CVE-2026-92574
Severity: important
Released on: 21/09/2026
Advisory:
Bugzilla: 2535436
Bugzilla Description: cri-o: CRI-O checkpoint restore bypasses destination security context
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-250
Affected Packages:
Package States: Confidential Compute Attestation,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-15801
Severity: important
Released on: 21/09/2026
Advisory:
Bugzilla: 2500823
Bugzilla Description: cri-o: cri-o: Insufficient validation during container checkpoint restore
CVSS Score:
CVSSv3 Score: 8.0
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-94213
Severity: moderate
Released on: 20/09/2026
Advisory:
Bugzilla: 2537310
Bugzilla Description: keycloak-services: keycloak-services: Authorization Services policy evaluation endpoint leaks user identity
CVSS Score:
CVSSv3 Score: 4.9
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-94215
Severity: moderate
Released on: 20/09/2026
Advisory:
Bugzilla: 2537312
Bugzilla Description: keycloak-services: keycloak-services: Cross-realm client read/write via request-level cache missing realm ownership check
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-94217
Severity: moderate
Released on: 19/09/2026
Advisory:
Bugzilla: 2537313
Bugzilla Description: keycloak-services: keycloak-services: UMA scope merge across resource owners via resource name collision
CVSS Score:
CVSSv3 Score: 3.5
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-94218
Severity: low
Released on: 19/09/2026
Advisory:
Bugzilla: 2537314
Bugzilla Description: keycloak-services: keycloak-services: 2FA setup enforcement bypass via authentication session restart endpoint
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-92768
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2469258
Bugzilla Description: cockpit-machines: cockpit-machines: Sensitive data exposure via command-line arguments
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-214
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92747
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2469260
Bugzilla Description: cockpit-machines: cockpit-machines: Sensitive Data Exposure of guest credentials via JSON argument in process list
CVSS Score:
CVSSv3 Score: 5.0
Vector:
CWE: CWE-214
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92745
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2476266
Bugzilla Description: cockpit-machines: cockpit-machines: Information Disclosure of RHSM Offline Token via Process Arguments
CVSS Score:
CVSSv3 Score: 5.0
Vector:
CWE: CWE-214
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91203
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2465632
Bugzilla Description: cockpit-files: cockpit-files: Arbitrary file ownership and permission modification via symlink race condition
CVSS Score:
CVSSv3 Score: 6.0
Vector:
CWE: CWE-363
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91202
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2465834
Bugzilla Description: cockpit-files: cockpit-files: Arbitrary file ownership change via symlink following in privileged paste
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-61
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91205
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2466442
Bugzilla Description: cockpit-files: cockpit-files: Local attacker can hijack file ownership via symlink race
CVSS Score:
CVSSv3 Score: 6.0
Vector:
CWE: CWE-363
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91147
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2479230
Bugzilla Description: cockpit: Cockpit: Denial of Service in `cockpit-ws` due to URL-root handling without a trailing slash
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-91149
Severity: important
Released on: 18/09/2026
Advisory:
Bugzilla: 2479422
Bugzilla Description: cockpit: Cockpit: Denial of Service via unbounded connection thread spawning
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-91142
Severity: low
Released on: 18/09/2026
Advisory:
Bugzilla: 2479459
Bugzilla Description: cockpit: Integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ILP32 builds
CVSS Score:
CVSSv3 Score: 3.6
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-93685
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2518377
Bugzilla Description: multicluster-observability-addon: multicluster-observability-addon: possible unauthenticated debug/metrics endpoint via cmdfactory.NewControllerCommandConfig (confirmed exposed by engineering)
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-200
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-85511
Severity: low
Released on: 18/09/2026
Advisory:
Bugzilla: 2483140
Bugzilla Description: wildfly-elytron-realm-token: parameter injection in EAP's elytron oauth2
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-290
Affected Packages:
Package States: Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,
Full Details
CVE document


CVE-2026-10832
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2484703
Bugzilla Description: org.wildfly.security/wildfly-elytron-asn1: Unbounded Memory Allocation in WildFly Elytron ASN.1 DERDecoder via Crafted DER Payload
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-770
Affected Packages:
Package States: Cryostat 4,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Lightspeed for Runtimes Operator,Red Hat Process Automation 7,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93653
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2537005
Bugzilla Description: poppler: poppler: unbounded CPU loop in SplashOutputDev::tilingPatternFill via unvalidated tiling-pattern repeat count (denial of service)
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-606
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-75885
Severity: important
Released on: 18/09/2026
Advisory:
Bugzilla: 2517885
Bugzilla Description: openshift/console: openshift/console: Unauthenticated SSRF and resource exhaustion via devfile parser endpoint
CVSS Score:
CVSSv3 Score: 9.3
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-93999
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2537165
Bugzilla Description: keycloak-services: keycloak-services: Token refresh continues issuing tokens for disabled audience clients
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-94000
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2537168
Bugzilla Description: keycloak-services: keycloak-services: Delegated admin with manage-users can escalate to realm-admin via group membership
CVSS Score:
CVSSv3 Score: 6.6
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-94001
Severity: moderate
Released on: 18/09/2026
Advisory:
Bugzilla: 2537169
Bugzilla Description: keycloak-services: keycloak-services: Admin credential DELETE bypasses denied reset-password permission
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-54451
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2536605
Bugzilla Description: protobuf: Elixir protobuf: Denial of Service via unbounded recursion in message decoding
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-8674
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2536382
Bugzilla Description: glibc: glibc DNS stub resolver: Denial of Service via long search domain in configuration
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-1025
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-85999
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2536116
Bugzilla Description: soupsieve: Soup Sieve: Denial of Service via crafted CSS selectors
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-1333
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Migration Toolkit for Applications 8,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Virtualization 4,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-86000
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2536121
Bugzilla Description: soupsieve: Soup Sieve: Denial of Service via crafted CSS selectors
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-1333
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Migration Toolkit for Applications 8,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Virtualization 4,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-85078
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2536074
Bugzilla Description: sanic: Sanic: Request smuggling via incomplete chunked-body handling
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-444
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-85077
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2536070
Bugzilla Description: sanic: Sanic: HTTP response header injection leading to session fixation or cache poisoning
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-93
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-92987
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2536068
Bugzilla Description: roxmltree: roxmltree: Denial of Service via Quadratic Parsing
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1050
Affected Packages:
Package States: Confidential Compute Attestation,Logging Subsystem for Red Hat OpenShift,Red Hat Enterprise Linux 10,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Profile Analyzer,Red Hat Trusted Profile Analyzer,
Full Details
CVE document


CVE-2026-89059
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2519756
Bugzilla Description: resteasy-core: RESTEasy: IIOImageProvider Unbounded Image Decode (Decompression-Bomb DoS)
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-409
Affected Packages:
Package States: Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Certificate System 10,Red Hat Certificate System 11,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Satellite 6,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-89058
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2519775
Bugzilla Description: resteasy-core: RESTEasy: CorsFilter Reflects Arbitrary Origin with Credentials under Wildcard Config
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE:
Affected Packages:
Package States: Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Certificate System 10,Red Hat Certificate System 11,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Satellite 6,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-92962
Severity: low
Released on: 17/09/2026
Advisory:
Bugzilla: 2536028
Bugzilla Description: vm2: vm2: Information disclosure via stack trace interception
CVSS Score:
CVSSv3 Score: 2.5
Vector:
CWE: CWE-915
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-92963
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2536030
Bugzilla Description: vm2: vm2: Sensitive information disclosure due to internal state access
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-767
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-92961
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2536046
Bugzilla Description: vm2: vm2: Denial of Service via memory exhaustion
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-92959
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2536043
Bugzilla Description: vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-358
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-92958
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2536039
Bugzilla Description: vm2: vm2: Sandbox escape via denylist bypass in NodeVM
CVSS Score:
CVSSv3 Score: 8.5
Vector:
CWE: CWE-1220
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-92952
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2536057
Bugzilla Description: vm2: vm2: Sandbox Symbol Filtering Bypass leading to Host Stream State Corruption
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-184
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-92949
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2536060
Bugzilla Description: vm2: vm2: Sandbox bypass allows unauthorized data modification.
CVSS Score:
CVSSv3 Score: 4.0
Vector:
CWE: CWE-807
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-92945
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2536029
Bugzilla Description: vm2: vm2: Module allowlist bypass allows access to restricted packages
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-1025
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-92942
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2536038
Bugzilla Description: vm2: vm2: Denial of Service via timeout bypass in sandboxed code
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1100
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-92936
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2536055
Bugzilla Description: vm2: vm2: Information Disclosure via Error Stack Formatting
CVSS Score:
CVSSv3 Score: 5.8
Vector:
CWE: CWE-497
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-92933
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2536056
Bugzilla Description: vm2: vm2: Information Disclosure via util.getCallSites
CVSS Score:
CVSSv3 Score: 5.8
Vector:
CWE: CWE-497
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-92973
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2536059
Bugzilla Description: ansi2html: ansi2html: Cross-Site Scripting via OSC 8 hyperlink handling
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-79
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,
Full Details
CVE document


CVE-2026-77874
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2513748
Bugzilla Description: org.hibernate/hibernate-core: Hibernate ORM: SQL Injection via unescaped JSON path segment allows data exfiltration and authorization bypass
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-89
Affected Packages:
Package States: Cryostat 4,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat JBoss Web Server 5,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenStack Platform 13 (Queens),Red Hat Satellite 6,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-89418
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2536016
Bugzilla Description: google-protobuf: google-protobuf: Denial of Service via uncontrolled recursion in protobuf group field parsing
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-606
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-81829
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2524980
Bugzilla Description: smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: Unauthenticated same-origin SSRF via unsanitized JWT kid header in AwsAlbKeyResolver
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-22
Affected Packages:
Package States: Exploit Intelligence,Red Hat build of Apicurio Registry 3,Red Hat build of Apicurio Registry 3,Red Hat build of Quarkus,Red Hat build of Quarkus,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,
Full Details
CVE document


CVE-2026-87742
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2530522
Bugzilla Description: quarkus-websockets-next: Denial of Service (OOM) in quarkus-websockets-next via unbounded message buffering
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Exploit Intelligence,Red Hat build of Quarkus,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,
Full Details
CVE document


CVE-2026-87743
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2530523
Bugzilla Description: quarkus-vertx-http: Authorization Bypass via Path Normalization Discrepancy in Quarkus HTTP Security
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-551
Affected Packages:
Package States: Exploit Intelligence,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Fuse 7,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-92382
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2535972
Bugzilla Description: usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write
CVSS Score:
CVSSv3 Score: 4.1
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-92925
Severity: important
Released on: 17/09/2026
Advisory:
Bugzilla: 2535971
Bugzilla Description: redis: Redis: Out-of-bounds read via crafted cluster bus packets
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Pen Drive Powered by Red Hat Lightspeed,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-90982
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2535831
Bugzilla Description: @fastify/static: @fastify/static: Information disclosure via route guard bypass on case-insensitive filesystems
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-178
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-92894
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2535902
Bugzilla Description: rubygem-foreman_ansible: Unscoped LookupValue deletion allows cross-model override value destruction
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-92893
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2535903
Bugzilla Description: rubygem-foreman_ansible: Ansible inventory API ignores view_hosts permission filters, exposes hidden parameters
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-92904
Severity: moderate
Released on: 17/09/2026
Advisory:
Bugzilla: 2535942
Bugzilla Description: rubygem-foreman_remote_execution: Job output readable without object-level view_job_invocations check
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-92598
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2536089
Bugzilla Description: nodemailer: Nodemailer: Domain allow-list bypass via improper international domain name encoding
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-289
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-92596
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2536015
Bugzilla Description: nodemailer: Nodemailer: Denial of Service in addressparser component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1050
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-64684
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2535732
Bugzilla Description: rmcp: RMCP: Sensitive HTTP headers leaked during cross-origin redirects
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-212
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92828
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2515746
Bugzilla Description: service-ca-operator: Operator ServiceAccount bound to cluster-admin
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-250
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81871
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68778, RHSA-2026:68910, RHSA-2026:68932, RHSA-2026:68941, RHSA-2026:68777, RHSA-2026:68821, RHSA-2026:68729, RHSA-2026:68905, RHSA-2026:68716, RHSA-2026:68903, RHSA-2026:68717, RHSA-2026:68926, RHSA-2026:68912, RHSA-2026:68715,
Bugzilla: 2535725
Bugzilla Description: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-295
Affected Packages: distribution-main-3.1.1-0.2.hum1,helm4-main-4.3.0-0.2.hum1,caddy-main-2.11.4-0.4.hum1,helm3-main-3.22.0-0.2.hum1,grafana12-4-main-12.4.10-0.6.hum1,grafana13-2-main-13.2.1-0.5.hum1,tempo3-0-main-3.0.3-0.3.hum1,opentofu1-12-main-1.12.6-0.3.hum1,tempo2-10-main-2.10.8-0.3.hum1,grafana13-1-main-13.1.6-0.2.hum1,grafana12-4-main-12.4.10-0.5.hum1,jaeger-main-2.20.0-0.9.hum1,loki3-6-main-3.6.17-0.2.hum1,loki3-7-main-3.7.8-0.2.hum1,
Package States: Assisted Installer for Red Hat OpenShift Container Platform 2,Logging Subsystem for Red Hat OpenShift,Logging Subsystem for Red Hat OpenShift,Multiarch Tuning Operator,Multiarch Tuning Operator,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Global Hub,OpenShift Developer Tools and Services,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-85469
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2528219
Bugzilla Description: quay-builder-qemu: quay-builder-qemu: Release workflow uses third-party Action pinned to mutable @master with registry credentials in scope
CVSS Score:
CVSSv3 Score: 8.0
Vector:
CWE: CWE-1357
Affected Packages:
Package States: Red Hat Quay 3,
Full Details
CVE document


CVE-2026-81872
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68778, RHSA-2026:68910, RHSA-2026:68290, RHSA-2026:68821, RHSA-2026:68729, RHSA-2026:68905, RHSA-2026:68716, RHSA-2026:68272, RHSA-2026:68591, RHSA-2026:68717, RHSA-2026:68926, RHSA-2026:68715,
Bugzilla: 2535727
Bugzilla Description: go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-835
Affected Packages: grafana13-2-main-13.2.1-0.5.hum1,opentelemetry-collector-contrib-main-0.161.0-0.1.hum1,opentofu1-12-main-1.12.6-0.3.hum1,distribution-main-3.1.1-0.2.hum1,helm4-main-4.3.0-0.2.hum1,grafana13-1-main-13.1.6-0.2.hum1,caddy-main-2.11.4-0.4.hum1,jaeger-main-2.20.0-0.9.hum1,helm3-main-3.22.0-0.2.hum1,opentelemetry-collector-k8s-main-0.161.0-0.1.hum1,grafana12-4-main-12.4.10-0.6.hum1,opentelemetry-collector-main-0.161.0-0.1.hum1,
Package States: Assisted Installer for Red Hat OpenShift Container Platform 2,Logging Subsystem for Red Hat OpenShift,Logging Subsystem for Red Hat OpenShift,Multiarch Tuning Operator,Multiarch Tuning Operator,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Global Hub,OpenShift Developer Tools and Services,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-62949
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2535643
Bugzilla Description: asyncssh: AsyncSSH: Denial of Service via zero-sized SSH packets
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,
Full Details
CVE document


CVE-2026-91105
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2535621
Bugzilla Description: hplip: HPLIP: Remote code execution and privilege escalation vulnerabilities
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91103
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2535613
Bugzilla Description: hplip: HPLIP: Multiple vulnerabilities leading to remote code execution, privilege escalation, and denial of service
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91102
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2535622
Bugzilla Description: HPLIP: HPLIP: Multiple vulnerabilities could lead to remote code execution
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-494
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91101
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2535617
Bugzilla Description: hplip: HPLIP: Remote Code Execution and Privilege Escalation Vulnerabilities
CVSS Score:
CVSSv3 Score: 4.6
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91100
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2535615
Bugzilla Description: hplip: HPLIP: Multiple vulnerabilities allow remote code execution, privilege escalation, and denial of service.
CVSS Score:
CVSSv3 Score: 6.6
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91099
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2535600
Bugzilla Description: hplip: HPLIP: Multiple vulnerabilities enabling local code execution and privilege escalation
CVSS Score:
CVSSv3 Score: 5.1
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91098
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2535603
Bugzilla Description: hplip: HPLIP: Multiple vulnerabilities allow remote code execution and privilege escalation
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-494
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-86003
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2535596
Bugzilla Description: github.com/coredns/coredns: CoreDNS: Unauthorized DNS record modification via unvalidated DNS updates
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-306
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Connectivity Link 1,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-91097
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2535607
Bugzilla Description: hplip: HPLIP: Multiple vulnerabilities enable remote code execution and privilege escalation
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-94
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-82399
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2535609
Bugzilla Description: github.com/coredns/coredns: CoreDNS: Denial of Service due to unauthenticated memory exhaustion in custom transports
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1050
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Connectivity Link 1,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81176
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2535592
Bugzilla Description: devalue: Devalue: Denial of Service via malformed input parsing
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-1285
Affected Packages:
Package States: Red Hat Build of Podman Desktop,Red Hat OpenShift AI (RHOAI),Red Hat Trusted Artifact Signer,
Full Details
CVE document


CVE-2026-69147
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2535581
Bugzilla Description: vllm: vLLM: GPU memory exhaustion via PyNvVideoCodec decode bypass
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-57173
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2535557
Bugzilla Description: vllm: vLLM: Denial of Service via unauthenticated audio decompression
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-59944
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:63151,
Bugzilla: 2535546
Bugzilla Description: composer: Composer: Security bypass allows execution of unauthorized binaries via symlinked paths
CVSS Score:
CVSSv3 Score: 5.0
Vector:
CWE: CWE-59
Affected Packages: composer-main-2.10.3-1.hum1,
Package States:
Full Details
CVE document


CVE-2026-92627
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:61630,
Bugzilla: 2535513
Bugzilla Description: HDF5: HDF5: Memory corruption via crafted HDF5 file
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-825
Affected Packages: hdf5-main-2.2.0-0.1.1.hum1,
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenStack Platform 13 (Queens),
Full Details
CVE document


CVE-2026-63127
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2535503
Bugzilla Description: rmcp: RMCP: Token impersonation via missing OAuth resource field validation
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-289
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-63128
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2535485
Bugzilla Description: rmcp: RMCP: Denial of Service via unauthenticated session table leak
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-77409
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68290,
Bugzilla: 2535494
Bugzilla Description: github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service due to synchronous event channel blocking
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages: opentelemetry-collector-contrib-main-0.161.0-0.1.hum1,
Package States: Cryostat 4,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Multicluster Global Hub,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-77412
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68290,
Bugzilla: 2535499
Bugzilla Description: github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via Malicious AMQP Field Length
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-805
Affected Packages: opentelemetry-collector-contrib-main-0.161.0-0.1.hum1,
Package States: Cryostat 4,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Multicluster Global Hub,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-77404
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68290,
Bugzilla: 2535489
Bugzilla Description: github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Connection configuration overwrite via unsanitized TLS path parameter injection
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-140
Affected Packages: opentelemetry-collector-contrib-main-0.161.0-0.1.hum1,
Package States: Cryostat 4,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Multicluster Global Hub,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-77410
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68290,
Bugzilla: 2535500
Bugzilla Description: github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via unbounded body buffer allocation
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages: opentelemetry-collector-contrib-main-0.161.0-0.1.hum1,
Package States: Cryostat 4,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Multicluster Global Hub,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-77406
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68290,
Bugzilla: 2535493
Bugzilla Description: github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via signed-to-unsigned integer casting
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-190
Affected Packages: opentelemetry-collector-contrib-main-0.161.0-0.1.hum1,
Package States: Cryostat 4,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Multicluster Global Hub,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-77403
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68290,
Bugzilla: 2535498
Bugzilla Description: github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via AMQP frame size negotiation
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-839
Affected Packages: opentelemetry-collector-contrib-main-0.161.0-0.1.hum1,
Package States: Cryostat 4,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Multicluster Global Hub,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-77407
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68290,
Bugzilla: 2535487
Bugzilla Description: github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Fields
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-256
Affected Packages: opentelemetry-collector-contrib-main-0.161.0-0.1.hum1,
Package States: Cryostat 4,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Multicluster Global Hub,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-92615
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2518323
Bugzilla Description: flightctl: flightctl: Package-global go-git HTTPS transport mutated per-repo -- cross-tenant TLS-config bleed
CVSS Score:
CVSSv3 Score: 6.6
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Edge Manager 1,
Full Details
CVE document


CVE-2026-90997
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2533141
Bugzilla Description: keycloak-services: Keycloak: Replay protection bypass leads to unauthorized access via database driver semantics mismatch
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-294
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,
Full Details
CVE document


