CVE-2026-71870
Severity: moderate
Released on: 07/08/2026
Advisory:
Bugzilla: 2512627
Bugzilla Description: pypdf: pypdf: Denial of Service via crafted PDF with large /ToUnicode streams
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-770
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-71852
Severity: moderate
Released on: 07/08/2026
Advisory:
Bugzilla: 2512615
Bugzilla Description: pypdf: pypdf: Denial of Service via crafted PDF with large CID font width ranges
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1050
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18938
Severity: moderate
Released on: 07/08/2026
Advisory:
Bugzilla: 2478995
Bugzilla Description: p11-kit: Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems
CVSS Score:
CVSSv3 Score: 6.2
Vector:
CWE: CWE-122
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-12261
Severity: moderate
Released on: 07/08/2026
Advisory:
Bugzilla: 2512413
Bugzilla Description: nltk: NLTK: Resource poisoning via improper package archive extraction
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-367
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2025-63235
Severity: important
Released on: 07/08/2026
Advisory:
Bugzilla: 2512606
Bugzilla Description: codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-772
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-71430
Severity: important
Released on: 06/08/2026
Advisory:
Bugzilla: 2512248
Bugzilla Description: re2: node-re2: Denial of Service due to excessive string length in replacements
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,
Full Details
CVE document


CVE-2026-71497
Severity: moderate
Released on: 06/08/2026
Advisory:
Bugzilla: 2512346
Bugzilla Description: org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-1289
Affected Packages:
Package States: Cryostat 4,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat AMQ Broker 7,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat build of Quarkus,Red Hat build of Quarkus Native builder,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-61632
Severity: moderate
Released on: 06/08/2026
Advisory:
Bugzilla: 2512227
Bugzilla Description: pymdown-extensions: PyMdown Extensions: Information disclosure via path traversal in b64 extension
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-67422
Severity: important
Released on: 06/08/2026
Advisory:
Bugzilla: 2512322
Bugzilla Description: pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1333
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-66808
Severity: important
Released on: 06/08/2026
Advisory:
Bugzilla: 2509774
Bugzilla Description: hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-88
Affected Packages:
Package States: Multicluster Engine for Kubernetes,
Full Details
CVE document


CVE-2026-71436
Severity: important
Released on: 06/08/2026
Advisory:
Bugzilla: 2512242
Bugzilla Description: mermaid: Mermaid XY Charts: Denial of Service via invalid X-Axis parameters
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Build of Podman Desktop,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-18427
Severity: important
Released on: 06/08/2026
Advisory:
Bugzilla: 2512116
Bugzilla Description: @fastify/static: @fastify/static: Information disclosure via route guard bypass
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-41
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-61477
Severity: low
Released on: 06/08/2026
Advisory:
Bugzilla: 2512066
Bugzilla Description: libvirt: libvirt: newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection
CVSS Score:
CVSSv3 Score: 2.3
Vector:
CWE: CWE-93
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux for NVIDIA 26,
Full Details
CVE document


CVE-2026-46581
Severity: important
Released on: 06/08/2026
Advisory:
Bugzilla: 2483136
Bugzilla Description: wildfly-clustering-faces-mojarra: com.sun.faces:jsf-impl: org.glassfish:jakarta.faces: mojarra: Unauthenticated RCE in EAP JSF applications via EL injection in ui:include
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-94
Affected Packages:
Package States: Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,
Full Details
CVE document


CVE-2026-68480
Severity: important
Released on: 06/08/2026
Advisory:
Bugzilla: 2508363
Bugzilla Description: kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-201
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68481
Severity: moderate
Released on: 06/08/2026
Advisory:
Bugzilla: 2511994
Bugzilla Description: org.apache.cxf/cxf-rt-rs-security-oauth2: Apache CXF: Revocation bypass allows unauthorized access
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-303
Affected Packages:
Package States: Red Hat build of Apache Camel for Spring Boot 4,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat JBoss Web Server 5,
Full Details
CVE document


CVE-2026-18649
Severity: moderate
Released on: 06/08/2026
Advisory:
Bugzilla: 2510614
Bugzilla Description: gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay RTP depayloaders
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-7867
Severity: important
Released on: 06/08/2026
Advisory:
Bugzilla: 2466747
Bugzilla Description: udisks2: udisks2: Local Privilege Escalation via as-user option spoofing
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-15816
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2500889
Bugzilla Description: dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die()
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-78
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-71313
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511782
Bugzilla Description: github.com/rclone/rclone: rclone: Path Traversal allows arbitrary file write
CVSS Score:
CVSSv3 Score: 6.9
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-71312
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511773
Bugzilla Description: github.com/rclone/rclone: rclone: Server-Side Command Execution via Malicious SFTP Filenames
CVSS Score:
CVSSv3 Score: 8.0
Vector:
CWE: CWE-78
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-71311
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511771
Bugzilla Description: github.com/rclone/rclone: rclone: FTP command injection via CRLF in filename encoding
CVSS Score:
CVSSv3 Score: 6.4
Vector:
CWE: CWE-93
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-34966
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511770
Bugzilla Description: code.gitea.io/gitea: Gitea: Information disclosure via Server-Side Request Forgery (SSRF) bypass
CVSS Score:
CVSSv3 Score: 7.6
Vector:
CWE: CWE-918
Affected Packages:
Package States: OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,
Full Details
CVE document


CVE-2026-71310
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511772
Bugzilla Description: github.com/rclone/rclone: rclone: Denial of Service via unbounded HTTP CONNECT response headers
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-71309
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511774
Bugzilla Description: github.com/rclone/rclone: rclone: Backend Root Escape via Incomplete Path Validation
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-18839
Severity: low
Released on: 05/08/2026
Advisory:
Bugzilla: 2511010
Bugzilla Description: popt-devel: popt-static: size_t underflow in singleOptionHelp
CVSS Score:
CVSSv3 Score: 2.2
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-70428
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511664
Bugzilla Description: jenkins: Jenkins: Arbitrary file write via path traversal
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-22
Affected Packages:
Package States: OpenShift Developer Tools and Services,
Full Details
CVE document


CVE-2026-49331
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2483252
Bugzilla Description: openshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on whitelisted paths
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-345
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-16443
Severity: important
Released on: 05/08/2026
Advisory: RHSA-2026:50848, RHSA-2026:50847, RHSA-2026:50849, RHSA-2026:50846,
Bugzilla: 2503139
Bugzilla Description: keycloak-services: keycloak-services: SAML broker metadata import disables response signature validation
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-347
Affected Packages: rhbk/keycloak-rhel9:26.6-11,rhbk/keycloak-operator-bundle:26.4.14-1,rhbk-keycloak-rhel9/rhbk-keycloak-rhel9,keycloak-services,rhbk-openshift-rhel9/rhbk-openshift-rhel9,rhbk/keycloak-rhel9-operator:26.6-11,rhbk/keycloak-rhel9-operator:26.4-22,rhbk/keycloak-operator-bundle:26.6.5-1,rhbk/keycloak-rhel9:26.4-22,
Package States: Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-71227
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2462867
Bugzilla Description: libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
CVSS Score:
CVSSv3 Score: 5.1
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-71281
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511563
Bugzilla Description: peft: peft: Arbitrary Code Execution via Unsafe Deserialization in LoRA-GA and CorDA Modules
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-502
Affected Packages:
Package States: Lightspeed Core,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-71267
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511585
Bugzilla Description: microtar: microtar: Stack buffer overflow via overly long filenames
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-71226
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2462114
Bugzilla Description: libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi's one-shot AIO path
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-416
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-71225
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2462011
Bugzilla Description: libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-330
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-71235
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511475
Bugzilla Description: github.com/absmach/magistrala: Magistrala IoT Platform: Arbitrary Code Execution via Unrestricted Script Execution
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-94
Affected Packages:
Package States: Assisted Installer for Red Hat OpenShift Container Platform 2,Builds for Red Hat OpenShift,cert-manager Operator for Red Hat OpenShift,Compliance Operator,Confidential Compute Attestation,Cryostat 4,Custom Metric Autoscaler operator for Red Hat Openshift,Deployment Validation Operator,External Secrets Operator for Red Hat OpenShift,Fence Agents Remediation Operator,File Integrity Operator,Gatekeeper 3,Logging Subsystem for Red Hat OpenShift,Logical Volume Manager Storage,Logical Volume Manager Storage,Logical Volume Manager Storage,Machine Deletion Remediation Operator,Migration Toolkit for Applications 8,Migration Toolkit for Containers,mirror registry for Red Hat OpenShift 2,Multiarch Tuning Operator,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Global Hub,Network Observability Operator,Node HealthCheck Operator,OpenShift API for Data Protection,OpenShift Developer Tools and Services,OpenShift Lightspeed,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Source-to-Image (S2I),Power monitoring for Red Hat OpenShift,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AMQ Clients,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Connectivity Link 1,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Lightspeed for Runtimes Operator,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Cluster Manager CLI,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Workspaces Operator,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift for Windows Containers,Red Hat OpenShift on AWS,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Service Interconnect 2,Red Hat Service Interconnect 2,Red Hat Web Terminal,Security Profiles Operator,Service Telemetry Framework 1.5,streams for Apache Kafka 2,streams for Apache Kafka 3,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager - Tech Preview,
Full Details
CVE document


CVE-2026-59679
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2509620
Bugzilla Description: libxfont2: Font Server Client encoding[] Out-Of-Bounds Read/Write
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-44950
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2509622
Bugzilla Description: libxfonts2: libXfont2: Privilege Escalation via Heap Buffer Overflow in Font Server Client
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-10059
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2483187
Bugzilla Description: cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token
CVSS Score:
CVSSv3 Score: 9.1
Vector:
CWE: CWE-266
Affected Packages:
Package States: Multicluster Engine for Kubernetes,
Full Details
CVE document


CVE-2026-10090
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2483292
Bugzilla Description: multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-267
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-71202
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511381
Bugzilla Description: raster: Raster: Denial of Service via integer underflow in image cropping function
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-191
Affected Packages:
Package States: Logging Subsystem for Red Hat OpenShift,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-67592
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511341
Bugzilla Description: org.apache.qpid/protonj2: Apache Qpid ProtonJ2: Denial of Service via uncontrolled incoming data transfers
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AMQ Clients,
Full Details
CVE document


CVE-2026-66277
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511340
Bugzilla Description: org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via uncontrolled transfer frames
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat AMQ Clients,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Quarkus,Red Hat JBoss Enterprise Application Platform Expansion Pack,
Full Details
CVE document


CVE-2026-66274
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511337
Bugzilla Description: org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via unbounded type nesting
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat AMQ Clients,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Quarkus,Red Hat JBoss Enterprise Application Platform Expansion Pack,
Full Details
CVE document


CVE-2026-67589
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511321
Bugzilla Description: org.apache.qpid/protonj2: Apache Qpid ProtonJ2: Denial of Service via excessive memory allocation
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AMQ Clients,
Full Details
CVE document


CVE-2026-67588
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511324
Bugzilla Description: org.apache.qpid/protonj2: Apache Qpid ProtonJ2: Denial of Service via unbounded symbol value caching
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AMQ Clients,
Full Details
CVE document


CVE-2026-15572
Severity: important
Released on: 05/08/2026
Advisory: RHSA-2026:50848, RHSA-2026:50847, RHSA-2026:50849, RHSA-2026:50846,
Bugzilla: 2499592
Bugzilla Description: keycloak-services: keycloak-services: DCR protocol mapper type-swap policy bypass allows privilege escalation
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-843
Affected Packages: rhbk/keycloak-rhel9:26.6-11,rhbk/keycloak-operator-bundle:26.4.14-1,rhbk/keycloak-rhel9,rhbk/keycloak-rhel9-operator:26.6-11,rhbk/keycloak-rhel9-operator:26.4-22,rhbk/keycloak-operator-bundle:26.6.5-1,rhbk/keycloak-rhel9:26.4-22,
Package States:
Full Details
CVE document


