521493
Bugzilla Description: kernel: hwmon: (ltc4282) Clamp negative current limits
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74660
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521495
Bugzilla Description: kernel: netfilter: ebt_nflog: pin the NFLOG backend
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74692
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521496
Bugzilla Description: kernel: net/smc: fix TOCTOU race between smc_listen_out() and listener close
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74610
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521497
Bugzilla Description: kernel: tls: don't leave a full plaintext sk_msg ring unpushed
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74705
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521498
Bugzilla Description: kernel: udp: fix potential use-after-free in tunnel segmentation
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74708
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521499
Bugzilla Description: kernel: xsk: validate launch-time metadata size
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1284
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74658
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521500
Bugzilla Description: kernel: futex: Prevent robust futex exit race some more
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74637
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521501
Bugzilla Description: kernel: perf/core: Fix group leader use-after-free after sibling detach
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74636
Severity: low
Released on: 22/08/2026
Advisory:
Bugzilla: 2521502
Bugzilla Description: kernel: tracing: Fix race between update_event_fields and, event_define_fields
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74627
Severity: moderate
Released on: 22/08/2026
Advisory:
Bugzilla: 2521503
Bugzilla Description: kernel: net: devmem: prevent net-iov / page mixing
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-44517
Severity: moderate
Released on: 21/08/2026
Advisory:
Bugzilla: 2521191
Bugzilla Description: github.com/containers/buildah: Buildah: Build breakout via malicious Git repository or tar archive
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-77219
Severity: important
Released on: 21/08/2026
Advisory:
Bugzilla: 2521196
Bugzilla Description: emacs: GNU Emacs: Heap over-read leading to information disclosure via crafted image
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-66786
Severity: moderate
Released on: 21/08/2026
Advisory:
Bugzilla: 2507531
Bugzilla Description: submariner: submariner: ipsec.conf stanza injection via remote-supplied CableName and Subnets
CVSS Score:
CVSSv3 Score: 9.1
Vector:
CWE: CWE-94
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-54789
Severity: important
Released on: 21/08/2026
Advisory:
Bugzilla: 2521051
Bugzilla Description: mod_auth_openidc: mod_auth_openidc: Denial of Service via malformed state cookie parsing
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-49114
Severity: important
Released on: 21/08/2026
Advisory:
Bugzilla: 2521048
Bugzilla Description: onnx: ONNX: Arbitrary file write via symlink following and path traversal
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-63125
Severity: critical
Released on: 21/08/2026
Advisory:
Bugzilla: 2521013
Bugzilla Description: incus: Incus vulnerable to root RCE via image backup.yaml symlink
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-61
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-62941
Severity: critical
Released on: 21/08/2026
Advisory:
Bugzilla: 2521017
Bugzilla Description: incus: Incus: Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-367
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-62940
Severity: critical
Released on: 21/08/2026
Advisory:
Bugzilla: 2521016
Bugzilla Description: incus: Incus has a project restriction bypass via instance migration config override
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-863
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-62867
Severity: critical
Released on: 21/08/2026
Advisory:
Bugzilla: 2521014
Bugzilla Description: incus: Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-88
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-48769
Severity: critical
Released on: 21/08/2026
Advisory:
Bugzilla: 2521021
Bugzilla Description: incus: Incus has an arbitrary file write on its client due to trusted image hash
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-345
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-48755
Severity: critical
Released on: 21/08/2026
Advisory:
Bugzilla: 2521019
Bugzilla Description: incus: Incus has an argument injection in backup compression algorithm leading to AFW and ACE
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-88
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-48753
Severity: critical
Released on: 21/08/2026
Advisory:
Bugzilla: 2521008
Bugzilla Description: incus: Incus has an arbitrary file write via path traversal in S3 multipart upload
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-22
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-48752
Severity: critical
Released on: 21/08/2026
Advisory:
Bugzilla: 2521009
Bugzilla Description: incus: Incus has arbitrary file read+write on host via templates/ symlink in malicious image
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-61
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-48751
Severity: critical
Released on: 21/08/2026
Advisory:
Bugzilla: 2521007
Bugzilla Description: incus: Incus has a restricted project bypass leading to arbitrary command execution
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-863
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-48750
Severity: critical
Released on: 21/08/2026
Advisory:
Bugzilla: 2521003
Bugzilla Description: incus: Incus has an arbitrary file write on host via `exec-output` symlink in crafted image
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-61
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-48749
Severity: critical
Released on: 21/08/2026
Advisory:
Bugzilla: 2521004
Bugzilla Description: incus: Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-61
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-59296
Severity: moderate
Released on: 21/08/2026
Advisory:
Bugzilla: 2520949
Bugzilla Description: io.micrometer/micrometer-registry-statsd: io.micrometer/micrometer-core: Micrometer: Line-protocol and log injection via unsanitized input allows metric and log spoofing
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-93
Affected Packages:
Package States: Exploit Intelligence,Red Hat AMQ Broker 7,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-74866
Severity: moderate
Released on: 21/08/2026
Advisory:
Bugzilla: 2520904
Bugzilla Description: @fastify/busboy: @fastify/busboy: CRLF injection via multipart Content-Disposition filename and name
CVSS Score:
CVSSv3 Score: 5.8
Vector:
CWE: CWE-93
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-79655
Severity: important
Released on: 21/08/2026
Advisory:
Bugzilla: 2523363
Bugzilla Description: sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-59
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-77680
Severity: moderate
Released on: 21/08/2026
Advisory:
Bugzilla: 2520892
Bugzilla Description: libsoup3: libsoup: quadratic CPU denial of service in HTTP Range coalescing after CVE-2025-32907 fix
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-407
Affected Packages:
Package States: Red Hat Enterprise Linux 10,
Full Details
CVE document


CVE-2026-74581
Severity: important
Released on: 21/08/2026
Advisory: RHSA-2026:60485, RHSA-2026:60484, RHSA-2026:59994, RHSA-2026:60486, RHSA-2026:60438, RHSA-2026:59723, RHSA-2026:60437,
Bugzilla: 2520980
Bugzilla Description: kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res->rt6 pointer
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-416
Affected Packages: kernel-0:5.14.0-427.147.1.el9_4,kernel-0:5.14.0-687.42.1.el9_8,kernel-0:5.14.0-570.136.1.el9_6,kernel-0:4.18.0-372.209.1.el8_6,kernel-rt-0:5.14.0-284.189.1.rt14.474.el9_2,kernel-0:4.18.0-305.202.1.el8_4,kernel-0:5.14.0-284.189.1.el9_2,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74583
Severity: important
Released on: 21/08/2026
Advisory:
Bugzilla: 2521054
Bugzilla Description: kernel: net/sched: cls_route: fix fastmap use-after-free on filter
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74580
Severity: important
Released on: 21/08/2026
Advisory:
Bugzilla: 2521055
Bugzilla Description: kernel: vhost: reset the vring metadata cache on vring reconfiguration
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74582
Severity: important
Released on: 21/08/2026
Advisory:
Bugzilla: 2521057
Bugzilla Description: kernel: packet: use consistent hard_header_len in non-ring send paths
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-79992
Severity: important
Released on: 21/08/2026
Advisory:
Bugzilla: 2523665
Bugzilla Description: emacs: local shell command injection through the user field in emacs tramp
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-78
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-77648
Severity: low
Released on: 20/08/2026
Advisory:
Bugzilla: 2520853
Bugzilla Description: glance: OpenStack Glance: Server-Side Request Forgery allows internal URL access by administrators
CVSS Score:
CVSSv3 Score: 2.2
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-72848
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520844
Bugzilla Description: langchain-community: langchain-community: Server-Side Request Forgery and Information Disclosure via nested sitemap entries
CVSS Score:
CVSSv3 Score: 8.6
Vector:
CWE: CWE-918
Affected Packages:
Package States: Exploit Intelligence,Exploit Intelligence,Migration Toolkit for Applications 8,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-72818
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520843
Bugzilla Description: nltk: NLTK TweetTokenizer: Denial of Service via crafted URL input
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1333
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-55893
Severity: moderate
Released on: 20/08/2026
Advisory: RHSA-2026:59419,
Bugzilla: 2520815
Bugzilla Description: capstone: Capstone: Heap buffer overflow with potential code execution
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-805
Affected Packages: capstone-main-5.0.8-0.3.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-55894
Severity: moderate
Released on: 20/08/2026
Advisory: RHSA-2026:59419,
Bugzilla: 2520820
Bugzilla Description: capstone: Capstone: Denial of Service via crafted SH2A bytecode
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages: capstone-main-5.0.8-0.3.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-77643
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2520814
Bugzilla Description: xapian-core: Xapian xapian-core: Arbitrary code execution via incomplete HTML escaping
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-79
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-70654
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2520800
Bugzilla Description: libvips: libvips: Heap buffer overflow allows memory corruption and denial of service.
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-70651
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2520803
Bugzilla Description: libvips: libvips: Denial of Service via integer overflow in multi-page TIFF image processing
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-190
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-70652
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2520799
Bugzilla Description: libvips: libvips: Information disclosure or denial of service via heap buffer over-read when processing JPEGs with gain maps
CVSS Score:
CVSSv3 Score: 5.0
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-69242
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520797
Bugzilla Description: libvips: libvips: Integer overflow leads to heap buffer overflow and arbitrary memory access
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76018
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520790
Bugzilla Description: chromium-browser: Google Chrome: Arbitrary Code Execution via crafted file in Import component
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-641
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-43678
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520715
Bugzilla Description: swift-nio: swift-nio: Denial of Service via specially crafted WebSocket frame
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-53586
Severity: moderate
Released on: 20/08/2026
Advisory: RHSA-2026:59361,
Bugzilla: 2520691
Bugzilla Description: libgit2: libgit2: Information disclosure via HTTP redirect allows credential leakage
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-201
Affected Packages: libgit2-main-1.9.7-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,
Full Details
CVE document


CVE-2026-53583
Severity: moderate
Released on: 20/08/2026
Advisory: RHSA-2026:59361,
Bugzilla: 2520694
Bugzilla Description: libgit2: libgit2: Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-295
Affected Packages: libgit2-main-1.9.7-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,
Full Details
CVE document


CVE-2026-53585
Severity: moderate
Released on: 20/08/2026
Advisory: RHSA-2026:59361,
Bugzilla: 2520696
Bugzilla Description: libgit2: libgit2: Denial of Service via Unbounded Memory Allocation
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-770
Affected Packages: libgit2-main-1.9.7-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,
Full Details
CVE document


CVE-2026-53587
Severity: important
Released on: 20/08/2026
Advisory: RHSA-2026:59361,
Bugzilla: 2520693
Bugzilla Description: libgit2: libgit2: Denial of Service due to heap out-of-bounds read from malicious Git server
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-125
Affected Packages: libgit2-main-1.9.7-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,
Full Details
CVE document


CVE-2026-53584
Severity: low
Released on: 20/08/2026
Advisory: RHSA-2026:59361,
Bugzilla: 2520695
Bugzilla Description: libgit2: libgit2: Submodule path traversal allows arbitrary directory creation
CVSS Score:
CVSSv3 Score: 3.5
Vector:
CWE: CWE-22
Affected Packages: libgit2-main-1.9.7-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,
Full Details
CVE document