CVE-2026-77119
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535469
Bugzilla Description: bind9: bind: BIND 9: DNSSEC bypass via NSEC3 insecure-referral proof
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-290
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-75029
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535468
Bugzilla Description: bind: BIND 9: Denial of Service via crafted query responses
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-770
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-19668
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535476
Bugzilla Description: bind: BIND: Denial of Service via invalid DNSSEC records
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-770
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-19033
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535479
Bugzilla Description: bind: BIND: Unauthorized zone content updates via unauthenticated IXFR deltas
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-347
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80274
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535466
Bugzilla Description: bind: BIND: Denial of Service via crafted DNSSEC reply
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-617
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-61709
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68777, RHSA-2026:68821, RHSA-2026:67605,
Bugzilla: 2535473
Bugzilla Description: github.com/openfga/openfga: OpenFGA: Unauthorized access due to ListUsers API returning deliberately excluded users.
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-783
Affected Packages: grafana13-2-main-13.2.1-0.4.hum1,grafana12-4-main-12.4.10-0.5.hum1,grafana12-4-main-12.4.10-0.6.hum1,
Package States: Multicluster Global Hub,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Enterprise Linux 10,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-76163
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535467
Bugzilla Description: bind: BIND: Denial of Service via TKEY query with specific configuration
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-617
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-19666
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535477
Bugzilla Description: bind: BIND: Denial of Service via malformed DNS64 responses
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-617
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-92365
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2535464
Bugzilla Description: vllm: vllm-project vllm: Denial of Service via algorithmic complexity vulnerability
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-81563
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535461
Bugzilla Description: bind: BIND resolver: Denial of Service due to resource exhaustion in SVCB/HTTPS AliasMode processing
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-772
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-78301
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535463
Bugzilla Description: bind: BIND: DNS cache poisoning via malformed zone insertion
CVSS Score:
CVSSv3 Score: 5.8
Vector:
CWE: CWE-168
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-77692
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535462
Bugzilla Description: bind: BIND: Remote Denial of Service via crafted DNS-over-HTTPS request
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-617
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-92125
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2535447
Bugzilla Description: org.jenkins-ci.plugins/script-security: Jenkins Script Security Plugin: Arbitrary code execution via Groovy AST transformation bypass
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-184
Affected Packages:
Package States: OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,
Full Details
CVE document


CVE-2026-19941
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535457
Bugzilla Description: bind9: bind: BIND 9: DNS wildcard record existence can be masked by an attacker via inapplicable NSEC records
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-346
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-19662
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535445
Bugzilla Description: bind9: bind: BIND 9: Denial of Service via crafted DNSSEC responses
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-825
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-19667
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535435
Bugzilla Description: bind9: bind: BIND 9: Denial of Service via 16-bit length truncation in DNS negative cache handling
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-190
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81736
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68279,
Bugzilla: 2535432
Bugzilla Description: bind: BIND 9: Remote Denial of Service via cached SVCB/HTTPS AliasMode records
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-606
Affected Packages: bind-main-9.20.29-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-79651
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68277, RHSA-2026:68278, RHSA-2026:68276, RHSA-2026:68280,
Bugzilla: 2523345
Bugzilla Description: keycloak-services: keycloak-services: unauthenticated DoS via unbounded locale caching
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-400
Affected Packages: rhbk/keycloak-rhel9,rhbk/keycloak-rhel9:26.6-20,keycloak-services,keycloak/rhbk-openshift-rhel9,rhbk/keycloak-rhel9-operator:26.6-20,rhbk/keycloak-rhel9:26.4-26,rhbk/keycloak-operator-bundle:26.4.16-2,rhbk/keycloak-rhel9-operator:26.4-26,rhbk/keycloak-operator-bundle:26.6.7-3,
Package States: Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-74909
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68277, RHSA-2026:68278, RHSA-2026:68276, RHSA-2026:68280,
Bugzilla: 2517354
Bugzilla Description: keycloak-services: keycloak-services: Incomplete fix for CVE-2026-15573 allows policy enforcer bypass via percent-encoded URI segments
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-862
Affected Packages: rhbk/keycloak-rhel9:26.6-20,keycloak-services,keycloak/rhbk-openshift-rhel9,rhbk/keycloak-rhel9-operator:26.6-20,rhbk/keycloak-rhel9:26.4-26,rhbk/keycloak-operator-bundle:26.4.16-2,rhbk/keycloak-rhel9-operator:26.4-26,rhbk/keycloak-operator-bundle:26.6.7-3,
Package States: Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-19607
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68277, RHSA-2026:68278, RHSA-2026:68276, RHSA-2026:68280,
Bugzilla: 2514529
Bugzilla Description: keycloak-services: keycloak-services: Broker-originated username collision causes account lockout
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-287
Affected Packages: rhbk/keycloak-rhel9:26.6-20,keycloak-services,rhbk-openshift-rhel9/rhbk-openshift-rhel9,rhbk/keycloak-rhel9-operator:26.6-20,rhbk/keycloak-rhel9:26.4-26,rhbk/keycloak-operator-bundle:26.4.16-2,rhbk/keycloak-rhel9-operator:26.4-26,rhbk/keycloak-operator-bundle:26.6.7-3,
Package States: Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-17526
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68277, RHSA-2026:68278, RHSA-2026:68276, RHSA-2026:68280,
Bugzilla: 2507409
Bugzilla Description: keycloak-services: keycloak-services: Privilege escalation via impersonation role allows takeover of realm administrator accounts
CVSS Score:
CVSSv3 Score: 7.2
Vector:
CWE: CWE-862
Affected Packages: rhbk-keycloak-rhel9/rhbk-keycloak-rhel9,rhbk/keycloak-rhel9:26.6-20,keycloak-services,rhbk-openshift-rhel9/rhbk-openshift-rhel9,rhbk/keycloak-rhel9-operator:26.6-20,rhbk/keycloak-rhel9:26.4-26,rhbk/keycloak-operator-bundle:26.4.16-2,rhbk/keycloak-rhel9-operator:26.4-26,rhbk/keycloak-operator-bundle:26.6.7-3,
Package States: Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-18212
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68277, RHSA-2026:68278, RHSA-2026:68276, RHSA-2026:68280,
Bugzilla: 2508307
Bugzilla Description: keycloak-services: keycloak-services: SAML Redirect DEFLATE helpers leak native zlib state
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-401
Affected Packages: rhbk-keycloak-rhel9/rhbk-keycloak-rhel9,rhbk/keycloak-rhel9:26.6-20,keycloak-services,rhbk-openshift-rhel9/rhbk-openshift-rhel9,rhbk/keycloak-rhel9-operator:26.6-20,rhbk/keycloak-rhel9:26.4-26,rhbk/keycloak-operator-bundle:26.4.16-2,rhbk/keycloak-rhel9-operator:26.4-26,rhbk/keycloak-operator-bundle:26.6.7-3,
Package States: Red Hat Data Grid 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-92081
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2535071
Bugzilla Description: fastify: fastify: Denial of Service via unhandled exception on HTTP/2 trailer responses
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-248
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-85501
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68590,
Bugzilla: 2535057
Bugzilla Description: unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-770
Affected Packages: unbound-main-1.26.1-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-82720
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68590,
Bugzilla: 2535060
Bugzilla Description: unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-416
Affected Packages: unbound-main-1.26.1-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-82717
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68590,
Bugzilla: 2535051
Bugzilla Description: unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-787
Affected Packages: unbound-main-1.26.1-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81642
Severity: critical
Released on: 16/09/2026
Advisory: RHSA-2026:68590,
Bugzilla: 2535059
Bugzilla Description: unbound: Unbound: Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY
CVSS Score:
CVSSv3 Score: 9.8
Vector:
CWE: CWE-122
Affected Packages: unbound-main-1.26.1-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81634
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:68590,
Bugzilla: 2535054
Bugzilla Description: unbound: Unbound: Heap buffer overflow via malicious DNSSEC response
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-122
Affected Packages: unbound-main-1.26.1-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80225
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68590,
Bugzilla: 2535055
Bugzilla Description: unbound: Unbound: Denial of Service via continuous queries on TCP/DoT connection
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-1050
Affected Packages: unbound-main-1.26.1-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-78227
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68590,
Bugzilla: 2535052
Bugzilla Description: unbound: Unbound: Denial of Service via use-after-free in DoQ stream output buffer
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-416
Affected Packages: unbound-main-1.26.1-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-77955
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:68590,
Bugzilla: 2535053
Bugzilla Description: unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-345
Affected Packages: unbound-main-1.26.1-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-77860
Severity: low
Released on: 16/09/2026
Advisory: RHSA-2026:68590,
Bugzilla: 2535050
Bugzilla Description: unbound: Unbound: Denial of Service via 'serve-expired' code path bypass
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-675
Affected Packages: unbound-main-1.26.1-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-92091
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2533849
Bugzilla Description: jwcrypto: jwcrypto: denial of service via O(n^2) duplicate check on unbounded JWK key_ops array
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-407
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,
Full Details
CVE document


CVE-2026-19248
Severity: moderate
Released on: 16/09/2026
Advisory: RHSA-2026:59393, RHSA-2026:68801,
Bugzilla: 2535011
Bugzilla Description: qt5-qtbase: qt6-qtbase: Qt: Denial of Service vulnerability in XML parsing
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-776
Affected Packages: qt6-qtbase-main-6.11.2-2.hum1,qt5-qtbase-main-5.15.18-5.2.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92358
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla:
Bugzilla Description:
CVSS Score:
CVSSv3 Score: 6.4
Vector:
CWE: CWE-613
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-92220
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2534981
Bugzilla Description: vllm: vLLM: Resource consumption via argument manipulation in MoRIIO Acknowledgement Handler
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-42784
Severity: important
Released on: 16/09/2026
Advisory: RHSA-2026:42902,
Bugzilla: 2464122
Bugzilla Description: sequoia-openpgp: sequoia-openpgp: Cryptographic integrity compromise via key flag confusion
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-347
Affected Packages: rust-podman-sequoia-main-0.3.2-4.hum1,
Package States: Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Trusted Profile Analyzer,Red Hat Trusted Profile Analyzer,
Full Details
CVE document


CVE-2026-92218
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2534091
Bugzilla Description: release-service-utils: Server-Side Template Injection via two-pass non-sandboxed Jinja render
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-94
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-89775
Severity: important
Released on: 16/09/2026
Advisory:
Bugzilla: 2535049
Bugzilla Description: kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89912
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2535138
Bugzilla Description: kernel: KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-90021
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2535407
Bugzilla Description: kernel: usb: gadget: f_midi: initialize work in f_midi_alloc()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-93432
Severity: moderate
Released on: 16/09/2026
Advisory:
Bugzilla: 2536859
Bugzilla Description: io.quarkus.qute:quarkus-core: Cross-Site Scripting (XSS) and JSON Injection via Qute {#eval} Section in Quarkus
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-79
Affected Packages:
Package States: Exploit Intelligence,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat build of Quarkus,Red Hat Fuse 7,Red Hat Fuse 7,
Full Details
CVE document


CVE-2026-92000
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2534417
Bugzilla Description: adm-zip: adm-zip: Denial of Service via crafted ZIP archives with zero declared uncompressed size
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-91719
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2534925
Bugzilla Description: chromium-browser: chromium-browser: Code injection in XML
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-91
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-91732
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2534658
Bugzilla Description: chromium-browser: chromium-browser: Missing authorization in AppManifest
CVSS Score:
CVSSv3 Score: 7.2
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-91715
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2534920
Bugzilla Description: chromium-browser: chromium-browser: Type confusion in ServiceWorker
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-91746
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2534605
Bugzilla Description: chromium-browser: chromium-browser: Integer overflow in Compositing
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-190
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-91708
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2534419
Bugzilla Description: chromium-browser: chromium-browser: Race condition in Network
CVSS Score:
CVSSv3 Score: 5.8
Vector:
CWE: CWE-368
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-91748
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2534664
Bugzilla Description: chromium-browser: chromium-browser: Race condition in Extensions
CVSS Score:
CVSSv3 Score: 8.0
Vector:
CWE: CWE-368
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-91720
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2534673
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized resource in ANGLE
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-91727
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2534405
Bugzilla Description: chromium-browser: chromium-browser: Incorrect reference resolution in Extensions
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-386
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-88922
Severity: moderate
Released on: 15/09/2026
Advisory: RHSA-2026:68259, RHSA-2026:68255, RHSA-2026:68251, RHSA-2026:68261, RHSA-2026:68281,
Bugzilla: 2534192
Bugzilla Description: github.com/hashicorp/go-getter: Go-getter: Privilege escalation via crafted archive decompression
CVSS Score:
CVSSv3 Score: 6.7
Vector:
CWE: CWE-278
Affected Packages: opentofu1-12-main-1.12.6-0.2.hum1,opentofu1-10-main-1.10.10-0.4.hum1,syft-main-1.51.1-0.2.hum1,grype-main-0.118.0-0.2.hum1,trivy-main-0.74.0-0.3.hum1,
Package States: Exploit Intelligence,Exploit Intelligence,Red Hat Hardened Images,Red Hat Trusted Artifact Signer,
Full Details
CVE document


CVE-2026-92240
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2534187
Bugzilla Description: thunderbird: Out-of-bounds read in IMAP response parser
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92239
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2534197
Bugzilla Description: thunderbird: Thunderbird: Out-of-bounds read via maliciously constructed IMAP line
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92238
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2534199
Bugzilla Description: thunderbird: Thunderbird: Memory safety violations via maliciously crafted mail headers
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-19774
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2534102
Bugzilla Description: bluez: BlueZ: Arbitrary Code Execution via A2DP Stack-based Buffer Overflow
CVSS Score:
CVSSv3 Score: 8.0
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-85234
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2460997
Bugzilla Description: tftp: tftp-hpa: Denial of Service due to out-of-bounds read/write in remap engine
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-91992
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533894
Bugzilla Description: tornado: Tornado: Credential leak via HTTP client handle reuse
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-524
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,Migration Toolkit for Applications 8,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,
Full Details
CVE document


CVE-2026-91991
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533964
Bugzilla Description: tornado: Tornado: Cookie attribute injection via capitalized keyword arguments
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-915
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,Migration Toolkit for Applications 8,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,
Full Details
CVE document


CVE-2026-91990
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533953
Bugzilla Description: tornado: Tornado: Denial of Service via memory amplification in multipart parsing
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,Migration Toolkit for Applications 8,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,
Full Details
CVE document


CVE-2026-91986
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533967
Bugzilla Description: gix-transport: gix-transport: Information disclosure and virtual host spoofing via control character injection
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-93
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-91964
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533911
Bugzilla Description: FreeRDP: FreeRDP: Remote code execution via heap buffer overflow in Server Redirection PDU
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91963
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533930
Bugzilla Description: FreeRDP: FreeRDP: Remote code execution via uninitialized heap memory disclosure
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91962
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533933
Bugzilla Description: FreeRDP: FreeRDP: Remote out-of-bounds access via integer overflow in audin Apple backends
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91961
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533968
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via URBDRC control-transfer request with invalid OutputBufferSize
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91960
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533957
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via integer overflow and double free in WinPR
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91959
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533951
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service due to buffer over-read in RPC gateway
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91958
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533958
Bugzilla Description: FreeRDP: FreeRDP: Denial of service and potential code execution via malicious RDP file
CVSS Score:
CVSSv3 Score: 6.6
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91957
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533939
Bugzilla Description: FreeRDP: FreeRDP: Use-after-free vulnerability in smartcard RDPDR device handler leading to denial of service or potential code execution
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91955
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533907
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via crafted desktop dimensions
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91956
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533927
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via out-of-bounds read in URBDRC channel
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91954
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533906
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via crafted Surface Bits command
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91952
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533948
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via crafted AVC444 graphics updates
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-606
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91953
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533959
Bugzilla Description: FreeRDP: FreeRDP: Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption.
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91951
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533928
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service via out-of-bounds write in urbdrc client channel
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91949
Severity: critical
Released on: 15/09/2026
Advisory:
Bugzilla: 2533925
Bugzilla Description: freerdp: FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass
CVSS Score:
CVSSv3 Score: 9.3
Vector:
CWE: CWE-358
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91950
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533954
Bugzilla Description: FreeRDP: FreeRDP: Out-of-bounds read leads to denial of service or information disclosure
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91948
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533904
Bugzilla Description: FreeRDP: FreeRDP: Arbitrary code execution via oversized channel messages in SHOW_PROTOCOL
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-124
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91946
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533913
Bugzilla Description: FreeRDP: FreeRDP: Information Disclosure via RDPGFX ResetGraphics PDU
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91947
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533942
Bugzilla Description: FreeRDP: FreeRDP: Use-after-free vulnerability in DRDYNVC parser leads to memory corruption
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-91945
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533965
Bugzilla Description: FreeRDP: FreeRDP: Denial of Service due to out-of-bounds read in smartcard response processing
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2024-58384
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533897
Bugzilla Description: tornado: Tornado: CRLF injection in CurlAsyncHTTPClient allows arbitrary header injection or new HTTP requests.
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-93
Affected Packages:
Package States: Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,Migration Toolkit for Applications 8,OpenShift Lightspeed,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,
Full Details
CVE document


CVE-2026-55701
Severity: moderate
Released on: 15/09/2026
Advisory: RHSA-2026:63152,
Bugzilla: 2533955
Bugzilla Description: github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver: OpenTelemetry Collector Contrib githubreceiver: Unauthorized data injection via authentication bypass
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-306
Affected Packages: opentelemetry-collector-contrib-main-0.160.0-0.1.hum1,
Package States:
Full Details
CVE document


CVE-2026-54167
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533858
Bugzilla Description: github.com/openshift-pipelines/pipelines-as-code: Pipelines-as-Code: GitHub App token redirection via untrusted host header
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-345
Affected Packages:
Package States: Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat OpenShift Dev Spaces,Red Hat Web Terminal,
Full Details
CVE document


CVE-2026-54168
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533851
Bugzilla Description: github.com/openshift-pipelines/pipelines-as-code: Pipelines-as-Code: Information disclosure via unscoped GitHub App installation token
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-862
Affected Packages:
Package States: Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat OpenShift Dev Spaces,Red Hat Web Terminal,
Full Details
CVE document