CVE-2026-15573
Severity: important
Released on: 05/08/2026
Advisory: RHSA-2026:50848, RHSA-2026:50847, RHSA-2026:50849, RHSA-2026:50846,
Bugzilla: 2499593
Bugzilla Description: keycloak-services: keycloak-services: Authorization bypass via unnormalized URI matching in PathMatcher
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE:
Affected Packages: rhbk/keycloak-rhel9:26.6-11,rhbk/keycloak-operator-bundle:26.4.14-1,rhbk/keycloak-rhel9,keycloak-services,rhbk-openshift-rhel9/rhbk-openshift-rhel9,rhbk/keycloak-rhel9-operator:26.6-11,rhbk/keycloak-rhel9-operator:26.4-22,rhbk/keycloak-operator-bundle:26.6.5-1,rhbk/keycloak-rhel9:26.4-22,
Package States: Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-16071
Severity: moderate
Released on: 05/08/2026
Advisory: RHSA-2026:50848, RHSA-2026:50847, RHSA-2026:50849, RHSA-2026:50846,
Bugzilla: 2501720
Bugzilla Description: keycloak-services: keycloak-services: LDAP entry-DN user search bypasses configured users DN boundary
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE:
Affected Packages: rhbk/keycloak-rhel9:26.6-11,rhbk/keycloak-operator-bundle:26.4.14-1,rhbk-keycloak-rhel9/rhbk-keycloak-rhel9,keycloak-services,rhbk-openshift-rhel9/rhbk-openshift-rhel9,rhbk/keycloak-rhel9-operator:26.6-11,rhbk/keycloak-rhel9-operator:26.4-22,rhbk/keycloak-operator-bundle:26.6.5-1,rhbk/keycloak-rhel9:26.4-22,
Package States: Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-16100
Severity: moderate
Released on: 05/08/2026
Advisory: RHSA-2026:50848, RHSA-2026:50849,
Bugzilla: 2501730
Bugzilla Description: keycloak-services: keycloak-services: Unbounded metric cardinality in user event metrics via request-controlled error text
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE:
Affected Packages: rhbk/keycloak-rhel9:26.6-11,rhbk-keycloak-rhel9/rhbk-keycloak-rhel9,keycloak-services,rhbk/keycloak-rhel9-operator:26.6-11,rhbk-openshift-rhel9/rhbk-openshift-rhel9,rhbk/keycloak-operator-bundle:26.6.5-1,
Package States: Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-16102
Severity: important
Released on: 05/08/2026
Advisory: RHSA-2026:50848, RHSA-2026:50847, RHSA-2026:50849, RHSA-2026:50846,
Bugzilla: 2501735
Bugzilla Description: keycloak-services: keycloak-services: Default DCR policy allows role forgery via User Property mappers
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE:
Affected Packages: rhbk/keycloak-rhel9:26.6-11,rhbk/keycloak-operator-bundle:26.4.14-1,rhbk-keycloak-rhel9/rhbk-keycloak-rhel9,keycloak-services,rhbk-openshift-rhel9/rhbk-openshift-rhel9,rhbk/keycloak-rhel9-operator:26.6-11,rhbk/keycloak-rhel9-operator:26.4-22,rhbk/keycloak-operator-bundle:26.6.5-1,rhbk/keycloak-rhel9:26.4-22,
Package States: Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-16442
Severity: important
Released on: 05/08/2026
Advisory: RHSA-2026:50848, RHSA-2026:50847, RHSA-2026:50849, RHSA-2026:50846,
Bugzilla: 2503138
Bugzilla Description: keycloak-services: keycloak-services: SAML IdP-initiated broker login bypasses link-only restriction
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-346
Affected Packages: rhbk/keycloak-rhel9:26.6-11,rhbk/keycloak-operator-bundle:26.4.14-1,rhbk-keycloak-rhel9/rhbk-keycloak-rhel9,keycloak-services,rhbk-openshift-rhel9/rhbk-openshift-rhel9,rhbk/keycloak-rhel9-operator:26.6-11,rhbk/keycloak-rhel9-operator:26.4-22,rhbk/keycloak-operator-bundle:26.6.5-1,rhbk/keycloak-rhel9:26.4-22,
Package States: Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-64579
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511404
Bugzilla Description: kernel: xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64569
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511406
Bugzilla Description: kernel: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64574
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511407
Bugzilla Description: kernel: wifi: mac80211: tear down new links on vif update error path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64567
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511408
Bugzilla Description: kernel: btrfs: reject free space cache with more entries than pages
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64566
Severity:
Released on: 05/08/2026
Advisory:
Bugzilla: 2511410
Bugzilla Description: kernel: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
CVSS Score:
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64571
Severity:
Released on: 05/08/2026
Advisory:
Bugzilla: 2511411
Bugzilla Description: kernel: wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64578
Severity:
Released on: 05/08/2026
Advisory:
Bugzilla: 2511412
Bugzilla Description: kernel: ksmbd: validate compound request size before reading StructureSize2
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64572
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511413
Bugzilla Description: kernel: ipv4: fib: free fib_alias with kfree_rcu() on insert error path
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64575
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511414
Bugzilla Description: kernel: bpf: tcp: fix double sock release on batch realloc
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64577
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511415
Bugzilla Description: kernel: gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-124
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64573
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511417
Bugzilla Description: kernel: Bluetooth: qca: fix NVM tag length underflow in TLV parser
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64576
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511419
Bugzilla Description: kernel: nexthop: initialize extack in nh_res_bucket_migrate()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64570
Severity: moderate
Released on: 05/08/2026
Advisory:
Bugzilla: 2511421
Bugzilla Description: kernel: wifi: mac80211: fix fils_discovery double free on alloc failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64582
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511448
Bugzilla Description: kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67863
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511847
Bugzilla Description: open62541: open62541: Denial of Service via use-after-free vulnerability
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-67870
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511857
Bugzilla Description: open62541: open62541: Denial of Service via incomplete validation in AddReferences
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-476
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-67869
Severity: important
Released on: 05/08/2026
Advisory:
Bugzilla: 2511858
Bugzilla Description: open62541: open62541: Denial of Service via buffer overflow in Service_Call
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18785
Severity: moderate
Released on: 04/08/2026
Advisory:
Bugzilla: 2511141
Bugzilla Description: open62541: open62541: Use-after-free vulnerability via local manipulation
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-56848
Severity: important
Released on: 04/08/2026
Advisory:
Bugzilla: 2511089
Bugzilla Description: nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-15920
Severity: moderate
Released on: 04/08/2026
Advisory:
Bugzilla: 2511091
Bugzilla Description: django: Django: Cross-site scripting via unvalidated URLField values in the admin
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-79
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Discovery 2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Update Infrastructure 4 for Cloud Providers,Red Hat Update Infrastructure 5,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-15830
Severity: moderate
Released on: 04/08/2026
Advisory:
Bugzilla: 2511103
Bugzilla Description: django: Django: Denial of Service via parsing deeply nested geometry collections
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-606
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Discovery 2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Update Infrastructure 4 for Cloud Providers,Red Hat Update Infrastructure 5,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-15337
Severity: moderate
Released on: 04/08/2026
Advisory:
Bugzilla: 2511110
Bugzilla Description: django: Django: Denial-of-service vulnerability due to excessive memory consumption
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-1050
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Discovery 2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Update Infrastructure 4 for Cloud Providers,Red Hat Update Infrastructure 5,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-15307
Severity: important
Released on: 04/08/2026
Advisory:
Bugzilla: 2511095
Bugzilla Description: django: Django: Remote code execution via GeoDjango spatial lookups
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-434
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Discovery 2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Update Infrastructure 4 for Cloud Providers,Red Hat Update Infrastructure 5,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-68494
Severity: important
Released on: 04/08/2026
Advisory:
Bugzilla: 2511026
Bugzilla Description: com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Cryostat 4,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat AMQ Clients,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Certificate System 10,Red Hat Certificate System 11,Red Hat Data Grid 8,Red Hat Data Grid 8,Red Hat Data Grid 8,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat JBoss Web Server 7,Red Hat JBoss Web Server 7,Red Hat JBoss Web Server 7,Red Hat JBoss Web Server 7,Red Hat Lightspeed for Runtimes Operator,Red Hat Offline Knowledge Portal,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Single Sign-On 7,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-70368
Severity: moderate
Released on: 04/08/2026
Advisory:
Bugzilla: 2462029
Bugzilla Description: stunnel: Stack-based out-of-bounds read/write in stunnel s_vlog via oversized log message
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-70367
Severity: moderate
Released on: 04/08/2026
Advisory:
Bugzilla: 2462083
Bugzilla Description: stunnel: SSRF bypass in stunnel SOCKS proxy via IPv4-mapped IPv6 loopback and unspecified addresses allows access to loopback-only services
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-56846
Severity: important
Released on: 04/08/2026
Advisory: RHSA-2026:48305, RHSA-2026:48537,
Bugzilla: 2510856
Bugzilla Description: nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-400
Affected Packages: nodejs22-main-22.23.2-2.3.hum1,nodejs24-main-24.18.1-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-17614
Severity: moderate
Released on: 04/08/2026
Advisory:
Bugzilla: 2507631
Bugzilla Description: wildfly-core: Path Traversal on WildFly Domain Controller
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-42169
Severity: moderate
Released on: 04/08/2026
Advisory: RHSA-2026:50817,
Bugzilla: 2461725
Bugzilla Description: gimp: GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c)
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-131
Affected Packages: gimp-2:3.0.4-4.el9_8.9,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-42170
Severity: important
Released on: 04/08/2026
Advisory:
Bugzilla: 2461726
Bugzilla Description: gimp: GIMP DDS plug-in heap-based buffer overflow via BPP mismatch in load_layer() (ddsread.c)
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-131
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-64561
Severity: important
Released on: 04/08/2026
Advisory: RHSA-2026:45192, RHSA-2026:49030, RHSA-2026:47869, RHSA-2026:49031, RHSA-2026:48386, RHSA-2026:45114, RHSA-2026:45116, RHSA-2026:45115,
Bugzilla: 2510891
Bugzilla Description: kernel: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages: kernel-0:5.14.0-687.30.1.el9_8,kernel-0:6.12.0-55.94.1.el10_0,kernel-0:4.18.0-553.147.1.el8_10,kernel-0:5.14.0-427.141.1.el9_4,kernel-0:4.18.0-477.156.1.el8_8,kernel-0:5.14.0-570.131.1.el9_6,kernel-rt-0:4.18.0-553.147.1.rt7.488.el8_10,kernel-0:6.12.0-211.39.1.el10_2,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-51401
Severity: important
Released on: 04/08/2026
Advisory:
Bugzilla: 2511255
Bugzilla Description: vim: Vim: Arbitrary code execution via vms_fixfilename() function
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-641
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-51400
Severity: moderate
Released on: 04/08/2026
Advisory:
Bugzilla: 2511268
Bugzilla Description: vim: Vim: Arbitrary code execution via vms_fixfilename() function
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-94
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-8400
Severity: important
Released on: 04/08/2026
Advisory:
Bugzilla: 2512497
Bugzilla Description: java-1.8.0-ibm: Arbitrary class loading and instantiation via malicious IIOP server
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-470
Affected Packages:
Package States: Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-69240
Severity: critical
Released on: 03/08/2026
Advisory:
Bugzilla: 2510799
Bugzilla Description: sequelize: Sequelize: SQL Injection via improper handling of Oracle date functions
CVSS Score:
CVSSv3 Score: 9.8
Vector:
CWE: CWE-89
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-69198
Severity: moderate
Released on: 03/08/2026
Advisory: RHSA-2026:50826, RHSA-2026:49401,
Bugzilla: 2510803
Bugzilla Description: ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-1389
Affected Packages: grafana13-1-main-13.1.1-0.5.2.hum1,grafana12-4-main-12.4.6-0.3.hum1,
Package States: Cryostat 4,Cryostat 4,Cryostat 4,Exploit Intelligence,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat Build of Podman Desktop,Red Hat Connectivity Link 1,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Satellite 6,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-69192
Severity: important
Released on: 03/08/2026
Advisory: RHSA-2026:50826, RHSA-2026:50969, RHSA-2026:50854, RHSA-2026:50956,
Bugzilla: 2510801
Bugzilla Description: ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass
CVSS Score:
CVSSv3 Score: 8.6
Vector:
CWE: CWE-1389
Affected Packages: grafana13-1-main-13.1.1-0.5.2.hum1,grafana13-1-main-13.1.2-0.1.hum1,grafana12-4-main-12.4.7-0.1.hum1,grafana12-4-main-12.4.6-0.4.1.hum1,
Package States: Cryostat 4,Cryostat 4,Cryostat 4,Exploit Intelligence,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat Build of Podman Desktop,Red Hat Connectivity Link 1,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Satellite 6,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-69185
Severity: important
Released on: 03/08/2026
Advisory:
Bugzilla: 2510755
Bugzilla Description: socket.io-parser: Socket.IO: Denial of Service via memory exhaustion from crafted packets
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-18739
Severity: low
Released on: 03/08/2026
Advisory:
Bugzilla: 2510737
Bugzilla Description: popt-devel: popt-static: Off-by-one in poptStuffArgs
CVSS Score:
CVSSv3 Score: 2.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-69153
Severity: important
Released on: 03/08/2026
Advisory: RHSA-2026:50287, RHSA-2026:50079, RHSA-2026:50826, RHSA-2026:50070, RHSA-2026:50290,
Bugzilla: 2510719
Bugzilla Description: postcss: PostCSS: Information disclosure via crafted sourceMappingURL
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-22
Affected Packages: prometheus3-13-main-3.13.2-0.2.hum1,grafana12-4-main-12.4.6-0.4.hum1,grafana13-1-main-13.1.1-0.5.2.hum1,grafana13-1-main-13.1.1-0.5.1.hum1,prometheus3-5-main-3.5.5-0.7.hum1,
Package States: Cryostat 4,Cryostat 4,Cryostat 4,Gatekeeper 3,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat 3scale API Management Platform 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat Build of Podman Desktop,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Virtualization 4,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Single Sign-On 7,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-69152
Severity: important
Released on: 03/08/2026
Advisory: RHSA-2026:50079, RHSA-2026:50826, RHSA-2026:50290,
Bugzilla: 2510722
Bugzilla Description: brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages: grafana12-4-main-12.4.6-0.4.hum1,grafana13-1-main-13.1.1-0.5.2.hum1,grafana13-1-main-13.1.1-0.5.1.hum1,
Package States: Cryostat 4,Cryostat 4,Cryostat 4,Exploit Intelligence,Gatekeeper 3,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Podman Desktop,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Directory Server 11,Red Hat Directory Server 12,Red Hat Directory Server 13,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift Virtualization 4,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Single Sign-On 7,Red Hat Trusted Profile Analyzer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-69151
Severity: important
Released on: 03/08/2026
Advisory:
Bugzilla: 2510726
Bugzilla Description: @angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-79
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat build of Apicurio Registry 3,Red Hat Ceph Storage 4,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68945
Severity: important
Released on: 03/08/2026
Advisory:
Bugzilla: 2510710
Bugzilla Description: @angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-694
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat build of Apicurio Registry 3,Red Hat Ceph Storage 4,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68744
Severity: low
Released on: 03/08/2026
Advisory:
Bugzilla: 2509761
Bugzilla Description: sssd: sssd: NSS responder uninitialized heap disclosure in initgroups reply
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-68742
Severity: moderate
Released on: 03/08/2026
Advisory:
Bugzilla: 2509762
Bugzilla Description: sssd: sssd: NSS responder out-of-bounds read via unchecked addrlen in GETHOSTBYADDR
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-68743
Severity: moderate
Released on: 03/08/2026
Advisory:
Bugzilla: 2509760
Bugzilla Description: sssd: sssd: PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-12259
Severity: moderate
Released on: 03/08/2026
Advisory:
Bugzilla: 2510340
Bugzilla Description: nltk: nltk: Installation of attacker-controlled packages due to improper checksum validation
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-354
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-18651
Severity: moderate
Released on: 03/08/2026
Advisory:
Bugzilla: 2510617
Bugzilla Description: 389-ds-base: 389-ds-base: SASL PLAIN bind installs connection credentials before account-lock check, allowing continued access as a locked account
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-287
Affected Packages:
Package States: Red Hat Directory Server 11,Red Hat Directory Server 12,Red Hat Directory Server 13,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68580
Severity: important
Released on: 02/08/2026
Advisory:
Bugzilla: 2510125
Bugzilla Description: FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68579
Severity: critical
Released on: 02/08/2026
Advisory:
Bugzilla: 2510124
Bugzilla Description: FreeRDP: FreeRDP: Arbitrary Code Execution via Heap Overflow in Clipboard Processing
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67323
Severity: important
Released on: 01/08/2026
Advisory: RHSA-2026:44416, RHSA-2026:45785, RHSA-2026:45940,
Bugzilla: 2509976
Bugzilla Description: gitpython: GitPython: Arbitrary code execution via command injection due to unguarded Git options
CVSS Score:
CVSSv3 Score: 8.4
Vector:
CWE: CWE-88
Affected Packages: swift-lang-main-6.3.3-0.1.1.hum1,llvm21-main-21.1.8-8.hum1,llvm-main-22.1.8-4.1.hum1,
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-67302
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2509981
Bugzilla Description: FreeRDP: FreeRDP: Denial of service in camera redirection due to divide-by-zero
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67299
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2509985
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-416
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67318
Severity: moderate
Released on: 01/08/2026
Advisory: RHSA-2026:50826, RHSA-2026:49714,
Bugzilla: 2509989
Bugzilla Description: axios: axios: Denial of Service due to maxBodyLength bypass in HTTP/2 requests
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-770
Affected Packages: grafana13-1-main-13.1.1-0.5.2.hum1,grafana13-1-main-13.1.1-0.5.hum1,
Package States: Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-67306
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2509996
Bugzilla Description: FreeRDP: FreeRDP: Out-of-bounds read vulnerability via crafted RDP messages
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67295
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2509998
Bugzilla Description: FreeRDP: FreeRDP: Unauthorized File Access via Drive Redirection Vulnerability
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-66401
Severity: low
Released on: 01/08/2026
Advisory:
Bugzilla: 2510002
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via out-of-bounds read in UVC H.264 parser
CVSS Score:
CVSSv3 Score: 2.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67326
Severity: moderate
Released on: 01/08/2026
Advisory: RHSA-2026:44416, RHSA-2026:45785, RHSA-2026:45940,
Bugzilla: 2510003
Bugzilla Description: gitpython: GitPython: Remote Code Execution via Newline Injection in config_writer()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-93
Affected Packages: swift-lang-main-6.3.3-0.1.1.hum1,llvm21-main-21.1.8-8.hum1,llvm-main-22.1.8-4.1.hum1,
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-67312
Severity: important
Released on: 01/08/2026
Advisory: RHSA-2026:47619, RHSA-2026:48241, RHSA-2026:48758,
Bugzilla: 2510007
Bugzilla Description: axios: axios: Denial of Service via uncontrolled recursion in form data processing
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-674
Affected Packages: jaeger-main-2.20.0-0.8.hum1,grafana13-1-main-13.1.1-0.3.hum1,grafana12-4-main-12.4.6-0.2.hum1,
Package States: Cryostat 4,Cryostat 4,Gatekeeper 3,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,Network Observability Operator,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat build of Apicurio Registry 3,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Trusted Artifact Signer,Red Hat Trusted Profile Analyzer,Red Hat Trusted Profile Analyzer,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-67316
Severity: low
Released on: 01/08/2026
Advisory: RHSA-2026:50826, RHSA-2026:49714,
Bugzilla: 2510009
Bugzilla Description: axios: axios: Prototype Pollution allows unauthorized data transmission and network redirection
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-915
Affected Packages: grafana13-1-main-13.1.1-0.5.2.hum1,grafana13-1-main-13.1.1-0.5.hum1,
Package States: Cryostat 4,Cryostat 4,Gatekeeper 3,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,Network Observability Operator,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat build of Apicurio Registry 3,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Trusted Artifact Signer,Red Hat Trusted Profile Analyzer,Red Hat Trusted Profile Analyzer,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-67291
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2510010
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67321
Severity: important
Released on: 01/08/2026
Advisory: RHSA-2026:47619, RHSA-2026:48241, RHSA-2026:48758,
Bugzilla: 2510011
Bugzilla Description: axios: axios: Denial of Service via object serialization bypass
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages: jaeger-main-2.20.0-0.8.hum1,grafana13-1-main-13.1.1-0.3.hum1,grafana12-4-main-12.4.6-0.2.hum1,
Package States:
Full Details
CVE document


CVE-2026-67300
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2510013
Bugzilla Description: FreeRDP: FreeRDP: Use-After-Free vulnerability leading to denial of service
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67315
Severity: moderate
Released on: 01/08/2026
Advisory: RHSA-2026:50826, RHSA-2026:49714,
Bugzilla: 2510019
Bugzilla Description: axios: axios: NO_PROXY bypass allows exposure of local services
CVSS Score:
CVSSv3 Score: 5.8
Vector:
CWE: CWE-115
Affected Packages: grafana13-1-main-13.1.1-0.5.2.hum1,grafana13-1-main-13.1.1-0.5.hum1,
Package States: Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-67319
Severity: moderate
Released on: 01/08/2026
Advisory: RHSA-2026:49387, RHSA-2026:49401,
Bugzilla: 2510023
Bugzilla Description: axios: axios: Information disclosure and data manipulation via prototype pollution
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-915
Affected Packages: grafana13-1-main-13.1.1-0.4.hum1,grafana12-4-main-12.4.6-0.3.hum1,
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-67292
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2510028
Bugzilla Description: FreeRDP: FreeRDP: Information Disclosure and Denial of Service via WebSocket Ping
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67324
Severity: important
Released on: 01/08/2026
Advisory:
Bugzilla: 2510032
Bugzilla Description: gitpython: GitPython: Arbitrary Code Execution via Joined Short Options Bypass
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-78
Affected Packages:
Package States: Exploit Intelligence,Migration Toolkit for Applications 8,Pen Drive Powered by Red Hat Lightspeed,Pen Drive Powered by Red Hat Lightspeed,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-67303
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2510038
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via unsupported serial device control request
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67298
Severity: important
Released on: 01/08/2026
Advisory:
Bugzilla: 2510041
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via integer underflow in RAIL channel handling
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67320
Severity: important
Released on: 01/08/2026
Advisory: RHSA-2026:47619, RHSA-2026:48241, RHSA-2026:48758,
Bugzilla: 2509993
Bugzilla Description: axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-915
Affected Packages: jaeger-main-2.20.0-0.8.hum1,grafana13-1-main-13.1.1-0.3.hum1,grafana12-4-main-12.4.6-0.2.hum1,
Package States:
Full Details
CVE document