CVE-2026-63379
Severity: moderate
Released on: 20/08/2026
Advisory: RHSA-2026:60853,
Bugzilla: 2520667
Bugzilla Description: libevent: Libevent: HTTP header smuggling allows authorization bypass or cache poisoning
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-444
Affected Packages: libevent-main-2.1.12-19.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-63387
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520655
Bugzilla Description: libevent: Libevent: Off-by-one stack buffer overflow leading to denial of service or data corruption
CVSS Score:
CVSSv3 Score: 8.6
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-63384
Severity: important
Released on: 20/08/2026
Advisory: RHSA-2026:60853,
Bugzilla: 2520658
Bugzilla Description: libevent: Libevent: Denial of Service via integer conversion error in `evtag_unmarshal_header`
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-190
Affected Packages: libevent-main-2.1.12-19.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-63380
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2520656
Bugzilla Description: libevent: Libevent: Denial of Service via Null Pointer Dereference
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-63381
Severity: moderate
Released on: 20/08/2026
Advisory: RHSA-2026:60853,
Bugzilla: 2520657
Bugzilla Description: libevent: Libevent: Memory corruption due to use-after-free
CVSS Score:
CVSSv3 Score: 6.6
Vector:
CWE: CWE-825
Affected Packages: libevent-main-2.1.12-19.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-63495
Severity: important
Released on: 20/08/2026
Advisory: RHSA-2026:41176,
Bugzilla: 2520659
Bugzilla Description: libevent: Libevent: Remote denial of service via unbounded memory accumulation in WebSocket server
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages: libevent-main-2.1.12-19.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-63383
Severity: important
Released on: 20/08/2026
Advisory: RHSA-2026:60853,
Bugzilla: 2520654
Bugzilla Description: libevent: Libevent: Denial of Service via malformed RPC data
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-125
Affected Packages: libevent-main-2.1.12-19.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-63388
Severity: important
Released on: 20/08/2026
Advisory: RHSA-2026:60853,
Bugzilla: 2520661
Bugzilla Description: libevent: Libevent: Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling
CVSS Score:
CVSSv3 Score: 8.4
Vector:
CWE: CWE-787
Affected Packages: libevent-main-2.1.12-19.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-66785
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2507530
Bugzilla Description: submariner: submariner: unvalidated Endpoint.Spec.Subnets propagated into WireGuard AllowedIPs / IPsec enables traffic hijack
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-20
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-66787
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2507532
Bugzilla Description: lighthouse: lighthouse: cross-cluster DNS spoofing via unvalidated EndpointSlice and ServiceImport IPs
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-345
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-66788
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2507533
Bugzilla Description: lighthouse: lighthouse: arbitrary local-namespace injection via attacker-controlled LabelSourceNamespace
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-284
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-54770
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520616
Bugzilla Description: webob: WebOb: Open redirect vulnerability leading to phishing and token theft
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-601
Affected Packages:
Package States: Red Hat Ceph Storage 4,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-15679
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520600
Bugzilla Description: timm: Hugging Face PyTorch Image Models: Remote Code Execution via Deserialization of Untrusted Data
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-502
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-18309
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520559
Bugzilla Description: gimp: GIMP: Remote Code Execution via APNG file parsing integer overflow
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18308
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520576
Bugzilla Description: gimp: GIMP: Remote Code Execution via TIF File Parsing Integer Overflow
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18307
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520594
Bugzilla Description: gimp: GIMP: Remote code execution via TIF file parsing heap-based buffer overflow
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18306
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520591
Bugzilla Description: gimp: GIMP: Remote Code Execution via SGI File Parsing Integer Overflow
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18305
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520582
Bugzilla Description: gimp: GIMP: Remote Code Execution via TIF file parsing integer overflow
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18304
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520560
Bugzilla Description: gimp: GIMP: Arbitrary code execution via crafted TIF file parsing
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18303
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520583
Bugzilla Description: gimp: GIMP: Remote code execution via TIF file parsing vulnerability
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18302
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520579
Bugzilla Description: gimp: GIMP: Remote code execution via TIF file parsing heap-based buffer overflow
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18301
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520561
Bugzilla Description: gimp: GIMP: Remote code execution via PSD file parsing integer overflow
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18300
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520587
Bugzilla Description: gimp: gegl: GIMP: Remote code execution via integer overflow in HDR file parsing
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18299
Severity: important
Released on: 20/08/2026
Advisory: RHSA-2026:59152, RHSA-2026:59179, RHSA-2026:59972,
Bugzilla: 2520605
Bugzilla Description: gstreamer: GStreamer: Remote Code Execution via Use-After-Free in rtpsbcdepay
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-386
Affected Packages: gstreamer1-plugins-good-0:1.26.7-2.el10_2.8,gstreamer1-plugins-good-0:1.22.12-7.el9_8.8,gstreamer1-plugins-good-0:1.16.1-7.el8_10.7,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-18298
Severity: important
Released on: 20/08/2026
Advisory: RHSA-2026:59152, RHSA-2026:59133, RHSA-2026:59179,
Bugzilla: 2520590
Bugzilla Description: gstreamer: GStreamer: Remote code execution via heap-based buffer overflow in PNG file parsing
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-120
Affected Packages: gstreamer1-plugins-good-0:1.22.12-7.el9_8.8,gstreamer1-plugins-good-0:1.16.1-7.el8_10.7,gstreamer1-plugins-good-0:1.26.7-2.el10_2.7,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-18297
Severity: important
Released on: 20/08/2026
Advisory: RHSA-2026:59097, RHSA-2026:59487,
Bugzilla: 2520572
Bugzilla Description: gstreamer: GStreamer: Arbitrary code execution via OGG file parsing buffer overflow
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-120
Affected Packages: gstreamer1-plugins-base-0:1.16.1-6.el8_10.1,gstreamer1-plugins-base-0:1.26.7-2.el10_2.1,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18296
Severity: important
Released on: 20/08/2026
Advisory: RHSA-2026:59152, RHSA-2026:59133, RHSA-2026:59179,
Bugzilla: 2520580
Bugzilla Description: gstreamer: GStreamer: Remote Code Execution via MRF file parsing heap-based buffer overflow
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-120
Affected Packages: gstreamer1-plugins-good-0:1.22.12-7.el9_8.8,gstreamer1-plugins-good-0:1.16.1-7.el8_10.7,gstreamer1-plugins-good-0:1.26.7-2.el10_2.7,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-18295
Severity: important
Released on: 20/08/2026
Advisory: RHSA-2026:59152, RHSA-2026:59179,
Bugzilla: 2520606
Bugzilla Description: GStreamer: GStreamer: Remote code execution via MRF file parsing
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-787
Affected Packages: gstreamer1-plugins-good-0:1.22.12-7.el9_8.8,gstreamer1-plugins-good-0:1.16.1-7.el8_10.7,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-71492
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2520536
Bugzilla Description: banks: Banks: Arbitrary file write via path traversal
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-22
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-49825
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520368
Bugzilla Description: lxml: lxml-html-clean: lxml: URL bypass vulnerability in Cleaner via missing xlink:href
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-166
Affected Packages:
Package States: Lightspeed Core,Lightspeed Core,Lightspeed Core,Migration Toolkit for Applications 8,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform Ansible Core 2,Red Hat Ansible Automation Platform Ansible Core 2,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Update Infrastructure 4 for Cloud Providers,Red Hat Update Infrastructure 5,Red Hat Update Infrastructure 5,
Full Details
CVE document


CVE-2026-61898
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520354
Bugzilla Description: accountsservice: accountsservice: Arbitrary code execution via shell injection
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-78
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-61897
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520352
Bugzilla Description: accountsservice: AccountsService: Local privilege escalation via incomplete privilege drop in language helper scripts
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-273
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-77176
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2517502
Bugzilla Description: kata-containers: Insufficient validation of CreateContainer mount and storage rules in genpolicy
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-73
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-13097
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2515974
Bugzilla Description: ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-706
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-73199
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2471741
Bugzilla Description: ipa: FreeIPA: NULL Pointer Dereference in `ipa-enrollment` Extended Operation (`JOIN_OID`) via Missing Request Value
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-73198
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2472960
Bugzilla Description: ipa: FreeIPA: Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-73197
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2474697
Bugzilla Description: ipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-73196
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2474712
Bugzilla Description: ipa: FreeIPA: Authenticated DoS in `otptoken-add` via unbounded OTP key decoding/re-encoding
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-11861
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2487472
Bugzilla Description: FreeIPA: idm: ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76957
Severity: moderate
Released on: 20/08/2026
Advisory: RHSA-2026:60451,
Bugzilla: 2520125
Bugzilla Description: libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service
CVSS Score:
CVSSv3 Score: 4.9
Vector:
CWE: CWE-825
Affected Packages: expat-main-2.8.3-0.1.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-76956
Severity: moderate
Released on: 20/08/2026
Advisory: RHSA-2026:60451,
Bugzilla: 2520124
Bugzilla Description: libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-331
Affected Packages: expat-main-2.8.3-0.1.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-28984
Severity: important
Released on: 20/08/2026
Advisory: RHSA-2026:25918, RHSA-2026:28114, RHSA-2026:28147, RHSA-2026:28148, RHSA-2026:27785, RHSA-2026:28146, RHSA-2026:27728, RHSA-2026:25927, RHSA-2026:27804,
Bugzilla: 2520315
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages: webkit2gtk3-0:2.52.4-1.el8_8,webkit2gtk3-0:2.52.4-1.el9_8,webkit2gtk3-0:2.52.4-1.el8_4,webkit2gtk3-0:2.52.4-1.el8_10,webkit2gtk3-0:2.52.4-1.el9_4,webkit2gtk3-0:2.52.4-1.el8_6,webkit2gtk3-0:2.52.4-1.el9_6,webkitgtk4-0:2.52.4-1.el7_9,webkit2gtk3-0:2.52.4-1.el9_2,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-43804
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2520316
Bugzilla Description: webkitgtk: Visiting a website may lead to an app denial-of-service
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-664
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64713
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2520317
Bugzilla Description: webkitgtk: Websites may know if the user has visited a given link
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-200
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64719
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520318
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64728
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2520319
Bugzilla Description: webkitgtk: Maliciously crafted web content may violate iframe sandboxing policy
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-693
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64787
Severity: important
Released on: 20/08/2026
Advisory: RHSA-2026:42088, RHSA-2026:58550, RHSA-2026:54572, RHSA-2026:58564, RHSA-2026:42062, RHSA-2026:59326, RHSA-2026:59325, RHSA-2026:57348, RHSA-2026:54634,
Bugzilla: 2520320
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-416
Affected Packages: webkit2gtk3-0:2.52.5-1.el8_10,webkit2gtk3-0:2.52.5-1.el9_2,webkit2gtk3-0:2.52.5-1.el8_4,webkit2gtk3-0:2.52.5-1.el9_4,webkit2gtk3-0:2.52.5-1.el8_6,webkit2gtk3-0:2.52.5-1.el9_6,webkitgtk4-0:2.52.5-1.el7_9,webkit2gtk3-0:2.52.5-1.el8_8,webkit2gtk3-0:2.52.5-1.el9_8,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-64730
Severity: moderate
Released on: 20/08/2026
Advisory:
Bugzilla: 2520321
Bugzilla Description: webkitgtk: Visiting a website that frames malicious content may lead to UI spoofing
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-451
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64757
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520322
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64783
Severity: important
Released on: 20/08/2026
Advisory:
Bugzilla: 2520323
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-416
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76928
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520100
Bugzilla Description: wireshark: Wireshark: Denial of Service via X.509IF protocol dissector crash
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76891
Severity: low
Released on: 19/08/2026
Advisory:
Bugzilla: 2520092
Bugzilla Description: wireshark: Wireshark: Denial of Service via sharkd crash
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-248
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76885
Severity: low
Released on: 19/08/2026
Advisory:
Bugzilla: 2520090
Bugzilla Description: wireshark: Wireshark: Denial of Service via Tektronix K12xx file parsing
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76924
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520091
Bugzilla Description: wireshark: Wireshark: Denial of Service via Out-of-bounds Read in Kerberos Dissector
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76923
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520086
Bugzilla Description: wireshark: Wireshark: Denial of Service due to out-of-bounds read in Bluetooth HFP dissector
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76918
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520087
Bugzilla Description: wireshark: Wireshark: Denial of Service via SSH protocol dissector crash
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-248
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76917
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520089
Bugzilla Description: wireshark: Wireshark: Denial of Service via Heap-based Buffer Overflow in Bluetooth AVRCP Dissector
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76880
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520088
Bugzilla Description: wireshark: Wireshark: Denial of Service via RRC protocol dissector out-of-bounds write
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76879
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520098
Bugzilla Description: wireshark: Wireshark: Denial of Service via C12.22 protocol dissector crash
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76889
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520083
Bugzilla Description: wireshark: Wireshark: Denial of Service via UMTS FP protocol dissector crash
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76888
Severity: low
Released on: 19/08/2026
Advisory:
Bugzilla: 2520084
Bugzilla Description: wireshark: Wireshark: Heap-based Buffer Overflow in RDP dissector leads to Denial of Service
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76887
Severity: low
Released on: 19/08/2026
Advisory:
Bugzilla: 2520081
Bugzilla Description: wireshark: Wireshark: Denial of service via heap-based buffer overflow in dissection engine
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76886
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520079
Bugzilla Description: wireshark: Wireshark: Denial of Service via C12.22 protocol dissector crash
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76884
Severity: low
Released on: 19/08/2026
Advisory:
Bugzilla: 2520077
Bugzilla Description: wireshark: Wireshark: Denial of Service via ERF file parser crash
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-130
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76883
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520080
Bugzilla Description: wireshark: Wireshark: Denial of Service via heap-based buffer overflow in Catapult DCT2000 file parser
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76882
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520082
Bugzilla Description: wireshark: Wireshark: Denial of Service via Bluetooth Attribute Protocol dissector out-of-bounds read
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76881
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520078
Bugzilla Description: wireshark: Wireshark: Denial of service via CMS protocol dissector crash
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68554
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2520325
Bugzilla Description: coturn: Coturn: Unauthorized actions or resource manipulation via STUN request modification
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-354
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-68553
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2520746
Bugzilla Description: coturn: Coturn: Format string vulnerability leads to denial of service and information disclosure
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-134
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76827
Severity: moderate
Released on: 19/08/2026
Advisory: RHSA-2026:60391, RHSA-2026:60390, RHSA-2026:60386, RHSA-2026:60389, RHSA-2026:60388, RHSA-2026:60387,
Bugzilla: 2519896
Bugzilla Description: search-indexer: search-indexer: UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering)
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-693
Affected Packages: rhacm2/acm-search-indexer-rhel9:1787688957,rhacm2/acm-search-indexer-rhel9:1787247085,rhacm2/acm-search-indexer-rhel9:1787250074,rhacm2/acm-search-indexer-rhel9:1787262474,rhacm2/acm-search-indexer-rhel9:1787249293,rhacm2/acm-search-indexer-rhel9:1787248491,
Package States:
Full Details
CVE document