CVE-2026-39919
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533857
Bugzilla Description: ghostscript: ghostscript: Heap buffer overflow via JPEG 2000 output adapter
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-122
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-85013
Severity: moderate
Released on: 15/09/2026
Advisory: RHSA-2026:64766,
Bugzilla: 2465635
Bugzilla Description: environment-modules: Command injection in environment-modules Bash completion via malicious module names containing shell metacharacters
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-78
Affected Packages: environment-modules-main-5.6.2-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92079
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533802
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the Widget: Win32 component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-807
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92078
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533806
Bugzilla Description: firefox: thunderbird: Denial-of-service in the Security component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92077
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533803
Bugzilla Description: firefox: thunderbird: Denial-of-service in the SVG component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92076
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533804
Bugzilla Description: firefox: thunderbird: Incorrect boundary conditions in the Networking component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92075
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533800
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the Networking component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-305
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92074
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533805
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the Popup Blocker component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-807
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92073
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533765
Bugzilla Description: firefox: thunderbird: Privilege escalation in the Enterprise Policies component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92071
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533733
Bugzilla Description: firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-501
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92070
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533777
Bugzilla Description: firefox: thunderbird: Information disclosure in the Networking component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-201
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92069
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533794
Bugzilla Description: firefox: thunderbird: Spoofing issue in the DOM: Navigation component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-601
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92068
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533782
Bugzilla Description: firefox: Site isolation issue in the Reader Mode component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-653
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92067
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533748
Bugzilla Description: firefox: thunderbird: Use-after-free in the Widget: Gtk component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92066
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533768
Bugzilla Description: firefox: thunderbird: Sandbox escape in the Profile Backup component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-653
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92065
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533796
Bugzilla Description: firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92064
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533785
Bugzilla Description: firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-501
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92063
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533745
Bugzilla Description: firefox: thunderbird: Denial-of-service in the Audio/Video component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92062
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533784
Bugzilla Description: firefox: thunderbird: Privilege escalation in the Session Restore component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92061
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533731
Bugzilla Description: firefox: thunderbird: Incorrect boundary conditions in the Security: Process Sandboxing component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-403
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92060
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533783
Bugzilla Description: firefox: thunderbird: Use-after-free in the Internationalization component
CVSS Score:
CVSSv3 Score: 3.4
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92059
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533734
Bugzilla Description: firefox: thunderbird: Incorrect boundary conditions in the DOM: Editor component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92058
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533744
Bugzilla Description: firefox: thunderbird: Use-after-free in the Graphics component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92057
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533736
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the Enterprise Policies component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-1220
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92056
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533756
Bugzilla Description: firefox: thunderbird: Use-after-free in the Graphics: Text component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92055
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533766
Bugzilla Description: firefox: thunderbird: Privilege escalation in the DevTools component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-368
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92054
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533788
Bugzilla Description: firefox: thunderbird: Privilege escalation in the Memory component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92053
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533738
Bugzilla Description: firefox: thunderbird: Privilege escalation in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92052
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533749
Bugzilla Description: firefox: thunderbird: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92050
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533798
Bugzilla Description: firefox: thunderbird: Sandbox escape due to race condition in the XPConnect component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-368
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92049
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533772
Bugzilla Description: firefox: thunderbird: Use-after-free in the Widget: Win32 component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92048
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533787
Bugzilla Description: firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-501
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92047
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533767
Bugzilla Description: firefox: thunderbird: Privilege escalation in the Crash Reporting component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92046
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533730
Bugzilla Description: firefox: thunderbird: Use-after-free in the Graphics component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92045
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533746
Bugzilla Description: firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the WebRTC component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-653
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92044
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533755
Bugzilla Description: firefox: thunderbird: Information disclosure in the Networking: HTTP component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-201
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92043
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533750
Bugzilla Description: firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Audio/Video component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92042
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533732
Bugzilla Description: firefox: thunderbird: Race condition in the DOM: Content Processes component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92041
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533752
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the DOM: Networking component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-807
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92040
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533763
Bugzilla Description: firefox: thunderbird: Use-after-free in the JavaScript: WebAssembly component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92039
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533735
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the DOM: Notifications component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-358
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92038
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533761
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the Remote Settings Client component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-807
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92037
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533780
Bugzilla Description: firefox: thunderbird: Incorrect boundary conditions in the DOM: Animation component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92036
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533795
Bugzilla Description: firefox: thunderbird: Incorrect boundary conditions in the Networking: HTTP component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92035
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533789
Bugzilla Description: firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Graphics component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-501
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92034
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533759
Bugzilla Description: firefox: thunderbird: Site isolation issue in the Graphics component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-653
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92033
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533754
Bugzilla Description: firefox: Privilege escalation in Firefox for Android
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92032
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533743
Bugzilla Description: firefox: thunderbird: Sandbox escape due to invalid pointer in the Graphics component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92031
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533742
Bugzilla Description: firefox: thunderbird: Information disclosure in the Graphics: ImageLib component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-497
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92030
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533791
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-807
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92029
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533797
Bugzilla Description: firefox: thunderbird: Use-after-free in the SVG component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92028
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533758
Bugzilla Description: firefox: thunderbird: Use-after-free in the DOM: Core & HTML component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92027
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533757
Bugzilla Description: firefox: thunderbird: Use-after-free in the DOM: Streams component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92026
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533741
Bugzilla Description: firefox: thunderbird: Use-after-free in the Networking component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92025
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533793
Bugzilla Description: firefox: thunderbird: Use-after-free in the DOM: Navigation component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92024
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533737
Bugzilla Description: firefox: thunderbird: Use-after-free in the SVG component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92023
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533799
Bugzilla Description: firefox: thunderbird: Use-after-free in the XML component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92022
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533770
Bugzilla Description: firefox: thunderbird: Use-after-free in the DOM: HTML Parser component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92021
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533774
Bugzilla Description: firefox: thunderbird: Use-after-free in the JavaScript Engine: JIT component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92020
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533786
Bugzilla Description: firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92019
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533740
Bugzilla Description: firefox: thunderbird: Mitigation bypass in the Remote Settings Client component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-807
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92018
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533773
Bugzilla Description: firefox: thunderbird: Sandbox escape in the DOM: Core & HTML component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-791
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92017
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533779
Bugzilla Description: firefox: thunderbird: Privilege escalation in the DOM: Service Workers component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92016
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533764
Bugzilla Description: firefox: thunderbird: Use-after-free in the Disability Access APIs component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92015
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533760
Bugzilla Description: firefox: thunderbird: Privilege escalation in the WebExtensions component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92014
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533771
Bugzilla Description: firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92013
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533762
Bugzilla Description: firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92012
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533769
Bugzilla Description: firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92011
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533753
Bugzilla Description: firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92010
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533747
Bugzilla Description: firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92009
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533781
Bugzilla Description: firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92008
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533790
Bugzilla Description: firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92007
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533792
Bugzilla Description: firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92006
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533751
Bugzilla Description: firefox: thunderbird: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-653
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-92005
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533778
Bugzilla Description: firefox: thunderbird: Use-after-free in the Audio/Video: Web Codecs component
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-86818
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533688
Bugzilla Description: fast-uri: fast-uri: Mailto header injection via percent-encoded field-name desynchronization
CVSS Score:
CVSSv3 Score: 4.8
Vector:
CWE: CWE-838
Affected Packages:
Package States: Cost Management On Premise,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat Build of Podman Desktop,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Directory Server 11,Red Hat Directory Server 12,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-86472
Severity: moderate
Released on: 15/09/2026
Advisory: RHSA-2026:68143,
Bugzilla: 2533679
Bugzilla Description: fast-uri: fast-uri: Security bypass due to inconsistent host case normalization
CVSS Score:
CVSSv3 Score: 4.8
Vector:
CWE: CWE-178
Affected Packages: grafana12-4-main-12.4.10-0.4.hum1,
Package States: Cost Management On Premise,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Multicluster Engine for Kubernetes,Network Observability Operator,Network Observability Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat Build of Podman Desktop,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Directory Server 11,Red Hat Directory Server 12,Red Hat Discovery 2,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-91786
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533606
Bugzilla Description: gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-17495
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533595
Bugzilla Description: moment: Moment: Path Traversal via crafted non-string input to locale function
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-22
Affected Packages:
Package States: Multicluster Engine for Kubernetes,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat 3scale API Management Platform 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Apicurio Registry 3,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 4,Red Hat Ceph Storage 4,Red Hat Ceph Storage 9,Red Hat Discovery 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat Openshift Data Foundation 4,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Single Sign-On 7,Red Hat Trusted Artifact Signer,
Full Details
CVE document


CVE-2026-81320
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2524898
Bugzilla Description: hawtio-operator: hawtio-operator: TLS private key written to operator log at debug level
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-532
Affected Packages:
Package States: Red Hat build of Apache Camel - HawtIO 4,
Full Details
CVE document


CVE-2026-81303
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2524897
Bugzilla Description: hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routeHostName
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-441
Affected Packages:
Package States: Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apache Camel - HawtIO 4,
Full Details
CVE document


CVE-2026-90878
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2533580
Bugzilla Description: vllm: vLLM: Denial of Service via Jinja Template Rendering
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-606
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-90852
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533566
Bugzilla Description: com.github.luben/zstd-jni: luben zstd-jni: Remote use-after-free vulnerability in dictionary sharing
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-825
Affected Packages:
Package States: Exploit Intelligence,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat AMQ Clients,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat build of Quarkus,Red Hat Ceph Storage 9,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-91771
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2533555
Bugzilla Description: wandb: wandb: Arbitrary code execution via path traversal in file download
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-22
Affected Packages:
Package States: Exploit Intelligence,Red Hat AI Inference Server,Red Hat AI Inference Server,
Full Details
CVE document


CVE-2026-75092
Severity: important
Released on: 15/09/2026
Advisory: RHSA-2026:67609, RHSA-2026:67608,
Bugzilla: 2517499
Bugzilla Description: leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins
CVSS Score:
CVSSv3 Score: 7.3
Vector:
CWE: CWE-250
Affected Packages: leapp-repository-0:0.24.0-1.el9_8.1,leapp-repository-0:0.22.0-1.el9_6.2,
Package States: Red Hat Enterprise Linux 8,Red Hat OpenStack Platform 17.1,
Full Details
CVE document


CVE-2026-79699
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2523408
Bugzilla Description: podman: buildah: skopeo: containers/storage: Malicious tar whiteout header allows replacement of extraction destination directory
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-59
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Virtualization 4,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-79705
Severity: moderate
Released on: 15/09/2026
Advisory:
Bugzilla: 2523419
Bugzilla Description: podman: buildah: buildah/copier: Directory escape via crafted tar symlinks when used outside Buildah by non-root callers
CVSS Score:
CVSSv3 Score: 4.5
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Virtualization 4,Red Hat Quay 3,Red Hat Quay 3,
Full Details
CVE document


CVE-2026-91926
Severity: low
Released on: 15/09/2026
Advisory:
Bugzilla: 2533698
Bugzilla Description: gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated AV_PAIR entries in NTLM CHALLENGE
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-401
Affected Packages:
Package States: Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-92248
Severity: important
Released on: 15/09/2026
Advisory:
Bugzilla: 2534282
Bugzilla Description: gimp: integer overflow when generating a thumbnail preview for a PSD file
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-90831
Severity: moderate
Released on: 14/09/2026
Advisory: RHSA-2026:47171,
Bugzilla: 2533541
Bugzilla Description: binutils: GNU Binutils: Memory corruption via local manipulation of ELF String Table
CVSS Score:
CVSSv3 Score: 6.6
Vector:
CWE: CWE-787
Affected Packages: binutils-main-2.46.1-1.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-90830
Severity: moderate
Released on: 14/09/2026
Advisory: RHSA-2026:47171,
Bugzilla: 2533539
Bugzilla Description: binutils: GNU Binutils: Local denial of service via null pointer dereference in Section Merge
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages: binutils-main-2.46.1-1.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-90829
Severity: moderate
Released on: 14/09/2026
Advisory: RHSA-2026:47171,
Bugzilla: 2533532
Bugzilla Description: binutils: GNU Binutils: Null pointer dereference via SHT_GROUP Section manipulation
CVSS Score:
CVSSv3 Score: 6.6
Vector:
CWE: CWE-476
Affected Packages: binutils-main-2.46.1-1.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-90828
Severity: moderate
Released on: 14/09/2026
Advisory: RHSA-2026:47171,
Bugzilla: 2533528
Bugzilla Description: binutils: GNU Binutils: Null pointer dereference via elf_orphan_compatible function
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-476
Affected Packages: binutils-main-2.46.1-1.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-64753
Severity: moderate
Released on: 14/09/2026
Advisory:
Bugzilla: 2535532
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may disclose sensitive user information
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-359
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-90816
Severity: moderate
Released on: 14/09/2026
Advisory:
Bugzilla: 2533346
Bugzilla Description: ffmpeg: CPU exhaustion when processing a crafted HLS playlist
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-90815
Severity: moderate
Released on: 14/09/2026
Advisory:
Bugzilla: 2533334
Bugzilla Description: ffmpeg: out-of-bounds read in the Convolution Filter
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-82049
Severity: important
Released on: 14/09/2026
Advisory: RHSA-2026:68135, RHSA-2026:68132, RHSA-2026:68154, RHSA-2026:68309, RHSA-2026:65505,
Bugzilla: 2533296
Bugzilla Description: python: Python tarfile module: File modification and content disclosure via crafted archives
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-59
Affected Packages: python3-11-main-3.11.16-1.4.hum1,python3-12-main-3.12.14-1.3.hum1,python3-10-main-3.10.21-1.3.hum1,python3-13-main-3.13.15-1.3.hum1,python3-14-main-3.14.7-1.1.hum1,
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-82035
Severity: important
Released on: 14/09/2026
Advisory:
Bugzilla: 2533285
Bugzilla Description: pymupdf: PyMuPDF: Arbitrary file write via path traversal vulnerability
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,
Full Details
CVE document


CVE-2026-53659
Severity: important
Released on: 14/09/2026
Advisory:
Bugzilla: 2533236
Bugzilla Description: org.http4k/http4k-core: http4k: Denial of Service via unbounded gzip decompression
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-409
Affected Packages:
Package States: Red Hat Fuse 7,
Full Details
CVE document


CVE-2026-47256
Severity: moderate
Released on: 14/09/2026
Advisory: RHSA-2026:63152,
Bugzilla: 2533233
Bugzilla Description: github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter: opentelemetry-collector-contrib: OpenTelemetry Sentry Exporter: Path traversal allows unauthorized access to Sentry API endpoints
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-22
Affected Packages: opentelemetry-collector-contrib-main-0.160.0-0.1.hum1,
Package States:
Full Details
CVE document


CVE-2026-53495
Severity: moderate
Released on: 14/09/2026
Advisory:
Bugzilla: 2533230
Bugzilla Description: github.com/containerd/containerd: containerd: Denial of Service via CRI ExecSync goroutine leak
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Assisted Installer for Red Hat OpenShift Container Platform 2,Assisted Installer for Red Hat OpenShift Container Platform 2,Assisted Installer for Red Hat OpenShift Container Platform 2,AWS Load Balancer Operator,Compliance Operator,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Custom Metric Autoscaler operator for Red Hat Openshift,Deployment Validation Operator,Gatekeeper 3,Logging Subsystem for Red Hat OpenShift,Logical Volume Manager Storage,Logical Volume Manager Storage,Machine Deletion Remediation Operator,Machine Deletion Remediation Operator,MCP Server for Red Hat OpenShift,MCP Server for Red Hat OpenShift,Migration Toolkit for Containers,Migration Toolkit for Containers,Migration Toolkit for Virtualization,Migration Toolkit for Virtualization,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Global Hub,Multicluster Global Hub,Multicluster Global Hub,Multicluster Global Hub,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Serverless,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Pen Drive Powered by Red Hat Lightspeed,Power monitoring for Red Hat OpenShift,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ceph Storage 6,Red Hat Ceph Storage 9,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Developer Hub,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift for Windows Containers,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat Service Interconnect 2,Red Hat Trusted Artifact Signer,Red Hat Web Terminal,
Full Details
CVE document


CVE-2026-90804
Severity: moderate
Released on: 14/09/2026
Advisory: RHSA-2026:47171,
Bugzilla: 2533209
Bugzilla Description: binutils: GNU Binutils: Buffer overflow in Eh Frame Section Handler can lead to denial of service
CVSS Score:
CVSSv3 Score: 4.8
Vector:
CWE: CWE-805
Affected Packages: binutils-main-2.46.1-1.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-55073
Severity: moderate
Released on: 14/09/2026
Advisory:
Bugzilla: 2533208
Bugzilla Description: weasyprint: WeasyPrint: Local file read and Server-Side Request Forgery (SSRF) via URL fetcher bypass
CVSS Score:
CVSSv3 Score: 6.2
Vector:
CWE: CWE-1220
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,
Full Details
CVE document


CVE-2026-55451
Severity: important
Released on: 14/09/2026
Advisory:
Bugzilla: 2533213
Bugzilla Description: gettext-converter: gettext-converter: Denial of Service via Prototype Pollution
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-915
Affected Packages:
Package States: OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,
Full Details
CVE document


CVE-2026-90803
Severity: moderate
Released on: 14/09/2026
Advisory: RHSA-2026:47171,
Bugzilla: 2533196
Bugzilla Description: binutils: GNU Binutils ld: Buffer Overflow via Malformed Relocation
CVSS Score:
CVSSv3 Score: 6.6
Vector:
CWE: CWE-805
Affected Packages: binutils-main-2.46.1-1.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-90802
Severity: moderate
Released on: 14/09/2026
Advisory: RHSA-2026:47171,
Bugzilla: 2533185
Bugzilla Description: binutils: GNU Binutils: Denial of service via null pointer dereference in ld component
CVSS Score:
CVSSv3 Score: 5.0
Vector:
CWE: CWE-476
Affected Packages: binutils-main-2.46.1-1.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-90801
Severity: moderate
Released on: 14/09/2026
Advisory: RHSA-2026:47171,
Bugzilla: 2533176
Bugzilla Description: binutils: GNU Binutils ld: Buffer overflow in cache_bwrite via nbytes manipulation
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-120
Affected Packages: binutils-main-2.46.1-1.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-84445
Severity: important
Released on: 14/09/2026
Advisory:
Bugzilla: 2533175
Bugzilla Description: google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Assisted Installer for Red Hat OpenShift Container Platform 2,AWS Load Balancer Operator,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,Builds for Red Hat OpenShift,cert-manager Operator for Red Hat OpenShift,cert-manager Operator for Red Hat OpenShift,cert-manager Operator for Red Hat OpenShift,cert-manager Operator for Red Hat OpenShift,Compliance Operator,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Cost Management On Premise,Cryostat 4,Cryostat 4,Cryostat 4,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Deployment Validation Operator,DPU kit for NVIDIA,Exploit Intelligence,Exploit Intelligence,Exploit Intelligence,Exploit Intelligence,Exploit Intelligence,Exploit Intelligence,Exploit Intelligence,ExternalDNS Operator,ExternalDNS Operator,External Secrets Operator for Red Hat OpenShift,External Secrets Operator for Red Hat OpenShift,Fence Agents Remediation Operator,File Integrity Operator,File Integrity Operator,File Integrity Operator,File Integrity Operator,File Integrity Operator,File Integrity Operator,Gatekeeper 3,Job Set 1,Job Set 1,Job Set Tech Preview,Job Set Tech Preview,Job Set Tech Preview,Kernel Module Management Operator for Red Hat Openshift,Kernel Module Management Operator for Red Hat Openshift,Kernel Module Management Operator for Red Hat Openshift,Kube Descheduler Operator,Kube Descheduler Operator,Leader Worker Set,Leader Worker Set,Leader Worker Set,Lightspeed Core,Lightspeed Core,Logging Subsystem for Red Hat OpenShift,Logging Subsystem for Red Hat OpenShift,Logging Subsystem for Red Hat OpenShift,Logging Subsystem for Red Hat OpenShift,Logical Volume Manager Storage,Logical Volume Manager Storage,Logical Volume Manager Storage,Logical Volume Manager Storage,Logical Volume Manager Storage,Logical Volume Manager Storage,Logical Volume Manager Storage,Machine Deletion Remediation Operator,Machine Deletion Remediation Operator,MCP Lifecycle Operator,MCP Server for Red Hat OpenShift,MCP Server for Red Hat OpenShift,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,Migration Toolkit for Containers,Migration Toolkit for Containers,Migration Toolkit for Containers,Migration Toolkit for Containers,Migration Toolkit for Virtualization,Migration Toolkit for Virtualization,Multiarch Tuning Operator,Multiarch Tuning Operator,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Global Hub,Multicluster Global Hub,Multicluster Global Hub,Multicluster Global Hub,Network Observability Operator,Network Observability Operator,Network Observability Operator,Network Observability Operator,Node HealthCheck Operator,Node HealthCheck Operator,Node Maintenance Operator,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Run Once Duration Override Operator,OpenShift Run Once Duration Override Operator,OpenShift Secondary Scheduler Operator,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Power monitoring for Red Hat OpenShift,Power monitoring for Red Hat OpenShift,Power monitoring for Red Hat OpenShift,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Build of Kueue,Red Hat Build of Kueue,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 5,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 6,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 7,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 8,Red Hat Ceph Storage 8,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Connectivity Link 1,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Lightspeed for Runtimes Operator,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Cluster Manager CLI,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Workspaces Operator,Red Hat OpenShift Dev Workspaces Operator,Red Hat OpenShift Dev Workspaces Operator,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift for Windows Containers,Red Hat OpenShift for Windows Containers,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat Quay 3,Red Hat Quay 3,Red Hat Quay 3,Red Hat Quay 3,Red Hat Satellite 6,Red Hat Service Interconnect 1,Red Hat Service Interconnect 2,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Profile Analyzer,Red Hat Web Terminal,Security Profiles Operator,Security Profiles Operator,Self Node Remediation Operator,Self Node Remediation Operator,Self Node Remediation Operator,Service Telemetry Framework 1.5,Service Telemetry Framework 1.5,Storage-Based Remediation,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,
Full Details
CVE document


CVE-2025-24890
Severity: moderate
Released on: 14/09/2026
Advisory:
Bugzilla: 2533153
Bugzilla Description: gix-sec: gix-sec: Privilege escalation via incorrect repository trust on Windows
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-648
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-90996
Severity: moderate
Released on: 14/09/2026
Advisory:
Bugzilla: 2478986
Bugzilla Description: sssd: sssd: Denial of Service in NSS responder via crafted zero-length requests
CVSS Score:
CVSSv3 Score: 4.0
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-90995
Severity: moderate
Released on: 14/09/2026
Advisory:
Bugzilla: 2479464
Bugzilla Description: sssd: SSSD: Local denial of service due to NULL pointer dereference in PAM responder
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-90994
Severity: moderate
Released on: 14/09/2026
Advisory:
Bugzilla: 2479455
Bugzilla Description: sssd: sssd: Denial of Service via malformed PAM v1 requests
CVSS Score:
CVSSv3 Score: 4.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-90463
Severity: low
Released on: 14/09/2026
Advisory:
Bugzilla: 2479268
Bugzilla Description: sssd: Local OOB Read in NSS Service Request Parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`)
CVSS Score:
CVSSv3 Score: 4.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-90949
Severity: important
Released on: 14/09/2026
Advisory:
Bugzilla: 2533013
Bugzilla Description: gimp: gimp: heap-based buffer overflow in PSP loader due to selection-channel geometry mismatch
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-90948
Severity: important
Released on: 14/09/2026
Advisory:
Bugzilla: 2533008
Bugzilla Description: gimp: gimp: heap-based buffer overflow in ICO loader via integer overflow in embedded PNG dimensions
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-90713
Severity: low
Released on: 14/09/2026
Advisory:
Bugzilla: 2533014
Bugzilla Description: vllm: tiktoken: vLLM and tiktoken: Local Denial of Service vulnerability
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-770
Affected Packages:
Package States: Exploit Intelligence,Exploit Intelligence,Lightspeed Core,Lightspeed Core,Lightspeed Core,Migration Toolkit for Applications 8,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-90947
Severity: important
Released on: 14/09/2026
Advisory:
Bugzilla: 2533005
Bugzilla Description: gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-88932
Severity: moderate
Released on: 14/09/2026
Advisory:
Bugzilla: 2532957
Bugzilla Description: multer: multer: Denial of Service via orphaned disk writes on aborted uploads
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-459
Affected Packages:
Package States: Red Hat 3scale API Management Platform 2,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-90698
Severity: moderate
Released on: 14/09/2026
Advisory: RHSA-2026:63224,
Bugzilla: 2532955
Bugzilla Description: memcached: memcached: Denial of Service due to out-of-bounds read
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-125
Affected Packages: memcached-main-1.6.45-1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenStack Platform 13 (Queens),
Full Details
CVE document