CVE-2026-67338
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2509997
Bugzilla Description: jupyterlab: JupyterLab: Stored cross-site scripting in Extension Manager allows arbitrary code execution
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-79
Affected Packages:
Package States: Migration Toolkit for Applications 8,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-67294
Severity: low
Released on: 01/08/2026
Advisory:
Bugzilla: 2509999
Bugzilla Description: FreeRDP: FreeRDP: Server certificate validation bypass via improper Extended Key Usage (EKU) validation
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-295
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67322
Severity: important
Released on: 01/08/2026
Advisory: RHSA-2026:44416, RHSA-2026:45785, RHSA-2026:45940,
Bugzilla: 2510021
Bugzilla Description: gitpython: GitPython: Environment variable exfiltration via attacker-controlled clone URL
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-214
Affected Packages: swift-lang-main-6.3.3-0.1.1.hum1,llvm21-main-21.1.8-8.hum1,llvm-main-22.1.8-4.1.hum1,
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-66402
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2510026
Bugzilla Description: FreeRDP: FreeRDP: Server Identity Verification Bypass via TLS Certificate Validation Weaknesses
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-222
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67296
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2510029
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service due to RDPEI message processing
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-20
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67304
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2510034
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via null pointer dereference in smartcard cleanup
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67325
Severity: important
Released on: 01/08/2026
Advisory: RHSA-2026:44416, RHSA-2026:45785, RHSA-2026:45940,
Bugzilla: 2509975
Bugzilla Description: gitpython: GitPython: Command Injection via Git option prefix abbreviation
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-78
Affected Packages: swift-lang-main-6.3.3-0.1.1.hum1,llvm21-main-21.1.8-8.hum1,llvm-main-22.1.8-4.1.hum1,
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-67297
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2509986
Bugzilla Description: FreeRDP: FreeRDP: Resource exhaustion due to oversized chunked HTTP responses
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67301
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2509994
Bugzilla Description: FreeRDP: FreeRDP: Memory disclosure or denial of service via crafted RDP update orders
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67293
Severity: moderate
Released on: 01/08/2026
Advisory:
Bugzilla: 2510015
Bugzilla Description: FreeRDP: FreeRDP: Weakens TLS server authentication due to improper wildcard certificate hostname validation
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-295
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67313
Severity: important
Released on: 01/08/2026
Advisory: RHSA-2026:50826, RHSA-2026:48758, RHSA-2026:49714,
Bugzilla: 2510017
Bugzilla Description: axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-674
Affected Packages: jaeger-main-2.20.0-0.8.hum1,grafana13-1-main-13.1.1-0.5.2.hum1,grafana13-1-main-13.1.1-0.5.hum1,
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-67305
Severity: important
Released on: 01/08/2026
Advisory:
Bugzilla: 2510027
Bugzilla Description: FreeRDP: FreeRDP Windows Client: Remote Code Execution via Heap Buffer Overflow in Clipboard Processing
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-122
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67314
Severity: important
Released on: 01/08/2026
Advisory: RHSA-2026:50826, RHSA-2026:48758, RHSA-2026:49714,
Bugzilla: 2510030
Bugzilla Description: axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-915
Affected Packages: jaeger-main-2.20.0-0.8.hum1,grafana13-1-main-13.1.1-0.5.2.hum1,grafana13-1-main-13.1.1-0.5.hum1,
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-67317
Severity: moderate
Released on: 01/08/2026
Advisory: RHSA-2026:50826, RHSA-2026:49714,
Bugzilla: 2510031
Bugzilla Description: axios: axios: Denial of Service via maxBodyLength bypass with ReadableStream
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-770
Affected Packages: grafana13-1-main-13.1.1-0.5.2.hum1,grafana13-1-main-13.1.1-0.5.hum1,
Package States: Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-54787
Severity: low
Released on: 31/07/2026
Advisory: RHSA-2026:44162, RHSA-2026:47891, RHSA-2026:47889,
Bugzilla: 2509939
Bugzilla Description: github.com/sigstore/sigstore-go: sigstore-go: Signature bypass allows acceptance of bundles signed with expired keys
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-347
Affected Packages: spire1-14-main-1.14.7-0.3.hum1,spire1-15-main-1.15.2-0.3.hum1,trivy-main-0.72.0-0.1.3.hum1,
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-68770
Severity: important
Released on: 31/07/2026
Advisory:
Bugzilla: 2509932
Bugzilla Description: sentence-transformers: sentence-transformers: Remote Code Execution via Security Control Bypass
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-454
Affected Packages:
Package States: Lightspeed Core,Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-17566
Severity: critical
Released on: 31/07/2026
Advisory:
Bugzilla: 2509835
Bugzilla Description: pgAdmin 4: pgAdmin 4: Remote Code Execution via backslash-escape mismatch in Import/Export Data tool
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-78
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17348
Severity: moderate
Released on: 31/07/2026
Advisory:
Bugzilla: 2509842
Bugzilla Description: pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-306
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18141
Severity: important
Released on: 31/07/2026
Advisory: RHSA-2026:50340, RHSA-2026:50336, RHSA-2026:50479,
Bugzilla: 2508155
Bugzilla Description: aap-gateway: aap-gateway: Authentication bypass in Event-Driven Ansible via forged HTTP header
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-295
Affected Packages: automation-eda-controller-0:1.2.11-1.el9ap,ansible-automation-platform-27/gateway-rhel9:1785435970,ansible-automation-platform-26/gateway-rhel9:1785780020,
Package States: Red Hat Ansible Automation Platform 2,
Full Details
CVE document


CVE-2026-18967
Severity: moderate
Released on: 31/07/2026
Advisory:
Bugzilla: 2511604
Bugzilla Description: keycloak-services: keycloak-services: SAML OneTimeUse assertion replay in IdP-Initiated broker flow
CVSS Score:
CVSSv3 Score: 6.4
Vector:
CWE: CWE-294
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18446
Severity: important
Released on: 31/07/2026
Advisory: RHSA-2026:49387, RHSA-2026:49401,
Bugzilla: 2509801
Bugzilla Description: fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1289
Affected Packages: grafana13-1-main-13.1.1-0.4.hum1,grafana12-4-main-12.4.6-0.3.hum1,
Package States: Cryostat 4,Cryostat 4,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat build of Apicurio Registry 3,Red Hat Build of Podman Desktop,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-18358
Severity: moderate
Released on: 31/07/2026
Advisory:
Bugzilla: 2462876
Bugzilla Description: gnome-remote-desktop: gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-400
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18569
Severity: low
Released on: 31/07/2026
Advisory:
Bugzilla: 2509755
Bugzilla Description: keycloak-services: keycloak-services: OIDC backchannel logout accepts unsigned forged logout tokens
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-347
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-10079
Severity: important
Released on: 31/07/2026
Advisory:
Bugzilla: 2483158
Bugzilla Description: stackrox: stackrox: Deploy-time policy enforcement and visibility bypass via label injection
CVSS Score:
CVSSv3 Score: 8.5
Vector:
CWE: CWE-345
Affected Packages:
Package States: Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,
Full Details
CVE document


CVE-2026-11770
Severity: moderate
Released on: 31/07/2026
Advisory:
Bugzilla: 2484802
Bugzilla Description: 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-90
Affected Packages:
Package States: Red Hat Directory Server 11,Red Hat Directory Server 12,Red Hat Directory Server 13,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-15722
Severity: important
Released on: 31/07/2026
Advisory:
Bugzilla: 2499961
Bugzilla Description: 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-121
Affected Packages:
Package States: Red Hat Directory Server 11,Red Hat Directory Server 12,Red Hat Directory Server 13,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-58039
Severity: moderate
Released on: 31/07/2026
Advisory: RHSA-2026:48273, RHSA-2026:48305, RHSA-2026:48537,
Bugzilla: 2509653
Bugzilla Description: nodejs: Information disclosure due to improper permission enforcement
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-73
Affected Packages: nodejs26-main-26.5.1-1.5.hum1,nodejs22-main-22.23.2-2.3.hum1,nodejs24-main-24.18.1-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-18477
Severity: moderate
Released on: 31/07/2026
Advisory: RHSA-2026:49361,
Bugzilla: 2509735
Bugzilla Description: tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-367
Affected Packages: tar-main-1.35-9.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-18508
Severity: moderate
Released on: 31/07/2026
Advisory: RHSA-2026:50807,
Bugzilla: 2509843
Bugzilla Description: tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-59
Affected Packages: tar-main-1.35-9.2.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-68563
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2465419
Bugzilla Description: ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: Information disclosure of PostgreSQL data via insecure backup permissions
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-732
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-68562
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2466035
Bugzilla Description: ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: Information disclosure via Leapp report tampering
CVSS Score:
CVSSv3 Score: 6.2
Vector:
CWE: CWE-610
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18157
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2465250
Bugzilla Description: yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: Remote Code Execution via APT Argument Injection
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-88
Affected Packages:
Package States: Red Hat Enterprise Linux 10,
Full Details
CVE document