CVE-2026-76139
Severity: important
Released on: 19/08/2026
Advisory: RHSA-2026:60401, RHSA-2026:60400, RHSA-2026:60399, RHSA-2026:60404, RHSA-2026:60403, RHSA-2026:60402,
Bugzilla: 2519852
Bugzilla Description: acm-operator-bundle: acm-operator-bundle: Bundle build execs unpinned stolostron/release@master with full build credentials
CVSS Score:
CVSSv3 Score: 8.0
Vector:
CWE: CWE-829
Affected Packages: rhacm2/acm-operator-bundle:1787712120,rhacm2/acm-operator-bundle:1787738299,rhacm2/acm-operator-bundle:1787704547,rhacm2/acm-operator-bundle:1787711895,rhacm2/acm-operator-bundle:1787704476,rhacm2/acm-operator-bundle:1787704231,
Package States:
Full Details
CVE document


CVE-2026-75569
Severity: important
Released on: 19/08/2026
Advisory: RHSA-2026:59643, RHSA-2026:59642, RHSA-2026:59634, RHSA-2026:59636, RHSA-2026:59638, RHSA-2026:59637,
Bugzilla: 2519849
Bugzilla Description: mce-operator-bundle: mce-operator-bundle: Bundle-generation business logic fetched from mutable stolostron/release@master
CVSS Score:
CVSSv3 Score: 7.7
Vector:
CWE: CWE-829
Affected Packages: multicluster-engine/mce-operator-bundle:1787318262,multicluster-engine/mce-operator-bundle:1787321579,multicluster-engine/mce-operator-bundle:1787263075,multicluster-engine/mce-operator-bundle:1787317415,multicluster-engine/mce-operator-bundle:1787287150,multicluster-engine/mce-operator-bundle:1787083639,
Package States:
Full Details
CVE document


CVE-2026-69159
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2519828
Bugzilla Description: FreeRDP: FreeRDP: Out-of-bounds read leads to denial of service and information disclosure
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-63633
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519826
Bugzilla Description: freerdp: FreeRDP: Arbitrary code execution via heap buffer overflow in Opus audio decode
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-63652
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2519822
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service and heap corruption via malformed RDP audio PDU
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-50152
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519423
Bugzilla Description: ceph: ceph: MON subscription handler exposes config-key store to low-privilege CephX users
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Ceph Storage 4,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,
Full Details
CVE document


CVE-2026-54330
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519428
Bugzilla Description: ceph: ceph: RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-347
Affected Packages:
Package States: Red Hat Ceph Storage 4,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,
Full Details
CVE document


CVE-2026-39944
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519431
Bugzilla Description: ceph: ceph: RGW STS session tokens vulnerable to CBC bit-flip attack enabling admin privilege escalation
CVSS Score:
CVSSv3 Score: 8.5
Vector:
CWE: CWE-327
Affected Packages:
Package States: Red Hat Ceph Storage 4,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,
Full Details
CVE document


CVE-2026-63117
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2519821
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via ADPCM frame size calculation
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-55192
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519823
Bugzilla Description: FreeRDP: FreeRDP: Out-of-bounds read leads to memory disclosure or client crash
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-55194
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519824
Bugzilla Description: FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-55648
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2519816
Bugzilla Description: FreeRDP: FreeRDP: Integer overflow allows out-of-bounds read via malicious RDP server
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-55193
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519818
Bugzilla Description: FreeRDP: FreeRDP: Remote code execution or client crash via malicious TS Gateway
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-55564
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2519813
Bugzilla Description: FreeRDP: FreeRDP: Out-of-bounds read in glyph cache leads to denial of service and information disclosure
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-55191
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519817
Bugzilla Description: FreeRDP: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18874
Severity: moderate
Released on: 19/08/2026
Advisory: RHSA-2026:60391, RHSA-2026:60390, RHSA-2026:60386, RHSA-2026:60389, RHSA-2026:60388, RHSA-2026:60387,
Bugzilla: 2511115
Bugzilla Description: volsync-addon-controller: volsync-addon-controller: annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription
CVSS Score:
CVSSv3 Score: 6.2
Vector:
CWE: CWE-94
Affected Packages: rhacm2/acm-volsync-addon-controller-rhel9:1787266360,rhacm2/acm-volsync-addon-controller-rhel9:1787683560,rhacm2/acm-volsync-addon-controller-rhel9:1787266556,rhacm2/acm-volsync-addon-controller-rhel9:1787266564,
Package States:
Full Details
CVE document


CVE-2026-75147
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519763
Bugzilla Description: ffmpeg: FFmpeg: Information disclosure or denial of service via crafted AV1 RTP packet
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-75146
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519764
Bugzilla Description: ffmpeg: FFmpeg: Information disclosure and denial of service via out-of-bounds read in DASH demuxer
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-75145
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2519757
Bugzilla Description: ffmpeg: FFmpeg: Out-of-bounds memory access due to integer narrowing conversion
CVSS Score:
CVSSv3 Score: 5.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-75144
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519760
Bugzilla Description: ffmpeg: FFmpeg: Memory corruption via crafted Dirac data unit
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-75143
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519758
Bugzilla Description: ffmpeg: FFmpeg Heap Buffer Overflow via RIST Protocol Reader
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-75142
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519759
Bugzilla Description: ffmpeg: FFmpeg: Stack Buffer Overflow in MPEG-PS Muxer
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-70496
Severity: important
Released on: 19/08/2026
Advisory: RHSA-2026:60391, RHSA-2026:60390, RHSA-2026:60386, RHSA-2026:60389, RHSA-2026:60388, RHSA-2026:60387,
Bugzilla: 2511032
Bugzilla Description: search-v2-operator: search-v2-operator: operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-250
Affected Packages: rhacm2/acm-search-v2-rhel9:1787682033,rhacm2/acm-search-v2-rhel9:1787681674,rhacm2/acm-search-v2-rhel9:1787681686,rhacm2/acm-search-v2-rhel9:1787682112,rhacm2/acm-search-v2-rhel9:1787681651,rhacm2/acm-search-v2-rhel9:1787688827,rhacm2/search-collector-rhel9:1787229539,
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-71470
Severity: important
Released on: 19/08/2026
Advisory: RHSA-2026:60391, RHSA-2026:60390, RHSA-2026:60386, RHSA-2026:60389, RHSA-2026:60388, RHSA-2026:60387,
Bugzilla: 2512149
Bugzilla Description: acm-search-v2-rhel9: search-v2-operator: Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA
CVSS Score:
CVSSv3 Score: 9.1
Vector:
CWE: CWE-913
Affected Packages: rhacm2/acm-search-v2-rhel9:1787682033,rhacm2/acm-search-v2-rhel9:1787681674,rhacm2/acm-search-v2-rhel9:1787681686,rhacm2/acm-search-v2-rhel9:1787682112,rhacm2/acm-search-v2-rhel9:1787681651,rhacm2/acm-search-v2-rhel9:1787688827,
Package States:
Full Details
CVE document


CVE-2026-76878
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2517803
Bugzilla Description: aodh: python-watcher: aodh / python-watcher: cross-project alarm enumeration and webhook missing authorization
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-76233
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519598
Bugzilla Description: renovate: Renovate: Arbitrary command execution via gleam manager command injection
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-78
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76231
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2519628
Bugzilla Description: renovate: Renovate: Arbitrary command execution via unsanitized dependency names
CVSS Score:
CVSSv3 Score: 6.7
Vector:
CWE: CWE-78
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76228
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2519617
Bugzilla Description: renovate: Renovate: Arbitrary Code Execution via malicious Gradle Wrapper properties
CVSS Score:
CVSSv3 Score: 6.7
Vector:
CWE: CWE-78
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76229
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2519627
Bugzilla Description: renovate: Renovate: Arbitrary Command Injection via kustomize manager
CVSS Score:
CVSSv3 Score: 6.7
Vector:
CWE: CWE-78
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76222
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519609
Bugzilla Description: gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-22
Affected Packages:
Package States: Exploit Intelligence,Exploit Intelligence,Migration Toolkit for Applications 8,Pen Drive Powered by Red Hat Lightspeed,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-76221
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519596
Bugzilla Description: gitpython: GitPython: Arbitrary code execution via config-name injection
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-78
Affected Packages:
Package States: Exploit Intelligence,Exploit Intelligence,Migration Toolkit for Applications 8,Pen Drive Powered by Red Hat Lightspeed,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-76220
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519610
Bugzilla Description: gitpython: GitPython: Arbitrary command execution via crafted kwargs
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-78
Affected Packages:
Package States: Exploit Intelligence,Exploit Intelligence,Migration Toolkit for Applications 8,Pen Drive Powered by Red Hat Lightspeed,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-76219
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519597
Bugzilla Description: gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-88
Affected Packages:
Package States: Exploit Intelligence,Exploit Intelligence,Migration Toolkit for Applications 8,Pen Drive Powered by Red Hat Lightspeed,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-76218
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519603
Bugzilla Description: gitpython: GitPython: Remote Code Execution via malicious Git hooks
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-94
Affected Packages:
Package States: Exploit Intelligence,Exploit Intelligence,Migration Toolkit for Applications 8,Pen Drive Powered by Red Hat Lightspeed,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-76217
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2519621
Bugzilla Description: gitpython: GitPython: Arbitrary File Read via Crafted Parameters
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-88
Affected Packages:
Package States: Exploit Intelligence,Exploit Intelligence,Migration Toolkit for Applications 8,Pen Drive Powered by Red Hat Lightspeed,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2020-37267
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519611
Bugzilla Description: renovate: Renovate: Information disclosure via unredacted logging of authorization tokens
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-538
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-66794
Severity: important
Released on: 19/08/2026
Advisory: RHSA-2026:59593, RHSA-2026:59557, RHSA-2026:59579, RHSA-2026:59556, RHSA-2026:59559, RHSA-2026:59558,
Bugzilla: 2507539
Bugzilla Description: cluster-proxy-addon: cluster-proxy-addon: unauthenticated SSRF to arbitrary managed-cluster services via public Route
CVSS Score:
CVSSv3 Score: 9.3
Vector:
CWE: CWE-918
Affected Packages: multicluster-engine/cluster-proxy-addon-rhel9:1787275519,multicluster-engine/cluster-proxy-rhel9:1787276784,multicluster-engine/cluster-proxy-addon-rhel9:1787275318,multicluster-engine/cluster-proxy-addon-rhel9:1787274923,multicluster-engine/cluster-proxy-rhel9:1786983349,multicluster-engine/cluster-proxy-addon-rhel9:1787173361,
Package States:
Full Details
CVE document


CVE-2026-43961
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2460434
Bugzilla Description: vim: Vimscript injection via unescaped filename in netrw s:NetrwMarkFile() filter() expression allows arbitrary code execution
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-94
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-16440
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2519478
Bugzilla Description: openj9: Eclipse OpenJ9: Denial of Service via crafted .class file
CVSS Score:
CVSSv3 Score: 5.7
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-75900
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2517910
Bugzilla Description: swtpm: swtpm: Out-of-bounds read in SWTPM_NVRAM_CheckHeader due to sizeof(pointer) vs sizeof(struct) mismatch
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-58081
Severity: important
Released on: 19/08/2026
Advisory:
Bugzilla: 2519413
Bugzilla Description: iconv: iconv: Heap-based buffer overflow in encoding modules
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76235
Severity: moderate
Released on: 19/08/2026
Advisory:
Bugzilla: 2519497
Bugzilla Description: cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via CockpitLang cookie in send_login_html
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-401
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-71084
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2519277
Bugzilla Description: mysql-connector-odbc: MySQL Connector/ODBC: Denial of Service via unauthenticated local access
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-71079
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2519167
Bugzilla Description: mysql-connector-odbc: MySQL Connector/ODBC: Denial of Service via network access by a low privileged attacker
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-76038
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2518262
Bugzilla Description: chromium-browser: v8: V8: Remote code execution via type confusion in crafted HTML.
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76041
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2518263
Bugzilla Description: chromium-browser: Chromium: Information leak allows web origin policy bypass
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76047
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2518275
Bugzilla Description: chromium-browser: Chromium-browser: Arbitrary code execution via type confusion in V8
CVSS Score:
CVSSv3 Score: 8.3
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76045
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2518276
Bugzilla Description: chromium-browser: Google Chrome WebGL: Arbitrary code execution via use-after-free
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76042
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2518271
Bugzilla Description: chromium-browser: Google Chrome: Information disclosure via uninitialized resource in GPU
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76043
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2518273
Bugzilla Description: chromium-browser: v8: Google Chrome V8: Arbitrary code execution via incorrect calculation in HTML processing
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-190
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76039
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2518266
Bugzilla Description: chromium-browser: Chromium: Information disclosure via incorrect reference resolution
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-386
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76040
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2518272
Bugzilla Description: chromium-browser: chromium-browser: Arbitrary code execution via use-after-free vulnerability
CVSS Score:
CVSSv3 Score: 8.3
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76037
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2518261
Bugzilla Description: chromium-browser: Google Chrome: Arbitrary Code Execution via Link Following
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-59
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76044
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2518264
Bugzilla Description: chromium-browser: Google Chrome: Arbitrary code execution due to a race condition in USB
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-368
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76033
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2518270
Bugzilla Description: chromium-browser: Google Chrome: Site isolation bypass due to inappropriate CORS implementation
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-653
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-76036
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2518267
Bugzilla Description: chromium-browser: Dawn in Google Chrome: Arbitrary code execution via crafted HTML page
CVSS Score:
CVSSv3 Score: 8.3
Vector:
CWE: CWE-120
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-16732
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2518255
Bugzilla Description: fastify: fastify: Request spoofing via numeric trustProxy configuration
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-501
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-18504
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2518254
Bugzilla Description: fastify: fastify: Schema validation bypass via root primitive coercion mismatch
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-15571
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:56524, RHSA-2026:56523,
Bugzilla: 2499591
Bugzilla Description: keycloak-services: keycloak-services: Predictable account-linking hash enables account takeover via malicious OIDC client
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-341
Affected Packages: rhbk/keycloak-rhel9:26.6-12,rhbk/keycloak-rhel9,keycloak-services,rhbk-openshift-rhel9/rhbk-openshift-rhel9,rhbk/keycloak-operator-bundle:26.6.6-1,rhbk/keycloak-rhel9-operator:26.6-12,
Package States: Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-49452
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2518129
Bugzilla Description: weasyprint: WeasyPrint: CSS Injection via Presentational Hints
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-79
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,
Full Details
CVE document