CVE-2025-64031
Severity: moderate
Released on: 14/09/2026
Advisory: RHSA-2026:43818,
Bugzilla: 2532805
Bugzilla Description: libarchive: libarchive: Denial of Service via heap-based buffer overflow in gzip writer
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-120
Affected Packages: libarchive-main-3.8.8-3.1.hum1,
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2023-32803
Severity: important
Released on: 14/09/2026
Advisory: RHSA-2026:40570,
Bugzilla: 2532858
Bugzilla Description: ca-certificates: ca-certificates: Failure to remove TrustCor root certificates
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-459
Affected Packages: ca-certificates-main-2025.2.80_v9.0.304-9.hum1,
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-84635
Severity: important
Released on: 14/09/2026
Advisory:
Bugzilla: 2535531
Bugzilla Description: webkitgtk: Processing maliciously crafted web content may lead to an unexpected process termination
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-664
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-90781
Severity: moderate
Released on: 13/09/2026
Advisory: RHSA-2026:40573, RHSA-2026:67289,
Bugzilla: 2532707
Bugzilla Description: alsa-lib: alsa-lib: Denial of Service via off-by-one stack buffer overflow
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-120
Affected Packages: alsa-lib-main-1.2.16.1-2.hum1,alsa-lib-main-1.2.16.1-2.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-90776
Severity: important
Released on: 13/09/2026
Advisory:
Bugzilla: 2532697
Bugzilla Description: nodemailer: Nodemailer: Denial of Service via crafted email headers
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1333
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-90771
Severity: moderate
Released on: 13/09/2026
Advisory: RHSA-2026:67610, RHSA-2026:67573, RHSA-2026:67605,
Bugzilla: 2532688
Bugzilla Description: joi: joi: Prototype Pollution via custom messages
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-915
Affected Packages: grafana13-1-main-13.1.3-0.9.hum1,grafana13-2-main-13.2.1-0.4.hum1,grafana12-4-main-12.4.10-0.3.hum1,
Package States: Gatekeeper 3,Migration Toolkit for Containers,Red Hat Build of Podman Desktop,Red Hat Data Grid 8,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-90678
Severity: important
Released on: 13/09/2026
Advisory: RHSA-2026:60634,
Bugzilla: 2532644
Bugzilla Description: haproxy: HAProxy: HTTP Request Smuggling via HTTP/3 Multiplexer Desynchronization
CVSS Score:
CVSSv3 Score: 8.9
Vector:
CWE: CWE-444
Affected Packages: haproxy-main-3.0.27-0.1.hum1,
Package States: Red Hat Ceph Storage 5,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-52296
Severity: moderate
Released on: 13/09/2026
Advisory:
Bugzilla: 2532792
Bugzilla Description: ffmpeg: out-of-bounds read due to missing required padding in WMA extradata allocation paths
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-52297
Severity: moderate
Released on: 13/09/2026
Advisory:
Bugzilla: 2532794
Bugzilla Description: ffmpeg: out-of-bounds read due to insufficiently padded extradata in the MOV parsing path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2022-42917
Severity: moderate
Released on: 13/09/2026
Advisory:
Bugzilla: 2532800
Bugzilla Description: frr: FRRouting FRR: Privilege escalation via TOCTOU race condition
CVSS Score:
CVSSv3 Score: 6.7
Vector:
CWE: CWE-367
Affected Packages:
Package States: Fast Datapath for RHEL 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2024-53922
Severity: moderate
Released on: 13/09/2026
Advisory:
Bugzilla: 2532803
Bugzilla Description: kernel: Kernel: Denial of Service in buffer queue driver
CVSS Score:
CVSSv3 Score: 5.7
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-90616
Severity: important
Released on: 12/09/2026
Advisory:
Bugzilla: 2532613
Bugzilla Description: flatpak: Flatpak: Arbitrary code execution via missing symlink protection
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-59
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-90560
Severity: important
Released on: 12/09/2026
Advisory:
Bugzilla: 2532604
Bugzilla Description: com.github.luben/zstd-jni: zstd-jni: Denial of Service via out-of-bounds read in ZstdDictDecompress
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-125
Affected Packages:
Package States: Exploit Intelligence,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat AMQ Clients,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat build of Quarkus,Red Hat Ceph Storage 9,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-90558
Severity: critical
Released on: 12/09/2026
Advisory:
Bugzilla: 2532606
Bugzilla Description: sngrep: sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers
CVSS Score:
Vector:
CWE: CWE-120
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-90555
Severity: moderate
Released on: 12/09/2026
Advisory:
Bugzilla: 2532566
Bugzilla Description: vllm: vLLM: Denial of Service due to improper audio header validation
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-90554
Severity: moderate
Released on: 12/09/2026
Advisory:
Bugzilla: 2532572
Bugzilla Description: vllm: vLLM: Denial of Service via video audio extraction
CVSS Score:
CVSSv3 Score: 6.2
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-90553
Severity: important
Released on: 12/09/2026
Advisory:
Bugzilla: 2532579
Bugzilla Description: vllm: vLLM: Remote Code Execution via LlavaOnevision2 processor ignoring trust_remote_code
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-94
Affected Packages:
Package States: Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-90461
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532451
Bugzilla Description: ironic: OpenStack Ironic: Information disclosure via unexpected credential transmission
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-201
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-89769
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532161
Bugzilla Description: kernel: Linux kernel: Use-after-free due to IRQ leak in NXP PIT clocksource driver
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89768
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532171
Bugzilla Description: kernel: Linux kernel: Information disclosure via incorrect path derivation in nested overlayfs
CVSS Score:
CVSSv3 Score: 2.3
Vector:
CWE: CWE-41
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89766
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532287
Bugzilla Description: kernel: Linux kernel: Information disclosure in pidfd namespace handling
CVSS Score:
CVSSv3 Score: 2.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89765
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532295
Bugzilla Description: kernel: Kernel: Information disclosure in timers/itimer due to uninitialized padding
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-201
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89764
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532452
Bugzilla Description: kernel: Linux kernel (rust devres): Use-after-free due to race condition in concurrent resource revocation
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89763
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532156
Bugzilla Description: kernel: Linux kernel: Use-after-free in TPM trusted keys due to incorrect teardown ordering
CVSS Score:
CVSSv3 Score: 6.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89761
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532235
Bugzilla Description: kernel: Kernel: AppArmor out-of-bounds write allows local denial of service or privilege escalation
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89758
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532153
Bugzilla Description: kernel: Linux kernel: Denial of Service due to improper handling of device-private PMDs in memory management
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89755
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532241
Bugzilla Description: kernel: Linux kernel: System crash due to stale memory mapping in device migration
CVSS Score:
CVSSv3 Score: 4.1
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89754
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532276
Bugzilla Description: kernel: Linux kernel: Memory corruption via out-of-bounds write in mm/pagewalk
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89752
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532245
Bugzilla Description: kernel: Linux kernel: Denial of Service in memcg due to stale memory limit during reclaim
CVSS Score:
CVSSv3 Score: 4.1
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89751
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532152
Bugzilla Description: kernel: Linux kernel (x86/tdx): Off-by-one error in port I/O handling
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-193
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89750
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532248
Bugzilla Description: kernel: Linux kernel: Use-After-Free in tracing/user_events component
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89748
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532233
Bugzilla Description: kernel: Linux kernel: Ring buffer corruption in tracing due to retry exhaustion
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89746
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532209
Bugzilla Description: kernel: Linux kernel tracing: Use-after-free leads to Denial of Service
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89743
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532206
Bugzilla Description: kernel: Linux kernel: NSM information disclosure via out-of-bounds read
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89742
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532155
Bugzilla Description: kernel: Linux kernel: Arbitrary code execution via use-after-free in RapidIO mport character device.
CVSS Score:
CVSSv3 Score: 6.4
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89738
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532232
Bugzilla Description: kernel: Linux kernel: USB gadget `at91_udc` driver use-after-free vulnerability
CVSS Score:
CVSSv3 Score: 4.1
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89737
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532239
Bugzilla Description: kernel: Linux kernel: Thunderbolt driver use-after-free vulnerability
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89736
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532311
Bugzilla Description: kernel: Linux kernel USB audio gadget driver: Use-after-free leading to arbitrary code execution
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89735
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532401
Bugzilla Description: kernel: Linux kernel: USB gadget MIDI2 driver resource leak leads to denial of service
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89734
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532458
Bugzilla Description: kernel: Linux kernel: Denial of Service due to null pointer dereference in USB Video Class gadget driver
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89733
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532203
Bugzilla Description: kernel: Linux kernel: USB UVC gadget driver use-after-free vulnerability
CVSS Score:
CVSSv3 Score: 4.6
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89732
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532293
Bugzilla Description: kernel: Kernel: USB FunctionFS deadlock via ep0 read loop
CVSS Score:
CVSSv3 Score: 4.1
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89731
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532462
Bugzilla Description: kernel: Linux kernel: Out-of-bounds read in CXL/RAS AER handling
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89726
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532261
Bugzilla Description: kernel: Linux kernel: Out-of-bounds read in ucs2_strnlen() can lead to information disclosure
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89723
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532191
Bugzilla Description: kernel: nilfs2: Linux kernel: nilfs2 slab-out-of-bounds due to improper node block handling
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89721
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532300
Bugzilla Description: kernel: Linux kernel: `rockchip-samsung-dcphy` out-of-bounds read leads to denial of service
CVSS Score:
CVSSv3 Score: 4.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89719
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532158
Bugzilla Description: kernel: Linux kernel: zram out-of-bounds access leading to system instability
CVSS Score:
CVSSv3 Score: 4.1
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89717
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532278
Bugzilla Description: kernel: zram: NULL pointer dereference due to invalid compressor state
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89716
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532456
Bugzilla Description: kernel: Linux kernel zram: Denial of Service due to improper deflate parameter validation
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89714
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532288
Bugzilla Description: kernel: Linux kernel NFS: Denial of Service due to unbounded memory leak from failed mount attempts
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89712
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532255
Bugzilla Description: kernel: Linux kernel NFSD: Denial of service via use-after-free
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89713
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532459
Bugzilla Description: kernel: Linux kernel NFSD: Unauthorized truncation of append-only files via TOCTOU vulnerability
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89709
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532208
Bugzilla Description: kernel: Linux kernel: lockd and nfsd denial of service vulnerability
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89704
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532298
Bugzilla Description: kernel: Linux kernel: nfsd silent data loss due to incorrect writeback error handling
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89701
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532154
Bugzilla Description: kernel: Linux Kernel: Data integrity issue in nfsd due to improper timestamp validation
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-1284
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89700
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532454
Bugzilla Description: kernel: Linux kernel nfsd: Out-of-bounds read due to improper sockaddr length validation
CVSS Score:
CVSSv3 Score: 4.7
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89699
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532157
Bugzilla Description: kernel: Linux kernel: nfsd vulnerable to denial of service via oversized NFSv4 symlink targets
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89591
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532212
Bugzilla Description: kernel: Linux kernel: NULL pointer dereference in accel/rocket module
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89589
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532404
Bugzilla Description: kernel: Linux kernel: Denial of Service in ACPI/APEI/GHES due to spinlock deadlock
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89587
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532213
Bugzilla Description: kernel: Linux kernel: Stack buffer overflow in ACPI pfr_update can lead to memory corruption.
CVSS Score:
CVSSv3 Score: 5.7
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89490
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532316
Bugzilla Description: kernel: ocfs2: ocfs2: Denial of Service via readdir position truncation on 32-bit kernels
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-87910
Severity: moderate
Released on: 11/09/2026
Advisory: RHSA-2026:67575, RHSA-2026:67574, RHSA-2026:67572, RHSA-2026:67607, RHSA-2026:67606,
Bugzilla: 2531985
Bugzilla Description: python: Python tarfile module: Security filter bypass allows arbitrary file write
CVSS Score:
CVSSv3 Score: 5.7
Vector:
CWE: CWE-252
Affected Packages: python3-14-main-3.14.7-1.2.hum1,python3-13-main-3.13.15-1.2.hum1,python3-11-main-3.11.16-1.3.hum1,python3-12-main-3.12.14-1.2.hum1,python3-10-main-3.10.21-1.2.hum1,
Package States: Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-89090
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2531982
Bugzilla Description: github.com/aws/aws-sdk-go-v2: Amazon AWS SDK for Go v2: Denial of Service via crafted event stream header
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-248
Affected Packages:
Package States: AWS Load Balancer Operator,AWS Load Balancer Operator,cert-manager Operator for Red Hat OpenShift,cert-manager Operator for Red Hat OpenShift,Compliance Operator,Compliance Operator,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Cryostat 4,Cryostat 4,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,DPU kit for NVIDIA,DPU kit for NVIDIA,Exploit Intelligence,Exploit Intelligence,Exploit Intelligence,ExternalDNS Operator,External Secrets Operator for Red Hat OpenShift,File Integrity Operator,File Integrity Operator,Kernel Module Management Operator for Red Hat Openshift,Logging Subsystem for Red Hat OpenShift,Logging Subsystem for Red Hat OpenShift,Migration Toolkit for Virtualization,Migration Toolkit for Virtualization,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Global Hub,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift API for Data Protection,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat Advanced Cluster Security 4,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Build of Kueue,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Developer Hub,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Cluster Manager CLI,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift for Windows Containers,Red Hat OpenShift for Windows Containers,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift on AWS,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenStack Platform 18.0,Red Hat Satellite 6,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Web Terminal,Security Profiles Operator,Security Profiles Operator,streams for Apache Kafka 2,streams for Apache Kafka 3,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,
Full Details
CVE document


CVE-2026-68497
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2531964
Bugzilla Description: com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: CPU Denial of Service via unbounded numeric parsing
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-400
Affected Packages:
Package States: Exploit Intelligence,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,OpenShift Serverless,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Certificate System 10,Red Hat Certificate System 11,Red Hat Data Grid 8,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat JBoss Web Server 7,Red Hat JBoss Web Server 7,Red Hat JBoss Web Server 7,Red Hat JBoss Web Server 7,Red Hat Lightspeed for Runtimes Operator,Red Hat Offline Knowledge Portal,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenStack Platform 13 (Queens),Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-89329
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2470013
Bugzilla Description: device-mapper-multipath: Local Denial of Service via Blocking IPC Send Operations
CVSS Score:
CVSSv3 Score: 6.2
Vector:
CWE: CWE-1322
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-87776
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2531852
Bugzilla Description: compression: compression: Denial of Service via memory leak on premature response close
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Gatekeeper 3,Migration Toolkit for Containers,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,Node HealthCheck Operator,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Service Mesh 3,OpenShift Service Mesh 3,Red Hat 3scale API Management Platform 2,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat Build of Podman Desktop,Red Hat Ceph Storage 4,Red Hat Data Grid 8,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Discovery 2,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat Quay 3,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-87859
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2531809
Bugzilla Description: morgan: morgan: Log Injection via unescaped double quote in log fields
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-117
Affected Packages:
Package States: Cryostat 4,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Openshift Data Foundation 4,
Full Details
CVE document