CVE-2026-67550
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509949
Bugzilla Description: re2: Denial of Service via out-of-bounds read
CVSS Score:
CVSSv3 Score: 5.7
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-66066
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2509559
Bugzilla Description: activestorage: Active Storage: Remote Code Execution via Unsafe libvips Operations
CVSS Score:
CVSSv3 Score: 8.9
Vector:
CWE: CWE-434
Affected Packages:
Package States: Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-12932
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2509521
Bugzilla Description: openvpn: OpenVPN: Denial of Service due to memory leak in tls-crypt-v2 client key extraction
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-771
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-12996
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509536
Bugzilla Description: OpenVPN: OpenVPN: Denial of Service or memory leak via crafted packets
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-11771
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509516
Bugzilla Description: openvpn: OpenVPN: Denial of Service via crafted NTLM proxy response
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-13117
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509530
Bugzilla Description: OpenVPN: OpenVPN: Denial of service or memory leakage via incomplete TLS guard
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-7260
Severity: moderate
Released on: 30/07/2026
Advisory: RHSA-2026:47200,
Bugzilla: 2509255
Bugzilla Description: php: PHP: Denial of Service via circular symbolic links in phar archives
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-606
Affected Packages: php-main-8.5.9-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-17544
Severity: important
Released on: 30/07/2026
Advisory: RHSA-2026:47200,
Bugzilla: 2509256
Bugzilla Description: php: PHP: Arbitrary code execution via out-of-bounds write in bccomp()
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-787
Affected Packages: php-main-8.5.9-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-17543
Severity: important
Released on: 30/07/2026
Advisory: RHSA-2026:47200,
Bugzilla: 2509254
Bugzilla Description: php: ext-pgsql: PHP: SQL injection via improper backslash escaping
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-89
Affected Packages: php-main-8.5.9-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18570
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509756
Bugzilla Description: keycloak-services: keycloak-services: Full-scope-disabled client policy validation bypass via omitted fullScopeAllowed
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18571
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509759
Bugzilla Description: keycloak-services: keycloak-services: FGAP V2 group assignment bypass during user creation
CVSS Score:
CVSSv3 Score: 6.6
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18572
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509763
Bugzilla Description: keycloak-services: keycloak-services: UMA claim token can override authorization time-policy evaluation attributes
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18573
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509764
Bugzilla Description: keycloak-services: keycloak-services: Client access-type policy condition bypass during client update
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18369
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509234
Bugzilla Description: dogtag-pki: pki-core: redhat-pki: pki: ACME HTTP-01 validation SSRF via IP literal identifiers and unvalidated redirects
CVSS Score:
CVSSv3 Score: 5.8
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat Certificate System 10,Red Hat Certificate System 11,Red Hat Certificate System 9,Red Hat Certificate System 9,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18353
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2509192
Bugzilla Description: PIA: python: requests: urllib3: PIA: Unauthenticated Server-Side Request Forgery via OIDC issuer allowlist bypass
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-58043
Severity: important
Released on: 30/07/2026
Advisory: RHSA-2026:48273, RHSA-2026:48305, RHSA-2026:48537,
Bugzilla: 2509171
Bugzilla Description: nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-551
Affected Packages: nodejs26-main-26.5.1-1.5.hum1,nodejs22-main-22.23.2-2.3.hum1,nodejs24-main-24.18.1-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-56850
Severity: moderate
Released on: 30/07/2026
Advisory: RHSA-2026:48273, RHSA-2026:48305, RHSA-2026:48537,
Bugzilla: 2509179
Bugzilla Description: nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw
CVSS Score:
CVSSv3 Score: 4.1
Vector:
CWE: CWE-303
Affected Packages: nodejs26-main-26.5.1-1.5.hum1,nodejs22-main-22.23.2-2.3.hum1,nodejs24-main-24.18.1-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-58040
Severity: moderate
Released on: 30/07/2026
Advisory: RHSA-2026:48273, RHSA-2026:48305, RHSA-2026:48537,
Bugzilla: 2509175
Bugzilla Description: nodejs: HTTPS Agent TLS session reuse skips hostname verification
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-322
Affected Packages: nodejs26-main-26.5.1-1.5.hum1,nodejs22-main-22.23.2-2.3.hum1,nodejs24-main-24.18.1-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-18018
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508737
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Updater
CVSS Score:
CVSSv3 Score: 2.8
Vector:
CWE:
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18019
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508903
Bugzilla Description: chromium-browser: chromium-browser: Side-channel information leakage in Media
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-205
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18015
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508705
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Tint
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-653
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18017
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508777
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Dawn
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE:
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18014
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2509024
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in DevTools
CVSS Score:
Vector:
CWE: CWE-434
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18012
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508887
Bugzilla Description: chromium-browser: chromium-browser: Use after free in PDFium
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18008
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508864
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Settings
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18009
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508892
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Passwords
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-290
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18010
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2509019
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Passwords
CVSS Score:
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18007
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508912
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Input
CVSS Score:
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18004
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508940
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Speech
CVSS Score:
CVSSv3 Score: 3.2
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18005
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508954
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in WebXR
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18001
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508693
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in WebGL
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18002
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508957
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Google Lens
CVSS Score:
CVSSv3 Score: 5.0
Vector:
CWE: CWE-1289
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17999
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508897
Bugzilla Description: chromium-browser: chromium-browser: Incorrect security UI in PictureInPicture
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-368
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18000
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508981
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in USB
CVSS Score:
CVSSv3 Score: 2.8
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17998
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508732
Bugzilla Description: chromium-browser: chromium-browser: Incorrect security UI in Extensions
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17997
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508837
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Passwords
CVSS Score:
CVSSv3 Score: 2.4
Vector:
CWE: CWE-368
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17996
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508996
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Browser
CVSS Score:
CVSSv3 Score: 3.9
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17995
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508779
Bugzilla Description: chromium-browser: chromium-browser: Out of bounds read in Dawn
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17994
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508868
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Media
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17993
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508785
Bugzilla Description: chromium-browser: chromium-browser: Race in Updater
CVSS Score:
CVSSv3 Score: 3.9
Vector:
CWE: CWE-367
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17992
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508809
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in Skia
CVSS Score:
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17989
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508764
Bugzilla Description: chromium-browser: chromium-browser: Type Confusion in V8
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17990
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508907
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in WebAuthn
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17991
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508977
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in AI
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17987
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508791
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Notifications
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17988
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508816
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Navigation
CVSS Score:
CVSSv3 Score: 2.8
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17986
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508689
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Bluetooth
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17985
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508790
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Speech
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-653
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17984
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508710
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Browser
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17983
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508964
Bugzilla Description: chromium-browser: chromium-browser: Incorrect security UI in Global Media Controls
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17981
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508800
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Blink
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17982
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508893
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Cast
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17980
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2509002
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in UI
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17978
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508820
Bugzilla Description: chromium-browser: chromium-browser: Side-channel information leakage in WebCodecs
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-205
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17979
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508944
Bugzilla Description: chromium-browser: chromium-browser: Race in V8
CVSS Score:
Vector:
CWE: CWE-366
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17976
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508721
Bugzilla Description: chromium-browser: chromium-browser: Policy bypass in Extensions
CVSS Score:
Vector:
CWE: CWE-289
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17977
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508932
Bugzilla Description: chromium-browser: chromium-browser: Policy bypass in CSS
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17975
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2509009
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in IME
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-497
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17973
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508939
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Views
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17974
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508945
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in DevTools
CVSS Score:
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17970
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508747
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Passwords
CVSS Score:
CVSSv3 Score: 3.5
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17971
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508796
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Frame
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17968
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508717
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in WebXR
CVSS Score:
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17969
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2509001
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Passwords
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17966
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508758
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Views
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-497
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17964
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508797
Bugzilla Description: chromium-browser: chromium-browser: Incorrect security UI in UI
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17963
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508956
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in SVG
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17961
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508854
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Session
CVSS Score:
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17962
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508948
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Blink
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17959
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508738
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Network
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17956
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508817
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Scheduling
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-94
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17957
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508890
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in CORS
CVSS Score:
CVSSv3 Score: 2.8
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17958
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508902
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Views
CVSS Score:
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17955
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508756
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Payments
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17954
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508843
Bugzilla Description: chromium-browser: chromium-browser: Policy bypass in MHTML
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17952
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508823
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in V8
CVSS Score:
Vector:
CWE: CWE-551
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17953
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508998
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in WebView
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17951
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508715
Bugzilla Description: chromium-browser: webrtc: chromium-browser: Heap buffer overflow in WebRTC
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17950
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508869
Bugzilla Description: chromium-browser: chromium-browser: Policy bypass in Safebrowsing
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-494
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17949
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508929
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in GPU
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17948
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508959
Bugzilla Description: chromium-browser: chromium-browser: Type Confusion in V8
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17947
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2509013
Bugzilla Description: chromium-browser: chromium-browser: Use after free in WebSockets
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17946
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508766
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in Dawn
CVSS Score:
CVSSv3 Score: 2.8
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17945
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508947
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Navigation
CVSS Score:
CVSSv3 Score: 2.8
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17942
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508734
Bugzilla Description: chromium-browser: chromium-browser: Side-channel information leakage in SVG
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-205
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17943
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508873
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Parser
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-791
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17939
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508953
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Passwords
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-290
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17940
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508962
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Picture-in-Picture
CVSS Score:
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17938
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508786
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in FullScreen
CVSS Score:
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17937
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2509000
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in DevTools
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17935
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508748
Bugzilla Description: chromium-browser: chromium-browser: Heap buffer overflow in Codecs
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17934
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508780
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in DevTools
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17936
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508955
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in DevTools
CVSS Score:
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17932
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508751
Bugzilla Description: chromium-browser: chromium-browser: Use after free in DataTransfer
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17933
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508765
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in DOMStorage
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17930
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508711
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Extensions
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1289
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17931
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508824
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in DevTools
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17929
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508688
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in DevTools
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17927
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508841
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in DevTools
CVSS Score:
CVSSv3 Score: 2.8
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17928
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2509023
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in DataTransfer
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17926
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508858
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in DevTools
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17925
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508994
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Cast
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17924
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508729
Bugzilla Description: chromium-browser: chromium-browser: Use after free in DNS
CVSS Score:
CVSSv3 Score: 3.2
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17923
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508806
Bugzilla Description: chromium-browser: chromium-browser: Policy bypass in Enterprise
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-289
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17922
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508696
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Enterprise
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE:
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17920
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508911
Bugzilla Description: chromium-browser: chromium-browser: Use after free in V8
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17921
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2509018
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Navigation
CVSS Score:
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17918
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508712
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Sync
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17919
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508874
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Enterprise
CVSS Score:
CVSSv3 Score: 4.1
Vector:
CWE: CWE-266
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17916
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508699
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Settings
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-266
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17915
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508757
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in WebView
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17914
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508773
Bugzilla Description: chromium-browser: chromium-browser: Side-channel information leakage in Skia
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-205
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17911
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508698
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in SVG
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17910
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508774
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in NFC
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17909
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508989
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Isolated Web Apps
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17908
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508950
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Printing
CVSS Score:
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17907
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509004
Bugzilla Description: chromium-browser: Google Chrome: Information leakage via crafted HTML page
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17905
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508840
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in SurfaceCapture
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-940
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17906
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508851
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Bluetooth
CVSS Score:
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17904
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508834
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in NFC
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17902
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508690
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Editing
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17903
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508882
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Chromecast
CVSS Score:
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17901
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508754
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Sharing
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17899
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508772
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in DevTools
CVSS Score:
CVSSv3 Score: 2.8
Vector:
CWE: CWE-266
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17900
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508995
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Enterprise
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17898
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2508763
Bugzilla Description: chromium-browser: chromium-browser: Use after free in DevTools
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17895
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508857
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in DataTransfer
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17897
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508875
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in ORB
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17896
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508963
Bugzilla Description: chromium-browser: chromium-browser: Use after free in DevTools
CVSS Score:
CVSSv3 Score: 7.6
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17892
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508844
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in WebXR
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-497
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17894
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508866
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Views
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17893
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508871
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Updater
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17890
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508886
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in DevTools
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17888
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508891
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in WebUI
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17891
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508966
Bugzilla Description: chromium-browser: chromium-browser: Use after free in ANGLE
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17889
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508970
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in WebXR
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17887
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508718
Bugzilla Description: chromium-browser: chromium-browser: Use after free in TabStrip
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17885
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508846
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Paint
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17886
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508899
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Enterprise
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17884
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508978
Bugzilla Description: chromium-browser: chromium-browser: Object lifecycle issue in WebRTC
CVSS Score:
CVSSv3 Score: 7.6
Vector:
CWE: CWE-1341
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17881
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508789
Bugzilla Description: chromium-browser: chromium-browser: Use after free in WebXR
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-190
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17882
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508984
Bugzilla Description: chromium-browser: chromium-browser: Policy bypass in Extensions
CVSS Score:
CVSSv3 Score: 6.7
Vector:
CWE: CWE-653
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17880
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508775
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Autofill
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17877
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508845
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Chromoting
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-358
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17879
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508848
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Autofill
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17878
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508993
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in CSS
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17875
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508842
Bugzilla Description: chromium-browser: chromium-browser: Use after free in PDFium
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17876
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508915
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Payments
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17871
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508749
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Passwords
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17872
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508830
Bugzilla Description: chromium-browser: chromium-browser: Cryptographic Flaw in WebAppInstalls
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-1240
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17870
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508865
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Cast
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17866
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508745
Bugzilla Description: chromium-browser: chromium-browser: Type Confusion in Tab
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17868
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508798
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in USB
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-280
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17869
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508961
Bugzilla Description: chromium-browser: chromium-browser: Out of bounds read in WebXR
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17867
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508976
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Dawn
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17864
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508781
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Updater
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-428
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17863
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508799
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Browser
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE:
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17862
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508958
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Tracing
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17865
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509022
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Crypto
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-501
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17861
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508761
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Updater
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-434
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17860
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508880
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Mobile
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-1289
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17859
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508885
Bugzilla Description: chromium-browser: chromium-browser: Side-channel information leakage in Favicons
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17858
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509020
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in WebNN
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17857
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508686
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Network
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17856
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508714
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Network
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17855
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508719
Bugzilla Description: chromium-browser: chromium-browser: Race in DevTools
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-368
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17851
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508921
Bugzilla Description: chromium-browser: chromium-browser: Side-channel information leakage in Autofill
CVSS Score:
CVSSv3 Score: 5.8
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17852
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508974
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Media Router
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17853
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508991
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in DevTools
CVSS Score:
CVSSv3 Score: 8.9
Vector:
CWE: CWE-94
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17854
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509012
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in WebMCP
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17850
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508839
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Permissions
CVSS Score:
CVSSv3 Score: 9.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17848
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508965
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Codecs
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-190
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17845
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508692
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in CSS
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17844
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508703
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Cast
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17847
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508735
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in ANGLE
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17846
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508855
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Media
CVSS Score:
CVSSv3 Score: 7.9
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17840
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508926
Bugzilla Description: chromium-browser: chromium-browser: Incorrect security UI in Passwords
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17843
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508934
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in CSS
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17836
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508822
Bugzilla Description: chromium-browser: chromium-browser: Use after free in V8
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17837
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508832
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in DevTools
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17834
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508746
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Passwords
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-1289
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17833
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508753
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Passwords
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17832
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508694
Bugzilla Description: chromium-browser: chromium-browser: Use after free in ANGLE
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17831
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508942
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Passwords
CVSS Score:
CVSSv3 Score: 6.6
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17829
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508988
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Passwords
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17827
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508910
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in CSS
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17824
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508702
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in ServiceWorker
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-940
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17825
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508733
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Passwords
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-1220
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17823
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2509021
Bugzilla Description: chromium-browser: Google Chrome: Same-Origin Policy Bypass via Insufficient Policy Enforcement in WebXR
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17820
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508725
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Autofill
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17818
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508740
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Network
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17819
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508879
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in WebAppInstalls
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17821
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508927
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Extensions
CVSS Score:
CVSSv3 Score: 3.9
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17815
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508862
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in GuestView
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17816
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508922
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Speech
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-1220
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17817
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508938
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in ReportingAndNEL
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17811
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508739
Bugzilla Description: chromium-browser: chromium-browser: Use after free in ANGLE
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17812
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508933
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in DigitalCredentials
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17809
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508727
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Extensions
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17810
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508792
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in Dawn
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17808
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509005
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in WebGL
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-908
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17805
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508771
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Glic
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17807
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508905
Bugzilla Description: chromium-browser: chromium-browser: Use after free in V8
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17804
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508925
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Media
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17806
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508986
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Extensions
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-1289
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17801
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508762
Bugzilla Description: chromium-browser: chromium-browser: Out of bounds memory access in ANGLE
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17803
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508898
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Save to Drive
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17802
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508946
Bugzilla Description: chromium-browser: chromium-browser: Side-channel information leakage in GPU
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-205
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17800
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508973
Bugzilla Description: chromium-browser: chromium-browser: Side-channel information leakage in MediaRecording
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-201
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17799
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508811
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Safe Browsing
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-1289
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17798
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508877
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Cast
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17796
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508794
Bugzilla Description: chromium-browser: chromium-browser: Side-channel information leakage in WebXR
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-205
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17797
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508850
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in CSS
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17793
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508730
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Messages
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17792
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508742
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Credential Management
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-303
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17791
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508744
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Payments
CVSS Score:
CVSSv3 Score: 4.6
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17794
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508980
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Mobile
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-290
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17788
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508760
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Blink
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17787
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508930
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in DevTools
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17790
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508951
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in ANGLE
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17786
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508881
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in DevTools
CVSS Score:
CVSSv3 Score: 3.9
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17784
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508908
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Audio
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17785
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508983
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in ANGLE
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17783
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508872
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Loader
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17780
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508917
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Isolated Web Apps
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-425
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17781
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508999
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Extensions
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17779
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508805
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Site Isolation
CVSS Score:
CVSSv3 Score: 9.3
Vector:
CWE: CWE-653
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17777
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508904
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Autofill
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17776
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508968
Bugzilla Description: chromium-browser: chromium-browser: Policy bypass in Receiver
CVSS Score:
CVSSv3 Score: 8.0
Vector:
CWE: CWE-280
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17778
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2509017
Bugzilla Description: chromium-browser: Google Chrome: Arbitrary code execution via crafted Chrome Extension
CVSS Score:
CVSSv3 Score: 7.6
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17774
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508831
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Variations
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17773
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508936
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Cast
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17775
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509016
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in PresentationAPI
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17769
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508861
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Cast
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17771
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508949
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in Skia
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17772
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508985
Bugzilla Description: chromium-browser: chromium-browser: Out of bounds read in WebGL
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17767
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508743
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in WebView
CVSS Score:
CVSSv3 Score: 4.8
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17766
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508814
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Clipboard
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17768
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508937
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in WebSockets
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-1289
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17765
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509015
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in WebProtect
CVSS Score:
CVSSv3 Score: 6.2
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17763
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508776
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in GPU
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17764
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508923
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in FedCM
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17757
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508726
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in Skia
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17760
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508829
Bugzilla Description: chromium-browser: chromium-browser: Side-channel information leakage in NoStatePrefetch
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-205
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17759
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508943
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in Codecs
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17755
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508709
Bugzilla Description: chromium-browser: chromium-browser: Incorrect security UI in Extensions
CVSS Score:
CVSSv3 Score: 5.6
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17756
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508825
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Presentation
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17754
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508960
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Blink
CVSS Score:
CVSSv3 Score: 9.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17753
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509014
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Autofill
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17750
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508795
Bugzilla Description: chromium-browser: chromium-browser: Use after free in ANGLE
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17749
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508847
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Extensions
CVSS Score:
CVSSv3 Score: 8.6
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17751
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508901
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in AdFilter
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-94
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17752
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508916
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Views
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17746
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508815
Bugzilla Description: chromium-browser: chromium-browser: Use after free in GPU
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17748
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508914
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Extensions
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-653
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17747
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508935
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Payments
CVSS Score:
CVSSv3 Score: 5.7
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17742
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508704
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Payments
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17743
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508782
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in ControlledFrame
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17744
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508860
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in File Input
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-653
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17745
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508884
Bugzilla Description: chromium-browser: chromium-browser: Out of bounds read in Skia
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17739
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508784
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Extensions
CVSS Score:
CVSSv3 Score: 6.6
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17738
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508808
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Payments
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-1289
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17740
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508895
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in ANGLE
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17741
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508972
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in WebView
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17737
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508723
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Bluetooth
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17736
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508856
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in WebView
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17735
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509025
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in BFCache
CVSS Score:
CVSSv3 Score: 5.7
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17731
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508722
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Autofill
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-940
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17733
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508768
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in QUIC
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17734
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508802
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Autofill
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17730
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508920
Bugzilla Description: chromium-browser: chromium-browser: Side-channel information leakage in Autofill
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17728
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508720
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Extensions
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17729
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508736
Bugzilla Description: chromium-browser: chromium-browser: Use after free in V8
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17758
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508819
Bugzilla Description: chromium-browser: chromium-browser: Heap buffer overflow in Dawn
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17732
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509007
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in SVG
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17727
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508788
Bugzilla Description: chromium-browser: chromium-browser: Out of bounds write in WebGL
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17725
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508867
Bugzilla Description: chromium-browser: chromium-browser: Type Confusion in V8
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17726
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508900
Bugzilla Description: chromium-browser: chromium-browser: Integer overflow in WebGL
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-190
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17721
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508713
Bugzilla Description: chromium-browser: chromium-browser: Out of bounds write in ANGLE
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17722
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508752
Bugzilla Description: chromium-browser: chromium-browser: Object lifecycle issue in WebView
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-386
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17723
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508818
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Media
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17720
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508706
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Passwords
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17718
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508707
Bugzilla Description: chromium-browser: chromium-browser: Use after free in ANGLE
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17717
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508833
Bugzilla Description: chromium-browser: chromium-browser: Integer overflow in ANGLE
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-190
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17719
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508863
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Input
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17715
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508859
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Passwords
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17714
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508982
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in ANGLE
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17716
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508992
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Updater
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17713
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508700
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Accessibility
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-501
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17711
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508931
Bugzilla Description: chromium-browser: chromium-browser: Race in Downloads
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-368
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17712
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508941
Bugzilla Description: chromium-browser: chromium-browser: Race in Skia
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-368
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17710
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2509008
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in MHTML
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-653
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17709
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508769
Bugzilla Description: chromium-browser: chromium-browser: Race in Downloads
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-368
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17707
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508803
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in Media
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17708
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508909
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Audio
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17704
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508778
Bugzilla Description: chromium-browser: chromium-browser: Use after free in ANGLE
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17706
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508821
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Media
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17705
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508928
Bugzilla Description: chromium-browser: libxml: chromium-browser: Integer overflow in libxml
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-17702
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508687
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in Skia
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17701
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508812
Bugzilla Description: chromium-browser: chromium-browser: Out of bounds read in ANGLE
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17700
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508913
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Actor
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17698
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508918
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in UI
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17699
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508990
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Views
CVSS Score:
CVSSv3 Score: 7.9
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17697
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2509003
Bugzilla Description: chromium-browser: chromium-browser: Type Confusion in ANGLE
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17693
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508755
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in FileSystem
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-940
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17694
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508853
Bugzilla Description: chromium-browser: chromium-browser: Use after free in DOM
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17695
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508883
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in ANGLE
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-501
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17696
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508894
Bugzilla Description: chromium-browser: chromium-browser: Side-channel information leakage in Media
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-205
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17691
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508807
Bugzilla Description: chromium-browser: chromium-browser: Out of bounds write in ANGLE
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17692
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508870
Bugzilla Description: chromium-browser: chromium-browser: Use after free in DataTransfer
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17690
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508997
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in PDF
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17689
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2509006
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in ANGLE
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17688
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508695
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Input
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17686
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508828
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Passwords
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17687
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508849
Bugzilla Description: chromium-browser: ANGLE: chromium-browser: Type Confusion in ANGLE
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17683
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508701
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in ANGLE
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-497
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17685
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508810
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Autofill
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17680
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508691
Bugzilla Description: chromium-browser: chromium-browser: Heap buffer overflow in Color
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17681
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508888
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Web Authentication
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17679
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508969
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Print Preview
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17682
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508975
Bugzilla Description: chromium-browser: chromium-browser: Integer overflow in ANGLE
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-190
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17676
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508716
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in ANGLE
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-501
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17678
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508836
Bugzilla Description: chromium-browser: chromium-browser: Out of bounds read in ANGLE
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17677
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508971
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in ANGLE
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-501
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17675
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508724
Bugzilla Description: chromium-browser: chromium-browser: Out of bounds write in ANGLE
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17674
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508741
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in HTML
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE:
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17672
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508952
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Chromecast
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-1289
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17673
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508967
Bugzilla Description: chromium-browser: chromium-browser: Integer overflow in QUIC
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-190
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17670
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508827
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Views
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17671
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508979
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in ANGLE
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17666
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508728
Bugzilla Description: chromium-browser: chromium-browser: Cryptographic Flaw in Enterprise
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-347
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17667
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508767
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in ANGLE
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17665
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508801
Bugzilla Description: chromium-browser: chromium-browser: Use after free in V8
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17668
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508852
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized Use in ANGLE
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17664
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508804
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Loader
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17662
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508924
Bugzilla Description: chromium-browser: chromium-browser: Insufficient policy enforcement in Prefetch
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17663
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2509010
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in GPU
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17658
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508783
Bugzilla Description: chromium-browser: chromium-browser: Use after free in V8
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17661
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508826
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Loader
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17660
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508835
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Network
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17659
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2509011
Bugzilla Description: chromium-browser: chromium-browser: Inappropriate implementation in SiteIsolation
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-653
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17657
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508708
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Navigation
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17656
Severity: critical
Released on: 30/07/2026
Advisory:
Bugzilla: 2508889
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Ozone
CVSS Score:
CVSSv3 Score: 10.0
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17655
Severity: critical
Released on: 30/07/2026
Advisory:
Bugzilla: 2508906
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in ANGLE
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-1286
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17654
Severity: critical
Released on: 30/07/2026
Advisory:
Bugzilla: 2508697
Bugzilla Description: chromium-browser: chromium-browser: Race in Updater
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-367
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17653
Severity: critical
Released on: 30/07/2026
Advisory:
Bugzilla: 2508987
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Skia
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17651
Severity: critical
Released on: 30/07/2026
Advisory:
Bugzilla: 2508759
Bugzilla Description: chromium-browser: chromium-browser: Insufficient validation of untrusted input in Dawn
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17650
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2508770
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Compositing
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17652
Severity: critical
Released on: 30/07/2026
Advisory:
Bugzilla: 2508838
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Views
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-62946
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508878
Bugzilla Description: Imagemagick: ImageMagick: Denial of Service via integer overflow in JNX decoder on 32-bit systems
CVSS Score:
CVSSv3 Score: 5.1
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-62363
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2508731
Bugzilla Description: ImageMagick: ImageMagick: Denial of Service via crafted argument in fx operation
CVSS Score:
CVSSv3 Score: 5.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-16524
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2506023
Bugzilla Description: PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-78
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-16526
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2506026
Bugzilla Description: PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-403
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-16527
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2506031
Bugzilla Description: PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-306
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-16529
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2506032
Bugzilla Description: PCP: PCP: Denial of Service due to signed integer overflow
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-16530
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2506033
Bugzilla Description: PCP: PCP: Remote denial of service and information leakage
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-16531
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2506037
Bugzilla Description: PCP: PCP: Arbitrary file creation via path traversal in pmproxy logger servlet
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2022-4994
Severity: low
Released on: 30/07/2026
Advisory:
Bugzilla: 2509225
Bugzilla Description: kernel: KVM: x86: wean fast IN from emulator_pio_in
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18378
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2509249
Bugzilla Description: project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secret token exfiltration via user-controlled api_url (SSRF / confused deputy)
CVSS Score:
CVSSv3 Score: 7.6
Vector:
CWE: CWE-918
Affected Packages:
Package States: Cost Management Metrics Operator,
Full Details
CVE document


CVE-2026-18381
Severity: important
Released on: 30/07/2026
Advisory:
Bugzilla: 2509251
Bugzilla Description: project-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token exfiltration via user-controlled Prometheus service_address
CVSS Score:
CVSSv3 Score: 7.6
Vector:
CWE: CWE-918
Affected Packages:
Package States: Cost Management Metrics Operator,
Full Details
CVE document


CVE-2026-18382
Severity: moderate
Released on: 30/07/2026
Advisory:
Bugzilla: 2509253
Bugzilla Description: project-koku/koku-metrics-operator: koku-metrics-operator: service-account client credentials sent to user-controlled token_url
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-918
Affected Packages:
Package States: Cost Management Metrics Operator,
Full Details
CVE document


CVE-2026-62343
Severity: moderate
Released on: 29/07/2026
Advisory:
Bugzilla: 2508793
Bugzilla Description: ImageMagick: ImageMagick: Denial of Service via heap buffer over-write in morphology operation with invalid kernel
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-64685
Severity: moderate
Released on: 29/07/2026
Advisory:
Bugzilla: 2508813
Bugzilla Description: ImageMagick: ImageMagick: Information Disclosure via Crafted Image File
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-15157
Severity: moderate
Released on: 29/07/2026
Advisory: RHSA-2026:48273, RHSA-2026:48537,
Bugzilla: 2508677
Bugzilla Description: undici: undici: HTTP header injection via unvalidated blob-like body type property
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-93
Affected Packages: nodejs26-main-26.5.1-1.5.hum1,nodejs24-main-24.18.1-0.1.hum1,
Package States: Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-14643
Severity: moderate
Released on: 29/07/2026
Advisory: RHSA-2026:48273, RHSA-2026:48537,
Bugzilla: 2508676
Bugzilla Description: undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-524
Affected Packages: nodejs26-main-26.5.1-1.5.hum1,nodejs24-main-24.18.1-0.1.hum1,
Package States: Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-16728
Severity: moderate
Released on: 29/07/2026
Advisory: RHSA-2026:48273, RHSA-2026:48537,
Bugzilla: 2508678
Bugzilla Description: undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length
CVSS Score:
CVSSv3 Score: 4.8
Vector:
CWE: CWE-444
Affected Packages: nodejs26-main-26.5.1-1.5.hum1,nodejs24-main-24.18.1-0.1.hum1,
Package States: Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-54249
Severity: moderate
Released on: 29/07/2026
Advisory:
Bugzilla: 2508669
Bugzilla Description: pydantic-ai: Pydantic AI: Information disclosure through unvalidated file references.
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-918
Affected Packages:
Package States: Lightspeed Core,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,
Full Details
CVE document