CVE-2026-54552
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2518108
Bugzilla Description: sh: sh: Incomplete privilege drop allows child processes to retain privileged group access.
CVSS Score:
CVSSv3 Score: 7.9
Vector:
CWE: CWE-273
Affected Packages:
Package States: Red Hat OpenShift Virtualization 4,
Full Details
CVE document


CVE-2026-66780
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:60391, RHSA-2026:60390, RHSA-2026:60386, RHSA-2026:60389, RHSA-2026:60388, RHSA-2026:60387,
Bugzilla: 2507524
Bugzilla Description: submariner-operator: submariner-operator: flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-284
Affected Packages: rhacm2/submariner-addon-rhel9:1787362694,rhacm2/submariner-addon-rhel9:1787689013,rhacm2/submariner-addon-rhel9:1787365971,rhacm2/submariner-addon-rhel9:1787362658,rhacm2/submariner-addon-rhel9:1787362756,rhacm2/submariner-addon-rhel9:1787362733,
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-66781
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:60391, RHSA-2026:60390, RHSA-2026:60386, RHSA-2026:60389, RHSA-2026:60388, RHSA-2026:60387,
Bugzilla: 2507526
Bugzilla Description: submariner-operator: submariner-operator: IPsec PSK stored cleartext in Submariner CR spec
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-312
Affected Packages: rhacm2/submariner-addon-rhel9:1787362694,rhacm2/submariner-addon-rhel9:1787689013,rhacm2/submariner-addon-rhel9:1787365971,rhacm2/submariner-addon-rhel9:1787362658,rhacm2/submariner-addon-rhel9:1787362756,rhacm2/submariner-addon-rhel9:1787362733,
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-66782
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2507527
Bugzilla Description: submariner-operator: submariner-operator: broker API bearer token stored cleartext in CR spec
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-312
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-66783
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2507528
Bugzilla Description: submariner-operator: submariner-operator: arbitrary image override enables privileged code execution on every node
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-20
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-75924
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2515720
Bugzilla Description: managed-serviceaccount: managed-serviceaccount: Hub addon-manager ClusterRole grants cluster-wide Secret read/write and CSR approval
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-269
Affected Packages:
Package States: Multicluster Engine for Kubernetes,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-71365
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:59153, RHSA-2026:59155, RHSA-2026:59135, RHSA-2026:59136,
Bugzilla: 2511901
Bugzilla Description: awx: webhook status callback SSRF leaks the Git PAT
CVSS Score:
CVSSv3 Score: 7.7
Vector:
CWE: CWE-918
Affected Packages: automation-controller-0:4.7.16-1.el9ap,ansible-automation-platform-26/controller-rhel9:1787244009,automation-controller-0:4.6.32-1.el8ap,ansible-automation-platform-27/controller-rhel9:1787220257,automation-controller-0:4.6.32-1.el9ap,
Package States:
Full Details
CVE document


CVE-2026-63632
Severity: low
Released on: 18/08/2026
Advisory:
Bugzilla: 2517918
Bugzilla Description: onnx: ONNX: Denial of Service via out-of-bounds read in version converter
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-73834
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:60391, RHSA-2026:60390, RHSA-2026:60386, RHSA-2026:60389, RHSA-2026:60388, RHSA-2026:60387,
Bugzilla: 2517904
Bugzilla Description: must-gather: must-gather: embedded Secret data in ACM wrapper CRs collected without redaction
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-312
Affected Packages: rhacm2/acm-must-gather-rhel9:1787238730,rhacm2/acm-must-gather-rhel9:1787263322,rhacm2/acm-must-gather-rhel9:1787260453,rhacm2/acm-must-gather-rhel9:1787228698,rhacm2/acm-must-gather-rhel9:1787234748,rhacm2/acm-must-gather-rhel9:1787189811,
Package States:
Full Details
CVE document


CVE-2026-75485
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:60391, RHSA-2026:60390, RHSA-2026:60386, RHSA-2026:60389, RHSA-2026:60388, RHSA-2026:60387,
Bugzilla: 2517905
Bugzilla Description: must-gather: must-gather: cluster Proxy object dumped raw, bypassing inspect redaction of proxy basic-auth credentials
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-532
Affected Packages: rhacm2/acm-must-gather-rhel9:1787238730,rhacm2/acm-must-gather-rhel9:1787263322,rhacm2/acm-must-gather-rhel9:1787260453,rhacm2/acm-must-gather-rhel9:1787228698,rhacm2/acm-must-gather-rhel9:1787234748,rhacm2/acm-must-gather-rhel9:1787189811,
Package States:
Full Details
CVE document


CVE-2026-66793
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:60391, RHSA-2026:60390, RHSA-2026:60386, RHSA-2026:60389, RHSA-2026:60388, RHSA-2026:60387,
Bugzilla: 2507538
Bugzilla Description: governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-20
Affected Packages: rhacm2/acm-governance-policy-addon-controller-rhel9:1787227696,rhacm2/acm-governance-policy-addon-controller-rhel9:1787080755,rhacm2/acm-governance-policy-addon-controller-rhel9:1787259078,rhacm2/acm-governance-policy-addon-controller-rhel9:1787080753,rhacm2/acm-governance-policy-addon-controller-rhel9:1787683327,rhacm2/acm-governance-policy-addon-controller-rhel9:1787238535,
Package States:
Full Details
CVE document