CVE-2026-89162
Severity: low
Released on: 11/09/2026
Advisory: RHSA-2026:67534,
Bugzilla: 2531748
Bugzilla Description: pcre2: PCRE2: Information disclosure via pcre2_serialize_encode
CVSS Score:
CVSSv3 Score: 2.9
Vector:
CWE: CWE-125
Affected Packages: pcre2-main-10.48-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89161
Severity: important
Released on: 11/09/2026
Advisory: RHSA-2026:67534,
Bugzilla: 2531747
Bugzilla Description: pcre2: PCRE2: Memory corruption vulnerability in pcre2_jit_match
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-1341
Affected Packages: pcre2-main-10.48-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89160
Severity: low
Released on: 11/09/2026
Advisory: RHSA-2026:67534,
Bugzilla: 2531745
Bugzilla Description: pcre2: PCRE2: Denial of Service via out-of-bounds read during invalid UTF matching
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-125
Affected Packages: pcre2-main-10.48-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89158
Severity: moderate
Released on: 11/09/2026
Advisory: RHSA-2026:67534,
Bugzilla: 2531746
Bugzilla Description: PCRE2: PCRE2: Out-of-bounds write via integer overflow on 32-bit platforms
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-787
Affected Packages: pcre2-main-10.48-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89157
Severity: moderate
Released on: 11/09/2026
Advisory: RHSA-2026:67534,
Bugzilla: 2531744
Bugzilla Description: pcre2: PCRE2: Out-of-bounds write via large pattern input
CVSS Score:
CVSSv3 Score: 5.7
Vector:
CWE: CWE-787
Affected Packages: pcre2-main-10.48-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89156
Severity: low
Released on: 11/09/2026
Advisory: RHSA-2026:67534,
Bugzilla: 2531743
Bugzilla Description: PCRE2: PCRE2: Out-of-bounds read via invalid UTF data during JIT fallback
CVSS Score:
CVSSv3 Score: 2.9
Vector:
CWE: CWE-125
Affected Packages: pcre2-main-10.48-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89092
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2531725
Bugzilla Description: glibc: nscd stack overflow leads to degraded DNS resolution
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-77159
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2531811
Bugzilla Description: libvirt: Unsafe chown in qemuTPMEmulatorPrepareHost() allows arbitrary file ownership change via symlink
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-61
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-78807
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2531997
Bugzilla Description: wpa_supplicant: wpa_supplicant: Security bypass via missing PMKSA validation
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-322
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-89503
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532017
Bugzilla Description: kernel: ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89518
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532018
Bugzilla Description: kernel: sched_ext: Fix this_rq() assumptions in dispatch kfuncs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89682
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532019
Bugzilla Description: kernel: nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89529
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532020
Bugzilla Description: kernel: svcrdma: Reject oversized Read segments at decode time
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80961
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532021
Bugzilla Description: kernel: dm-pcache: validate kset key_num and intra-segment bounds
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89494
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532022
Bugzilla Description: kernel: ocfs2: validate lengths in dlm_mig_lockres_handler
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89497
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532023
Bugzilla Description: kernel: orangefs: skip leading spaces before parsing client debug masks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89590
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532024
Bugzilla Description: kernel: accel/rocket: Fix error path handling in rocket_job_run()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89643
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532025
Bugzilla Description: kernel: audit: avoid dropping live tree ref on fsnotify rule autoremove
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89534
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532026
Bugzilla Description: kernel: svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89593
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532027
Bugzilla Description: kernel: hugetlb: only adjust reservation during unmapping if mapcount is 0
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89620
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532028
Bugzilla Description: kernel: HID: intel-thc-hid: intel-quickspi: validate report size before copy
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89622
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532029
Bugzilla Description: kernel: HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81004
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532030
Bugzilla Description: kernel: ipmi:msghandler: Cancel work cleanly on an error
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80955
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532031
Bugzilla Description: kernel: dm-pcache: fix use-after-free and invalid seg operations in kset_replay()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89555
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532032
Bugzilla Description: kernel: mpls: reload header after pskb_may_pull()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89510
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532033
Bugzilla Description: kernel: RDMA/cxgb4: Cancel reg_work before freeing device on remove
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89626
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532034
Bugzilla Description: kernel: HID: sensor: custom: Fix field sysfs group cleanup on failure
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89476
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532035
Bugzilla Description: kernel: sctp: fix stream->outcnt underflow on duplicate RECONF responses
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80973
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532036
Bugzilla Description: kernel: ALSA: 6fire: bound the MIDI event length from the device
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80957
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532037
Bugzilla Description: kernel: dm-pcache: detect a cycle in the last-kset chain during replay
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89543
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532038
Bugzilla Description: kernel: sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89547
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532039
Bugzilla Description: kernel: SUNRPC: Check svc pool percpu counter allocation
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89624
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532040
Bugzilla Description: kernel: HID: universal-pidff: stop the device when force-feedback init fails
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89512
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532041
Bugzilla Description: kernel: remoteproc: scp: Fix device reference leak on failed lookup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89693
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532042
Bugzilla Description: kernel: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-252
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89598
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532043
Bugzilla Description: kernel: fbdev: ssd1307fb: defer I2C transfers from damage callbacks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80997
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532044
Bugzilla Description: kernel: net: ipa: fix stalled modem TX queue after runtime resume
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89654
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532045
Bugzilla Description: kernel: ceph: fix UAF in check_new_map() on session freed during unlock
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89648
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532046
Bugzilla Description: kernel: ceph: cap delegated inode count in ceph_parse_deleg_inos()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-606
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80992
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532047
Bugzilla Description: kernel: net: ravb: avoid dereferencing an invalid PTP clock
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89544
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532048
Bugzilla Description: kernel: SUNRPC: fix gssx_dec_option_array error path bugs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81016
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532049
Bugzilla Description: kernel: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89458
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532050
Bugzilla Description: kernel: s390/dasd: Do not complete a failed ESE read as successful
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89630
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532051
Bugzilla Description: kernel: smb: client: restore the data_offset bound in is_valid_oplock_break()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89566
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532052
Bugzilla Description: kernel: jbd2: check need_resched() when skipping busy checkpoint buffers
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-606
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81006
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532053
Bugzilla Description: kernel: ipmi: Remove all sysfs files on registration failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80935
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532054
Bugzilla Description: kernel: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89457
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532055
Bugzilla Description: kernel: s390/dasd: Guard sysfs discipline callbacks against unallocated private data
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89527
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532056
Bugzilla Description: kernel: svcrdma: Use svc_xprt_put to free listener on create failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89583
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532057
Bugzilla Description: kernel: Bluetooth: eir: Fix OOB read in eir_get_service_data()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89533
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532058
Bugzilla Description: kernel: svcrdma: Fix offset arithmetic in read_chunk_range
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89515
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532059
Bugzilla Description: kernel: scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89569
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532060
Bugzilla Description: kernel: Bluetooth: RFCOMM: serialize security confirmation handling
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80952
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532061
Bugzilla Description: kernel: i3c: master: Fix info leak and UAF in device unregister path
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89450
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532062
Bugzilla Description: kernel: iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-681
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89644
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532063
Bugzilla Description: kernel: btrfs: fix extent map leak in NOCOW direct I/O write
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89553
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532079
Bugzilla Description: kernel: nouveau/gem: reserve the bo in the info ioctl around the vma lookup
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89634
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532080
Bugzilla Description: kernel: smb: client: fix ALIGN() overflow in symlink_data() error context loop
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80995
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532081
Bugzilla Description: kernel: net: mctp: hold a reference to the route device in mctp_route_lookup()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80971
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532082
Bugzilla Description: kernel: ALSA: bcd2000: clear the URB pointers on disconnect
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89596
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532083
Bugzilla Description: kernel: forcedeth: fix off-by-one when saving/restoring non-PCI config space
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80994
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532084
Bugzilla Description: kernel: net: openvswitch: fix flow mask use-after-free on flow deletion
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89679
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532085
Bugzilla Description: kernel: nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89687
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532086
Bugzilla Description: kernel: nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81010
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532087
Bugzilla Description: kernel: io_uring/waitid: honor task_work cancellation
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89684
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532088
Bugzilla Description: kernel: nfsd: fix cpntf publish race in nfs4_init_cp_state
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89631
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532089
Bugzilla Description: kernel: smb: client: reject a tree connect response whose byte count is too small
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89475
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532090
Bugzilla Description: kernel: power: supply: bq24257: fix use-after-free on remove
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89446
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532091
Bugzilla Description: kernel: iommufd: Release current IOAS on xa_store() failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89660
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532092
Bugzilla Description: kernel: NFSD: Prevent client use-after-free during admin state revocation
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89516
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532093
Bugzilla Description: kernel: sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89560
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532094
Bugzilla Description: kernel: landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1220
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89480
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532095
Bugzilla Description: kernel: nvme-tcp: reject a read that transferred too few bytes
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-130
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80936
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532096
Bugzilla Description: kernel: wifi: mt76: mt7925: cancel mlo_pm_work on stop
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89495
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532097
Bugzilla Description: kernel: ocfs2: bound namelen in dlm_migrate_request_handler
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89686
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532098
Bugzilla Description: kernel: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89489
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532099
Bugzilla Description: kernel: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-822
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89511
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532100
Bugzilla Description: kernel: qede: Fix NULL pointer dereference in TPA fragment processing
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89652
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532101
Bugzilla Description: kernel: ceph: bound copied dentry name length in NFS export get_name
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89504
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532102
Bugzilla Description: kernel: regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89690
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532103
Bugzilla Description: kernel: nfsd: defer vfree of compound ops to fix rpc_status UAF
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80981
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532104
Bugzilla Description: kernel: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89650
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532105
Bugzilla Description: kernel: ceph: bound num_export_targets array for mds info v2/v3
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89467
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532106
Bugzilla Description: kernel: power: supply: qcom_battmgr: fix use-after-free
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89464
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532107
Bugzilla Description: kernel: power: supply: twl4030_charger: cancel workers via devm
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80958
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532108
Bugzilla Description: kernel: dm-pcache: clamp the tail kset read to the segment data region
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89537
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532109
Bugzilla Description: kernel: SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89484
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532110
Bugzilla Description: kernel: lockd: fix NULL dereference on lockowner allocation failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89669
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532111
Bugzilla Description: kernel: nfsd: initialize copy-notify stateid before publishing it
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89612
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532112
Bugzilla Description: kernel: ntfs: reject invalid MFT LCNs from boot sector
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89557
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532113
Bugzilla Description: kernel: md: do overflow check for sb->bblog_shift in super_1_load()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89538
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532114
Bugzilla Description: kernel: SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80953
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532115
Bugzilla Description: kernel: i3c: master: adi: initialize the lock before enabling interrupts
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-909
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89445
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532116
Bugzilla Description: kernel: iommufd: Fix UAF in selftest IOPF reporting
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89574
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532117
Bugzilla Description: kernel: dm array: validate array block headers on read
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89550
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532118
Bugzilla Description: kernel: SUNRPC: svcauth_gss: enforce krb5 token minimum length
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89659
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532119
Bugzilla Description: kernel: NFSD: Prevent client use-after-free during delegation revoke
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89567
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532120
Bugzilla Description: kernel: jbd2: bound shrinker scans by examined checkpoint buffers
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89440
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532121
Bugzilla Description: kernel: mmc: via-sdmmc: stop card-detect handling on probe failure
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89638
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532122
Bugzilla Description: kernel: smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-281
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80946
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532123
Bugzilla Description: kernel: fuse: copy request headers via a stack buffer for io-uring
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-501
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80980
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532124
Bugzilla Description: kernel: net/smc: stop killed, freed and out_of_sync sharing a byte
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89623
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532125
Bugzilla Description: kernel: HID: mcp2221: stop device IO before hid_hw_stop
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89559
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532126
Bugzilla Description: kernel: libnvdimm/labels: Prevent integer overflow in __nd_label_validate()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89655
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532127
Bugzilla Description: kernel: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89482
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532128
Bugzilla Description: kernel: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80998
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532129
Bugzilla Description: kernel: net: bnxt: ring the doorbell when SW USO exits early
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-841
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89658
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532130
Bugzilla Description: kernel: NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81012
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532131
Bugzilla Description: kernel: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-193
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89540
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532132
Bugzilla Description: kernel: sunrpc: init gssp_lock before publishing proc entry
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-909
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81002
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532133
Bugzilla Description: kernel: xdp: fix zero-copy frame layout
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80930
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532134
Bugzilla Description: kernel: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89757
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532135
Bugzilla Description: kernel: mm/mglru: fix and remove redundant unevictable folio handling
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89771
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532138
Bugzilla Description: kernel: ring-buffer: Fix subbuf resize race with ring buffer readers
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89710
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532139
Bugzilla Description: kernel: NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89722
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532142
Bugzilla Description: kernel: PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89697
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532144
Bugzilla Description: kernel: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89760
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532145
Bugzilla Description: kernel: mm, swap: don't free a hibernation slot that is in the swap cache
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89756
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532146
Bugzilla Description: kernel: mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89720
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532147
Bugzilla Description: kernel: ubifs: fix out-of-bounds read in signature length check
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89753
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532148
Bugzilla Description: kernel: mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89725
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532149
Bugzilla Description: kernel: media: cec: stm32: prevent out-of-bounds write on RX overflow
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89772
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532151
Bugzilla Description: kernel: btrfs: write-protect folios during data writeback
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80944
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532163
Bugzilla Description: kernel: wifi: mwifiex: Detach sync cmd buffer on interrupted wait
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89545
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532164
Bugzilla Description: kernel: sunrpc: defer rq_argp and rq_resp free until after RCU grace period
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89592
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532166
Bugzilla Description: kernel: accel/rocket: fix NULL dereference and integer overflow in rocket_job_push()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89611
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532167
Bugzilla Description: kernel: ntfs: validate non-resident attribute offsets
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80934
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532169
Bugzilla Description: kernel: wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-771
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80996
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532170
Bugzilla Description: kernel: net: l2tp: do not propagate multicast notification errors
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89469
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532173
Bugzilla Description: kernel: power: supply: lp8727: fix use-after-free in lp8727_release_irq()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89448
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532174
Bugzilla Description: kernel: iommu/vt-d: Force requesting ACS when tboot is enabled
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-358
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89546
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532175
Bugzilla Description: kernel: SUNRPC: close backchannel before destroying callback service
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81000
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532176
Bugzilla Description: kernel: net: tun: bound receive headroom
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux for NVIDIA 26,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80979
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532177
Bugzilla Description: kernel: net/smc: unregister the connection before draining the rx tasklet
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89521
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532178
Bugzilla Description: kernel: sched/core: Handle pick_task() releasing the rq lock
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89628
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532179
Bugzilla Description: kernel: HID: picolcd: clamp eeprom debugfs read to bytes actually received
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89678
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532180
Bugzilla Description: kernel: nfsd: fix partial-write detection in nfsd_direct_write
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-823
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89447
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532181
Bugzilla Description: kernel: iommufd: Avoid locking internal accesses during unmap
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89609
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532182
Bugzilla Description: kernel: ecryptfs: hold msg ctx list lock when cleaning daemon queue
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-820
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89485
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532183
Bugzilla Description: kernel: lockd: pin next file across nlm_inspect_file lock-drop
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89481
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532184
Bugzilla Description: kernel: nvme-tcp: fix host memory disclosure on R2T for a read command
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-201
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89565
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532185
Bugzilla Description: kernel: ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89461
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532186
Bugzilla Description: kernel: power: supply: max17040: synchronize work cancellation on suspend
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89513
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532187
Bugzilla Description: kernel: RISC-V: KVM: Fix PMU event info array size overflow
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89528
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532188
Bugzilla Description: kernel: svcrdma: Reject Read lists that exceed the page budget
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89581
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532189
Bugzilla Description: kernel: bpf, x86: Fix per-CPU address resolution into an extended register
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89605
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532190
Bugzilla Description: kernel: ecryptfs: release message context on send failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89436
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532194
Bugzilla Description: kernel: platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[]
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89506
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532195
Bugzilla Description: kernel: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80977
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532197
Bugzilla Description: kernel: net: skbuff: don't touch shared zerocopy state in skb_tx_error()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89444
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532198
Bugzilla Description: kernel: platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-256
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80967
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532200
Bugzilla Description: kernel: ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-909
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80983
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532201
Bugzilla Description: kernel: net/smc: fix socket refcount leak in smc_switch_conns()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89578
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532204
Bugzilla Description: kernel: dm-io: clone the source bio instead of copying its biovec
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80986
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532205
Bugzilla Description: kernel: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89642
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532207
Bugzilla Description: kernel: cifs: call pagecache_isize_extended() in cifs_setsize() when extending
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-201
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89573
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532210
Bugzilla Description: kernel: dm array: reject an array block whose value size is not the caller's
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-843
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89517
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532211
Bugzilla Description: kernel: sched_ext: Fix rq->core_pick corruption under core scheduling
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89685
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532214
Bugzilla Description: kernel: nfsd: fix clock domain mismatch in clients_still_reclaiming()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1025
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89509
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532215
Bugzilla Description: kernel: RDMA/ionic: Embed counter driver data in rdma_counter allocation
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89439
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532216
Bugzilla Description: kernel: platform/x86: ISST: Add a NULL check for sst_inst[]
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80945
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532217
Bugzilla Description: kernel: crypto: iaa - unmap dst before software fallback on decompress
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89530
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532218
Bugzilla Description: kernel: svcrdma: Reject inline replies that overflow the pull-up buffer
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89676
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532219
Bugzilla Description: kernel: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80968
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532220
Bugzilla Description: kernel: ALSA: mts64: Check card index validity at probe
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89558
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532221
Bugzilla Description: kernel: md/raid10: fix still_degraded being inverted in raid10_sync_request()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-480
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89617
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532222
Bugzilla Description: kernel: fs/ntfs3: validate dirty page table on log replay
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80987
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532223
Bugzilla Description: kernel: NTB: ntb_transport: Reject oversized TX buffers
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89541
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532224
Bugzilla Description: kernel: SUNRPC: harden gss_unwrap_resp_priv length checks
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81015
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532225
Bugzilla Description: kernel: platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-459
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80975
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532227
Bugzilla Description: kernel: mfd: qnap-mcu: keep the reply buffer alive past a command timeout
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-562
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80932
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532228
Bugzilla Description: kernel: vsock/virtio: flush works in dependency order
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89698
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532229
Bugzilla Description: kernel: nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89633
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532230
Bugzilla Description: kernel: smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89663
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532231
Bugzilla Description: kernel: nfsd: revoke copy-notify stateids before dropping their reference
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80950
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532234
Bugzilla Description: kernel: i3c: renesas: Check that the transfer is valid before accessing it
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89438
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532236
Bugzilla Description: kernel: platform/x86: ISST: Validate logical CPU id and clos id
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80948
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532237
Bugzilla Description: kernel: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89477
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532238
Bugzilla Description: kernel: sctp: fix NULL deref on untransmitted RECONF completion
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89608
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532240
Bugzilla Description: kernel: ecryptfs: pass packet set buffer size to parser
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89466
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532242
Bugzilla Description: kernel: power: supply: qcom_battmgr: terminate the strings from firmware
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89456
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532243
Bugzilla Description: kernel: s390/dasd: Propagate partial completion length across ERP recovery
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89599
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532244
Bugzilla Description: kernel: fbdev: omapfb: panel-dsi-cm: initialize lock before registering display
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89473
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532246
Bugzilla Description: kernel: power: supply: bq25890: Fix power_supply reference leak
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89597
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532247
Bugzilla Description: kernel: fbdev: uvesafb: unregister connector callback on init failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89647
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532249
Bugzilla Description: kernel: ceph: do not repeat ceph_trim_dentries() if no progress possible
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81001
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532250
Bugzilla Description: kernel: slip: fix use-after-free in sl_sync()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80988
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532251
Bugzilla Description: kernel: NTB: ntb_transport: Fail TX enqueue when the QP link is down
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89505
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532252
Bugzilla Description: kernel: RDMA/uverbs: Guard legacy bundles without method_elm
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89552
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532253
Bugzilla Description: kernel: params: fix charp corruption on allocation failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89501
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532254
Bugzilla Description: kernel: ring-buffer: Hold cpu_buffer::lock when resizing a subbuf
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-413
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80943
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532256
Bugzilla Description: kernel: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80965
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532257
Bugzilla Description: kernel: ALSA: serial-u16550: Check card index validity at probe
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89542
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532258
Bugzilla Description: kernel: SUNRPC: harden gss_krb5_unwrap_v2 against short tokens
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89575
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532259
Bugzilla Description: kernel: dm raid1: reserve space for NUL-terminator in build_constructor_string()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-170
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89645
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532260
Bugzilla Description: kernel: btrfs: drop recovered reloc root refs on recovery failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89449
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532262
Bugzilla Description: kernel: iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89455
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532263
Bugzilla Description: kernel: PCI: plda: Fix use-after-free of event IRQs during teardown
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89536
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532264
Bugzilla Description: kernel: SUNRPC: wait for in-flight client TLS handshake callback
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89584
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532265
Bugzilla Description: kernel: block: validate user space vectors during extraction
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1288
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89606
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532266
Bugzilla Description: kernel: ecryptfs: reject too-small tag 70 packets
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89649
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532268
Bugzilla Description: kernel: ceph: bound xattr value length in __build_xattrs()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89520
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532271
Bugzilla Description: kernel: sched/core: Make core-sched flips wait for in-flight selections
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-366
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89675
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532272
Bugzilla Description: kernel: nfsd: fix UAF in async copy cancel and shutdown
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89454
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532273
Bugzilla Description: kernel: PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80990
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532275
Bugzilla Description: kernel: net: thunderbolt: Release the Rx HopID that was handed out on mismatch
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80931
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532277
Bugzilla Description: kernel: w1: ds28e17: reject an oversize length on an I2C block read
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80985
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532279
Bugzilla Description: kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89571
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532280
Bugzilla Description: kernel: cxl/features: bound fwctl command payload to the input buffer
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89582
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532281
Bugzilla Description: kernel: bnx2x: fix double free in bnx2x_init_firmware() error path
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89651
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532282
Bugzilla Description: kernel: ceph: bound MDSCapAuth path and fs_name decode in handle_session()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80929
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532283
Bugzilla Description: kernel: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-279
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89585
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532284
Bugzilla Description: kernel: auxdisplay: charlcd: cancel backlight work on registration failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80966
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532285
Bugzilla Description: kernel: ALSA: portman2x4: Check card index validity at probe
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89670
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532286
Bugzilla Description: kernel: nfsd: hold rcu across localio cmpxchg retry
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81009
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532289
Bugzilla Description: kernel: io_uring/query: cap user size passed to copy_struct_to_user
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89479
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532290
Bugzilla Description: kernel: sctp: stop processing a packet once its association is deleted
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89580
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532292
Bugzilla Description: kernel: bpf: Disable preemption in __bpf_get_stack
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89636
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532294
Bugzilla Description: kernel: smb: client: clear ce->tgthint in free_tgts()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89568
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532296
Bugzilla Description: kernel: kho: fix size calculation in kho_preserved_memory_reserve()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1335
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89576
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532297
Bugzilla Description: kernel: dm-era: fix shadowed superblock leak on take-snap failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89600
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532299
Bugzilla Description: kernel: fanotify: fix use-after-free of file range info
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89657
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532301
Bugzilla Description: kernel: libceph: validate OSD extent maps before cursor advance
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89680
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532302
Bugzilla Description: kernel: nfsd: fix nfsd_file leak on inter-server COPY setup failure
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89618
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532303
Bugzilla Description: kernel: eventfs: Initialize ei->children and ei->list in init_ei()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89539
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532304
Bugzilla Description: kernel: SUNRPC: reject duplicate CREDS_VALUE options
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89563
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532305
Bugzilla Description: kernel: ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89572
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532306
Bugzilla Description: kernel: cpufreq: apple-soc: Fix OPP table cleanup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89508
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532308
Bugzilla Description: kernel: RDMA/ucma: Lock the handler in ucma_set_ib_path()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89526
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532309
Bugzilla Description: kernel: svcrdma: Validate Read chunk positions before reconstruction
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80970
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532310
Bugzilla Description: kernel: ALSA: FCP: do not copy out an uninitialised init response
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89744
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532312
Bugzilla Description: kernel: device property: fix infinite loop in fwnode_for_each_child_node()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89683
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532313
Bugzilla Description: kernel: nfsd: fix dentry ref leak on V4ROOT export filehandle lookup
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80993
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532314
Bugzilla Description: kernel: net: phylink: correctly validate returned PCS in phylink_inband_caps
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81005
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532315
Bugzilla Description: kernel: ipmi: si: Fix NULL pointer dereference after failed registration
CVSS Score:
CVSSv3 Score: 4.1
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80947
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532317
Bugzilla Description: kernel: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89614
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532318
Bugzilla Description: kernel: ntfs: bound the free-cluster bitmap scan to the volume
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89507
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532319
Bugzilla Description: kernel: RDMA/ucma: Lock the handler in ucma_write_cm_event()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89524
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532320
Bugzilla Description: kernel: wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89673
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532322
Bugzilla Description: kernel: nfsd: fix XDR padding calculation in ff_encode_getdeviceinfo
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80962
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532323
Bugzilla Description: kernel: dm-pcache: validate geometry fields from on-disk cache_info
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80964
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532324
Bugzilla Description: kernel: ALSA: virmidi: Check card index validity at probe
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80927
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532325
Bugzilla Description: kernel: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89564
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532326
Bugzilla Description: kernel: ip: orphan prefetched skbs before multicast forwarding
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89694
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532327
Bugzilla Description: kernel: nfsd: check client ownership when cancelling a copy-notify stateid
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-639
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89595
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532332
Bugzilla Description: kernel: fsnotify: Fix stale object mask after concurrent mark updates
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80933
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532333
Bugzilla Description: kernel: wifi: mt76: mt7996: validate default EEPROM firmware size
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89729
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532335
Bugzilla Description: kernel: HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89773
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532336
Bugzilla Description: kernel: drm/amd/display: Skip Update HDCP Config In Transition State
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89688
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532337
Bugzilla Description: kernel: nfsd: drop the stateid, not the stateowner, on seqid_op replay retry
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89519
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532339
Bugzilla Description: kernel: sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89502
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532342
Bugzilla Description: kernel: ring-buffer: Free cpu_buffer::free_page with subbuf_order
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89498
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532343
Bugzilla Description: kernel: orangefs: fix double-free of trailer_buf on readdir copy failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89601
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532345
Bugzilla Description: kernel: ext2: Fix lost inode updates for IS_SYNC inodes
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89661
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532346
Bugzilla Description: kernel: NFSD: Prevent post-shutdown use-after-free in unlock_filesystem
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89706
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532347
Bugzilla Description: kernel: nfsd: Reset write verifier when async COPY writeback fails
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81013
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532351
Bugzilla Description: kernel: platform/x86: hp-bioscfg: fix heap OOB read on empty password write
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89625
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532355
Bugzilla Description: kernel: HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89472
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532356
Bugzilla Description: kernel: power: supply: charger-manager: register regulators before exposing sysfs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89468
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532357
Bugzilla Description: kernel: power: supply: lp8788-charger: fix use-after-free on remove
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89747
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532358
Bugzilla Description: kernel: tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89442
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532359
Bugzilla Description: kernel: platform/x86: ISST: Validate socket ID in clos_assoc ioctl
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80959
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532361
Bugzilla Description: kernel: dm-pcache: bound the persisted tail-position offset
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89604
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532362
Bugzilla Description: kernel: efivarfs: Rate limit statfs() handler
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89739
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532363
Bugzilla Description: kernel: usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89460
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532364
Bugzilla Description: kernel: s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89656
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532365
Bugzilla Description: kernel: libceph: reject buckets with mismatched CRUSH ids
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80940
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532366
Bugzilla Description: kernel: wifi: rtw88: pci: fix resource leak on failed NAPI setup
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89730
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532368
Bugzilla Description: kernel: fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89745
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532369
Bugzilla Description: kernel: debugfs: Fix lockdown check for mmap_prepare
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-414
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80982
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532370
Bugzilla Description: kernel: net/smc: fix use-after-free in smc_rx_pipe_buf_release()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89474
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532371
Bugzilla Description: kernel: power: supply: bq256xx: drain usb_work before freeing the charger
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89523
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532372
Bugzilla Description: kernel: wifi: mt76: mt7925: cancel pending mlo_pm_work
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89695
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532373
Bugzilla Description: kernel: nfsd: cap decoded POSIX ACL count to bound sort cost
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-606
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89463
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532374
Bugzilla Description: kernel: power: supply: ucs1002: fix use-after-free on remove
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89551
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532375
Bugzilla Description: kernel: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-191
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89718
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532376
Bugzilla Description: kernel: zram: fix out-of-bounds access in writeback_store()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-131
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80928
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532381
Bugzilla Description: kernel: smack: fix cred UAF in smack_file_send_sigiotask()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89639
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532382
Bugzilla Description: kernel: cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-524
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89437
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532383
Bugzilla Description: kernel: platform/x86: int1092: Fix potential memory leak in sar_probe()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89741
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532384
Bugzilla Description: kernel: Revert "media: v4l2-dev: fix error handling in __video_register_device()"
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89674
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532385
Bugzilla Description: kernel: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89653
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532386
Bugzilla Description: kernel: ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89483
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532387
Bugzilla Description: kernel: nvme: zero the discard fallback page
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80937
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532388
Bugzilla Description: kernel: wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89681
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532389
Bugzilla Description: kernel: nfsd: fix layout fence worker double-reference race
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89493
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532390
Bugzilla Description: kernel: ocfs2: validate rl_used against rl_count in refcount block validator
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89619
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532392
Bugzilla Description: kernel: HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89531
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532393
Bugzilla Description: kernel: svcrdma: Reject connection when transport allocation fails
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89671
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532394
Bugzilla Description: kernel: nfsd: gate nfs3 setacl by argp->mask
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-115
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89616
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532395
Bugzilla Description: kernel: fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80963
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532397
Bugzilla Description: kernel: dm-stats: fix a crash if allocation of per-cpu data fails
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89471
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532398
Bugzilla Description: kernel: power: supply: cros_usbpd-charger: bound the EC-reported port count
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89691
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532399
Bugzilla Description: kernel: nfsd: clear opcnt on compound arg release to prevent OOB read
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80956
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532400
Bugzilla Description: kernel: dm-pcache: only hand out initialized cache segments
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89615
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532402
Bugzilla Description: kernel: fs/ntfs3: bound page_lcns[] index by the log record
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89602
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532403
Bugzilla Description: kernel: erofs: skip sufficiently large global buffers when resizing
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89637
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532405
Bugzilla Description: kernel: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89621
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532406
Bugzilla Description: kernel: HID: mcp2221: validate report size in mcp2221_raw_event()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89488
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532407
Bugzilla Description: kernel: openvswitch: Fix CT limit teardown use-after-free
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89696
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532408
Bugzilla Description: kernel: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89549
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532409
Bugzilla Description: kernel: sunrpc: route to a populated pool in svc_pool_for_cpu()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-821
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89465
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532410
Bugzilla Description: kernel: power: supply: rt9455: quiesce delayed work before teardown
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89632
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532415
Bugzilla Description: kernel: smb: client: fix use-before-check of ReparseDataLength in reparse_buf_ptr()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89767
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532416
Bugzilla Description: kernel: ovl: fix double end_creating() on the casefold-mismatch path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89443
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532417
Bugzilla Description: kernel: platform/x86: ISST: Validate level in perf mask ioctls
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89610
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532418
Bugzilla Description: kernel: ntfs: verify run length exceeding volume boundary
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89677
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532419
Bugzilla Description: kernel: nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89586
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532420
Bugzilla Description: kernel: ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-130
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80939
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532422
Bugzilla Description: kernel: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89740
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532424
Bugzilla Description: kernel: serial: imx: serialize imx_uart_ports[] lifetime
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89514
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532426
Bugzilla Description: kernel: scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80942
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532427
Bugzilla Description: kernel: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89724
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532428
Bugzilla Description: kernel: media: vicodec: fix out-of-bounds write in FWHT encoder
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80949
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532429
Bugzilla Description: kernel: wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81017
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532430
Bugzilla Description: kernel: platform/chrome: sensorhub: Bound the EC-reported sensor number
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81018
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532431
Bugzilla Description: kernel: platform/x86: think-lmi: Free system certificate signatures
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89613
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532432
Bugzilla Description: kernel: ntfs: reject invalid empty mapping pairs
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-130
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89762
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532435
Bugzilla Description: kernel: apparmor: fix cred UAF caused by begin_current_label_crit_section()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80984
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532437
Bugzilla Description: kernel: net/smc: do not dereference an unset send buffer on the SMC-D teardown path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89535
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532438
Bugzilla Description: kernel: svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89478
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532439
Bugzilla Description: kernel: sctp: drop a chunk if its transport was removed
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80991
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532440
Bugzilla Description: kernel: net: ravb: serialize PTP clock teardown
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-364
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89707
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532441
Bugzilla Description: kernel: nfsd: release path refs on follow_down() error
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89588
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532442
Bugzilla Description: kernel: ACPI: APEI: GHES: fix ARM section length accounting after header
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80938
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532443
Bugzilla Description: kernel: wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89491
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532444
Bugzilla Description: kernel: ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89715
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532445
Bugzilla Description: kernel: NFS/localio: fix ref leak on nfs_uuid_add_file failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89708
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532446
Bugzilla Description: kernel: nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89462
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532447
Bugzilla Description: kernel: power: supply: max17040: propagate register read errors
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-908
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89561
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532448
Bugzilla Description: kernel: ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89627
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532449
Bugzilla Description: kernel: HID: roccat: free buffered reports when destroying device
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89548
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532450
Bugzilla Description: kernel: SUNRPC: always drain cache_cleaner before destroying a cache_detail
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80989
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532453
Bugzilla Description: kernel: net: thunderbolt: Mark the connection down when bringing it up fails
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-1341
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81008
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532455
Bugzilla Description: kernel: interconnect: Fix use after free in icc_get() and of_icc_get_by_index()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80999
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532457
Bugzilla Description: kernel: net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-663
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89451
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532460
Bugzilla Description: kernel: iommu/sva: Set handle->dev before the SVA handle is visible
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89486
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532463
Bugzilla Description: kernel: ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89672
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532465
Bugzilla Description: kernel: nfsd: gate nfs2 setacl by argp->mask
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-266
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80969
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532468
Bugzilla Description: kernel: ALSA: mpu401: Check card index validity at probe
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80974
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532469
Bugzilla Description: kernel: mfd: sm501: Fix potential memory leaks during remove
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89703
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532470
Bugzilla Description: kernel: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89770
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532471
Bugzilla Description: kernel: iomap: don't free integrity payload that doesn't exist
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89702
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532472
Bugzilla Description: kernel: nfsd: size fh_verify server sockaddr slot by xpt_locallen
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89441
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532479
Bugzilla Description: kernel: mmc: via-sdmmc: cancel card-detect work on remove
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89728
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532480
Bugzilla Description: kernel: i3c: renesas: Fix out-of-bounds access for newdevs mask
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-805
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89692
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532481
Bugzilla Description: kernel: nfsd: clear CALLBACK_RUNNING on failed delegation recall queue
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89579
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532482
Bugzilla Description: kernel: bpf: Harden bloom filter sizing and indexing on 32-bit kernels
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80960
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532483
Bugzilla Description: kernel: dm-pcache: validate on-media seg_num against the cache device size
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89667
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532484
Bugzilla Description: kernel: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80976
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532485
Bugzilla Description: kernel: seg6: reset IP6CB after IPv6 decapsulation
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89662
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532486
Bugzilla Description: kernel: NFSD: Prevent lock owner use-after-free during client teardown
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80978
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532487
Bugzilla Description: kernel: net: cap advertised IP tunnel headroom
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89532
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532488
Bugzilla Description: kernel: svcrdma: Fix pcl_for_each_segment for empty chunks
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89492
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532489
Bugzilla Description: kernel: ocfs2: validate directory-index entry counts when reading metadata
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89705
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532490
Bugzilla Description: kernel: nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80972
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532492
Bugzilla Description: kernel: ALSA: aloop: Check card index validity at probe
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89603
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532493
Bugzilla Description: kernel: entry: Fix seccomp bypass after ptrace with TSYNC
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89556
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532494
Bugzilla Description: kernel: module: validate string table section types
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89759
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532495
Bugzilla Description: kernel: mm/kmemleak: avoid soft lockup when scanning task stacks
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1050
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89452
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532496
Bugzilla Description: kernel: iommu/msm: Unwind probe state on registration failure
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89689
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532497
Bugzilla Description: kernel: nfsd: don't free session slots that are still in use
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89665
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532498
Bugzilla Description: kernel: nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89499
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532499
Bugzilla Description: kernel: ring-buffer: Stop remote reader update when page swap fails
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-390
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89594
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532500
Bugzilla Description: kernel: hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-909
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89453
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532501
Bugzilla Description: kernel: iommu/amd: Put PCI device after handling PPR faults
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81011
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532502
Bugzilla Description: kernel: platform/x86: hp-bioscfg: pass validated element count to package parsers
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-81014
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532503
Bugzilla Description: kernel: platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89554
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532504
Bugzilla Description: kernel: mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-824
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89641
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532505
Bugzilla Description: kernel: cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89635
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532506
Bugzilla Description: kernel: ksmbd: only rebind the reopened file's own oplock on durable reconnect
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89711
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532508
Bugzilla Description: kernel: NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89525
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532509
Bugzilla Description: kernel: udf: reject VAT indexes equal to the entry count
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-1285
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89570
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532510
Bugzilla Description: kernel: cxl/mce: Make the MCE notifier per-region
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89522
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532511
Bugzilla Description: kernel: media: staging/ipu7: fix async notifier UAF on probe error path
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89496
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532512
Bugzilla Description: kernel: ocfs2: always run deallocs on copy-on-write completion
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89500
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532513
Bugzilla Description: kernel: ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-763
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89646
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532514
Bugzilla Description: kernel: ceph: fix leaked inode reference on writeback abort at umount
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89640
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532516
Bugzilla Description: kernel: cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89487
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532517
Bugzilla Description: kernel: openvswitch: only skb_tx_error() a packet we are about to drop
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89749
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532518
Bugzilla Description: kernel: tracing: Fix crash passing ERR_PTR to kthread_stop()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89666
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532519
Bugzilla Description: kernel: nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89727
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532521
Bugzilla Description: kernel: KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80951
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532522
Bugzilla Description: kernel: i3c: master: svc: bound IBI payload to the requested max_payload_len
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89607
Severity: important
Released on: 11/09/2026
Advisory:
Bugzilla: 2532523
Bugzilla Description: kernel: ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80954
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532524
Bugzilla Description: kernel: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-476
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89470
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532525
Bugzilla Description: kernel: power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-80941
Severity: low
Released on: 11/09/2026
Advisory:
Bugzilla: 2532526
Bugzilla Description: kernel: wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb()
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89668
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532527
Bugzilla Description: kernel: nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd()
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89664
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532528
Bugzilla Description: kernel: nfsd: release OPEN-decoded posix ACLs via op_release
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-911
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89629
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532529
Bugzilla Description: kernel: HID: corsair-void: Check size of status and firmware events before reading them
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89459
Severity: moderate
Released on: 11/09/2026
Advisory:
Bugzilla: 2532530
Bugzilla Description: kernel: s390/percpu: Fix MVIY_PERCPU() with older binutils
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-88
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-49838
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531686
Bugzilla Description: github.com/osrg/gobgp: GoBGP: Denial of Service via malformed BGP UPDATE message
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-49837
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531682
Bugzilla Description: github.com/osrg/gobgp: GoBGP: Malformed BGP OPEN message can disrupt BGP sessions
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-45769
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531963
Bugzilla Description: suricata: Suricata: Denial of Service via unbounded IKEv2 parser state
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-45768
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2532141
Bugzilla Description: suricata: Suricata: Denial of Service via unbounded LDAP responses
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-45767
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2533941
Bugzilla Description: suricata: Suricata: File overwrite via malicious rule load
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-73
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-45766
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531923
Bugzilla Description: suricata: Suricata: Denial of Service via unbounded NFS parser state structures
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-45765
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531990
Bugzilla Description: Suricata: Suricata: Denial of Service via unbounded DNP3 reassembly
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1284
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-45764
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531669
Bugzilla Description: suricata: Suricata http2: protocol-change type confusion can lead to denial of service
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-89011
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531620
Bugzilla Description: isomorphic-git: isomorphic-git: Information disclosure via prototype pollution in getRemoteInfo function.
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-915
Affected Packages:
Package States: Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-89298
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531871
Bugzilla Description: keycloak-services: keycloak-services: Confidential client secret disclosed to view-clients role via Client Registration GET
CVSS Score:
CVSSv3 Score: 4.9
Vector:
CWE: CWE-200
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-88059
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531610
Bugzilla Description: Angular: Angular: Information Leak via HttpTransferCache Bypass
CVSS Score:
CVSSv3 Score: 4.0
Vector:
CWE: CWE-524
Affected Packages:
Package States: A-MQ Interconnect 1,Red Hat Ceph Storage 4,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat OpenStack Platform 16.2,Red Hat Quay 3,Red Hat Quay 3,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-88057
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531602
Bugzilla Description: @angular/core: @angular/compiler: Angular: Arbitrary code execution via sanitization bypass in host bindings
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-79
Affected Packages:
Package States: Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat build of Apicurio Registry 3,Red Hat build of Apicurio Registry 3,Red Hat Ceph Storage 4,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Fuse 7,
Full Details
CVE document