CVE-2026-46678
Severity: moderate
Released on: 29/07/2026
Advisory:
Bugzilla: 2508674
Bugzilla Description: pydantic-ai: pydantic-ai-slim: Pydantic AI: Server-Side Request Forgery (SSRF) bypass exposes cloud credentials.
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-918
Affected Packages:
Package States: Lightspeed Core,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,
Full Details
CVE document


CVE-2026-5056
Severity: important
Released on: 29/07/2026
Advisory: RHSA-2026:49508,
Bugzilla: 2508623
Bugzilla Description: gstreamer: GStreamer: Arbitrary code execution via stack-based buffer overflow in qtdemux
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-121
Affected Packages: gstreamer1-plugins-good-0:1.26.7-2.el10_2.2,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18022
Severity: important
Released on: 29/07/2026
Advisory:
Bugzilla: 2508603
Bugzilla Description: pgvector: pgvector: Arbitrary Code Execution via Integer Wraparound
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Lightspeed Core,Lightspeed Core,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Trusted Profile Analyzer,Red Hat Trusted Profile Analyzer,
Full Details
CVE document


CVE-2026-13346
Severity: moderate
Released on: 29/07/2026
Advisory: RHSA-2026:48788,
Bugzilla: 2508514
Bugzilla Description: pip: pip: Arbitrary file installation via malicious package indexes
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-22
Affected Packages: python-pip-main-26.2-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-62995
Severity: moderate
Released on: 29/07/2026
Advisory: RHSA-2026:48758,
Bugzilla: 2508524
Bugzilla Description: joserfc: joserfc: JWT Malleability via Non-Standard Padding
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-1286
Affected Packages: jaeger-main-2.20.0-0.8.hum1,
Package States: Lightspeed Core,Migration Toolkit for Applications 8,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux command line assistant,Red Hat OpenShift Virtualization 4,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-16729
Severity: moderate
Released on: 29/07/2026
Advisory: RHSA-2026:48273, RHSA-2026:48537,
Bugzilla: 2508506
Bugzilla Description: undici: Undici: Cookie attribute injection allows bypassing security protections
CVSS Score:
CVSSv3 Score: 4.8
Vector:
CWE: CWE-140
Affected Packages: nodejs26-main-26.5.1-1.5.hum1,nodejs24-main-24.18.1-0.1.hum1,
Package States: Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-13697
Severity: important
Released on: 29/07/2026
Advisory: RHSA-2026:48273, RHSA-2026:48537,
Bugzilla: 2508485
Bugzilla Description: undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-524
Affected Packages: nodejs26-main-26.5.1-1.5.hum1,nodejs24-main-24.18.1-0.1.hum1,
Package States: Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-52791
Severity: moderate
Released on: 29/07/2026
Advisory:
Bugzilla: 2508489
Bugzilla Description: fuse-overlayfs: fuse-overlayfs: Privilege Escalation Vulnerability via SUID/SGID Bit Preservation
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-281
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-55707
Severity: important
Released on: 29/07/2026
Advisory:
Bugzilla: 2507588
Bugzilla Description: openstack-neutron: openstack-neutron: Shared-network consumer can re-scope another project's subnets via subnetpool onboarding
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-55995
Severity: important
Released on: 29/07/2026
Advisory:
Bugzilla: 2508414
Bugzilla Description: open-isns: open-iscsi: Denial of Service via double-free in iSNS attribute decoder
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-67216
Severity: moderate
Released on: 29/07/2026
Advisory:
Bugzilla: 2508418
Bugzilla Description: cJSON: Denial of Service due to inefficient JSON object comparison
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Hardened Images,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-16308
Severity: important
Released on: 29/07/2026
Advisory: RHSA-2026:47172, RHSA-2026:50848, RHSA-2026:50847, RHSA-2026:47189, RHSA-2026:50849, RHSA-2026:50846,
Bugzilla: 2506373
Bugzilla Description: io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages: rhbk/keycloak-rhel9:26.6-11,rhbk/keycloak-operator-bundle:26.4.14-1,rhbk-keycloak-rhel9/rhbk-keycloak-rhel9,rhbk-openshift-rhel9/rhbk-openshift-rhel9,rhbk/keycloak-rhel9-operator:26.6-11,rhbk/keycloak-rhel9-operator:26.4-22,rhbk/keycloak-operator-bundle:26.6.5-1,resteasy-reactive-common-processor,resteasy-reactive-client-processor,rhbk/keycloak-rhel9:26.4-22,
Package States: Cryostat 4,Cryostat 4,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apicurio Registry 3,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,streams for Apache Kafka 2,streams for Apache Kafka 2,streams for Apache Kafka 3,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-44944
Severity: important
Released on: 29/07/2026
Advisory:
Bugzilla: 2508412
Bugzilla Description: open-iscsi: open-iscsi: Authentication bypass in iscsiuio control socket
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-1220
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-44943
Severity: important
Released on: 29/07/2026
Advisory:
Bugzilla: 2508419
Bugzilla Description: open-iscsi: open-iscsi: Privilege Escalation via Path Traversal
CVSS Score:
CVSSv3 Score: 8.6
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-50642
Severity: moderate
Released on: 29/07/2026
Advisory:
Bugzilla: 2508367
Bugzilla Description: diff-so-fancy: diff-so-fancy: Terminal escape injection allows command execution
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-94
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-18220
Severity: important
Released on: 29/07/2026
Advisory:
Bugzilla: 2507670
Bugzilla Description: binutils: binutils: Out-of-bounds write in BFD DLX ELF backend relocation processing
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-56390
Severity: moderate
Released on: 29/07/2026
Advisory:
Bugzilla: 2508370
Bugzilla Description: bison: GNU Bison: Arbitrary file overwrite via grammar-defined output paths
CVSS Score:
CVSSv3 Score: 5.6
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-64556
Severity: important
Released on: 29/07/2026
Advisory:
Bugzilla: 2508319
Bugzilla Description: kernel: perf/core: Detach event groups during remove_on_exec
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64557
Severity: moderate
Released on: 29/07/2026
Advisory:
Bugzilla: 2508320
Bugzilla Description: kernel: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64558
Severity: important
Released on: 29/07/2026
Advisory:
Bugzilla: 2508480
Bugzilla Description: kernel: s390/pkey: Check length in pkey_pckmo handler implementation
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64559
Severity: moderate
Released on: 29/07/2026
Advisory:
Bugzilla: 2508488
Bugzilla Description: kernel: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-51992
Severity: critical
Released on: 29/07/2026
Advisory:
Bugzilla: 2508493
Bugzilla Description: ClickHouse Server: ClickHouse Server: Arbitrary code execution via SQL Injection in create dictionaries function
CVSS Score:
CVSSv3 Score: 9.8
Vector:
CWE: CWE-89
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-64560
Severity: important
Released on: 29/07/2026
Advisory:
Bugzilla: 2508504
Bugzilla Description: kernel: posix-cpu-timers: Prevent UAF caused by non-leader exec() race
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-18107
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2508140
Bugzilla Description: criu: criu: container escape via rseq critical section hijack during checkpoint/restore
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-269
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-18103
Severity: low
Released on: 28/07/2026
Advisory:
Bugzilla: 2508081
Bugzilla Description: dhcp-server: dhcp-server: Persistent denial of service due to buffer overflow via OMAPI
CVSS Score:
CVSSv3 Score: 4.9
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-54620
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2508116
Bugzilla Description: sqlite3-ruby: sqlite3: sqlite3-ruby: Use-After-Free vulnerability in SQLite aggregate function callbacks
CVSS Score:
CVSSv3 Score: 4.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-54619
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2508082
Bugzilla Description: sqlite3-ruby: sqlite3: sqlite3-ruby: Use-after-free when redefining SQLite functions with different arity
CVSS Score:
CVSSv3 Score: 4.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-71190
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2503395
Bugzilla Description: openstack-swift: openstack-swift: Unauthenticated denial of service via catastrophic backtracking in Accept header parser
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1333
Affected Packages:
Package States: Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-71191
Severity: important
Released on: 28/07/2026
Advisory:
Bugzilla: 2503670
Bugzilla Description: openstack-swift: openstack-swift: S3API presigned URL unsigned header authorization bypass
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-71192
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2503678
Bugzilla Description: openstack-swift: openstack-swift: S3API cross-tenant object read via Swift-native header injection
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-66299
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2508085
Bugzilla Description: tomcat: Apache Tomcat: Denial of Service via WebSocket chat example
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat JBoss Web Server 5,
Full Details
CVE document


CVE-2026-18201
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2508290
Bugzilla Description: keycloak-services: keycloak-services: Generic identity-provider creation can bind brokers to organizations without manage-organizations
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-6879
Severity: low
Released on: 28/07/2026
Advisory: RHSA-2026:48278, RHSA-2026:48253, RHSA-2026:48238, RHSA-2026:48246, RHSA-2026:48279,
Bugzilla: 2508122
Bugzilla Description: python: Python: Performance degradation in XML processing due to quadratic time complexity
CVSS Score:
CVSSv3 Score: 2.2
Vector:
CWE: CWE-770
Affected Packages: python3-12-main-3.12.13-3.8.hum1,python3-10-main-3.10.20-3.2.hum1,python3-14-main-3.14.6-2.2.hum1,python3-13-main-3.13.14-1.7.hum1,python3-11-main-3.11.15-5.5.hum1,
Package States:
Full Details
CVE document


CVE-2026-18203
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2508291
Bugzilla Description: keycloak-services: keycloak-services: Group policy extendChildren matches sibling group path prefixes
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18206
Severity: low
Released on: 28/07/2026
Advisory:
Bugzilla: 2508292
Bugzilla Description: keycloak-services: keycloak-services: Client policy source-host wildcard domain matching bypass
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-20
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18207
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla:
Bugzilla Description:
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-285
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18208
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2508304
Bugzilla Description: keycloak-services: keycloak-services: Inactive out-of-audience token introspection leaks signed JWT claim
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18209
Severity: low
Released on: 28/07/2026
Advisory:
Bugzilla: 2508305
Bugzilla Description: keycloak-services: keycloak-services: OIDC redirect_uri fragment bypass in HTTP parameter pollution check
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-1288
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18211
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2508306
Bugzilla Description: keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-20
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18214
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2508308
Bugzilla Description: keycloak-services: keycloak-services: Google external access-token exchange bypasses hosted-domain restriction
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18215
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2508309
Bugzilla Description: keycloak-services: keycloak-services: Microsoft external access-token exchange bypasses configured tenant
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-287
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18217
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2508311
Bugzilla Description: keycloak-services: keycloak-services: SAML HTTP-Redirect binding response preserves query string leading to parameter pollution
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-20
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-49332
Severity: important
Released on: 28/07/2026
Advisory:
Bugzilla: 2483253
Bugzilla Description: openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on WSGI/PHP upstreams
CVSS Score:
CVSSv3 Score: 8.5
Vector:
CWE: CWE-436
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-18047
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2507956
Bugzilla Description: dogtag-pki: pki-core: redhat-pki: pki: ACME admin enable/disable endpoint authentication bypass via trailing slash
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-288
Affected Packages:
Package States: Red Hat Certificate System 10,Red Hat Certificate System 11,Red Hat Certificate System 9,Red Hat Certificate System 9,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-65624
Severity: important
Released on: 28/07/2026
Advisory: RHSA-2026:47231, RHSA-2026:47236,
Bugzilla: 2507960
Bugzilla Description: cowboy: Cowboy: Denial of Service via HTTP/1.1 duplicate header names
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1050
Affected Packages: rabbitmq-server4-3-main-4.3.4-0.2.hum1,rabbitmq-server4-2-main-4.2.9-0.2.hum1,
Package States:
Full Details
CVE document


CVE-2026-58216
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2502721
Bugzilla Description: samba: kpasswd service: kpasswd packet that contains malformed ASN.1 might cause the server to access 6 bytes of unallocated memory leading server to crash
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-58222
Severity: important
Released on: 28/07/2026
Advisory:
Bugzilla: 2502722
Bugzilla Description: samba: Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-90
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-58221
Severity: important
Released on: 28/07/2026
Advisory:
Bugzilla: 2502726
Bugzilla Description: samba: authenticated LDAP access to internal LDB special DNs permits domain takeover
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-284
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-58218
Severity: moderate
Released on: 28/07/2026
Advisory:
Bugzilla: 2502728
Bugzilla Description: samba: DNS signing DoS via TKEY name cache exhaustion
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-410
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-6949
Severity: important
Released on: 28/07/2026
Advisory:
Bugzilla: 2502730
Bugzilla Description: samba: TSIG packet with crafted name compression can crash DNS server
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-17072
Severity: low
Released on: 28/07/2026
Advisory:
Bugzilla: 2506750
Bugzilla Description: gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_flac_stream_headers when parsing FLAC codec data in Matroska containers
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-59248
Severity: important
Released on: 28/07/2026
Advisory: RHSA-2026:47231, RHSA-2026:47236,
Bugzilla: 2507959
Bugzilla Description: cowlib: Cowlib: Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages: rabbitmq-server4-3-main-4.3.4-0.2.hum1,rabbitmq-server4-2-main-4.2.9-0.2.hum1,
Package States:
Full Details
CVE document


CVE-2026-53669
Severity: moderate
Released on: 27/07/2026
Advisory: RHSA-2026:48780, RHSA-2026:48799,
Bugzilla: 2507843
Bugzilla Description: react-router: React Router: Open Redirect vulnerability via backslashes in navigation components
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-601
Affected Packages: prometheus3-5-main-3.5.5-0.6.hum1,prometheus3-13-main-3.13.1-0.5.hum1,
Package States: Cryostat 4,Cryostat 4,Cryostat 4,Exploit Intelligence,Gatekeeper 3,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Migration Toolkit for Virtualization,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,Network Observability Operator,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 5,Red Hat Ceph Storage 9,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Single Sign-On 7,Red Hat Trusted Artifact Signer,Red Hat Trusted Profile Analyzer,Red Hat Trusted Profile Analyzer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-55685
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507833
Bugzilla Description: react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Cryostat 4,Cryostat 4,Cryostat 4,Exploit Intelligence,Gatekeeper 3,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Migration Toolkit for Virtualization,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,Network Observability Operator,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 5,Red Hat Ceph Storage 9,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Single Sign-On 7,Red Hat Trusted Artifact Signer,Red Hat Trusted Profile Analyzer,Red Hat Trusted Profile Analyzer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-53668
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507837
Bugzilla Description: react-router: react-router-dom: React Router: Cross-Site Scripting (XSS) via open redirects
CVSS Score:
CVSSv3 Score: 6.9
Vector:
CWE: CWE-601
Affected Packages:
Package States: A-MQ Interconnect 1,Cryostat 4,Cryostat 4,Cryostat 4,Cryostat 4,Exploit Intelligence,Gatekeeper 3,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Migration Toolkit for Virtualization,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,Network Observability Operator,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 5,Red Hat Ceph Storage 9,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenStack Platform 17.1,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Single Sign-On 7,Red Hat Single Sign-On 7,Red Hat Trusted Artifact Signer,Red Hat Trusted Profile Analyzer,Red Hat Trusted Profile Analyzer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-53667
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507836
Bugzilla Description: react-router: React Router: Untrusted redirects due to missing protocol validation
CVSS Score:
CVSSv3 Score: 6.9
Vector:
CWE: CWE-601
Affected Packages:
Package States: Cryostat 4,Cryostat 4,Cryostat 4,Exploit Intelligence,Gatekeeper 3,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Migration Toolkit for Virtualization,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,Network Observability Operator,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 5,Red Hat Ceph Storage 9,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Single Sign-On 7,Red Hat Trusted Artifact Signer,Red Hat Trusted Profile Analyzer,Red Hat Trusted Profile Analyzer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-53666
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507839
Bugzilla Description: react-router: React Router: Information disclosure via client-side constructor execution
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-502
Affected Packages:
Package States: Cryostat 4,Cryostat 4,Cryostat 4,Exploit Intelligence,Gatekeeper 3,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Migration Toolkit for Virtualization,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,Network Observability Operator,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 5,Red Hat Ceph Storage 9,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Single Sign-On 7,Red Hat Trusted Artifact Signer,Red Hat Trusted Profile Analyzer,Red Hat Trusted Profile Analyzer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-64649
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507639
Bugzilla Description: next: Next.js: Server-Side Request Forgery via malicious host redirection in Server Actions
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Trusted Artifact Signer,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-64648
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507642
Bugzilla Description: next: Next.js: Information disclosure via server-side fetch cache
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-524
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Trusted Artifact Signer,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-64647
Severity: low
Released on: 27/07/2026
Advisory:
Bugzilla: 2507640
Bugzilla Description: next: Next.js: Information disclosure via server-side request caching
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-524
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Trusted Artifact Signer,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-12383
Severity: important
Released on: 27/07/2026
Advisory: RHSA-2026:50340, RHSA-2026:50319, RHSA-2026:50336,
Bugzilla: 2489127
Bugzilla Description: eda-server: ExternalEventStreamViewSet trusts Subject header without validation and leaks expected DN
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-345
Affected Packages: automation-eda-controller-0:1.2.11-1.el9ap,ansible-automation-platform-27/eda-controller-rhel9:1785374869,automation-eda-controller-0:1.1.21-1.el9ap,automation-eda-controller-0:1.1.21-1.el8ap,
Package States:
Full Details
CVE document