CVE-2026-63639
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2517906
Bugzilla Description: valkey: Valkey: Remote code execution via use-after-free in stream deserialization
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-56684
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2517907
Bugzilla Description: valkey: Valkey: Remote code execution via TLS pending-data processing use-after-free
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74989
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2517838
Bugzilla Description: firefox: Internally found bugs fixed in Firefox 154
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74985
Severity: low
Released on: 18/08/2026
Advisory:
Bugzilla: 2517844
Bugzilla Description: firefox: thunderbird: Privilege escalation in the Enterprise Policies component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74986
Severity: low
Released on: 18/08/2026
Advisory:
Bugzilla: 2517850
Bugzilla Description: firefox: thunderbird: Site isolation issue in the CSS Parsing and Computation component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-501
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74988
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2517867
Bugzilla Description: firefox: thunderbird: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-130
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74980
Severity: low
Released on: 18/08/2026
Advisory:
Bugzilla: 2517829
Bugzilla Description: firefox: Clickjacking issue in the Downloads component in Firefox for Android
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-1021
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74982
Severity: low
Released on: 18/08/2026
Advisory:
Bugzilla: 2517847
Bugzilla Description: firefox: thunderbird: Denial-of-service in the Widget component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74984
Severity: low
Released on: 18/08/2026
Advisory:
Bugzilla: 2517857
Bugzilla Description: firefox: thunderbird: Race condition in the JavaScript Engine component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74981
Severity: low
Released on: 18/08/2026
Advisory:
Bugzilla: 2517873
Bugzilla Description: firefox: thunderbird: Site isolation issue in the Audio/Video: Web Codecs component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-501
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74979
Severity: low
Released on: 18/08/2026
Advisory:
Bugzilla: 2517827
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the Add-ons Manager component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-807
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74977
Severity: low
Released on: 18/08/2026
Advisory:
Bugzilla: 2517830
Bugzilla Description: firefox: thunderbird: Integer overflow in the Graphics component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74978
Severity: low
Released on: 18/08/2026
Advisory:
Bugzilla: 2517843
Bugzilla Description: firefox: thunderbird: Clickjacking issue in the Widget component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-1021
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74975
Severity: low
Released on: 18/08/2026
Advisory:
Bugzilla: 2517876
Bugzilla Description: firefox: Spoofing issue in the Downloads component in Firefox for Android
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-494
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74970
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2517818
Bugzilla Description: firefox: thunderbird: Site isolation issue in the Graphics component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-501
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74966
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2517855
Bugzilla Description: firefox: thunderbird: Information disclosure in the Form Autofill component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-359
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74961
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2517865
Bugzilla Description: firefox: thunderbird: Side-channel in the Web Audio component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-208
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74968
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2517875
Bugzilla Description: firefox: thunderbird: Site isolation issue in the Graphics: WebRender component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-501
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74954
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2517852
Bugzilla Description: firefox: thunderbird: Information disclosure due to side-channel in the Storage: Cache API component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-524
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74955
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2517864
Bugzilla Description: firefox: thunderbird: Privilege escalation in the Request Handling component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-551
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74956
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2517869
Bugzilla Description: firefox: Same-origin policy bypass in the DOM: Service Workers component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-346
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74958
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2517871
Bugzilla Description: firefox: thunderbird: Information disclosure in the WebRTC component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-201
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74950
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2517828
Bugzilla Description: firefox: thunderbird: Privilege escalation in the Downloads API component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-648
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74952
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2517842
Bugzilla Description: firefox: thunderbird: Privilege escalation in the Application Update component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-250
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74951
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2517854
Bugzilla Description: firefox: Clickjacking issue in Firefox for Android
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-1021
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74947
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2517861
Bugzilla Description: firefox: thunderbird: Privilege escalation due to invalid pointer in the Graphics component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74938
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2517821
Bugzilla Description: firefox: Mitigation bypass in the JavaScript: GC component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-807
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-75874
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2517832
Bugzilla Description: firefox: thunderbird: Sandbox escape in the Remote Settings Client component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-653
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74990
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517839
Bugzilla Description: firefox: thunderbird: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74937
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2517848
Bugzilla Description: firefox: thunderbird: Use-after-free in the JavaScript: GC component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74983
Severity: low
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517819
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the Data Loss Prevention component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-807
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74987
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517823
Bugzilla Description: firefox: thunderbird: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74976
Severity: low
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517851
Bugzilla Description: firefox: thunderbird: JIT miscompilation in the JavaScript Engine: JIT component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-733
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74974
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517853
Bugzilla Description: firefox: thunderbird: Same-origin policy bypass in the Graphics: ImageLib component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-346
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74971
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517831
Bugzilla Description: firefox: thunderbird: Information disclosure in the DOM: UI Events & Focus Handling component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-360
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74973
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517836
Bugzilla Description: firefox: Race condition, use-after-free in the Graphics component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-825
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74969
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517846
Bugzilla Description: firefox: thunderbird: Use-after-free in the Layout: Text and Fonts component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-825
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74972
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517862
Bugzilla Description: firefox: thunderbird: Information disclosure in the DOM: Push Subscriptions component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-201
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74965
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517834
Bugzilla Description: firefox: Privilege escalation in the Shell Integration component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-266
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74967
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517858
Bugzilla Description: firefox: thunderbird: Same-origin policy bypass in the Audio/Video: Playback component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-940
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74963
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517866
Bugzilla Description: firefox: thunderbird: Same-origin policy bypass in the Networking: Cookies component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-346
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74964
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517870
Bugzilla Description: firefox: Integer overflow in the Graphics component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-190
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74960
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517845
Bugzilla Description: firefox: thunderbird: Site isolation issue in the WebExtensions component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-501
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74959
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517849
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the Storage: Cache API component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-807
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74957
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517856
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the Safe Browsing component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-807
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74962
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517872
Bugzilla Description: firefox: Site isolation issue in the Networking: Cookies component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-1100
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74953
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517822
Bugzilla Description: firefox: thunderbird: Privilege escalation in the Networking: Cookies component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-472
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74948
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517825
Bugzilla Description: firefox: thunderbird: Information disclosure in the Graphics component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-497
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74946
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517835
Bugzilla Description: firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74949
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517837
Bugzilla Description: firefox: thunderbird: Privilege escalation due to use-after-free in the Graphics: Canvas2D component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74943
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517826
Bugzilla Description: firefox: thunderbird: Use-after-free in the Graphics: ImageLib component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74942
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517859
Bugzilla Description: firefox: Privilege escalation in the Remote Settings Client component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-266
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74945
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517863
Bugzilla Description: firefox: thunderbird: Information disclosure in the Graphics: Text component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-201
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74944
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517868
Bugzilla Description: firefox: thunderbird: Use-after-free in the DOM: Core & HTML component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74941
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517833
Bugzilla Description: firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-266
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74940
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517841
Bugzilla Description: firefox: thunderbird: Use-after-free in the Graphics: Text component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74939
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517860
Bugzilla Description: firefox: thunderbird: Privilege escalation in the DOM: Navigation component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-266
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74934
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517820
Bugzilla Description: firefox: thunderbird: Site isolation issue in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-653
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74936
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517840
Bugzilla Description: firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74935
Severity: important
Released on: 18/08/2026
Advisory: RHSA-2026:58897, RHSA-2026:58898, RHSA-2026:58899,
Bugzilla: 2517874
Bugzilla Description: firefox: thunderbird: Privilege escalation in the DOM: Networking component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-266
Affected Packages: firefox-0:140.14.0-1.el10_2,firefox-0:140.14.0-1.el8_10,firefox-0:140.14.0-1.el9_8,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-23938
Severity: low
Released on: 18/08/2026
Advisory:
Bugzilla: 2517809
Bugzilla Description: zabbix: Zabbix: Denial of Service via crafted JavaScript scripts
CVSS Score:
CVSSv3 Score: 2.7
Vector:
CWE: CWE-770
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-75838
Severity: important
Released on: 18/08/2026
Advisory:
Bugzilla: 2517772
Bugzilla Description: dompurify: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-79
Affected Packages:
Package States: Migration Toolkit for Virtualization,Multicluster Engine for Kubernetes,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat 3scale API Management Platform 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Apicurio Registry 3,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 6,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-60589
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:55788, RHSA-2026:55799, RHSA-2026:55777, RHSA-2026:55776, RHSA-2026:55787, RHSA-2026:55798, RHSA-2026:55775, RHSA-2026:55774, RHSA-2026:55783, RHSA-2026:55782, RHSA-2026:55781, RHSA-2026:57765, RHSA-2026:55779, RHSA-2026:57118, RHSA-2026:55789, RHSA-2026:55778, RHSA-2026:57175, RHSA-2026:57177, RHSA-2026:58266, RHSA-2026:55780,
Bugzilla: 2513035
Bugzilla Description: OpenJDK: Improve Resource Resolving (2026-08 Security Update)
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE:
Affected Packages: java-21-openjdk-portable-main-21.0.12.1.1-0.1.hum1,java-25-openjdk-1:25.0.4.1.1-1.1.el9,java-25-openjdk-windows,java-25-openjdk-main-25.0.4.1.1-1.1.hum1,java-25-openjdk-1:25.0.4.1.1-1.1.el10,java-17-openjdk-1:17.0.20.1.1-1.2.el9,java-21-openjdk-1:21.0.12.1.1-1.1.el8,java-25-openjdk-portable,java-21-openjdk-1:21.0.12.1.1-1.1.el9,java-1.8.0-openjdk-windows,java-11-openjdk-windows,java-17-openjdk-portable,java-11-openjdk-1:11.0.32.1.1-1.el8,java-17-openjdk-windows,java-11-openjdk-1:11.0.32.1.1-1.el9,java-21-openjdk-main-21.0.12.1.1-1.0.hum1,java-1.8.0-openjdk-portable,java-21-openjdk-portable,java-21-openjdk-1:21.0.12.1.1-1.1.el10,java-21-openjdk-1:21.0.12.1.1-1.2.el9,java-1.8.0-openjdk-1:1.8.0.504.b01-1.2.el9,java-11-openjdk-1:11.0.32.1.1-1.el7_9,java-21-openjdk-windows,java-25-openjdk-portable-main-25.0.4.1.1-0.1.hum1,java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el7_9,java-11-openjdk-portable,java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8,java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el9,java-21-openjdk-1:21.0.12.1.1-1.2.el10,java-17-openjdk-1:17.0.20.1.1-1.1.el8,java-17-openjdk-1:17.0.20.1.1-1.1.el9,
Package States: Exploit Intelligence,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-61308
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:55788, RHSA-2026:55799, RHSA-2026:55777, RHSA-2026:55776, RHSA-2026:55787, RHSA-2026:55798, RHSA-2026:55775, RHSA-2026:55774, RHSA-2026:55783, RHSA-2026:55782, RHSA-2026:55781, RHSA-2026:57765, RHSA-2026:55779, RHSA-2026:57118, RHSA-2026:55789, RHSA-2026:55778, RHSA-2026:57175, RHSA-2026:57177, RHSA-2026:58266, RHSA-2026:55780,
Bugzilla: 2513037
Bugzilla Description: OpenJDK: Enhance HTTP Connections (2026-08 Security Update)
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE:
Affected Packages: java-21-openjdk-portable-main-21.0.12.1.1-0.1.hum1,java-25-openjdk-1:25.0.4.1.1-1.1.el9,java-25-openjdk-windows,java-25-openjdk-main-25.0.4.1.1-1.1.hum1,java-25-openjdk-1:25.0.4.1.1-1.1.el10,java-17-openjdk-1:17.0.20.1.1-1.2.el9,java-21-openjdk-1:21.0.12.1.1-1.1.el8,java-25-openjdk-portable,java-21-openjdk-1:21.0.12.1.1-1.1.el9,java-1.8.0-openjdk-windows,java-11-openjdk-windows,java-17-openjdk-portable,java-11-openjdk-1:11.0.32.1.1-1.el8,java-17-openjdk-windows,java-11-openjdk-1:11.0.32.1.1-1.el9,java-21-openjdk-main-21.0.12.1.1-1.0.hum1,java-1.8.0-openjdk-portable,java-21-openjdk-portable,java-21-openjdk-1:21.0.12.1.1-1.1.el10,java-21-openjdk-1:21.0.12.1.1-1.2.el9,java-1.8.0-openjdk-1:1.8.0.504.b01-1.2.el9,java-11-openjdk-1:11.0.32.1.1-1.el7_9,java-21-openjdk-windows,java-25-openjdk-portable-main-25.0.4.1.1-0.1.hum1,java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el7_9,java-11-openjdk-portable,java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8,java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el9,java-21-openjdk-1:21.0.12.1.1-1.2.el10,java-17-openjdk-1:17.0.20.1.1-1.1.el8,java-17-openjdk-1:17.0.20.1.1-1.1.el9,
Package States: Exploit Intelligence,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-70907
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:55788, RHSA-2026:55799, RHSA-2026:55777, RHSA-2026:55776, RHSA-2026:55787, RHSA-2026:55798, RHSA-2026:55775, RHSA-2026:55774, RHSA-2026:55783, RHSA-2026:55782, RHSA-2026:55781, RHSA-2026:57765, RHSA-2026:55779, RHSA-2026:57118, RHSA-2026:55789, RHSA-2026:55778, RHSA-2026:57175, RHSA-2026:57177, RHSA-2026:58266, RHSA-2026:55780,
Bugzilla: 2513038
Bugzilla Description: OpenJDK: Enhance TLS server (2026-08 Security Update)
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE:
Affected Packages: java-21-openjdk-portable-main-21.0.12.1.1-0.1.hum1,java-25-openjdk-1:25.0.4.1.1-1.1.el9,java-25-openjdk-windows,java-25-openjdk-main-25.0.4.1.1-1.1.hum1,java-25-openjdk-1:25.0.4.1.1-1.1.el10,java-17-openjdk-1:17.0.20.1.1-1.2.el9,java-21-openjdk-1:21.0.12.1.1-1.1.el8,java-25-openjdk-portable,java-21-openjdk-1:21.0.12.1.1-1.1.el9,java-1.8.0-openjdk-windows,java-11-openjdk-windows,java-17-openjdk-portable,java-11-openjdk-1:11.0.32.1.1-1.el8,java-17-openjdk-windows,java-11-openjdk-1:11.0.32.1.1-1.el9,java-21-openjdk-main-21.0.12.1.1-1.0.hum1,java-1.8.0-openjdk-portable,java-21-openjdk-portable,java-21-openjdk-1:21.0.12.1.1-1.1.el10,java-21-openjdk-1:21.0.12.1.1-1.2.el9,java-1.8.0-openjdk-1:1.8.0.504.b01-1.2.el9,java-11-openjdk-1:11.0.32.1.1-1.el7_9,java-21-openjdk-windows,java-25-openjdk-portable-main-25.0.4.1.1-0.1.hum1,java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el7_9,java-11-openjdk-portable,java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8,java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el9,java-21-openjdk-1:21.0.12.1.1-1.2.el10,java-17-openjdk-1:17.0.20.1.1-1.1.el8,java-17-openjdk-1:17.0.20.1.1-1.1.el9,
Package States: Exploit Intelligence,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-70906
Severity: moderate
Released on: 18/08/2026
Advisory: RHSA-2026:55799, RHSA-2026:55798, RHSA-2026:57177, RHSA-2026:57765, RHSA-2026:57118,
Bugzilla: 2513039
Bugzilla Description: OpenJDK: Improve font loading (2026-08 Security Update)
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE:
Affected Packages: java-25-openjdk-portable,java-25-openjdk-1:25.0.4.1.1-1.1.el9,java-25-openjdk-windows,java-25-openjdk-main-25.0.4.1.1-1.1.hum1,java-25-openjdk-1:25.0.4.1.1-1.1.el10,java-25-openjdk-portable-main-25.0.4.1.1-0.1.hum1,
Package States: Exploit Intelligence,Red Hat build of OpenJDK 11 ELS,Red Hat build of OpenJDK 11 ELS,Red Hat build of OpenJDK 11 ELS,Red Hat build of OpenJDK 17,Red Hat build of OpenJDK 17,Red Hat build of OpenJDK 1.8,Red Hat build of OpenJDK 1.8,Red Hat build of OpenJDK 21,Red Hat build of OpenJDK 21,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-79652
Severity: moderate
Released on: 18/08/2026
Advisory:
Bugzilla: 2523347
Bugzilla Description: keycloak-services: keycloak-services: JWT Bearer authorization grant does not enforce consentRequired
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-65331
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524575
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-43794
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524565
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to memory corruption
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-65351
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524585
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64782
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524573
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-667
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-43795
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524566
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-65340
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524583
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-65337
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524581
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-65336
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524580
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64784
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524574
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-65341
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524584
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to memory corruption
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-65335
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524579
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-65334
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524578
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-65338
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524582
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-65333
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524577
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64778
Severity: moderate
Released on: 17/08/2026
Advisory:
Bugzilla: 2524569
Bugzilla Description: webkitgtk: Visiting a maliciously crafted website may leak sensitive data
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-200
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64781
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524572
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-20
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64715
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524567
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-416
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64780
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524571
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-20
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64779
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524570
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-667
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-65332
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2524576
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64849
Severity: important
Released on: 17/08/2026
Advisory: RHSA-2026:60520,
Bugzilla: 2517655
Bugzilla Description: mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
CVSS Score:
CVSSv3 Score: 8.5
Vector:
CWE: CWE-918
Affected Packages: rhoai/odh-mlflow-rhel9:1787226790,
Package States: Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-34398
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2517633
Bugzilla Description: FreeCAD: FreeCAD: Arbitrary Code Execution via malicious BIM project template
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-94
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-34789
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2517629
Bugzilla Description: FreeCAD: FreeCAD: Arbitrary code execution via crafted document restoration
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-502
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-66795
Severity: important
Released on: 17/08/2026
Advisory: RHSA-2026:59593, RHSA-2026:59557, RHSA-2026:59579, RHSA-2026:59556, RHSA-2026:59559, RHSA-2026:59558,
Bugzilla: 2507540
Bugzilla Description: managedcluster-import-controller: managedcluster-import-controller: CSR auto-approver does not validate certificate Subject, signerName, or requester identity
CVSS Score:
CVSSv3 Score: 9.1
Vector:
CWE: CWE-295
Affected Packages: multicluster-engine/managedcluster-import-controller-rhel9:1787078307,multicluster-engine/managedcluster-import-controller-rhel9:1786577915,multicluster-engine/managedcluster-import-controller-rhel9:1787260779,multicluster-engine/managedcluster-import-controller-rhel9:1787259044,multicluster-engine/managedcluster-import-controller-rhel9:1787078272,multicluster-engine/managedcluster-import-controller-rhel9:1787078330,
Package States:
Full Details
CVE document