CVE-2026-88033
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531595
Bugzilla Description: org.mongodb/mongodb-driver-core: MongoDB Java Driver: Data disclosure and denial of service via query-operator injection in GridFS file IDs
CVSS Score:
CVSSv3 Score: 8.3
Vector:
CWE: CWE-94
Affected Packages:
Package States: Exploit Intelligence,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Debezium 3,Red Hat build of Quarkus,Red Hat Fuse 7,
Full Details
CVE document


CVE-2026-88031
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531587
Bugzilla Description: go.mongodb.org/mongo-driver: go.mongodb.org/mongo-driver/v2: MongoDB Go Driver: Data deletion via query-operator injection in GridFS file IDs
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-1287
Affected Packages:
Package States: Assisted Installer for Red Hat OpenShift Container Platform 2,Assisted Installer for Red Hat OpenShift Container Platform 2,Assisted Installer for Red Hat OpenShift Container Platform 2,Assisted Installer for Red Hat OpenShift Container Platform 2,Compliance Operator,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Confidential Compute Attestation,Cryostat 4,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,Custom Metric Autoscaler operator for Red Hat Openshift,ExternalDNS Operator,ExternalDNS Operator,External Secrets Operator for Red Hat OpenShift,File Integrity Operator,File Integrity Operator,File Integrity Operator,File Integrity Operator,Lightspeed Core,Lightspeed Core,Logging Subsystem for Red Hat OpenShift,Logging Subsystem for Red Hat OpenShift,Logging Subsystem for Red Hat OpenShift,Logical Volume Manager Storage,MCP Server for Red Hat OpenShift,Migration Toolkit for Containers,Migration Toolkit for Containers,Migration Toolkit for Containers,Migration Toolkit for Virtualization,Migration Toolkit for Virtualization,Migration Toolkit for Virtualization,Migration Toolkit for Virtualization,Migration Toolkit for Virtualization,Migration Toolkit for Virtualization,Migration Toolkit for Virtualization,Migration Toolkit for Virtualization,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Engine for Kubernetes,Multicluster Global Hub,Node HealthCheck Operator,OpenShift API for Data Protection,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Lightspeed,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Pipelines,OpenShift Serverless,OpenShift Serverless,OpenShift Service Mesh 3,Pen Drive Powered by Red Hat Lightspeed,Power monitoring for Red Hat OpenShift,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat 3scale API Management Platform 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Advanced Cluster Management for Kubernetes 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ceph Storage 5,Red Hat Ceph Storage 5,Red Hat Ceph Storage 6,Red Hat Ceph Storage 6,Red Hat Ceph Storage 7,Red Hat Ceph Storage 7,Red Hat Ceph Storage 7,Red Hat Ceph Storage 8,Red Hat Ceph Storage 8,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Ceph Storage 9,Red Hat Certification Program for Red Hat Enterprise Linux 9,Red Hat Developer Hub,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Edge Manager 1,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift distributed tracing 3,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenShift Virtualization 4,Red Hat OpenStack Platform 18.0,Red Hat OpenStack Platform 18.0,Red Hat Service Interconnect 2,Red Hat Service Interconnect 2,Red Hat Service Interconnect 2,Red Hat Service Interconnect 2,Red Hat Service Interconnect 2,Red Hat Service Interconnect 2,Red Hat Service Interconnect 2,Red Hat Service Interconnect 2,Red Hat Service Interconnect 2,Red Hat Service Interconnect 2,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Trusted Artifact Signer,Red Hat Web Terminal,Security Profiles Operator,Security Profiles Operator,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,Zero Trust Workload Identity Manager - Tech Preview,
Full Details
CVE document


CVE-2026-88030
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531585
Bugzilla Description: rubygem-mongo: MongoDB Ruby Driver: Data disclosure and denial of service via query-operator injection
CVSS Score:
CVSSv3 Score: 8.3
Vector:
CWE: CWE-917
Affected Packages:
Package States: Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-88029
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531586
Bugzilla Description: pymongo: MongoDB Python Driver: Data disclosure and denial of service via query-operator injection
CVSS Score:
CVSSv3 Score: 8.3
Vector:
CWE: CWE-943
Affected Packages:
Package States: Red Hat Enterprise Linux 8,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-88024
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531580
Bugzilla Description: rust-mongodb: MongoDB Rust Driver (GridFS): Data disclosure and deletion via query-operator injection in file IDs.
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-94
Affected Packages:
Package States: Logging Subsystem for Red Hat OpenShift,
Full Details
CVE document


CVE-2026-88054
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531576
Bugzilla Description: tesseract: Tesseract: Denial of Service via crafted model with empty stack dereference
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-89046
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531577
Bugzilla Description: zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-125
Affected Packages:
Package States: Exploit Intelligence,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat build of Quarkus,Red Hat Ceph Storage 9,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-89045
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531570
Bugzilla Description: com.github.luben/zstd-jni: zstd-jni: Denial of Service via negative length parameter
CVSS Score:
CVSSv3 Score: 4.0
Vector:
CWE: CWE-835
Affected Packages:
Package States: Exploit Intelligence,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat build of Quarkus,Red Hat Ceph Storage 9,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-88053
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531573
Bugzilla Description: tesseract: Tesseract: Heap out-of-bounds write leads to heap corruption via crafted data file
CVSS Score:
CVSSv3 Score: 8.4
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-88052
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531579
Bugzilla Description: tesseract: Tesseract: Heap out-of-bounds write can lead to arbitrary code execution
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-88051
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531566
Bugzilla Description: tesseract: Tesseract: Heap out-of-bounds write via crafted .traineddata model
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-88050
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531551
Bugzilla Description: tesseract: Tesseract: Out-of-bounds write leads to Denial of Service
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-88049
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531554
Bugzilla Description: tesseract: Tesseract: Heap out-of-bounds write allows arbitrary code execution or denial of service
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-88048
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531546
Bugzilla Description: tesseract: Tesseract: Heap out-of-bounds write/read leading to information disclosure via crafted data
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-88047
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531550
Bugzilla Description: tesseract: Tesseract: Stack buffer overflow via crafted .traineddata file
CVSS Score:
CVSSv3 Score: 8.4
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-88046
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531548
Bugzilla Description: github.com/rclone/rclone: rclone: Unauthorized data modification via path traversal in source object names
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-22
Affected Packages:
Package States: Cryostat 4,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-88045
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531549
Bugzilla Description: github.com/rclone/rclone: rclone: Memory exhaustion leading to Denial of Service
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Cryostat 4,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-88015
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531541
Bugzilla Description: github.com/rclone/rclone: rclone: Denial of Service via crafted Range request against translated symlink
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-125
Affected Packages:
Package States: OpenShift Service Mesh 3,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Virtualization 4,
Full Details
CVE document


CVE-2026-88014
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531538
Bugzilla Description: github.com/rclone/rclone: rclone: Arbitrary file write via Zip Slip vulnerability
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-22
Affected Packages:
Package States: Cryostat 4,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-88013
Severity: low
Released on: 10/09/2026
Advisory:
Bugzilla: 2531530
Bugzilla Description: github.com/rclone/rclone: rclone: Information disclosure via HTTP backend forwarding headers on redirect
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-212
Affected Packages:
Package States: Cryostat 4,Red Hat Advanced Cluster Management for Kubernetes 2,
Full Details
CVE document