CVE-2026-64646
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507643
Bugzilla Description: next: Next.js: Denial of Service via excessive memory consumption in Server Actions
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Trusted Artifact Signer,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-64644
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507624
Bugzilla Description: next: Next.js: Denial of Service via malicious image optimization
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Trusted Artifact Signer,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-64643
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507626
Bugzilla Description: next: Next.js: Information disclosure via Server Action ID exposure
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-201
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Trusted Artifact Signer,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-64642
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507617
Bugzilla Description: next: Next.js: Authentication bypass leading to unauthorized access
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-807
Affected Packages:
Package States: Cryostat 4,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat AMQ Broker 7,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Openshift Data Foundation 4,Red Hat Single Sign-On 7,Red Hat Trusted Artifact Signer,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-64641
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507613
Bugzilla Description: next: Next.js: Denial of Service via crafted requests to App Router with Server Actions
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Cryostat 4,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat AMQ Broker 7,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Openshift Data Foundation 4,Red Hat Single Sign-On 7,Red Hat Trusted Artifact Signer,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-64645
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507618
Bugzilla Description: next: Next.js: Server-Side Request Forgery vulnerability
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Trusted Artifact Signer,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-45623
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507595
Bugzilla Description: postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-22
Affected Packages:
Package States: Cryostat 4,Cryostat 4,Cryostat 4,Gatekeeper 3,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat 3scale API Management Platform 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat Build of Podman Desktop,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Virtualization 4,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Single Sign-On 7,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-54272
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507593
Bugzilla Description: ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification
CVSS Score:
CVSSv3 Score: 7.2
Vector:
CWE: CWE-918
Affected Packages:
Package States: Confidential Compute Attestation,Cryostat 4,Cryostat 4,Cryostat 4,Exploit Intelligence,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat Build of Podman Desktop,Red Hat Connectivity Link 1,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Satellite 6,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-54890
Severity: important
Released on: 27/07/2026
Advisory: RHSA-2026:47009,
Bugzilla: 2507571
Bugzilla Description: erlang/otp: erts: otp: Erlang/OTP: Denial of Service via integer underflow in ETF decoding
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-191
Affected Packages: erlang27-main-27.3.4.15-0.1.hum1,
Package States:
Full Details
CVE document


CVE-2026-59251
Severity: important
Released on: 27/07/2026
Advisory: RHSA-2026:47009,
Bugzilla: 2507572
Bugzilla Description: Erlang/OTP: public_key: Erlang/OTP public_key: Denial of Service via crafted TLS certificate chains
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages: erlang27-main-27.3.4.15-0.1.hum1,
Package States:
Full Details
CVE document


CVE-2026-55953
Severity: important
Released on: 27/07/2026
Advisory: RHSA-2026:47009,
Bugzilla: 2507558
Bugzilla Description: erlang/otp: Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-940
Affected Packages: erlang27-main-27.3.4.15-0.1.hum1,
Package States: Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-55737
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507544
Bugzilla Description: erlang-otp: Erlang OTP: Denial of Service via crafted external term format binary
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-17574
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507552
Bugzilla Description: HDF5: HDF5: Denial of Service via crafted HDF5 file processing
CVSS Score:
CVSSv3 Score: 5.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-17573
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507553
Bugzilla Description: hdf5: HDF5 library: Denial of Service via crafted HDF5 file processing
CVSS Score:
CVSSv3 Score: 5.0
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-17572
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507561
Bugzilla Description: hdf5: HDF5: Denial of Service via crafted file requiring user interaction
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-47078
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507547
Bugzilla Description: otp: Erlang OTP: Arbitrary file write via relative path traversal in zip module
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat Hardened Images,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-42792
Severity: important
Released on: 27/07/2026
Advisory: RHSA-2026:47009,
Bugzilla: 2507551
Bugzilla Description: erlang-otp: epmd: Erlang OTP epmd: Remote Denial of Service via connection exhaustion
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-253
Affected Packages: erlang27-main-27.3.4.15-0.1.hum1,
Package States:
Full Details
CVE document


CVE-2026-15003
Severity: moderate
Released on: 27/07/2026
Advisory: RHSA-2026:47171,
Bugzilla: 2497805
Bugzilla Description: binutils: GNU Binutils: Heap-buffer-overflow in linker leads to information disclosure and denial of service
CVSS Score:
CVSSv3 Score: 5.6
Vector:
CWE: CWE-125
Affected Packages: binutils-main-2.46.1-1.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-17513
Severity: low
Released on: 27/07/2026
Advisory:
Bugzilla: 2507471
Bugzilla Description: whisper.cpp: whisper.cpp: Denial of Service via ftype argument manipulation
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-617
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-17512
Severity: low
Released on: 27/07/2026
Advisory:
Bugzilla: 2507460
Bugzilla Description: whisper.cpp: whisper.cpp: Information disclosure via out-of-bounds read
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-125
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-66053
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507445
Bugzilla Description: thrift: Apache Thrift Python bindings: Information disclosure due to improper certificate validation
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-295
Affected Packages:
Package States: Confidential Compute Attestation,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Update Service,
Full Details
CVE document


CVE-2026-58023
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507440
Bugzilla Description: thrift: Apache Thrift: Information disclosure and denial of service due to out-of-bounds read
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Confidential Compute Attestation,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Update Service,
Full Details
CVE document


CVE-2026-55971
Severity: important
Released on: 27/07/2026
Advisory: RHSA-2026:49716, RHSA-2026:49715, RHSA-2026:51358,
Bugzilla: 2507448
Bugzilla Description: thrift: Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow
CVSS Score:
CVSSv3 Score: 8.4
Vector:
CWE: CWE-122
Affected Packages: thrift-0:0.24.0-1.el9ai,thrift-0:0.24.0-2.el9ai,
Package States: Confidential Compute Attestation,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Update Service,
Full Details
CVE document


CVE-2026-55970
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507438
Bugzilla Description: thrift: Apache Thrift C++ bindings: Information disclosure due to buffer over-read vulnerability
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Confidential Compute Attestation,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Update Service,
Full Details
CVE document


CVE-2026-55969
Severity: important
Released on: 27/07/2026
Advisory: RHSA-2026:46989, RHSA-2026:46974, RHSA-2026:46987,
Bugzilla: 2507433
Bugzilla Description: thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-190
Affected Packages: jaeger-main-2.20.0-0.5.hum1,tempo2-10-main-2.10.7-0.2.hum1,tempo3-0-main-3.0.2-0.2.hum1,
Package States: Confidential Compute Attestation,Cryostat 4,Multicluster Global Hub,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift Update Service,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-55968
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507437
Bugzilla Description: thrift: Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Confidential Compute Attestation,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Update Service,
Full Details
CVE document


CVE-2026-49158
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507435
Bugzilla Description: thrift: Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-409
Affected Packages:
Package States: Confidential Compute Attestation,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Update Service,
Full Details
CVE document


CVE-2026-48586
Severity: important
Released on: 27/07/2026
Advisory: RHSA-2026:43799, RHSA-2026:46989, RHSA-2026:43581, RHSA-2026:45780, RHSA-2026:46931, RHSA-2026:46974, RHSA-2026:46987,
Bugzilla: 2507434
Bugzilla Description: thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-409
Affected Packages: opentelemetry-collector-main-0.157.0-0.1.hum1,jaeger-main-2.20.0-0.5.hum1,loki3-7-main-3.7.4-0.1.hum1,jaeger-main-2.20.0-0.4.hum1,tempo2-10-main-2.10.7-0.2.hum1,opentelemetry-collector-contrib-main-0.157.0-0.1.hum1,tempo3-0-main-3.0.2-0.2.hum1,
Package States: Confidential Compute Attestation,Cryostat 4,Multicluster Global Hub,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift Update Service,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-48145
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507431
Bugzilla Description: apache-thrift: Apache Thrift: Information disclosure due to improper certificate validation
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-297
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,
Full Details
CVE document


CVE-2026-45112
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507439
Bugzilla Description: thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Confidential Compute Attestation,Cryostat 4,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Connectivity Link 1,Red Hat Data Grid 8,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Update Service,
Full Details
CVE document


CVE-2026-43871
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507441
Bugzilla Description: thrift: Apache Thrift: Denial of Service via infinite loop
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Confidential Compute Attestation,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Update Service,
Full Details
CVE document


CVE-2026-41608
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507442
Bugzilla Description: thrift: Apache Thrift Python bindings: Denial of Service via data amplification
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-409
Affected Packages:
Package States: Confidential Compute Attestation,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Update Service,
Full Details
CVE document


CVE-2026-16554
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507414
Bugzilla Description: cJSON: cJSON: Remote code execution due to integer overflow via crafted JSON
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 8,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-64535
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507404
Bugzilla Description: kernel: nvmet-tcp: Fix potential UAF when ddgst mismatch
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux for NVIDIA 26,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-15928
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507394
Bugzilla Description: xmlrpc-c: XMLRPC-C Library: Cross-Site Scripting in error page component
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-79
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-17501
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507392
Bugzilla Description: llama.cpp: llama.cpp: Denial of Service due to resource allocation manipulation in JSON-Schema-to-GBNF Conversion
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-1050
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-64534
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507399
Bugzilla Description: kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64533
Severity:
Released on: 27/07/2026
Advisory:
Bugzilla: 2507401
Bugzilla Description: kernel: fs/ntfs3: validate lcns_follow in log_replay conversion
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64531
Severity: important
Released on: 27/07/2026
Advisory: RHSA-2026:51603, RHSA-2026:51604,
Bugzilla: 2507402
Bugzilla Description: kernel: net: openvswitch: reject oversized nested action attrs
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-130
Affected Packages: kernel-rt-0:5.14.0-284.186.1.rt14.471.el9_2,kernel-0:5.14.0-284.186.1.el9_2,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-64536
Severity:
Released on: 27/07/2026
Advisory:
Bugzilla: 2507403
Bugzilla Description: kernel: staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64532
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507406
Bugzilla Description: kernel: fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}
CVSS Score:
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-17527
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507413
Bugzilla Description: virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated ClusterRole grants create on datavolumes/source, allowing unauthorized PVC clone
CVSS Score:
CVSSv3 Score: 7.7
Vector:
CWE: CWE-639
Affected Packages:
Package States: Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,
Full Details
CVE document