CVE-2026-73560
Severity: moderate
Released on: 17/08/2026
Advisory:
Bugzilla: 2517604
Bugzilla Description: vllm: vLLM: Server-Side Request Forgery and arbitrary file read via improper media processing
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-71486
Severity: moderate
Released on: 17/08/2026
Advisory:
Bugzilla: 2517595
Bugzilla Description: vllm: vLLM: Denial of Service via unbounded token ID decoding
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-70495
Severity: important
Released on: 17/08/2026
Advisory: RHSA-2026:60391, RHSA-2026:60390, RHSA-2026:60386, RHSA-2026:60389, RHSA-2026:60388, RHSA-2026:60387,
Bugzilla: 2511031
Bugzilla Description: search-v2-operator: search-v2-operator: cluster-wide impersonate on users/groups shared across 4 pods grants hub system:masters
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-269
Affected Packages: rhacm2/acm-search-v2-rhel9:1787682033,rhacm2/acm-search-v2-rhel9:1787681674,rhacm2/acm-search-v2-rhel9:1787681686,rhacm2/acm-search-v2-rhel9:1787682112,rhacm2/acm-search-v2-rhel9:1787681651,rhacm2/acm-search-v2-rhel9:1787688827,
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-71472
Severity: important
Released on: 17/08/2026
Advisory: RHSA-2026:60391, RHSA-2026:60390, RHSA-2026:60386, RHSA-2026:60389, RHSA-2026:60388, RHSA-2026:60387,
Bugzilla: 2512151
Bugzilla Description: acm-search-v2-rhel9: search-v2-operator: Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM
CVSS Score:
CVSSv3 Score: 9.1
Vector:
CWE: CWE-78
Affected Packages: rhacm2/acm-search-v2-rhel9:1787682033,rhacm2/acm-search-v2-rhel9:1787681674,rhacm2/acm-search-v2-rhel9:1787681686,rhacm2/acm-search-v2-rhel9:1787682112,rhacm2/acm-search-v2-rhel9:1787681651,rhacm2/acm-search-v2-rhel9:1787688827,
Package States:
Full Details
CVE document


CVE-2026-46345
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2517528
Bugzilla Description: compliance-trestle: compliance-trestle: Arbitrary file write via path traversal vulnerability
CVSS Score:
CVSSv3 Score: 8.4
Vector:
CWE: CWE-22
Affected Packages:
Package States: File Integrity Operator,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-54284
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2517527
Bugzilla Description: sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1333
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Discovery 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Update Infrastructure 4 for Cloud Providers,Red Hat Update Infrastructure 5,Red Hat Update Infrastructure 5,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-59893
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2517523
Bugzilla Description: sqlparse: sqlparse: Denial of Service via inefficient SQL parsing
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1333
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Discovery 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Update Infrastructure 4 for Cloud Providers,Red Hat Update Infrastructure 5,Red Hat Update Infrastructure 5,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-66792
Severity: important
Released on: 17/08/2026
Advisory: RHSA-2026:60391, RHSA-2026:60390, RHSA-2026:60386, RHSA-2026:60389, RHSA-2026:60388, RHSA-2026:60387,
Bugzilla: 2507537
Bugzilla Description: multicloud-operators-subscription: multicloud-operators-subscription: IsClusterAdmin() trusts user-settable annotations on managed clusters
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-863
Affected Packages: rhacm2/multicluster-operators-application-rhel9:1787259284,rhacm2/multicluster-operators-application-rhel9:1787238598,rhacm2/multicluster-operators-subscription-rhel9:1787242108,rhacm2/multicluster-operators-application-rhel9:1787262214,rhacm2/multicluster-operators-application-rhel9:1787242135,rhacm2/multicluster-operators-application-rhel9:1786976940,rhacm2/multicluster-operators-subscription-rhel9:1787263693,rhacm2/multicluster-operators-subscription-rhel9:1787242321,rhacm2/multicluster-operators-application-rhel9:1787242131,rhacm2/multicluster-operators-subscription-rhel9:1787240030,rhacm2/multicluster-operators-subscription-rhel9:1787263584,rhacm2/multicluster-operators-subscription-rhel9:1787170830,
Package States: Multicluster Global Hub,Multicluster Global Hub,Multicluster Global Hub,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,
Full Details
CVE document