CVE-2026-88914
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531416
Bugzilla Description: gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux CEA-608 closed-caption parser
CVSS Score:
CVSSv3 Score: 4.4
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-88889
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531447
Bugzilla Description: renovate: Renovate: Remote code execution via command injection in Maven Wrapper manager
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-78
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-88888
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531420
Bugzilla Description: renovate: Renovate: Command Injection via Mix organization
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-78
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-88886
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531439
Bugzilla Description: renovate: Renovate: Arbitrary Command Execution via crafted Gradle Wrapper distributionUrl
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-78
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-88884
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531432
Bugzilla Description: renovate: mend-renovate-ce: mend-renovate-enterprise-edition: Renovate: Security control bypass via digest updates
CVSS Score:
CVSSv3 Score: 5.8
Vector:
CWE: CWE-807
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-88883
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531423
Bugzilla Description: renovate: Renovate: Information disclosure of TLS private keys via incomplete log sanitization
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-117
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-88879
Severity: critical
Released on: 10/09/2026
Advisory:
Bugzilla: 2531425
Bugzilla Description: github.com/traefik/traefik: Traefik: Identity spoofing via HTTP header alias
CVSS Score:
CVSSv3 Score: 9.6
Vector:
CWE: CWE-444
Affected Packages:
Package States: Red Hat OpenShift Dev Spaces,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,
Full Details
CVE document


CVE-2026-88878
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531451
Bugzilla Description: github.com/traefik/traefik: Traefik: Denial of Service via HTTP/3 timeout bypass
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat OpenShift Dev Spaces,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,
Full Details
CVE document


CVE-2026-88877
Severity: critical
Released on: 10/09/2026
Advisory:
Bugzilla: 2531428
Bugzilla Description: github.com/traefik/traefik: Traefik v3.7.0 Authentication Bypass via from-to-www-redirect
CVSS Score:
CVSSv3 Score: 9.1
Vector:
CWE: CWE-639
Affected Packages:
Package States: Red Hat OpenShift Dev Spaces,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,
Full Details
CVE document


CVE-2026-84828
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2527320
Bugzilla Description: pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-732
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,
Full Details
CVE document


CVE-2026-88859
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531401
Bugzilla Description: evolution: evolution: javascript execution via spoofed vCard control bypasses mail script-markup restriction
CVSS Score:
CVSSv3 Score: 6.3
Vector:
CWE: CWE-84
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-87962
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531399
Bugzilla Description: com.tdunning/t-digest: t-digest: t-digest: Denial of Service via unvalidated length fields
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Fuse 7,Red Hat Offline Knowledge Portal,
Full Details
CVE document


CVE-2026-61915
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2526315
Bugzilla Description: cyrus-imapd: cyrus-imapd: VPATCH BYPARAM double-free in CalDAV
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-415
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-61911
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2526313
Bugzilla Description: cyrus-imapd: cyrus-imapd: Sieve fileinto mailbox existence oracle
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-497
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-61910
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2526311
Bugzilla Description: cyrus-imapd: cyrus-imapd: Mailbox/set let sharee change special-use role on shared mailboxes
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-61909
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2526308
Bugzilla Description: cyrus-imapd: cyrus-imapd: CalDAV/CardDAV multiget bypasses per-href ACL
CVSS Score:
CVSSv3 Score: 5.0
Vector:
CWE: CWE-420
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-61908
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2526304
Bugzilla Description: cyrus-imapd: cyrus-imapd: JMAP email-header blob ID out-of-bounds index
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-88763
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531301
Bugzilla Description: skupper-router: skupper-router: Unbounded recursion in AMQP field parser leads to denial of service
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-674
Affected Packages:
Package States: Red Hat Service Interconnect 2,
Full Details
CVE document


CVE-2026-57822
Severity: moderate
Released on: 10/09/2026
Advisory: RHSA-2026:66488, RHSA-2026:66545,
Bugzilla: 2495823
Bugzilla Description: artemis-core-client: activemq-artemis: Unsafe deserialization via JsonUtil CompositeData on management address
CVSS Score:
CVSSv3 Score: 4.9
Vector:
CWE: CWE-502
Affected Packages: artemis-core-client,
Package States: Red Hat build of Apache Camel for Spring Boot 4,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-49363
Severity: moderate
Released on: 10/09/2026
Advisory: RHSA-2026:66488, RHSA-2026:66545,
Bugzilla: 2492627
Bugzilla Description: artemis-server: artemis-server: Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-306
Affected Packages: artemis-server,
Package States: Red Hat build of Apache Camel for Spring Boot 4,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,
Full Details
CVE document


CVE-2026-57967
Severity: important
Released on: 10/09/2026
Advisory: RHSA-2026:66488, RHSA-2026:66545, RHSA-2026:67604,
Bugzilla: 2480638
Bugzilla Description: artemis-server: Apache Artemis — session hijack via missing authentication
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-306
Affected Packages: eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el7eap,eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el7eap,eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap,eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap,eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el7eap,eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el8eap,eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el7eap,eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el7eap,eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el9eap,eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el7eap,eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap,eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap,eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap,artemis-server,eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap,eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el7eap,eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el7eap,eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el9eap,eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el8eap,eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap,
Package States: Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,
Full Details
CVE document


CVE-2026-49364
Severity: important
Released on: 10/09/2026
Advisory: RHSA-2026:66488, RHSA-2026:66545, RHSA-2026:67604,
Bugzilla: 2478013
Bugzilla Description: wildfly-messaging-activemq-subsystem: artemis-server: jgroups: artemis cluster password leak via jgroups spoof
CVSS Score:
CVSSv3 Score: 8.0
Vector:
CWE:
Affected Packages: eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el7eap,eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el7eap,eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap,eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap,eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el7eap,eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el8eap,eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el7eap,eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el7eap,eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el9eap,eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el7eap,eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap,eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap,eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap,artemis-server,eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap,eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el7eap,eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el7eap,eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el9eap,eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el8eap,eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap,
Package States: Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat Build of Keycloak,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform 8,
Full Details
CVE document


CVE-2026-49362
Severity: important
Released on: 10/09/2026
Advisory: RHSA-2026:66488, RHSA-2026:66545, RHSA-2026:67604,
Bugzilla: 2477945
Bugzilla Description: artemis-server: undertow-core: wildfly-messaging-activemq-subsystem: artemis core protocol permits unauthed queue creation
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE:
Affected Packages: eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el7eap,eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el7eap,eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el8eap,eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el8eap,eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el7eap,eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el8eap,eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el7eap,eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el7eap,eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el9eap,eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el7eap,eap7-jackson-core-0:2.18.9-1.redhat_00003.1.el8eap,eap7-jackson-jaxrs-providers-0:2.18.9-1.redhat_00003.1.el8eap,eap7-jackson-databind-0:2.18.9-1.redhat_00003.1.el9eap,eap7-jackson-modules-java8-0:2.18.9-1.redhat_00003.1.el8eap,artemis-server,eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el9eap,eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el7eap,eap7-jackson-modules-base-0:2.18.9-1.redhat_00003.1.el7eap,eap7-activemq-artemis-0:2.16.0-23.redhat_00058.1.el9eap,eap7-wildfly-0:7.4.25-6.GA_redhat_00005.1.el8eap,eap7-jackson-annotations-0:2.18.9-1.redhat_00003.1.el8eap,
Package States: Red Hat AMQ Clients,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel for Spring Boot 4,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform 8,
Full Details
CVE document


CVE-2026-67593
Severity: important
Released on: 10/09/2026
Advisory: RHSA-2026:66488, RHSA-2026:66545,
Bugzilla: 2510277
Bugzilla Description: artemis-openwire-protocol: AMQ Broker Artemis: pre-authentication arbitrary durable queue deletion via OpenWire RemoveSubscriptionInfo
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-306
Affected Packages: artemis-openwire-protocol,
Package States: Red Hat build of Apache Camel for Spring Boot 4,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,
Full Details
CVE document


CVE-2026-84939
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531282
Bugzilla Description: org.apache.freemarker/freemarker: Apache FreeMarker: Path traversal via malformed locale identifier
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-22
Affected Packages:
Package States: Exploit Intelligence,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apicurio Registry 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Fuse 7,Red Hat Fuse 7,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93579
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2536970
Bugzilla Description: io.netty/netty-codec-http2: Netty: HTTP/2 header field values are not validated by default (CR/LF/NUL passthrough)
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93578
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2536969
Bugzilla Description: io.netty/netty-handler-ssl-ocsp: Netty: Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat build of Apache Camel for Spring Boot 4,
Full Details
CVE document


CVE-2026-93576
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536968
Bugzilla Description: io.netty/netty-codec-smtp: Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-93
Affected Packages:
Package States: Red Hat build of Apache Camel for Spring Boot 4,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93575
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536967
Bugzilla Description: io.netty/netty-codec-mqtt: Netty: Resource Exhaustion in MqttDecoder
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat build of Apache Camel for Spring Boot 4,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93574
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2536966
Bugzilla Description: io.netty/netty-codec-http: Netty: HTTP request smuggling via post-digit whitespace in chunk-size parsing
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-444
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat AMQ Clients,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93573
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2536964
Bugzilla Description: io.netty/netty-codec-http: Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-444
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat AMQ Clients,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93572
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536963
Bugzilla Description: io.netty/netty-codec-redis: Netty: RedisArrayAggregator nested RESP headers multiply patched preallocation limits
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat build of Apache Camel for Spring Boot 4,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93569
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536962
Bugzilla Description: io.netty/netty-codec-http2: HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-444
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93568
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536961
Bugzilla Description: io.netty/netty-codec-http2: io.netty/netty-codec-http3: Netty: HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-20
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93567
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536955
Bugzilla Description: io.netty/netty-codec-http2: HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-20
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93566
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2536954
Bugzilla Description: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to control characters in the chunk-size line
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat AMQ Clients,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93565
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536952
Bugzilla Description: io.netty/netty-codec-http: Netty RtspDecoder Method-Token Smuggling via Trailing Control Byte
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat AMQ Clients,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93564
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536953
Bugzilla Description: io.netty/netty-codec-haproxy: Netty: HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (incomplete fix of PR #16881)
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93563
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536976
Bugzilla Description: io.netty/netty-codec-smtp: Netty: Unbounded multi-line response accumulation in SmtpResponseDecoder leads to memory-exhaustion DoS
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat build of Apache Camel for Spring Boot 4,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93562
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2536951
Bugzilla Description: io.netty/netty-codec-http: Netty: Incomplete validation of malformed Transfer-Encoding allows HTTP request smuggling
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat AMQ Clients,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93561
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536949
Bugzilla Description: io.netty/netty-codec-memcache: Netty: Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat build of Apache Camel for Spring Boot 4,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93560
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536939
Bugzilla Description: io.netty/netty-codec-stomp: Netty: STOMP codec content-length long-to-int truncation causes infinite decode loop DoS
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat build of Apache Camel for Spring Boot 4,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93558
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536932
Bugzilla Description: io.netty/netty-codec-http: Netty: Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of Service
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat AMQ Clients,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93494
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536898
Bugzilla Description: io.netty/netty-codec-stomp: Netty: ByteBuf Leak in StompSubframeDecoder When a Frame Body Is Never Terminated
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat build of Apache Camel for Spring Boot 4,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93493
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2536897
Bugzilla Description: io.netty/netty-handler-ssl-ocsp: Netty: OCSP Validation Silently Skipped When a Response Omits the Optional nextUpdate Field
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-299
Affected Packages:
Package States: Red Hat build of Apache Camel for Spring Boot 4,
Full Details
CVE document


CVE-2026-93492
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2536895
Bugzilla Description: io.netty/netty-codec-http2: Netty: HTTP/2 HpackEncoder DoS with large table size
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-1035
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93491
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536891
Bugzilla Description: io.netty/netty-codec-http: Netty: Denial of Service via unbounded HttpServerCodec HTTP/1.1 pipeline queue
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat AMQ Clients,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-93488
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2536887
Bugzilla Description: io.netty/netty-codec-http: Netty: Denial of Service via unbounded concurrent SPDY streams
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-770
Affected Packages:
Package States: Red Hat AMQ Broker 7,Red Hat AMQ Clients,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Data Grid 8,Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-87933
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531215
Bugzilla Description: cJSON: cJSON: Memory corruption via use after free in cJSONUtils_MergePatch
CVSS Score:
CVSSv3 Score: 8.6
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Hardened Images,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-84042
Severity: important
Released on: 10/09/2026
Advisory:
Bugzilla: 2531222
Bugzilla Description: crun: crun: rootful krun with passt executes container payload as host root
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-269
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-88264
Severity: moderate
Released on: 10/09/2026
Advisory:
Bugzilla: 2531223
Bugzilla Description: crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs
CVSS Score:
CVSSv3 Score: 5.6
Vector:
CWE: CWE-59
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-89060
Severity: important
Released on: 10/09/2026
Advisory: RHSA-2026:67542, RHSA-2026:67543, RHSA-2026:67540, RHSA-2026:67541, RHSA-2026:67539,
Bugzilla: 2531596
Bugzilla Description: stolostron/multicluster-observability-addon: Cross-namespace Secret disclosure in multicluster-observability-addon via unvalidated configuration references
CVSS Score:
CVSSv3 Score: 7.7
Vector:
CWE: CWE-551
Affected Packages: rhacm2/acm-multicluster-observability-addon-rhel9:1789126262,rhacm2/acm-multicluster-observability-addon-rhel9:1789126267,rhacm2/acm-multicluster-observability-addon-rhel9:1789126264,
Package States:
Full Details
CVE document


CVE-2026-19816
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2515940
Bugzilla Description: packagekit: PackageKit: PackageKit dnf5 ignores SIMULATE on RepoRemove
CVSS Score:
CVSSv3 Score: 7.1
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-88770
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2531302
Bugzilla Description: keycloak-services: keycloak-services: Device Authorization Grant issues tokens to brute-force-locked accounts
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-307
Affected Packages:
Package States: Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-87877
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2531003
Bugzilla Description: com.github.luben/zstd-jni: zstd-jni: Use-After-Free vulnerability allows memory corruption and denial of service
CVSS Score:
CVSSv3 Score: 7.7
Vector:
CWE: CWE-416
Affected Packages:
Package States: Exploit Intelligence,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat build of Quarkus,Red Hat Ceph Storage 9,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-87824
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530998
Bugzilla Description: com.github.luben/zstd-jni: zstd-jni: Denial of Service (DoS) via out-of-bounds read in Zstd.trainFromBufferDirect
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-125
Affected Packages:
Package States: Exploit Intelligence,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat build of Quarkus,Red Hat Ceph Storage 9,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-87825
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2531007
Bugzilla Description: com.github.luben/zstd-jni: zstd-jni: Data corruption or denial of service via use-after-free vulnerability
CVSS Score:
CVSSv3 Score: 7.7
Vector:
CWE: CWE-825
Affected Packages:
Package States: Exploit Intelligence,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat build of Quarkus,Red Hat Ceph Storage 9,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-87823
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2531004
Bugzilla Description: com.github.luben/zstd-jni: zstd-jni: Denial of Service or Information Disclosure via out-of-bounds read
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-125
Affected Packages:
Package States: Exploit Intelligence,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat build of Quarkus,Red Hat Ceph Storage 9,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-87822
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2531002
Bugzilla Description: t-digest: t-digest: Denial of Service via NaN centroid injection during deserialization
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-502
Affected Packages:
Package States: Red Hat Fuse 7,Red Hat Offline Knowledge Portal,
Full Details
CVE document