CVE-2026-51302
Severity:
Released on: 27/07/2026
Advisory: RHSA-2026:45779,
Bugzilla: 2507543
Bugzilla Description: sqlite: SQLite: Arbitrary code execution via malicious SQL statement
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages: sqlite-main-3.53.4-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-51296
Severity:
Released on: 27/07/2026
Advisory:
Bugzilla: 2507546
Bugzilla Description: sqlite: SQLite: Use-after-free vulnerability leads to denial of service and information disclosure
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-51297
Severity:
Released on: 27/07/2026
Advisory: RHSA-2026:45779,
Bugzilla: 2507548
Bugzilla Description: sqlite: sqlite: Arbitrary code execution via use-after-free in JSON parsing
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages: sqlite-main-3.53.4-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-51300
Severity:
Released on: 27/07/2026
Advisory:
Bugzilla: 2507549
Bugzilla Description: sqlite: SQLite: Application crash and information leakage due to use-after-free
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-51303
Severity:
Released on: 27/07/2026
Advisory:
Bugzilla: 2507555
Bugzilla Description: sqlite: SQLite: Arbitrary code execution via specially crafted SQL queries
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-51298
Severity: moderate
Released on: 27/07/2026
Advisory: RHSA-2026:45779,
Bugzilla: 2507556
Bugzilla Description: sqlite: SQLite: Denial of Service via use-after-free in JSON extraction
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages: sqlite-main-3.53.4-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-51304
Severity:
Released on: 27/07/2026
Advisory: RHSA-2026:45779,
Bugzilla: 2507560
Bugzilla Description: sqlite: sqlite: Arbitrary code execution via malicious SQL statement
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages: sqlite-main-3.53.4-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-51235
Severity: important
Released on: 27/07/2026
Advisory: RHSA-2026:51105,
Bugzilla: 2507594
Bugzilla Description: LibRaw: LibRaw: Buffer Overflow vulnerability in image processing
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-120
Affected Packages: LibRaw-0:0.21.1-2.el9_8.1,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-64553
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507720
Bugzilla Description: kernel: net: psample: fix info leak in PSAMPLE_ATTR_DATA
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-212
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64541
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507721
Bugzilla Description: kernel: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64552
Severity: important
Released on: 27/07/2026
Advisory:
Bugzilla: 2507729
Bugzilla Description: kernel: virtio-net: fix len check in receive_big()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64551
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507746
Bugzilla Description: kernel: sctp: validate STALE_COOKIE cause length before reading staleness
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64554
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507747
Bugzilla Description: kernel: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64544
Severity: low
Released on: 27/07/2026
Advisory:
Bugzilla: 2507766
Bugzilla Description: kernel: crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64550
Severity:
Released on: 27/07/2026
Advisory:
Bugzilla: 2507767
Bugzilla Description: kernel: net: qualcomm: rmnet: validate MAP frame length before ingress parsing
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64543
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507768
Bugzilla Description: kernel: tipc: fix use-after-free of the discoverer in tipc_disc_rcv()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64537
Severity: low
Released on: 27/07/2026
Advisory:
Bugzilla: 2507777
Bugzilla Description: kernel: bridge: cfm: reject invalid CCM interval at configuration time
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64545
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507787
Bugzilla Description: kernel: net, bpf: check master for NULL in xdp_master_redirect()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64539
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507790
Bugzilla Description: kernel: Bluetooth: eir: Fix stack OOB write when prepending the Flags AD
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64548
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507793
Bugzilla Description: kernel: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64547
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507794
Bugzilla Description: kernel: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64549
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507795
Bugzilla Description: kernel: Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64555
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507799
Bugzilla Description: kernel: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-681
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64540
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507802
Bugzilla Description: kernel: usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64542
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507809
Bugzilla Description: kernel: ipv6: ndisc: fix NULL deref in accept_untracked_na()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64546
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507814
Bugzilla Description: kernel: drm/edid: fix OOB read in drm_parse_tiled_block()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64538
Severity: moderate
Released on: 27/07/2026
Advisory:
Bugzilla: 2507822
Bugzilla Description: kernel: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change()
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux for NVIDIA 26,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2024-14040
Severity: moderate
Released on: 26/07/2026
Advisory:
Bugzilla: 2507346
Bugzilla Description: kernel: net: nexthop: Increase weight to u16
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-66011
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507302
Bugzilla Description: Imagemagick: ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-66373
Severity: important
Released on: 25/07/2026
Advisory: RHSA-2026:43236,
Bugzilla: 2506985
Bugzilla Description: redis: Redis: Remote Code Execution via specially crafted RESTORE payload
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1341
Affected Packages: valkey-main-9.0.5-0.1.hum1,
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64326
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507027
Bugzilla Description: kernel: block: skip sync_blockdev() on surprise removal in bdev_mark_dead()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-390
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-64332
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507028
Bugzilla Description: kernel: USB: ulpi: fix memory leak on registration failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-64524
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507029
Bugzilla Description: kernel: drm/hyperv: validate resolution_count and fix WIN8 fallback
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64441
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507030
Bugzilla Description: kernel: staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64355
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507031
Bugzilla Description: kernel: bpf: Reject fragmented frames in devmap
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64278
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507032
Bugzilla Description: kernel: i2c: imx-lpi2c: mark I2C adapter when hardware is powered down
CVSS Score:
Vector:
CWE: CWE-820
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-64448
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507033
Bugzilla Description: kernel: smb: client: restrict implied bcc[0] exemption to responses without data area
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64369
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507034
Bugzilla Description: kernel: s390: Revert support for DCACHE_WORD_ACCESS
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-64385
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507035
Bugzilla Description: kernel: smb: client: fix double-free in SMB2_ioctl() replay
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64281
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507036
Bugzilla Description: kernel: svcrdma: wake sq waiters when the transport closes
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64396
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507037
Bugzilla Description: kernel: ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64481
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507038
Bugzilla Description: kernel: ALSA: hda/cs35l41: Fix firmware load work teardown
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64260
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507039
Bugzilla Description: kernel: fuse-uring: Avoid queue->stopped races and set/read that value under lock
CVSS Score:
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64300
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507040
Bugzilla Description: kernel: perf/aux: Fix page UAF in map_range()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64265
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507041
Bugzilla Description: kernel: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64382
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507042
Bugzilla Description: kernel: smb: client: fix double-free in SMB2_open() replay
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64435
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507043
Bugzilla Description: kernel: audit: Fix data races of skb_queue_len() readers on audit_queue
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-820
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64502
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507044
Bugzilla Description: kernel: iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64482
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507045
Bugzilla Description: kernel: ALSA: gus: check snd_ctl_new1() return value
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64387
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507046
Bugzilla Description: kernel: smb: client: fix query directory replay double-free
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64318
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507047
Bugzilla Description: kernel: partitions: aix: bound the pp_count scan to the ppe array
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64359
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507048
Bugzilla Description: kernel: nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
CVSS Score:
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64308
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507049
Bugzilla Description: kernel: crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD)
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-909
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64415
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507050
Bugzilla Description: kernel: mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64458
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507051
Bugzilla Description: kernel: mm/damon/ops-common: handle extreme intervals in damon_hot_score()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64484
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507052
Bugzilla Description: kernel: ALSA: es1938: check snd_ctl_new1() return value
CVSS Score:
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64270
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507053
Bugzilla Description: kernel: Input: mms114 - reject an oversized device packet size
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64323
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507054
Bugzilla Description: kernel: udf: validate VAT header length against the VAT inode size
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64336
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507055
Bugzilla Description: kernel: USB: serial: keyspan_pda: fix information leak
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64497
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507056
Bugzilla Description: kernel: iio: chemical: scd30: Cleanup initializations and fix sign-extension bug
CVSS Score:
Vector:
CWE: CWE-681
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64317
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507057
Bugzilla Description: kernel: isofs: bound Rock Ridge symlink components to the SL record
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64360
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507058
Bugzilla Description: kernel: hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64358
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507059
Bugzilla Description: kernel: media: mtk-jpeg: cancel workqueue on release for supported platforms only
CVSS Score:
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64370
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507060
Bugzilla Description: kernel: posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64320
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507061
Bugzilla Description: kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64388
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507062
Bugzilla Description: kernel: smb/client: fix chown/chgrp with SMB3 POSIX Extensions
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-279
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64463
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507063
Bugzilla Description: kernel: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-459
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64416
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507064
Bugzilla Description: kernel: mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64489
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507065
Bugzilla Description: kernel: ALSA: ymfpci: check snd_ctl_new1() return value
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64256
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507066
Bugzilla Description: kernel: xfs: don't wrap around quota ids in dqiterate
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64521
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507067
Bugzilla Description: kernel: pinctrl: meson: amlogic-a4: fix deadlock issue
CVSS Score:
Vector:
CWE: CWE-764
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64272
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507068
Bugzilla Description: kernel: Input: mms114 - fix touch indexing for MMS134S and MMS136
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64443
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507069
Bugzilla Description: kernel: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64447
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507070
Bugzilla Description: kernel: staging: media: ipu7: fix double-free and use-after-free in error paths
CVSS Score:
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64327
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507071
Bugzilla Description: kernel: usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64333
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507072
Bugzilla Description: kernel: USB: serial: digi_acceleport: fix write buffer corruption
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64510
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507073
Bugzilla Description: kernel: ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64258
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507074
Bugzilla Description: kernel: fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref
CVSS Score:
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64426
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507075
Bugzilla Description: kernel: io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64391
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507076
Bugzilla Description: kernel: ksmbd: use opener credentials for ADS I/O
CVSS Score:
Vector:
CWE: CWE-250
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64527
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507077
Bugzilla Description: kernel: drm/hyperv: validate VMBus packet size in receive callback
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64347
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507078
Bugzilla Description: kernel: usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64267
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507079
Bugzilla Description: kernel: fuse: avoid 32-bit prune notification count wrap
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64528
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507080
Bugzilla Description: kernel: tty: serial: samsung: Remove redundant port lock acquisition in rx helpers
CVSS Score:
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64399
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507081
Bugzilla Description: kernel: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
CVSS Score:
Vector:
CWE: CWE-250
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64392
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507082
Bugzilla Description: kernel: ksmbd: use opener credentials for delete-on-close
CVSS Score:
Vector:
CWE: CWE-270
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64329
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507083
Bugzilla Description: kernel: usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64453
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507084
Bugzilla Description: kernel: usb: misc: usbio: fix disconnect UAF in client teardown
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64313
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507085
Bugzilla Description: kernel: crypto: ecc - Fix carry overflow in vli multiplication
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64487
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507086
Bugzilla Description: kernel: ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64488
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507087
Bugzilla Description: kernel: ALSA: aoa: check snd_ctl_new1() return value
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64468
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507088
Bugzilla Description: kernel: binder: fix UAF in binder_free_transaction()
CVSS Score:
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64268
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507089
Bugzilla Description: kernel: RDMA/siw: bound Read Response placement to the RREAD length
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64307
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507090
Bugzilla Description: kernel: crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG)
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-455
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64310
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507091
Bugzilla Description: kernel: crypto: ccp - Do not initialize SNP for SEV ioctls
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-909
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64471
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507092
Bugzilla Description: kernel: Bluetooth: btusb: fix use-after-free on registration failure
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64526
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507093
Bugzilla Description: kernel: ethtool: tsconfig: fix missing ethnl_ops_complete()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-459
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64473
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507094
Bugzilla Description: kernel: vfio: Remove device debugfs before releasing devres
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64460
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507095
Bugzilla Description: kernel: PCI/IOV: Skip VF Resizable BAR restore on read error
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64319
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507096
Bugzilla Description: kernel: nvmet-auth: validate reply message payload bounds against transfer length
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64411
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507097
Bugzilla Description: kernel: netfilter: ebtables: terminate table name before find_table_lock()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64266
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507098
Bugzilla Description: kernel: fuse: re-lock request before returning from fuse_ref_folio()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64412
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507099
Bugzilla Description: kernel: netfilter: ebtables: module names must be null-terminated
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64476
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507100
Bugzilla Description: kernel: vfio/pci: Latch disable_idle_d3 per device
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64289
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507101
Bugzilla Description: kernel: iommufd: Set upper bounds on cache invalidation entry_num and entry_len
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-606
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64414
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507102
Bugzilla Description: kernel: netfilter: handle unreadable frags
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-390
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64465
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507103
Bugzilla Description: kernel: usb: xhci: Fix sleep in atomic context in xhci_free_streams()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64469
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507104
Bugzilla Description: kernel: binder: fix UAF in binder_thread_release()
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64407
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507105
Bugzilla Description: kernel: Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64504
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507107
Bugzilla Description: kernel: iio: accel: bmc150: clamp the device-reported FIFO frame count
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64381
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507108
Bugzilla Description: kernel: smb: client: Fix next buffer leak in receive_encrypted_standard()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64455
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507109
Bugzilla Description: kernel: USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64413
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507110
Bugzilla Description: kernel: netfilter: ebtables: zero chainstack array
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64408
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507111
Bugzilla Description: kernel: Bluetooth: bnep: pin L2CAP connection during netdev registration
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64389
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507112
Bugzilla Description: kernel: ksmbd: validate NTLMv2 response before updating session key
CVSS Score:
Vector:
CWE: CWE-179
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64390
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507113
Bugzilla Description: kernel: ksmbd: track the connection owning a byte-range lock
CVSS Score:
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64470
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507114
Bugzilla Description: kernel: Bluetooth: btusb: fix use-after-free on marvell probe failure
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64501
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507115
Bugzilla Description: kernel: iio: adc: ad_sigma_delta: fix CS held asserted and state leaks
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64513
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507116
Bugzilla Description: kernel: KVM: x86: Unconditionally recompute CR8 intercept on PPR update
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64335
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507117
Bugzilla Description: kernel: USB: serial: digi_acceleport: fix broken rx after throttle
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64438
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507118
Bugzilla Description: kernel: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64304
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507119
Bugzilla Description: kernel: crypto: qat - validate RSA CRT component lengths
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64444
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507120
Bugzilla Description: kernel: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64417
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507121
Bugzilla Description: kernel: mm: shrinker: fix NULL pointer dereference in debugfs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64523
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507122
Bugzilla Description: kernel: net/handshake: Take a long-lived file reference at submit
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64286
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507123
Bugzilla Description: kernel: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64498
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507124
Bugzilla Description: kernel: iio: buffer: hw-consumer: free scan_mask on buffer release
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64483
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507125
Bugzilla Description: kernel: ALSA: firewire: isight: bound the sample count to the packet payload
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64282
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507126
Bugzilla Description: kernel: KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64341
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507127
Bugzilla Description: kernel: USB: iowarrior: fix use-after-free on disconnect race
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64284
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507128
Bugzilla Description: kernel: KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64287
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507129
Bugzilla Description: kernel: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64262
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507130
Bugzilla Description: kernel: fuse-uring: end fuse_req on io-uring cancel task work
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64429
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507131
Bugzilla Description: kernel: gpio: eic-sprd: use raw_spinlock_t in the irq startup path
CVSS Score:
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64340
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507132
Bugzilla Description: kernel: USB: legousbtower: fix use-after-free on disconnect race
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64264
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507133
Bugzilla Description: kernel: fuse-uring: fix EFAULT clobber in fuse_uring_commit
CVSS Score:
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64383
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507134
Bugzilla Description: kernel: smb: client: fix double-free in SMB2_flush() replay
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64379
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507135
Bugzilla Description: kernel: smb: client: mask server-provided mode to 07777 in modefromsid
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-279
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64525
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507136
Bugzilla Description: kernel: xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64405
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507137
Bugzilla Description: kernel: Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64301
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507138
Bugzilla Description: kernel: regulator: scmi: fix of_node refcount leak in scmi_regulator_probe()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64420
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507139
Bugzilla Description: kernel: mfd: cros_ec: Delay dev_set_drvdata() until probe success
CVSS Score:
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64450
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507140
Bugzilla Description: kernel: tipc: fix out-of-bounds read in broadcast Gap ACK blocks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64457
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507141
Bugzilla Description: kernel: virtio_pci: fix vq info pointer lookup via wrong index
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64315
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507142
Bugzilla Description: kernel: crypto: caam - use print_hex_dump_devel to guard key hex dumps
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-215
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64274
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507143
Bugzilla Description: kernel: Input: goodix - clamp the device-reported contact count
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64312
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507144
Bugzilla Description: kernel: crypto: pcrypt - restore callback for non-parallel fallback
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64380
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507145
Bugzilla Description: kernel: smb: client: harden POSIX SID length parsing
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64480
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507146
Bugzilla Description: kernel: ALSA: ice1712: check snd_ctl_new1() return value
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64475
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507147
Bugzilla Description: kernel: vfio/pci: Release the VGA arbiter client on register_device() failure
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64371
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507148
Bugzilla Description: kernel: proc: protect ptrace_may_access() with exec_update_lock (part 1)
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64361
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507149
Bugzilla Description: kernel: hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64434
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507150
Bugzilla Description: kernel: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64291
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507151
Bugzilla Description: kernel: iommufd: Set veventq_depth upper bound
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64503
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507152
Bugzilla Description: kernel: iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64508
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507153
Bugzilla Description: kernel: bpf: Support for hardening against JIT spraying
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64419
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507154
Bugzilla Description: kernel: mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64486
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507155
Bugzilla Description: kernel: ALSA: cmipci: check snd_ctl_new1() return value
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64279
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507156
Bugzilla Description: kernel: i2c: core: fix adapter deregistration race
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64446
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507157
Bugzilla Description: kernel: staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
CVSS Score:
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64305
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507158
Bugzilla Description: kernel: crypto: qat - protect service table iterations with service_lock
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64330
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507159
Bugzilla Description: kernel: usb: typec: tcpm: Validate SVID index in svdm_consume_modes()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64422
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507160
Bugzilla Description: kernel: net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64529
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507161
Bugzilla Description: kernel: crypto: qat - remove unused character device and IOCTLs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-749
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64306
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507162
Bugzilla Description: kernel: crypto: drbg - Fix returning success on failure in CTR_DRBG
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64505
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507163
Bugzilla Description: kernel: usb: gadget: function: rndis: add length check for header
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64522
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507164
Bugzilla Description: kernel: net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64428
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507165
Bugzilla Description: kernel: gpio: sch: use raw_spinlock_t in the irq startup path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64257
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507166
Bugzilla Description: kernel: smb: client: reject overlapping data areas in SMB2 responses
CVSS Score:
Vector:
CWE: CWE-130
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64344
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507167
Bugzilla Description: kernel: USB: idmouse: fix use-after-free on disconnect race
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64445
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507168
Bugzilla Description: kernel: staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64302
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507169
Bugzilla Description: kernel: x86/mm: Fix freeing of PMD-sized vmemmap pages
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64404
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507170
Bugzilla Description: kernel: Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64425
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507171
Bugzilla Description: kernel: io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
CVSS Score:
Vector:
CWE: CWE-1050
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64519
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507172
Bugzilla Description: kernel: NFSD: Fix infinite loop in layout state revocation
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64430
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507173
Bugzilla Description: kernel: NTB: epf: Avoid calling pci_irq_vector() from hardirq context
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64295
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507174
Bugzilla Description: kernel: mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN access
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64288
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507175
Bugzilla Description: kernel: KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64343
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507176
Bugzilla Description: kernel: USB: ldusb: fix use-after-free on disconnect race
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64374
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507177
Bugzilla Description: kernel: sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64492
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507178
Bugzilla Description: kernel: iio: temperature: tmp006: use devm_iio_trigger_register
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64263
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507179
Bugzilla Description: kernel: fuse-uring: fix moving cancelled entry to ent_in_userspace list
CVSS Score:
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64410
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507180
Bugzilla Description: kernel: netfilter: flowtable: IPIP tunnel hardware offload is not yet support
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-166
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64436
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507181
Bugzilla Description: kernel: net: af_key: initialize alg_key_len for IPComp states
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64506
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507182
Bugzilla Description: kernel: wifi: rtw89: correct drop logic for malformed AMPDU frames
CVSS Score:
Vector:
CWE: CWE-841
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64518
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507183
Bugzilla Description: kernel: tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key()
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64375
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507184
Bugzilla Description: kernel: proc: protect ptrace_may_access() with exec_update_lock (FD links)
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64461
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507185
Bugzilla Description: kernel: PCI: mediatek: Fix IRQ domain leak when port fails to enable
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64491
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507186
Bugzilla Description: kernel: ALSA: usx2y: us144mkii: fix work UAF on disconnect
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64348
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507187
Bugzilla Description: kernel: usb: free iso schedules on failed submit
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64338
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507188
Bugzilla Description: kernel: USB: misc: uss720: unregister parport on probe failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64334
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507189
Bugzilla Description: kernel: USB: serial: digi_acceleport: fix hard lockup on disconnect
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64511
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507190
Bugzilla Description: kernel: ACPI: NFIT: core: Fix possible NULL pointer dereference
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64372
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507191
Bugzilla Description: kernel: cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64280
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507192
Bugzilla Description: kernel: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64496
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507193
Bugzilla Description: kernel: iio: event: Fix event FIFO reset race
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64400
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507194
Bugzilla Description: kernel: ksmbd: prevent path traversal bypass by restricting caseless retry
CVSS Score:
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64357
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507195
Bugzilla Description: kernel: xfs: fix exchmaps reservation limit check
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64275
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507196
Bugzilla Description: kernel: Input: elan_i2c - prevent division by zero and arithmetic underflow
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64466
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507197
Bugzilla Description: kernel: rust_binder: clear freeze listener on node removal
CVSS Score:
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64316
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507198
Bugzilla Description: kernel: crypto: caam - use print_hex_dump_devel to guard key hex dumps
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64273
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507199
Bugzilla Description: kernel: Input: iforce - bound the device-reported force-feedback effect index
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64500
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507200
Bugzilla Description: kernel: iio: adc: lpc32xx: Initialize completion before requesting IRQ
CVSS Score:
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64464
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507201
Bugzilla Description: kernel: xhci: sideband: fix ring sg table pages leak
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64356
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507202
Bugzilla Description: kernel: xfs: fix memory leak in xfs_dqinode_metadir_create()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64294
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507203
Bugzilla Description: kernel: mm: do file ownership checks with the proper mount idmap
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-283
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64467
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507204
Bugzilla Description: kernel: rust_binder: use a u64 stride when cleaning up the offsets array
CVSS Score:
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64376
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507205
Bugzilla Description: kernel: firmware_loader: fix device reference leak in firmware_upload_register()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64454
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507206
Bugzilla Description: kernel: usb: dwc3: run gadget disconnect from sleepable suspend context
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64472
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507207
Bugzilla Description: kernel: vfio/mlx5: Fix racy bitfields and tighten struct layout
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64298
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507208
Bugzilla Description: kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-358
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64423
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507209
Bugzilla Description: kernel: ipv4: igmp: remove multicast group from hash table on device destruction
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64478
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507210
Bugzilla Description: kernel: ALSA: usb-audio: avoid kobject path lookup in DualSense match
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64495
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507211
Bugzilla Description: kernel: iio: gyro: bmg160: bail out when bandwidth/filter is not in table
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64494
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507212
Bugzilla Description: kernel: iio: light: gp2ap002: fix runtime PM leak on read error
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64368
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507213
Bugzilla Description: kernel: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64402
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507214
Bugzilla Description: kernel: coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64517
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507215
Bugzilla Description: kernel: drm/xe/gsc: Fix double-free of managed BO in error path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64386
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507216
Bugzilla Description: kernel: smb: client: fix query_info() replay double-free
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64394
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507217
Bugzilla Description: kernel: ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY
CVSS Score:
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64507
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507218
Bugzilla Description: kernel: x86/bugs: Enable IBPB flush on BPF JIT allocation
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-515
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64514
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507219
Bugzilla Description: kernel: userfaultfd: gate must_wait writability check on pte_present()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64364
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507220
Bugzilla Description: kernel: HID: multitouch: fix out-of-bounds bit access on mt_io_flags
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64462
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507221
Bugzilla Description: kernel: PCI: altera: Fix resource leaks on probe failure
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64303
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507222
Bugzilla Description: kernel: spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64311
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507223
Bugzilla Description: kernel: crypto: loongson - Remove broken and unused loongson-rng
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64345
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507224
Bugzilla Description: kernel: usb: gadget: f_printer: take kref only for successful open
CVSS Score:
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64271
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507225
Bugzilla Description: kernel: Input: touchwin - reset the packet index on every complete packet
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64283
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507226
Bugzilla Description: kernel: KVM: guest_memfd: Treat memslot binding offset+size as unsigned values
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64299
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507227
Bugzilla Description: kernel: tracing: Prevent out-of-bounds read in glob matching
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64353
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507228
Bugzilla Description: kernel: bpf: Keep dynamic inner array lookups nullable
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64339
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507229
Bugzilla Description: kernel: usb: misc: usbio: bound bulk IN response length to the received transfer
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64337
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507230
Bugzilla Description: kernel: usb: mtu3: unmap request DMA on queue failure
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64367
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507231
Bugzilla Description: kernel: HID: hid-goodix-spi: validate report size to prevent stack buffer overflow
CVSS Score:
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64432
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507232
Bugzilla Description: kernel: fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64449
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507233
Bugzilla Description: kernel: staging: vme_user: bound slave read/write to the kern_buf size
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64439
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507234
Bugzilla Description: kernel: crypto: krb5 - filter out async aead implementations at alloc
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64516
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507235
Bugzilla Description: kernel: drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64401
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507236
Bugzilla Description: kernel: smb: client: resolve SWN tcon from live registrations
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64421
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507237
Bugzilla Description: kernel: media: nxp: imx8-isi: Fix use-after-free on remove
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64324
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507238
Bugzilla Description: kernel: udf: validate free block extents against the partition length
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1285
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64297
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507239
Bugzilla Description: kernel: module: decompress: check return value of module_extend_max_pages()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64365
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507240
Bugzilla Description: kernel: HID: letsketch: fix UAF on inrange_timer at driver unbind
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64292
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507241
Bugzilla Description: kernel: iommufd: Move vevent memory allocation outside spinlock
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64403
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507242
Bugzilla Description: kernel: Bluetooth: L2CAP: validate option length before reading conf opt value
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64409
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507243
Bugzilla Description: kernel: Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64352
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507244
Bugzilla Description: kernel: bpf: Allow LPM map access from sleepable BPF programs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64493
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507245
Bugzilla Description: kernel: iio: pressure: mpl115: fix runtime PM leak on read error
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64328
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507246
Bugzilla Description: kernel: usb: gadget: f_fs: Fix DMA fence leak
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64520
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507247
Bugzilla Description: kernel: firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64259
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507248
Bugzilla Description: kernel: fuse-uring: make a fuse_req on SQE commit only findable after memcpy
CVSS Score:
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64322
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507249
Bugzilla Description: kernel: udf: validate sparing table length as an entry count, not a byte count
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64474
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507250
Bugzilla Description: kernel: vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64499
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507251
Bugzilla Description: kernel: iio: adc: ti-ads1119: fix PM reference leak in buffer preenable
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64366
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507252
Bugzilla Description: kernel: HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64440
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507253
Bugzilla Description: kernel: staging: rtl8723bs: fix OOB write in HT_caps_handler()
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64269
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507254
Bugzilla Description: kernel: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64456
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507255
Bugzilla Description: kernel: hwrng: virtio: clamp device-reported used.len at copy_data()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64452
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507256
Bugzilla Description: kernel: 6lowpan: fix NHC entry use-after-free on error path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64285
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507257
Bugzilla Description: kernel: KVM: SEV: Pin source page for write when adding CPUID data for SNP guest
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64342
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507258
Bugzilla Description: kernel: USB: iowarrior: fix use-after-free on disconnect
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64314
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507259
Bugzilla Description: kernel: crypto: chacha20poly1305 - validate poly1305 template argument
CVSS Score:
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64424
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507260
Bugzilla Description: kernel: netpoll: fix a use-after-free on shutdown path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64431
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507261
Bugzilla Description: kernel: ntfs: avoid calling post_write_mst_fixup() for invalid index_block
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64349
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507262
Bugzilla Description: kernel: usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup()
CVSS Score:
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64346
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507263
Bugzilla Description: kernel: usb: gadget: udc: Fix use-after-free in gadget_match_driver
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64293
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507264
Bugzilla Description: kernel: iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64377
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507265
Bugzilla Description: kernel: cpufreq: qcom-cpufreq-hw: Fix possible double free
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64437
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507266
Bugzilla Description: kernel: ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64509
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507267
Bugzilla Description: kernel: rust: block: fix GenDisk cleanup paths
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64362
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507268
Bugzilla Description: kernel: HID: lg-g15: cancel pending work on remove to fix a use-after-free
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64442
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507269
Bugzilla Description: kernel: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()
CVSS Score:
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64393
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507270
Bugzilla Description: kernel: ksmbd: run set info with opener credentials
CVSS Score:
Vector:
CWE: CWE-270
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64373
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507271
Bugzilla Description: kernel: cpufreq: Fix hotplug-suspend race during reboot
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64350
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507272
Bugzilla Description: kernel: usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64398
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507273
Bugzilla Description: kernel: ksmbd: add a permission check for FSCTL_SET_ZERO_DATA
CVSS Score:
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64261
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507274
Bugzilla Description: kernel: fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64351
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507275
Bugzilla Description: kernel: net: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64485
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507276
Bugzilla Description: kernel: ALSA: compress: Fix task creation error unwind
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64490
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507277
Bugzilla Description: kernel: ALSA: virtio: Validate control metadata from the device
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64395
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507278
Bugzilla Description: kernel: ksmbd: require source read access for duplicate extents
CVSS Score:
Vector:
CWE: CWE-358
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64451
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507279
Bugzilla Description: kernel: tracing: Fix NULL pointer dereference in func_set_flag()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64309
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507280
Bugzilla Description: kernel: crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT)
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64363
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507281
Bugzilla Description: kernel: HID: appleir: fix UAF on pending key_up_timer in remove()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64477
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507282
Bugzilla Description: kernel: x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64331
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507283
Bugzilla Description: kernel: usbip: vudc: fix NULL deref in vep_dequeue()
CVSS Score:
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64354
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507284
Bugzilla Description: kernel: bpf: Validate BTF repeated field counts before expansion
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64418
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507285
Bugzilla Description: kernel: mm: shrinker: fix shrinker_info teardown race with expansion
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64290
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507286
Bugzilla Description: kernel: iommufd: Break the loop on failure in iommufd_fault_fops_read()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64384
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507287
Bugzilla Description: kernel: smb: client: fix change notify replay double-free
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64459
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507288
Bugzilla Description: kernel: tcp: restore RCU grace period in tcp_ao_destroy_sock
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64433
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507289
Bugzilla Description: kernel: Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64277
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507290
Bugzilla Description: kernel: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64325
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507291
Bugzilla Description: kernel: wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64515
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507292
Bugzilla Description: kernel: wifi: mac80211: fix MLE defragmentation
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-823
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64406
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507293
Bugzilla Description: kernel: Bluetooth: fix UAF in bt_accept_dequeue()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64427
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507294
Bugzilla Description: kernel: HID: logitech-dj: Fix maxfield check in DJ short report validation
CVSS Score:
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64296
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507295
Bugzilla Description: kernel: exfat: bound uniname advance in exfat_find_dir_entry()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64378
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507296
Bugzilla Description: kernel: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64479
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507297
Bugzilla Description: kernel: ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64512
Severity: low
Released on: 25/07/2026
Advisory:
Bugzilla: 2507298
Bugzilla Description: kernel: ACPI: CPPC: Suppress UBSAN warning caused by field misuse
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1335
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64321
Severity: moderate
Released on: 25/07/2026
Advisory:
Bugzilla: 2507299
Bugzilla Description: kernel: nvme: target: rdma: fix ndev refcount leak on queue connect
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64397
Severity:
Released on: 25/07/2026
Advisory:
Bugzilla: 2507300
Bugzilla Description: kernel: ksmbd: serialize QUERY_DIRECTORY requests per file
CVSS Score:
Vector:
CWE: CWE-562
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64276
Severity: important
Released on: 25/07/2026
Advisory:
Bugzilla: 2507301
Bugzilla Description: kernel: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-66041
Severity: important
Released on: 24/07/2026
Advisory:
Bugzilla: 2506935
Bugzilla Description: ffmpeg: FFmpeg: Arbitrary code execution via crafted PGS/SUP subtitle file
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-66040
Severity: important
Released on: 24/07/2026
Advisory:
Bugzilla: 2506936
Bugzilla Description: ffmpeg: FFmpeg: Arbitrary code execution via crafted PNG image
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-66039
Severity: important
Released on: 24/07/2026
Advisory:
Bugzilla: 2506937
Bugzilla Description: ffmpeg: FFmpeg: Arbitrary code execution via crafted CAF file
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-66038
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506938
Bugzilla Description: FFmpeg: Information disclosure via malformed zlib video stream
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-66037
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506911
Bugzilla Description: FFmpeg: FFmpeg: Denial of Service via uncontrolled resource consumption in IAMF demuxer
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-66036
Severity: important
Released on: 24/07/2026
Advisory:
Bugzilla: 2506909
Bugzilla Description: ffmpeg: FFmpeg: Arbitrary code execution via crafted video in vf_hqdn3d filter
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-17107
Severity: important
Released on: 24/07/2026
Advisory: RHSA-2026:48284, RHSA-2026:47949, RHSA-2026:47974, RHSA-2026:46885, RHSA-2026:47388, RHSA-2026:47735, RHSA-2026:47953,
Bugzilla: 2506771
Bugzilla Description: cluster-proxy: cluster-proxy: Impersonation header injection in service-proxy grants cluster-admin on every managed cluster
CVSS Score:
CVSSv3 Score: 8.5
Vector:
CWE: CWE-441
Affected Packages: multicluster-engine/cluster-proxy-rhel9:1784342329,multicluster-engine/cluster-proxy-rhel9:1783278220,multicluster-engine/cluster-proxy-rhel9:1784925025,multicluster-engine/cluster-proxy-rhel9:1783985960,multicluster-engine/cluster-proxy-rhel9:1784926298,
Package States:
Full Details
CVE document