CVE-2026-71491
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2517518
Bugzilla Description: sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1050
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Discovery 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Update Infrastructure 4 for Cloud Providers,Red Hat Update Infrastructure 5,Red Hat Update Infrastructure 5,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-59894
Severity: moderate
Released on: 17/08/2026
Advisory:
Bugzilla: 2517515
Bugzilla Description: sqlparse: sqlparse: Arbitrary code execution via unescaped backslashes in generated snippets
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-94
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Discovery 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Update Infrastructure 4 for Cloud Providers,Red Hat Update Infrastructure 5,Red Hat Update Infrastructure 5,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-73646
Severity: important
Released on: 17/08/2026
Advisory: RHSA-2026:50287, RHSA-2026:54520,
Bugzilla: 2517456
Bugzilla Description: postcss: PostCSS: Information disclosure via path traversal in source map auto-loading
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-22
Affected Packages: prometheus3-13-main-3.13.2-0.2.hum1,prometheus3-5-main-3.5.5-0.8.hum1,
Package States: Cost Management On Premise,Gatekeeper 3,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat 3scale API Management Platform 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 4,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Single Sign-On 7,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-19693
Severity: important
Released on: 17/08/2026
Advisory:
Bugzilla: 2517432
Bugzilla Description: extract-zip: extract-zip: Arbitrary file write via symlink in archive
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-59
Affected Packages:
Package States: Multicluster Engine for Kubernetes,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 4,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-15218
Severity: moderate
Released on: 17/08/2026
Advisory: RHSA-2026:60520,
Bugzilla: 2498426
Bugzilla Description: models-as-a-service: Red Hat OpenShift AI: maas-api and maas-controller ServiceAccounts with excessive permissions lead to privilege escalation
CVSS Score:
CVSSv3 Score: 7.9
Vector:
CWE: CWE-266
Affected Packages: rhoai/odh-maas-api-rhel9:1787153683,
Package States: Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-19999
Severity: moderate
Released on: 17/08/2026
Advisory:
Bugzilla: 2517330
Bugzilla Description: assimp: Assimp: Remote buffer overflow allows information disclosure or denial of service
CVSS Score:
CVSSv3 Score: 5.6
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-19970
Severity: moderate
Released on: 17/08/2026
Advisory:
Bugzilla: 2517292
Bugzilla Description: assimp: Assimp: Remote heap-based buffer overflow vulnerability
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-19969
Severity: moderate
Released on: 17/08/2026
Advisory:
Bugzilla: 2517289
Bugzilla Description: assimp: Assimp: Buffer overflow in 3DGS MDL7 model processing
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-19968
Severity: moderate
Released on: 17/08/2026
Advisory:
Bugzilla: 2517287
Bugzilla Description: assimp: Assimp: Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-19967
Severity: moderate
Released on: 17/08/2026
Advisory:
Bugzilla: 2517288
Bugzilla Description: assimp: Assimp: Heap-based buffer overflow in file decompression
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18963
Severity: critical
Released on: 17/08/2026
Advisory: RHSA-2026:56524, RHSA-2026:56523, RHSA-2026:56520, RHSA-2026:56519,
Bugzilla: 2511595
Bugzilla Description: keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass
CVSS Score:
CVSSv3 Score: 9.1
Vector:
CWE: CWE-640
Affected Packages: rhbk/keycloak-rhel9:26.6-12,rhbk-keycloak-rhel9/rhbk-keycloak-rhel9,keycloak-services,rhbk-openshift-rhel9/rhbk-openshift-rhel9,rhbk/keycloak-operator-bundle:26.6.6-1,rhbk/keycloak-rhel9-operator:26.6-12,rhbk/keycloak-rhel9-operator:26.4-23,rhbk/keycloak-rhel9:26.4-23,rhbk/keycloak-operator-bundle:26.4.15-1,
Package States: Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-74579
Severity: low
Released on: 17/08/2026
Advisory:
Bugzilla: 2517319
Bugzilla Description: kernel: netfilter: nft_payload: fix mask build for partial field offload
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1335
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-75032
Severity: moderate
Released on: 17/08/2026
Advisory:
Bugzilla: 2517490
Bugzilla Description: bluez: BlueZ: Out-of-bounds read in AVRCP parse_media_element and parse_media_folder
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-74797
Severity: low
Released on: 16/08/2026
Advisory:
Bugzilla: 2517222
Bugzilla Description: github.com/opentofu/opentofu: OpenTofu: Denial of Service via malicious zip archives
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-400
Affected Packages:
Package States: Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-74796
Severity: moderate
Released on: 16/08/2026
Advisory:
Bugzilla: 2517217
Bugzilla Description: github.com/opentofu/opentofu: OpenTofu: Arbitrary file write via symlink following path traversal
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-59
Affected Packages:
Package States: Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2024-58375
Severity: moderate
Released on: 16/08/2026
Advisory:
Bugzilla: 2517223
Bugzilla Description: github.com/opentofu/opentofu: OpenTofu: Sensitive information disclosure via static evaluation
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-497
Affected Packages:
Package States: Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-74578
Severity: moderate
Released on: 16/08/2026
Advisory:
Bugzilla: 2517196
Bugzilla Description: kernel: crypto: algif_skcipher - force synchronous processing on trees without ctx->state
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1204
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-73194
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516959
Bugzilla Description: perl-DBI: DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-73193
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516960
Bugzilla Description: perl-DBI: DBI: Arbitrary Code Execution on 32-bit Perl via Integer Wraparound
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72428
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516226
Bugzilla Description: kernel: bpf: Fix stack slot index in nospec checks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1285
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72245
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516227
Bugzilla Description: kernel: gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72403
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516228
Bugzilla Description: kernel: ALSA: FCP: Fix NULL pointer dereference in interface lookup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72190
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516229
Bugzilla Description: kernel: ntfs: fix mrec_lock ABBA deadlock in rename
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72292
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516230
Bugzilla Description: kernel: KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72454
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516231
Bugzilla Description: kernel: i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72025
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516232
Bugzilla Description: kernel: s390/monwriter: Reject buffer reuse with different data length
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72310
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516233
Bugzilla Description: kernel: smb: client: fix overflow in passthrough ioctl bounds check
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72396
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516234
Bugzilla Description: kernel: hwmon: adm1275: Prevent reading uninitialized stack
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72042
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516235
Bugzilla Description: kernel: ipmi: Fix user refcount underflow in event delivery
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72305
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516236
Bugzilla Description: kernel: VDUSE: avoid leaking information to userspace
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72309
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516237
Bugzilla Description: kernel: tracing/remotes: Fix leak in trace_remote_alloc_buffer() error path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72470
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516238
Bugzilla Description: kernel: fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72011
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516239
Bugzilla Description: kernel: s390/diag: Add missing array_index_nospec() call to memtop_get_page_count()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72490
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516240
Bugzilla Description: kernel: staging: rtl8723bs: fix stainfo check in rtw_aes_decrypt
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72189
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516241
Bugzilla Description: kernel: ntfs: fail attrlist updates when the superblock is inactive
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72068
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516242
Bugzilla Description: kernel: posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72296
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516243
Bugzilla Description: kernel: net: ife: require ETH_HLEN to be pullable in ife_decode()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72458
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516244
Bugzilla Description: kernel: apparmor: fix NULL pointer dereference in unpack_pdb
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72373
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516245
Bugzilla Description: kernel: afs: Fix missing NULL pointer check in afs_break_some_callbacks()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72308
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516246
Bugzilla Description: kernel: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72088
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516247
Bugzilla Description: kernel: scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72069
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516248
Bugzilla Description: kernel: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72445
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516249
Bugzilla Description: kernel: ALSA: usb-audio: qcom: clear opened when stream enable fails
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72220
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516250
Bugzilla Description: kernel: sunrpc: harden rq_procinfo lifecycle to prevent double-free
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72287
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516252
Bugzilla Description: kernel: KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72019
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516253
Bugzilla Description: kernel: macsec: don't read an unset MAC header in macsec_encrypt()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68466
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516254
Bugzilla Description: kernel: mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72248
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516255
Bugzilla Description: kernel: netfilter: flowtable: support IPIP tunnel with direct xmit
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72059
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516256
Bugzilla Description: kernel: net: wwan: t7xx: destroy DMA pool on CLDMA late init failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72259
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516257
Bugzilla Description: kernel: ASoC: mediatek: mt8192: Release reserved memory on cleanup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72430
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516258
Bugzilla Description: kernel: net/sched: act_ct: fix nf_connlabels leak on two error paths
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72277
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516259
Bugzilla Description: kernel: KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72116
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516260
Bugzilla Description: kernel: can: bcm: fix stale rx/tx ops after device removal
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72472
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516261
Bugzilla Description: kernel: nfs: use nfsi->rwsem to protect traversal of the file lock list
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72483
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516262
Bugzilla Description: kernel: usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1335
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72411
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516263
Bugzilla Description: kernel: net: dsa: mxl862xx: fix use-after-free of DSA ports in crc_err_work
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72327
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516264
Bugzilla Description: kernel: drm/v3d: Reject invalid indirect BO handle in indirect CSD setup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72032
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516265
Bugzilla Description: kernel: net/mlx5: HWS, fix matcher leak on resize target setup failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72486
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516266
Bugzilla Description: kernel: mailbox: mtk-adsp: fix UAF during device teardown
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72056
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516267
Bugzilla Description: kernel: net: ena: clean up XDP TX queues when regular TX setup fails
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-459
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72155
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516268
Bugzilla Description: kernel: mtd: spi-nor: swp: Improve locking user experience
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-130
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72014
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516269
Bugzilla Description: kernel: drbd: reject data replies with an out-of-range payload size
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72163
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516270
Bugzilla Description: kernel: ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72183
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516271
Bugzilla Description: kernel: landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path
CVSS Score:
CVSSv3 Score: 6.4
Vector:
CWE: CWE-501
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72051
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516272
Bugzilla Description: kernel: net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-270
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72303
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516273
Bugzilla Description: kernel: ASoC: SOF: ipc4-control: Validate notification payload size
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72361
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516274
Bugzilla Description: kernel: drm/xe/hw_engine: Fix double-free of managed BO in error path
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72087
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516275
Bugzilla Description: kernel: scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72029
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516276
Bugzilla Description: kernel: net: wwan: iosm: bound device offsets in the MUX downlink decoder
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72247
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516277
Bugzilla Description: kernel: netfilter: nf_conncount: fix zone comparison in tuple dedup
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-628
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72222
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516278
Bugzilla Description: kernel: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72238
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516279
Bugzilla Description: kernel: x86/boot: Validate console=uart8250 baud rate to fix early boot hang
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72160
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516280
Bugzilla Description: kernel: ocfs2: reject dinodes with non-canonical i_mode type
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1286
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72198
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516281
Bugzilla Description: kernel: ntfs: reject non-resident records for resident-only attributes
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72066
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516282
Bugzilla Description: kernel: cpu: hotplug: Bound hotplug states sysfs output
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72146
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516283
Bugzilla Description: kernel: dmaengine: sh: rz-dmac: Move interrupt request after everything is set up
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72037
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516284
Bugzilla Description: kernel: net: lan743x: Initialize eth_syslock spinlock before use
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68470
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516285
Bugzilla Description: kernel: wifi: mac80211: validate extension-frame layout before RX
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1285
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72290
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516286
Bugzilla Description: kernel: KVM: s390: pci: Fix GISC refcount leak on AIF enable failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72182
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516287
Bugzilla Description: kernel: power: supply: charger-manager: fix refcount leak in is_full_charged()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72278
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516288
Bugzilla Description: kernel: KVM: arm64: nv: Re-translate VNCR before injecting abort
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-280
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72300
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516289
Bugzilla Description: kernel: ASoC: SOF: topology: validate vendor array size before parsing
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72434
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516290
Bugzilla Description: kernel: netfilter: ipset: make sure gc is properly stopped
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72199
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516291
Bugzilla Description: kernel: ntfs: validate resident index root values on lookup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1288
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72484
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516292
Bugzilla Description: kernel: staging: most: video: avoid double free on video register failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72476
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516293
Bugzilla Description: kernel: dmaengine: Fix possible use after free
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72341
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516294
Bugzilla Description: kernel: net/mlx5e: Fix publication race for priv->channel_stats[]
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72284
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516295
Bugzilla Description: kernel: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72370
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516296
Bugzilla Description: kernel: iomap: release pages on atomic dio size mismatch
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72377
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516297
Bugzilla Description: kernel: afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72480
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516298
Bugzilla Description: kernel: iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72381
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516299
Bugzilla Description: kernel: ksmbd: fix use-after-free of fp->owner.name in durable handle owner check
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72357
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516300
Bugzilla Description: kernel: uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-344
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72329
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516301
Bugzilla Description: kernel: net/liquidio: drop cached VF pci_dev LUT
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72024
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516302
Bugzilla Description: kernel: mac802154: remove interfaces with RCU list deletion
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72175
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516303
Bugzilla Description: kernel: fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72280
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516304
Bugzilla Description: kernel: KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72423
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516305
Bugzilla Description: kernel: bpf: Guard conntrack opts error writes
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72052
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516306
Bugzilla Description: kernel: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72171
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516307
Bugzilla Description: kernel: mtd: slram: remove failed entries from the device list
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72254
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516308
Bugzilla Description: kernel: netfilter: nft_fib: reject fib expression on the netdev egress hook
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72269
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516309
Bugzilla Description: kernel: fbdev: uvesafb: fix potential memory leak in uvesafb_probe()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72495
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516310
Bugzilla Description: kernel: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72023
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516311
Bugzilla Description: kernel: octeontx2-pf: fix SQB pointer leak on init failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72197
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516312
Bugzilla Description: kernel: fs/ntfs3: bound DeleteIndexEntryAllocation memmove length
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72299
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516313
Bugzilla Description: kernel: tipc: restrict socket queue dumps in enqueue tracepoints
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68458
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516314
Bugzilla Description: kernel: binder: cache secctx size before release zeroes it
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72090
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516315
Bugzilla Description: kernel: accel/amdxdna: Use caller client for debug BO sync
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-648
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72158
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516316
Bugzilla Description: kernel: fpga: dfl: add bounds check in dfh_get_param_size()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72089
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516317
Bugzilla Description: kernel: accel/ivpu: Reject firmware log with size smaller than header
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72039
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516318
Bugzilla Description: kernel: bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72048
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516319
Bugzilla Description: kernel: ieee802154: ca8210: fix cas_ctl leak on spi_async failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72038
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516320
Bugzilla Description: kernel: net: liquidio: fix BAR resource leak on PF number failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72061
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516321
Bugzilla Description: kernel: net: sit: require CAP_NET_ADMIN in the device netns for changelink
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72252
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516322
Bugzilla Description: kernel: netfilter: nft_set_pipapo: don't leak bad clone into future transaction
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72345
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516323
Bugzilla Description: kernel: net/mlx5: LAG, Fix off-by-one in single-FDB error rollback
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-193
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72422
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516324
Bugzilla Description: kernel: ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72218
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516325
Bugzilla Description: kernel: lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72263
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516326
Bugzilla Description: kernel: ASoC: SOF: topology: fix memory leak in snd_sof_load_topology
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72065
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516327
Bugzilla Description: kernel: net: mana: Validate the packet length reported by the NIC
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72453
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516328
Bugzilla Description: kernel: regcache: Do not overwrite error code when finalizing cache after error
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72156
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516329
Bugzilla Description: kernel: fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72145
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516330
Bugzilla Description: kernel: platform/x86/intel/tpmi: use cleanup helpers in mem_write()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72086
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516331
Bugzilla Description: kernel: scsi: xen: scsiback: Free the command tag on the TMR submit-failure path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72257
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516332
Bugzilla Description: kernel: ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72077
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516333
Bugzilla Description: kernel: Input: ims-pcu - fix firmware leak in async update
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72138
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516334
Bugzilla Description: kernel: xen/gntdev: fix error handling in ioctl
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72079
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516335
Bugzilla Description: kernel: Input: ims-pcu - fix use-after-free and double-free in disconnect
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-826
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72006
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516336
Bugzilla Description: kernel: net/mlx5: free mlx5_st_idx_data on final dealloc
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72070
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516337
Bugzilla Description: kernel: wifi: libertas_tf: fix use-after-free in lbtf_free_adapter()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72075
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516338
Bugzilla Description: kernel: Input: ims-pcu - fix race condition in reset_device sysfs callback
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-414
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72481
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516339
Bugzilla Description: kernel: iio: magnetometer: ak8975: fix potential kernel stack memory leak
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72095
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516340
Bugzilla Description: kernel: dma-fence: Make dma_fence_dedup_array() robust against 0-count input
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72475
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516341
Bugzilla Description: kernel: dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72179
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516342
Bugzilla Description: kernel: riscv: cacheinfo: Fix node reference leak in populate_cache_leaves
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72188
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516343
Bugzilla Description: kernel: ntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-252
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72237
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516345
Bugzilla Description: kernel: perf/x86/amd/brs: Fix kernel address leakage
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1220
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72384
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516346
Bugzilla Description: kernel: irqchip/ts4800: Fix missing chained handler cleanup on remove
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72105
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516347
Bugzilla Description: kernel: dm-log: fix a bitset_size overflow on 32bit machines
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72348
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516348
Bugzilla Description: kernel: netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-130
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72271
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516349
Bugzilla Description: kernel: fbdev: i740fb: fix potential memory leak in i740fb_probe()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68479
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516350
Bugzilla Description: kernel: Bluetooth: btrtl: validate firmware patch bounds
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72285
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516351
Bugzilla Description: kernel: KVM: TDX: Reject concurrent change to CPUID entry count
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72351
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516352
Bugzilla Description: kernel: gue: validate REMCSUM private option length
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72196
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516353
Bugzilla Description: kernel: fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72383
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516354
Bugzilla Description: kernel: sctp: fix addr_wq_timer race in sctp_free_addr_wq()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72044
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516355
Bugzilla Description: kernel: ksmbd: fix stack buffer overflow in multichannel session-key copy
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72436
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516356
Bugzilla Description: kernel: netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72191
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516357
Bugzilla Description: kernel: ntfs3: validate split-point offset in indx_insert_into_buffer
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72264
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516358
Bugzilla Description: kernel: fbdev: tridentfb: fix potential memory leak in trident_pci_probe()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68472
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516359
Bugzilla Description: kernel: wifi: cfg80211: validate EHT MLE before MLD ID read
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72101
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516360
Bugzilla Description: kernel: dm-integrity: fix leaking uninitialized kernel memory
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-909
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72416
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516361
Bugzilla Description: kernel: netfilter: nft_compat: ebtables emulation must reject non-bridge targets
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-358
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72312
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516362
Bugzilla Description: kernel: octeontx2-af: fix VF bringup affecting PF promiscuous state
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72324
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516363
Bugzilla Description: kernel: gpio: mvebu: free generic chips on unbind
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72389
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516364
Bugzilla Description: kernel: bridge: stp: Fix a potential use-after-free when deleting a bridge
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72448
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516365
Bugzilla Description: kernel: octeontx2-pf: Fix leak of SQ timestamp buffer on teardown
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72180
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516366
Bugzilla Description: kernel: mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-281
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72184
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516367
Bugzilla Description: kernel: ntfs: fix hole runlist memory leak in insert range error path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72267
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516368
Bugzilla Description: kernel: fbdev: carminefb: fix potential memory leak in alloc_carmine_fb()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72362
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516369
Bugzilla Description: kernel: drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72244
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516370
Bugzilla Description: kernel: gpu/buddy: bail out of try_harder when alignment cannot be honoured
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1285
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68474
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516371
Bugzilla Description: kernel: powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72367
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516373
Bugzilla Description: kernel: iomap: guard io_size EOF trim against concurrent truncate underflow
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72442
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516374
Bugzilla Description: kernel: netfilter: flowtable: fix and simplify IP6IP6 tunnel handling
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72202
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516375
Bugzilla Description: kernel: ntfs: avoid heap allocation for free-cluster readahead state
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72074
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516376
Bugzilla Description: kernel: Input: ims-pcu - fix type confusion in CDC union descriptor parsing
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72007
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516377
Bugzilla Description: kernel: pmdomain: imx: Fix i.MX8MP VC8000E power up sequence
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72346
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516378
Bugzilla Description: kernel: platform/x86: bitland-mifs-wmi: Fix NULL pointer dereference during suspend/resume
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72185
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516379
Bugzilla Description: kernel: ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68477
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516380
Bugzilla Description: kernel: ipvs: fix more places with wrong ipv6 transport offsets
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-354
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72249
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516381
Bugzilla Description: kernel: netfilter: flowtable: use dst in this direction when pushing IPIP header
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68464
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516382
Bugzilla Description: kernel: mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72224
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516383
Bugzilla Description: kernel: nvdimm/btt: Free arenas on btt_init() error paths
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72376
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516384
Bugzilla Description: kernel: afs: Fix misplaced inc of net->cells_outstanding
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72464
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516385
Bugzilla Description: kernel: xprtrdma: Repost Receive buffers for malformed replies
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72018
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516386
Bugzilla Description: kernel: dibs: loopback: validate offset and size in move_data()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68462
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516387
Bugzilla Description: kernel: bpf: Reject negative const offsets for buffer pointers
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72173
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516388
Bugzilla Description: kernel: fs/proc/task_mmu: do not warn on seeing non-migration pmd entry
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72469
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516389
Bugzilla Description: kernel: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72363
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516390
Bugzilla Description: kernel: netfs: Fix folio state after ENOMEM whilst under writeback iteration
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72169
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516391
Bugzilla Description: kernel: kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72404
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516392
Bugzilla Description: kernel: tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72268
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516393
Bugzilla Description: kernel: fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72387
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516394
Bugzilla Description: kernel: drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72421
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516395
Bugzilla Description: kernel: ipv4: fib: Don't ignore error route in local/main tables
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-390
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72318
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516396
Bugzilla Description: kernel: cifs: validate DFS referral string offsets
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72283
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516397
Bugzilla Description: kernel: KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72121
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516398
Bugzilla Description: kernel: can: bcm: add locking when updating filter and timer values
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72073
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516399
Bugzilla Description: kernel: mmc: vub300: fix use-after-free on probe failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72207
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516400
Bugzilla Description: kernel: ntfs: not change 0-byte $DATA attribute to non-resident
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-915
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72281
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516401
Bugzilla Description: kernel: KVM: arm64: account pKVM reclaim against the VM mm
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72115
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516402
Bugzilla Description: kernel: can: bcm: track a single source interface for ANYDEV timeout/throttle ops
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72231
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516403
Bugzilla Description: kernel: batman-adv: tt: avoid request storms during pending request
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72402
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516404
Bugzilla Description: kernel: bpf: Mask pseudo pointer values in verifier logs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-117
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72394
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516405
Bugzilla Description: kernel: hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72390
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516406
Bugzilla Description: kernel: net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72236
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516407
Bugzilla Description: kernel: s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72246
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516408
Bugzilla Description: kernel: netfilter: flowtable: use correct direction to set up tunnel route
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-628
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72356
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516409
Bugzilla Description: kernel: cifs: Fix missing credit release on failure in cifs_issue_read()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72256
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516410
Bugzilla Description: kernel: netfilter: xt_cluster: reject template conntracks in hash match
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72036
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516411
Bugzilla Description: kernel: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72221
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516412
Bugzilla Description: kernel: sunrpc: wait for in-flight TLS handshake callback when cancel loses race
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72076
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516413
Bugzilla Description: kernel: Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72142
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516414
Bugzilla Description: kernel: i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72302
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516415
Bugzilla Description: kernel: ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72119
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516416
Bugzilla Description: kernel: can: bcm: extend bcm_tx_lock usage for data and timer updates
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72242
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516417
Bugzilla Description: kernel: selinux: avoid sk_socket dereference in selinux_sctp_bind_connect()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72433
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516418
Bugzilla Description: kernel: netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-562
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72107
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516419
Bugzilla Description: kernel: dm era: fix out-of-bounds memory access for non-zero start sector
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72382
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516420
Bugzilla Description: kernel: ksmbd: reject undersized DACLs before parsing ACEs
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72055
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516421
Bugzilla Description: kernel: net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-270
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72379
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516422
Bugzilla Description: kernel: fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-708
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72435
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516423
Bugzilla Description: kernel: netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72333
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516424
Bugzilla Description: kernel: Bluetooth: L2CAP: fix tx ident leak for commands without a response
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72438
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516425
Bugzilla Description: kernel: md/raid10: fix writes_pending and barrier reference leaks on discard failures
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72291
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516426
Bugzilla Description: kernel: KVM: s390: Fix unlikely race in try_get_locked_pte()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72041
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516427
Bugzilla Description: kernel: espintcp: use sk_msg_free_partial to fix partial send
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72418
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516428
Bugzilla Description: kernel: netfilter: nf_conncount: prevent connlimit drops for early confirmed ct
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72211
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516429
Bugzilla Description: kernel: ntfs: grow index root value before reparent header update
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-130
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72053
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516430
Bugzilla Description: kernel: net: ipip: require CAP_NET_ADMIN in the device netns for changelink
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-280
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72046
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516431
Bugzilla Description: kernel: gve: fix header buffer corruption with header-split and HW-GRO
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1285
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72167
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516432
Bugzilla Description: kernel: mtd: rawnand: pl353: fix probe resource allocation
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72385
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516433
Bugzilla Description: kernel: tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72063
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516434
Bugzilla Description: kernel: gpio: tegra: do not call pinctrl for GPIO direction
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72187
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516435
Bugzilla Description: kernel: ntfs: avoid self-deadlock during inode eviction
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72097
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516436
Bugzilla Description: kernel: dm-verity: fix a possible NULL pointer dereference
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72084
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516437
Bugzilla Description: kernel: scsi: target: Bound PR-OUT TransportID parsing to the received buffer
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68455
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516438
Bugzilla Description: kernel: liveupdate: validate session type before performing operation
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1287
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72332
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516439
Bugzilla Description: kernel: accel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72012
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516441
Bugzilla Description: kernel: tracing/osnoise: Call synchronize_rcu() when unregistering
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72343
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516442
Bugzilla Description: kernel: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72451
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516443
Bugzilla Description: kernel: xfrm: Fix xfrm state cache insertion race
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72118
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516444
Bugzilla Description: kernel: can: bcm: fix CAN frame rx/tx statistics
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72030
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516446
Bugzilla Description: kernel: ata: libata-core: Reject an invalid concurrent positioning ranges count
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72203
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516447
Bugzilla Description: kernel: ntfs: skip extent mft records in writeback to prevent deadlock
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72130
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516448
Bugzilla Description: kernel: nvmet-auth: reject short AUTH_RECEIVE buffers
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72462
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516449
Bugzilla Description: kernel: apparmor: fix race in unix socket mediation when peer_path is used
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72143
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516450
Bugzilla Description: kernel: platform/x86: ISST: Restore SST-PP control to all domains
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-628
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68475
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516451
Bugzilla Description: kernel: reset: sunxi: fix memory region leak on ioremap failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68469
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516452
Bugzilla Description: kernel: wifi: mwifiex: fix permanently busy scans after multiple roam iterations
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72134
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516453
Bugzilla Description: kernel: spi: imx: reconfigure for PIO when DMA cannot be started
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-909
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72027
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516454
Bugzilla Description: kernel: mm/compaction: handle free_pages_prepare() properly in compaction_free()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-252
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72487
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516455
Bugzilla Description: kernel: PCI: Check ROM header and data structure addr before accessing
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-72339
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516456
Bugzilla Description: kernel: qede: fix off-by-one in BD ring consumption on build_skb failure
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-193
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72174
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516457
Bugzilla Description: kernel: fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72152
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516458
Bugzilla Description: kernel: tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72253
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516459
Bugzilla Description: kernel: netfilter: nf_conntrack_sip: validate skb_dst() before accessing it
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72419
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516460
Bugzilla Description: kernel: netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72216
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516461
Bugzilla Description: kernel: remoteproc: qcom: Fix leak when custom dump_segments addition fails
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72375
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516462
Bugzilla Description: kernel: afs: Fix reinitialisation of the inode, in particular ->lock_work
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-909
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72209
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516463
Bugzilla Description: kernel: ntfs: validate attribute values on lookup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72213
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516464
Bugzilla Description: kernel: mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72054
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516465
Bugzilla Description: kernel: net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1220
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72457
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516466
Bugzilla Description: kernel: apparmor: fail policy unpack on accept2 allocation failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-252
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72195
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516467
Bugzilla Description: kernel: fs/ntfs3: bound attr_off in UpdateResidentValue against data_off
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72386
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516468
Bugzilla Description: kernel: drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72251
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516469
Bugzilla Description: kernel: netfilter: nf_nat_sip: reload possible stale data pointer
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72350
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516470
Bugzilla Description: kernel: netfilter: xt_u32: reject invalid shift counts
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1335
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72301
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516471
Bugzilla Description: kernel: ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72439
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516472
Bugzilla Description: kernel: md/raid10: fix writes_pending leak on write request failures
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72111
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516473
Bugzilla Description: kernel: bpf: Reset register bounds before narrowing retval range in check_mem_access()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72319
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516474
Bugzilla Description: kernel: ipvs: ensure inner headers in ICMP errors are in headroom
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72401
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516475
Bugzilla Description: kernel: bpf: Fix insn_aux_data leak on verifier err_free_env path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72371
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516476
Bugzilla Description: kernel: afs: Fix the volume AFS_VOLUME_RM_TREE is set on
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72314
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516477
Bugzilla Description: kernel: regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1025
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72407
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516478
Bugzilla Description: kernel: geneve: validate inner network offset in geneve_gro_complete()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-823
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72426
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516479
Bugzilla Description: kernel: bpf: Preserve pointer spill metadata during half-slot cleanup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72420
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516480
Bugzilla Description: kernel: md/raid5: avoid R5_Overlap races while breaking stripe batches
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72441
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516481
Bugzilla Description: kernel: ieee802154: fix kernel-infoleak in dgram_recvmsg()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72103
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516482
Bugzilla Description: kernel: dm: avoid leaking the caller's thread keyring via the table device file
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72460
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516483
Bugzilla Description: kernel: apparmor: check label build before no_new_privs test
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72082
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516484
Bugzilla Description: kernel: scsi: elx: efct: Fix refcount leak in efct_hw_io_abort()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72214
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516485
Bugzilla Description: kernel: power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72210
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516486
Bugzilla Description: kernel: ntfs: fix off-by-one in mapping pairs decoding bounds checks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72200
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516488
Bugzilla Description: kernel: ntfs: detect mapping-pairs LCN accumulator overflow
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72359
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516489
Bugzilla Description: kernel: drm/xe: fix NPD in bo_meminfo()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72102
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516490
Bugzilla Description: kernel: dm_early_create: fix freeing used table on dm_resume failure
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72427
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516491
Bugzilla Description: kernel: bpf: Fix effective prog array index with BPF_F_PREORDER
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72233
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516492
Bugzilla Description: kernel: batman-adv: bla: reacquire gw address after skb realloc
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72232
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516493
Bugzilla Description: kernel: batman-adv: ensure minimal ethernet header on TX
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72226
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516494
Bugzilla Description: kernel: batman-adv: tt: prevent TVLV OOB check overflow
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72355
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516495
Bugzilla Description: kernel: netfs: Fix barriering when walking subrequest list
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72276
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516496
Bugzilla Description: kernel: fbdev: metronomefb: fix potential memory leak in metronomefb_probe()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72217
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516497
Bugzilla Description: kernel: SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72206
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516498
Bugzilla Description: kernel: ntfs: validate index block header more strictly
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1288
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72417
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516500
Bugzilla Description: kernel: netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72098
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516501
Bugzilla Description: kernel: dm-verity: fix buffer overflow in FEC calculation
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72154
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516502
Bugzilla Description: kernel: openrisc: Fix jump_label smp syncing
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72323
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516503
Bugzilla Description: kernel: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72081
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516504
Bugzilla Description: kernel: scsi: elx: efct: Fix I/O leak on unsupported additional CDB
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72176
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516505
Bugzilla Description: kernel: mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72113
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516506
Bugzilla Description: kernel: can: bcm: add missing device refcount for CAN filter removal
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72347
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516507
Bugzilla Description: kernel: netfilter: xt_connmark: reject invalid shift parameters
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1335
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68473
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516508
Bugzilla Description: kernel: powerpc/uaccess: correct check for CONFIG_PPC_E500 in mask_user_address()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1025
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72293
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516509
Bugzilla Description: kernel: KVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-909
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72446
Severity: important
Released on: 15/08/2026
Advisory:
Bugzilla: 2516510
Bugzilla Description: kernel: ALSA: usb-audio: qcom: reject stream disable with no active interface
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-124
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72397
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516511
Bugzilla Description: kernel: hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-681
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72126
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516512
Bugzilla Description: kernel: can: isotp: use unconditional synchronize_rcu() in isotp_release()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72013
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516513
Bugzilla Description: kernel: riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72316
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516514
Bugzilla Description: kernel: dm era: fix NULL pointer dereference in metadata_open()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72344
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516515
Bugzilla Description: kernel: net/mlx5e: TC, skip peer flow cleanup when LAG seq is unavailable
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72225
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516516
Bugzilla Description: kernel: jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72094
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516517
Bugzilla Description: kernel: dma-buf: dma-fence: Fix potential NULL pointer dereference
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72321
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516518
Bugzilla Description: kernel: ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72295
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516519
Bugzilla Description: kernel: LoongArch: KVM: Validate irqchip index in irqfd routing
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-823
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72331
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516520
Bugzilla Description: kernel: accel/amdxdna: Fix VMA access race
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72135
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516521
Bugzilla Description: kernel: tpm: Make the TPM character devices non-seekable
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-823
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72468
Severity: low
Released on: 15/08/2026
Advisory:
Bugzilla: 2516522
Bugzilla Description: kernel: xprtrdma: Initialize re_id before removal registration
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72072
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516523
Bugzilla Description: kernel: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72488
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516524
Bugzilla Description: kernel: soundwire: fix bug in sdw_add_element_group_count found by syzkaller
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1285
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-72022
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516525
Bugzilla Description: kernel: llc: fix SAP refcount leak in llc_ui_autobind()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72288
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516526
Bugzilla Description: kernel: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72261
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516527
Bugzilla Description: kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72489
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516528
Bugzilla Description: kernel: staging: nvec: fix use-after-free in nvec_rx_completed()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-72108
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516529
Bugzilla Description: kernel: dm thin metadata: fix metadata snapshot consistency on commit failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-72408
Severity: moderate
Released on: 15/08/2026
Advisory:
Bugzilla: 2516530
Bugzilla Description: kernel: geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document