CVE-2026-66035
Severity: moderate
Released on: 24/07/2026
Advisory: RHSA-2026:46955,
Bugzilla: 2506851
Bugzilla Description: libssh2: libssh2: Arbitrary code execution via heap buffer overflow during SSH negotiation
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-120
Affected Packages: libssh2-main-1.11.1-10.3.hum1,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-66034
Severity: moderate
Released on: 24/07/2026
Advisory: RHSA-2026:46927,
Bugzilla: 2506860
Bugzilla Description: libssh2: libssh2: Information disclosure and potential arbitrary code execution via heap out-of-bounds read
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-125
Affected Packages: libssh2-main-1.11.1-10.2.hum1,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-66033
Severity: moderate
Released on: 24/07/2026
Advisory: RHSA-2026:46927,
Bugzilla: 2506853
Bugzilla Description: libssh2: libssh2: Denial of Service via integer underflow in AES-GCM cipher negotiation
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-125
Affected Packages: libssh2-main-1.11.1-10.2.hum1,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-66032
Severity: moderate
Released on: 24/07/2026
Advisory: RHSA-2026:46927,
Bugzilla: 2506857
Bugzilla Description: libssh2: libssh2: Arbitrary code execution via double-free in SFTP session
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1341
Affected Packages: libssh2-main-1.11.1-10.2.hum1,
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-18218
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2508313
Bugzilla Description: keycloak-services: keycloak-services: Client not-before revocation ignored when realm not-before is older but nonzero
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-17059
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506746
Bugzilla Description: keycloak-services: keycloak-services: Information disclosure via role-users endpoint bypasses per-user view filter
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-639
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-66010
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506731
Bugzilla Description: dompurify: DOMPurify: Cross-Site Scripting (XSS) via custom element attribute bypass
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-79
Affected Packages:
Package States: Cryostat 4,Cryostat 4,Cryostat 4,Migration Toolkit for Virtualization,Multicluster Engine for Kubernetes,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat build of Apicurio Registry 3,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 9,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Self-service automation portal 2,streams for Apache Kafka 2,streams for Apache Kafka 3,
Full Details
CVE document


CVE-2026-56392
Severity: moderate
Released on: 24/07/2026
Advisory: RHBA-2026:47115, RHSA-2026:40724,
Bugzilla: 2506694
Bugzilla Description: coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-787
Affected Packages: coreutils-0:8.30-20.el8_10,coreutils-main-9.11-5.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-56391
Severity: moderate
Released on: 24/07/2026
Advisory: RHSA-2026:46515,
Bugzilla: 2506691
Bugzilla Description: coreutils: GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte input
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-125
Affected Packages: coreutils-main-9.11-5.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-66140
Severity: important
Released on: 24/07/2026
Advisory:
Bugzilla: 2506674
Bugzilla Description: exim: Exim: Privilege escalation via directory traversal due to mishandled queue-name arguments
CVSS Score:
CVSSv3 Score: 8.4
Vector:
CWE: CWE-22
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-66138
Severity: important
Released on: 24/07/2026
Advisory:
Bugzilla: 2506676
Bugzilla Description: ironic-python-agent: OpenStack Ironic Python Agent: Arbitrary code execution via malicious configuration
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-78
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-17039
Severity: low
Released on: 24/07/2026
Advisory:
Bugzilla: 2506720
Bugzilla Description: pki-core: dogtag-pki: redhat-pki: pki-core: CA renewal request processing omits realm authorization check performed by enrollment path
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat Certificate System 10,Red Hat Certificate System 11,Red Hat Certificate System 9,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64227
Severity: low
Released on: 24/07/2026
Advisory:
Bugzilla: 2506775
Bugzilla Description: kernel: ACPI: driver: Check ACPI_COMPANION() against NULL during probe
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux for NVIDIA 26,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-64254
Severity: low
Released on: 24/07/2026
Advisory:
Bugzilla: 2506776
Bugzilla Description: kernel: NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux for NVIDIA 26,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-64212
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506777
Bugzilla Description: kernel: wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64230
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506778
Bugzilla Description: kernel: regulator: tps65219: fix irq_data.rdev not being assigned
CVSS Score:
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux for NVIDIA 26,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-64228
Severity: low
Released on: 24/07/2026
Advisory:
Bugzilla: 2506779
Bugzilla Description: kernel: net: ethtool: phy: avoid NULL deref when PHY driver is unbound
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux for NVIDIA 26,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-64238
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506780
Bugzilla Description: kernel: gpio: shared: fix deadlock on shared proxy's parent removal
CVSS Score:
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux for NVIDIA 26,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-64255
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506782
Bugzilla Description: kernel: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-823
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64209
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506783
Bugzilla Description: kernel: phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config
CVSS Score:
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64215
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506784
Bugzilla Description: kernel: drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table
CVSS Score:
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64218
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506786
Bugzilla Description: kernel: batman-adv: bla: fix report_work leak on backbone_gw purge
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux for NVIDIA 26,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-64226
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506787
Bugzilla Description: kernel: sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64250
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506788
Bugzilla Description: kernel: LoongArch: Report dying CPU to RCU in stop_this_cpu()
CVSS Score:
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64241
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506789
Bugzilla Description: kernel: gpio: rockchip: teardown bugs and resource leaks
CVSS Score:
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64219
Severity: important
Released on: 24/07/2026
Advisory:
Bugzilla: 2506790
Bugzilla Description: kernel: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64232
Severity: low
Released on: 24/07/2026
Advisory:
Bugzilla: 2506791
Bugzilla Description: kernel: block: recompute nr_integrity_segments in blk_insert_cloned_request
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64235
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506792
Bugzilla Description: kernel: x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64237
Severity: low
Released on: 24/07/2026
Advisory:
Bugzilla: 2506793
Bugzilla Description: kernel: Input: elan_i2c - validate firmware size before use
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64229
Severity: low
Released on: 24/07/2026
Advisory:
Bugzilla: 2506795
Bugzilla Description: kernel: x86/mm: Disable broadcast TLB flush when PCID is disabled
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64224
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506796
Bugzilla Description: kernel: octeontx2-pf: fix double free in rvu_rep_rsrc_init()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64247
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506797
Bugzilla Description: kernel: KVM: x86: hyper-v: Bound the bank index when querying sparse banks
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64249
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506798
Bugzilla Description: kernel: fpga: region: fix use-after-free in child_regions_with_firmware()
CVSS Score:
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64213
Severity: low
Released on: 24/07/2026
Advisory:
Bugzilla: 2506799
Bugzilla Description: kernel: hwmon: (lm90) Add lock protection to lm90_alert
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-820
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64214
Severity: low
Released on: 24/07/2026
Advisory:
Bugzilla: 2506800
Bugzilla Description: kernel: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64252
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506801
Bugzilla Description: kernel: MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
CVSS Score:
Vector:
CWE: CWE-823
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64220
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506802
Bugzilla Description: kernel: device property: set fwnode->secondary to NULL in fwnode_init()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64243
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506803
Bugzilla Description: kernel: ASoC: codecs: simple-mux: Fix enum control bounds check
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64217
Severity: important
Released on: 24/07/2026
Advisory:
Bugzilla: 2506805
Bugzilla Description: kernel: netfs: Fix overrun check in netfs_extract_user_iter()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64231
Severity: low
Released on: 24/07/2026
Advisory:
Bugzilla: 2506806
Bugzilla Description: kernel: drm/msm/dsi: don't dump registers past the mapped region
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux for NVIDIA 26,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-64223
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506807
Bugzilla Description: kernel: wifi: mac80211: consume only present negotiated TTLM maps
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64211
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506809
Bugzilla Description: kernel: srcu: Don't queue workqueue handlers to never-online CPUs
CVSS Score:
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64251
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506810
Bugzilla Description: kernel: pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64244
Severity: low
Released on: 24/07/2026
Advisory:
Bugzilla: 2506811
Bugzilla Description: kernel: drivers/base/memory: set mem->altmap after successful device registration
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64221
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506812
Bugzilla Description: kernel: spi: ti-qspi: fix use-after-free after DMA setup failure
CVSS Score:
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64248
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506814
Bugzilla Description: kernel: MIPS: smp: report dying CPU to RCU in stop_this_cpu()
CVSS Score:
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64242
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506815
Bugzilla Description: kernel: usb: gadget: net2280: Fix double free in probe error path
CVSS Score:
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64253
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506816
Bugzilla Description: kernel: kernel/fork: clear PF_BLOCK_TS in copy_process()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-64222
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506817
Bugzilla Description: kernel: octeontx2-pf: avoid double free of pool->stack on AQ init failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64236
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506818
Bugzilla Description: kernel: i2c: davinci: fix division by zero on missing clock-frequency
CVSS Score:
Vector:
CWE: CWE-369
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-64239
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506819
Bugzilla Description: kernel: mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64246
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506821
Bugzilla Description: kernel: power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
CVSS Score:
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64210
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506823
Bugzilla Description: kernel: net/mlx5e: xsk: Fix unlocked writing to ICOSQ
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-820
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64225
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506824
Bugzilla Description: kernel: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux for NVIDIA 26,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-64233
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506825
Bugzilla Description: kernel: usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind
CVSS Score:
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64245
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506826
Bugzilla Description: kernel: fbdev: modedb: fix a possible UAF in fb_find_mode()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64208
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506827
Bugzilla Description: kernel: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64234
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506828
Bugzilla Description: kernel: tty: serial: pch_uart: add check for dma_alloc_coherent()
CVSS Score:
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-64216
Severity: moderate
Released on: 24/07/2026
Advisory:
Bugzilla: 2506830
Bugzilla Description: kernel: netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE:
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-64240
Severity:
Released on: 24/07/2026
Advisory:
Bugzilla: 2506831
Bugzilla Description: kernel: media: rc: igorplugusb: fix control request setup packet
CVSS Score:
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-16805
Severity: important
Released on: 23/07/2026
Advisory:
Bugzilla: 2506639
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Blink
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-16804
Severity: important
Released on: 23/07/2026
Advisory:
Bugzilla: 2506643
Bugzilla Description: chromium-browser: Google Chrome: Sandbox escape via crafted HTML page
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-16807
Severity: important
Released on: 23/07/2026
Advisory:
Bugzilla: 2506636
Bugzilla Description: chromium-browser: Google Chrome Codecs: Sandbox escape via crafted HTML page
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-16806
Severity: important
Released on: 23/07/2026
Advisory:
Bugzilla: 2506637
Bugzilla Description: chromium-browser: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE:
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-65706
Severity: moderate
Released on: 23/07/2026
Advisory:
Bugzilla: 2506586
Bugzilla Description: FFmpeg: FFmpeg: Arbitrary Code Execution via Crafted Video Frame
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-65705
Severity: moderate
Released on: 23/07/2026
Advisory:
Bugzilla: 2506591
Bugzilla Description: FFmpeg: FFmpeg: Arbitrary code execution via out-of-bounds write in vf_floodfill video filter
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document