CVE-2026-87872
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530988
Bugzilla Description: community.general: community.general: OCAPI module_utils (ocapi_command, ocapi_info) hardcode validate_certs=False with no override, enabling TLS man-in-the-middle and credential disclosure
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-295
Affected Packages:
Package States: Red Hat Ceph Storage 5,Red Hat Ceph Storage 9,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-18147
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2508181
Bugzilla Description: freeipa: ipa: FreeIPA/IdM: Cross-Site Scripting vulnerability allows arbitrary code execution via crafted URL
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-79
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-87853
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530888
Bugzilla Description: sssd: sssd: IdP authentication prefix comparison allows cross-user impersonation
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-187
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-56711
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530917
Bugzilla Description: vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87817
Severity: important
Released on: 09/09/2026
Advisory: RHSA-2026:68764, RHSA-2026:68780,
Bugzilla: 2530744
Bugzilla Description: GitPython: GitPython: Remote Code Execution via Git directory impersonation
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-22
Affected Packages: satellite/iop-vmaas-rhel9:1789611858,satellite/iop-vmaas-rhel9:1789611998,
Package States: Exploit Intelligence,Exploit Intelligence,Migration Toolkit for Applications 8,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-87818
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530755
Bugzilla Description: GitPython: GitPython: Information disclosure through arbitrary file read
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-73
Affected Packages:
Package States: Exploit Intelligence,Exploit Intelligence,Migration Toolkit for Applications 8,Red Hat AI Inference Server,Red Hat AI Inference Server,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-73334
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530719
Bugzilla Description: org.apache.parquet/parquet-hadoop: Apache Parquet Hadoop: KMS token disclosure due to missing host validation
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat Fuse 7,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-87795
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530661
Bugzilla Description: com.github.luben/zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-125
Affected Packages:
Package States: Exploit Intelligence,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat build of Quarkus,Red Hat Ceph Storage 9,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Hardened Images,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-61907
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2526303
Bugzilla Description: cyrus-imapd: cyrus-imapd: JMAP snooze bypasses destination-mailbox ACL
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-863
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-87083
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530476
Bugzilla Description: tilelang: tile-ai tilelang: Remote deserialization vulnerability in Kernel Cache
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-502
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-87619
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530379
Bugzilla Description: chromium-browser: chromium-browser: Observable discrepancy in Prefetch
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-204
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87598
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530474
Bugzilla Description: chromium-browser: chromium-browser: Incorrect authorization in ServiceWorker
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-940
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87626
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530465
Bugzilla Description: chromium-browser: chromium-browser: Incorrect authorization in DeviceBoundSessionCredentials
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87566
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530394
Bugzilla Description: chromium-browser: chromium-browser: Observable discrepancy in Layout
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-204
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87468
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530429
Bugzilla Description: chromium-browser: chromium-browser: Incorrect authorization in Isolated
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-551
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87635
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530428
Bugzilla Description: chromium-browser: chromium-browser: UI misrepresentation in Payments
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87616
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530439
Bugzilla Description: chromium-browser: chromium-browser: Improper initialization in Views
CVSS Score:
CVSSv3 Score: 9.0
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87574
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530400
Bugzilla Description: chromium-browser: chromium-browser: Information leak in ServiceWorker
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87452
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530436
Bugzilla Description: chromium-browser: chromium-browser: Incorrect authorization in GPU
CVSS Score:
CVSSv3 Score: 4.8
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87501
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530449
Bugzilla Description: chromium-browser: chromium-browser: UI misrepresentation in Passwords
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87475
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530448
Bugzilla Description: chromium-browser: chromium-browser: Missing authorization in Omnibox
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-551
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87476
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530261
Bugzilla Description: chromium-browser: chromium-browser: Incorrect authorization in Loader
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-551
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87497
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530390
Bugzilla Description: chromium-browser: chromium-browser: Uninitialized resource in Codecs
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-824
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87645
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530318
Bugzilla Description: chromium-browser: chromium-browser: Improper state validation in Safebrowsing
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-79
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87443
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530446
Bugzilla Description: chromium-browser: chromium-browser: Missing authorization in Actor
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-425
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87471
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530269
Bugzilla Description: chromium-browser: chromium-browser: Incorrect authorization in ServiceWorker
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-266
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87465
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530263
Bugzilla Description: chromium-browser: chromium-browser: Incorrect authorization in Downloads
CVSS Score:
CVSSv3 Score: 4.6
Vector:
CWE: CWE-1021
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87588
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530327
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Chromecast
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87636
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530404
Bugzilla Description: chromium-browser: chromium-browser: Type confusion in XML
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87657
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530374
Bugzilla Description: chromium-browser: chromium-browser: Use after free in V8
CVSS Score:
CVSSv3 Score: 5.7
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87612
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530397
Bugzilla Description: chromium-browser: chromium-browser: Type confusion in V8
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87498
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530372
Bugzilla Description: chromium-browser: chromium-browser: Missing authorization in WebUI
CVSS Score:
CVSSv3 Score: 7.9
Vector:
CWE: CWE-346
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87499
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530388
Bugzilla Description: chromium-browser: chromium-browser: Incorrect authorization in Network
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-653
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87564
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530445
Bugzilla Description: chromium-browser: chromium-browser: Type confusion in V8
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-843
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87460
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530251
Bugzilla Description: chromium-browser: chromium-browser: Use after free in Platform
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-825
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87444
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530442
Bugzilla Description: chromium-browser: chromium-browser: Memory corruption in Codecs
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87766
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2530542
Bugzilla Description: bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-59
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-87876
Severity: low
Released on: 09/09/2026
Advisory: RHSA-2026:67568,
Bugzilla: 2530991
Bugzilla Description: cups: OpenPrinting CUPS: Remaining case-insensitive username matching in scheduler side paths (CVE-2026-27447 follow-up)
CVSS Score:
CVSSv3 Score: 3.0
Vector:
CWE: CWE-178
Affected Packages: cups-main-2.4.19-4.2.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-87875
Severity: moderate
Released on: 09/09/2026
Advisory: RHSA-2026:66600,
Bugzilla: 2530994
Bugzilla Description: cups: OpenPrinting CUPS: Heap out-of-bounds read in cupsUTF32ToUTF8() via missing source-length bound
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-125
Affected Packages: cups-main-2.4.19-4.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-87874
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2530995
Bugzilla Description: community.general: community.general: memcached cache plugin deserializes untrusted pickle data from memcached, enabling cache-poisoning remote code execution on the Ansible controller
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-502
Affected Packages:
Package States: Red Hat Ceph Storage 5,Red Hat Ceph Storage 9,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-80919
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2531054
Bugzilla Description: kernel: drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-833
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-88265
Severity: moderate
Released on: 09/09/2026
Advisory:
Bugzilla: 2531224
Bugzilla Description: crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and chown
CVSS Score:
CVSSv3 Score: 5.6
Vector:
CWE: CWE-59
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-88924
Severity: important
Released on: 09/09/2026
Advisory:
Bugzilla: 2531456
Bugzilla Description: gvfs: gvfs-admin socket ownership race permits local root
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-53938
Severity: important
Released on: 08/09/2026
Advisory:
Bugzilla: 2530240
Bugzilla Description: cjose: cjose: Heap buffer overflow in AES Key Wrap decryption leads to denial of service
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-787
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-87053
Severity: moderate
Released on: 08/09/2026
Advisory:
Bugzilla: 2530044
Bugzilla Description: operator-sdk-builder: operator-sdk-builder: Final container image runs as root (USER root never reverted)
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-250
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87054
Severity: moderate
Released on: 08/09/2026
Advisory:
Bugzilla: 2530045
Bugzilla Description: operator-sdk-builder: operator-sdk-builder: containers-policy.json defaults to insecureAcceptAnything for non-Red Hat registries
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-345
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87055
Severity: low
Released on: 08/09/2026
Advisory:
Bugzilla: 2530046
Bugzilla Description: operator-sdk-builder: operator-sdk-builder: Base image referenced by mutable tag rather than sha256 digest
CVSS Score:
CVSSv3 Score: 2.6
Vector:
CWE: CWE-829
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87056
Severity: low
Released on: 08/09/2026
Advisory:
Bugzilla: 2530047
Bugzilla Description: operator-sdk-builder: operator-sdk-builder: No automated dependency-update configuration for submodules or Containerfile
CVSS Score:
CVSSv3 Score: 2.6
Vector:
CWE: CWE-1104
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87049
Severity: important
Released on: 08/09/2026
Advisory:
Bugzilla: 2530049
Bugzilla Description: operator-foundry: operator-foundry: Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-269
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87050
Severity: moderate
Released on: 08/09/2026
Advisory:
Bugzilla: 2530050
Bugzilla Description: operator-foundry: operator-foundry: GitHub Actions and reusable workflow not pinned to commit SHA
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-829
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87051
Severity: low
Released on: 08/09/2026
Advisory:
Bugzilla: 2530051
Bugzilla Description: operator-foundry: operator-foundry: resolveAndValidatePath performs lexical containment only — symlinks can escape the build context
CVSS Score:
CVSSv3 Score: 2.6
Vector:
CWE: CWE-59
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87052
Severity: low
Released on: 08/09/2026
Advisory:
Bugzilla: 2530053
Bugzilla Description: operator-foundry: operator-foundry: No automated dependency-update or vulnerability-scanning configuration
CVSS Score:
CVSSv3 Score: 2.6
Vector:
CWE: CWE-1104
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87057
Severity: moderate
Released on: 08/09/2026
Advisory:
Bugzilla: 2530054
Bugzilla Description: olm-operator-konflux-sample: olm-operator-konflux-sample: Runtime base images referenced by mutable floating tags
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-829
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87058
Severity: low
Released on: 08/09/2026
Advisory:
Bugzilla: 2530055
Bugzilla Description: olm-operator-konflux-sample: olm-operator-konflux-sample: Hermetic build disabled by default; bundle build performs live network fetches
CVSS Score:
CVSSv3 Score: 2.6
Vector:
CWE: CWE-829
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87059
Severity: low
Released on: 08/09/2026
Advisory:
Bugzilla: 2530056
Bugzilla Description: olm-operator-konflux-sample: olm-operator-konflux-sample: Unpinned pip dependency installation in bundle builder stage
CVSS Score:
CVSSv3 Score: 2.6
Vector:
CWE: CWE-494
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87060
Severity: low
Released on: 08/09/2026
Advisory:
Bugzilla: 2530057
Bugzilla Description: olm-operator-konflux-sample: olm-operator-konflux-sample: Renovate automerge enabled with base-image update exclusions
CVSS Score:
CVSSv3 Score: 2.6
Vector:
CWE: CWE-1357
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87061
Severity: low
Released on: 08/09/2026
Advisory:
Bugzilla: 2530058
Bugzilla Description: olm-operator-konflux-sample: olm-operator-konflux-sample: bundle-hack/update_bundle.sh lacks fail-fast shell options
CVSS Score:
CVSSv3 Score: 2.6
Vector:
CWE: CWE-252
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87062
Severity: moderate
Released on: 08/09/2026
Advisory:
Bugzilla: 2530061
Bugzilla Description: konflux-operator-tasks: konflux-operator-tasks: GitHub Actions referenced by mutable tag/branch instead of commit SHA
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-829
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87063
Severity: low
Released on: 08/09/2026
Advisory:
Bugzilla: 2530062
Bugzilla Description: konflux-operator-tasks: konflux-operator-tasks: tkn CLI installed from network without checksum or signature verification
CVSS Score:
CVSSv3 Score: 2.6
Vector:
CWE: CWE-494
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87064
Severity: low
Released on: 08/09/2026
Advisory:
Bugzilla: 2530063
Bugzilla Description: konflux-operator-tasks: konflux-operator-tasks: GitHub workflows lack explicit least-privilege permissions blocks
CVSS Score:
CVSSv3 Score: 2.6
Vector:
CWE: CWE-269
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-87065
Severity: low
Released on: 08/09/2026
Advisory:
Bugzilla: 2530064
Bugzilla Description: konflux-operator-tasks: konflux-operator-tasks: Tekton task steps run as root without defense-in-depth securityContext hardening
CVSS Score:
CVSSv3 Score: 2.6
Vector:
CWE: CWE-250
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-58649
Severity: moderate
Released on: 08/09/2026
Advisory: RHSA-2026:68316, RHSA-2026:67524, RHSA-2026:67525, RHSA-2026:67613, RHSA-2026:68676, RHSA-2026:68233, RHSA-2026:67530, RHSA-2026:67528, RHSA-2026:67614,
Bugzilla: 2528870
Bugzilla Description: dotnet10.0: dotnet9.0: dotnet8.0: .NET Information Disclosure Vulnerability
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-346
Affected Packages: dotnet9.0-0:9.0.121-1.el9_8,dotnet10.0-0:10.0.112-1.el9_8,dotnet9.0-0:9.0.121-1.el8_10,dotnet8.0-0:8.0.131-1.el8_10,dotnet8.0-0:8.0.131-1.el9_8,dotnet10.0-0:10.0.112-1.el10_2,dotnet10.0-0:10.0.112-1.el8_10,dotnet8.0-0:8.0.131-1.el10_2,dotnet9.0-0:9.0.121-1.el10_2,
Package States: Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-69806
Severity: important
Released on: 08/09/2026
Advisory: RHSA-2026:67613, RHSA-2026:68676, RHSA-2026:68233, RHSA-2026:67530, RHSA-2026:67528, RHSA-2026:67614,
Bugzilla: 2528921
Bugzilla Description: dotnet10.0: dotnet9.0: .NET Elevation of Privilege Vulnerability
CVSS Score:
CVSSv3 Score: 7.0
Vector:
CWE: CWE-200
Affected Packages: dotnet9.0-0:9.0.121-1.el9_8,dotnet10.0-0:10.0.112-1.el9_8,dotnet9.0-0:9.0.121-1.el8_10,dotnet10.0-0:10.0.112-1.el10_2,dotnet10.0-0:10.0.112-1.el8_10,dotnet9.0-0:9.0.121-1.el10_2,
Package States: Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-12611
Severity: important
Released on: 08/09/2026
Advisory:
Bugzilla: 2529778
Bugzilla Description: org.eclipse.jetty.http2/http2-common: org.eclipse.jetty.http2/jetty-http2-common: Jetty: Denial of Service via HTTP/2 race condition
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat AMQ Broker 7,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apicurio Registry 3,Red Hat Fuse 7,Red Hat Offline Knowledge Portal,Red Hat Offline Knowledge Portal,Red Hat OpenStack Platform 13 (Queens),
Full Details
CVE document


CVE-2026-19203
Severity: important
Released on: 08/09/2026
Advisory:
Bugzilla: 2529768
Bugzilla Description: org.eclipse.jetty/jetty-http: Jetty: HTTP request smuggling via crafted chunked requests
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-444
Affected Packages:
Package States: Exploit Intelligence,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat AMQ Broker 7,Red Hat build of Apache Camel 4 for Quarkus 3,Red Hat build of Apache Camel for Spring Boot 4,Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Offline Knowledge Portal,Red Hat Offline Knowledge Portal,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenStack Platform 13 (Queens),Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-11573
Severity: important
Released on: 08/09/2026
Advisory:
Bugzilla: 2529762
Bugzilla Description: qtbase: qt5-qtbase: qt6-qtbase: qtbase: Denial of Service via uncontrolled recursion in XML serialization
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-776
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,
Full Details
CVE document


CVE-2026-80219
Severity: important
Released on: 08/09/2026
Advisory:
Bugzilla: 2524895
Bugzilla Description: hawtio-operator: hawtio-operator: OAuthClient created with GrantMethod auto and no secret enables OAuth token theft
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-1390
Affected Packages:
Package States: Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apache Camel - HawtIO 4,
Full Details
CVE document


CVE-2026-77968
Severity: important
Released on: 08/09/2026
Advisory: RHSA-2026:66120,
Bugzilla: 2524896
Bugzilla Description: hawtio-operator: hawtio-operator: Cluster-wide secrets read/write granted to operator ServiceAccount
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-269
Affected Packages: rhbac-4/hawtio-operator-bundle:2.0.1-8,rhbac-4/hawtio-rhel9-operator:2.0.1-10,
Package States: Red Hat build of Apache Camel - HawtIO 4,
Full Details
CVE document


CVE-2026-78234
Severity: important
Released on: 08/09/2026
Advisory: RHSA-2026:66120,
Bugzilla: 2524894
Bugzilla Description: hawtio-operator: hawtio-operator: Service-CA signing oracle allows arbitrary-CN certificate issuance to namespace edit users
CVSS Score:
CVSSv3 Score: 9.9
Vector:
CWE: CWE-295
Affected Packages: rhbac-4/hawtio-operator-bundle:2.0.1-8,rhbac-4/hawtio-rhel9-operator:2.0.1-10,
Package States: Red Hat build of Apache Camel - HawtIO 4,Red Hat build of Apache Camel - HawtIO 4,
Full Details
CVE document


CVE-2026-86564
Severity: low
Released on: 08/09/2026
Advisory:
Bugzilla: 2529682
Bugzilla Description: dpdk: dpdk: Missing length validation before reading command_data in virtio-net control queue handler
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-125
Affected Packages:
Package States: Fast Datapath for RHEL 10,Fast Datapath for RHEL 10,Fast Datapath for RHEL 8,Fast Datapath for RHEL 8,Fast Datapath for RHEL 8,Fast Datapath for RHEL 8,Fast Datapath for RHEL 8,Fast Datapath for RHEL 8,Fast Datapath for RHEL 8,Fast Datapath for RHEL 9,Fast Datapath for RHEL 9,Fast Datapath for RHEL 9,Fast Datapath for RHEL 9,Fast Datapath for RHEL 9,Fast Datapath for RHEL 9,Fast Datapath for RHEL 9,Fast Datapath for RHEL 9,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-76561
Severity: important
Released on: 07/09/2026
Advisory:
Bugzilla: 2519523
Bugzilla Description: pki-core: Dogtag/PKI: certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint)
CVSS Score:
CVSSv3 Score: 7.2
Vector:
CWE: CWE-78
Affected Packages:
Package States: Red Hat Certificate System 9,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-86321
Severity: moderate
Released on: 07/09/2026
Advisory:
Bugzilla: 2529509
Bugzilla Description: com.github.fge/jackson-coreutils: java-json-tools jackson-coreutils: Server-Side Request Forgery via JsonLoader.fromURL
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat Fuse 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 7,Red Hat JBoss Enterprise Application Platform 8,Red Hat JBoss Enterprise Application Platform Expansion Pack,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-86469
Severity: moderate
Released on: 07/09/2026
Advisory:
Bugzilla: 2473839
Bugzilla Description: glib2: TOCTOU Symlink Race in `G_FILE_CREATE_REPLACE_DESTINATION` Fallback Path
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-59
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-86318
Severity: moderate
Released on: 07/09/2026
Advisory:
Bugzilla: 2529484
Bugzilla Description: java-json-tools/json-patch: java-json-tools json-patch: Remote stack-based buffer overflow via JSON manipulation
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-120
Affected Packages:
Package States: Red Hat build of Apicurio Registry 3,Red Hat build of Debezium 3,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat Build of Keycloak,Red Hat build of Quarkus,Red Hat Fuse 7,
Full Details
CVE document


CVE-2026-86308
Severity: moderate
Released on: 07/09/2026
Advisory:
Bugzilla: 2529462
Bugzilla Description: cms: light0011 cms: Information disclosure via Debug Mode configuration
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-215
Affected Packages:
Package States: Red Hat Enterprise Linux 10,
Full Details
CVE document


CVE-2026-86425
Severity: low
Released on: 07/09/2026
Advisory:
Bugzilla: 2529445
Bugzilla Description: ImageMagick: PerlMagick: ImageMagick: Denial of Service due to heap-use-after-free vulnerability
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-86424
Severity: low
Released on: 07/09/2026
Advisory:
Bugzilla: 2529434
Bugzilla Description: ImageMagick: ImageMagick: Local attacker can modify files via TOCTOU symlink race
CVSS Score:
CVSSv3 Score: 2.5
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-86423
Severity: low
Released on: 07/09/2026
Advisory:
Bugzilla: 2529436
Bugzilla Description: ImageMagick: ImageMagick: Denial of service via heap-use-after-free in PerlMagick's GetList method
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-825
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-86422
Severity: low
Released on: 07/09/2026
Advisory:
Bugzilla: 2529438
Bugzilla Description: ImageMagick: ImageMagick: Information disclosure and modification via TOCTOU symlink race on Windows
CVSS Score:
CVSSv3 Score: 3.3
Vector:
CWE: CWE-367
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-86421
Severity: low
Released on: 07/09/2026
Advisory:
Bugzilla: 2529440
Bugzilla Description: ImageMagick: ImageMagick: Denial of Service via memory leak in MSL decoder
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-86420
Severity: low
Released on: 07/09/2026
Advisory:
Bugzilla: 2529441
Bugzilla Description: ImageMagick: ImageMagick: Denial of Service due to memory budget exhaustion
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,
Full Details
CVE document


CVE-2026-18922
Severity: critical
Released on: 07/09/2026
Advisory: RHSA-2026:64783, RHSA-2026:64784, RHSA-2026:64785, RHSA-2026:64790, RHSA-2026:64780, RHSA-2026:64791, RHSA-2026:64792, RHSA-2026:64781, RHSA-2026:64793, RHSA-2026:64771, RHSA-2026:64804, RHSA-2026:64776, RHSA-2026:64811, RHSA-2026:64789, RHSA-2026:64778, RHSA-2026:64779,
Bugzilla: 2511388
Bugzilla Description: 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property
CVSS Score:
CVSSv3 Score: 9.8
Vector:
CWE: CWE-287
Affected Packages: 389-ds-base-0:2.4.5-29.el9_4,389-ds-base-0:2.6.1-24.el9_6,389-ds-base-0:3.0.6-21.el10_0,redhat-ds:12-9020020260903155914.1674d574,389-ds:1.4-8040020260901171549.96015a92,389-ds-base-0:2.8.0-10.el9_8,389-ds-base-0:1.2.11.15-97.el6_10.1,389-ds-base-0:3.2.0-10.el10_2,redhat-ds:11-8080020260903102346.f969626e,redhat-ds:11-8100020260904171440.37ed7c03,redhat-ds:12-9040020260903102623.1674d574,389-ds:1.4-8080020260831180218.6dbb3803,389-ds:1.4-8100020260904155442.25e700aa,389-ds-base-0:1.3.11.1-15.el7_9,389-ds:1.4-8060020260901145727.824efc52,389-ds-base-0:2.2.4-22.el9_2,
Package States: Red Hat Directory Server 12,Red Hat Directory Server 13,
Full Details
CVE document


CVE-2026-19843
Severity: important
Released on: 07/09/2026
Advisory: RHSA-2026:64780, RHSA-2026:64792, RHSA-2026:64793, RHSA-2026:64782, RHSA-2026:65375, RHSA-2026:64769, RHSA-2026:64779, RHSA-2026:64768,
Bugzilla: 2515965
Bugzilla Description: 389-ds-base: 389-ds-base: Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor
CVSS Score:
CVSSv3 Score: 8.4
Vector:
CWE: CWE-78
Affected Packages: 389-ds-base-0:3.0.6-4.el10dsrv,redhat-ds:12-9040020260903102623.1674d574,redhat-ds:12-9020020260903155914.1674d574,389-ds-base-0:3.2.0-7.el10dsrv,redhat-ds:12-9060020260903100230.1674d574,redhat-ds:11-8080020260903102346.f969626e,redhat-ds:11-8100020260904171440.37ed7c03,redhat-ds:12-9080020260908092641.1674d574,
Package States: Red Hat Directory Server 11,Red Hat Directory Server 12,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-76560
Severity: important
Released on: 07/09/2026
Advisory: RHSA-2026:64783, RHSA-2026:64784, RHSA-2026:64785, RHSA-2026:64790, RHSA-2026:64780, RHSA-2026:64791, RHSA-2026:64792, RHSA-2026:64781, RHSA-2026:64793, RHSA-2026:64771, RHSA-2026:64804, RHSA-2026:64776, RHSA-2026:64789, RHSA-2026:64778, RHSA-2026:64779, RHSA-2026:65119,
Bugzilla: 2519521
Bugzilla Description: 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-863
Affected Packages: 389-ds-base-0:2.4.5-29.el9_4,389-ds-base-0:2.6.1-24.el9_6,389-ds-base-0:3.0.6-21.el10_0,redhat-ds:12-9020020260903155914.1674d574,389-ds:1.4-8040020260901171549.96015a92,389-ds-base-0:2.8.0-10.el9_8,389-ds-base-0:3.2.0-10.el10_2,redhat-ds:11-8080020260903102346.f969626e,redhat-ds:11-8100020260904171440.37ed7c03,redhat-ds:12-9040020260903102623.1674d574,389-ds:1.4-8080020260831180218.6dbb3803,389-ds:1.4-8100020260904155442.25e700aa,dirsrv/dirsrv-container-rhel10:1788851765,389-ds-base-0:1.3.11.1-15.el7_9,389-ds:1.4-8060020260901145727.824efc52,389-ds-base-0:2.2.4-22.el9_2,
Package States: Red Hat Directory Server 11,Red Hat Directory Server 12,Red Hat Directory Server 12,Red Hat Directory Server 13,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 8,
Full Details
CVE document


CVE-2026-76578
Severity: critical
Released on: 07/09/2026
Advisory:
Bugzilla: 2519522
Bugzilla Description: ipa: freeipa: FreeIPA: unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI
CVSS Score:
CVSSv3 Score: 9.8
Vector:
CWE: CWE-306
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-79678
Severity: important
Released on: 07/09/2026
Advisory:
Bugzilla: 2523356
Bugzilla Description: freeIPA: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-95
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-19204
Severity: important
Released on: 07/09/2026
Advisory:
Bugzilla: 2529344
Bugzilla Description: org.eclipse.jetty.websocket/websocket-core-common: Jetty: Denial of Service via crafted WebSocket frame with unknown opcode
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1284
Affected Packages:
Package States: Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-18355
Severity: important
Released on: 07/09/2026
Advisory: RHSA-2026:64783, RHSA-2026:64784, RHSA-2026:64785, RHSA-2026:64790, RHSA-2026:64780, RHSA-2026:64791, RHSA-2026:64792, RHSA-2026:64781, RHSA-2026:64793, RHSA-2026:64771, RHSA-2026:64804, RHSA-2026:64776, RHSA-2026:64789, RHSA-2026:64778, RHSA-2026:64779, RHSA-2026:65119,
Bugzilla: 2509186
Bugzilla Description: 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet()
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-191
Affected Packages: 389-ds-base-0:2.4.5-29.el9_4,389-ds-base-0:2.6.1-24.el9_6,389-ds-base-0:3.0.6-21.el10_0,redhat-ds:12-9020020260903155914.1674d574,389-ds:1.4-8040020260901171549.96015a92,389-ds-base-0:2.8.0-10.el9_8,389-ds-base-0:3.2.0-10.el10_2,redhat-ds:11-8080020260903102346.f969626e,redhat-ds:11-8100020260904171440.37ed7c03,redhat-ds:12-9040020260903102623.1674d574,389-ds:1.4-8080020260831180218.6dbb3803,389-ds:1.4-8100020260904155442.25e700aa,dirsrv/dirsrv-container-rhel10:1788851765,389-ds-base-0:1.3.11.1-15.el7_9,389-ds:1.4-8060020260901145727.824efc52,389-ds-base-0:2.2.4-22.el9_2,
Package States: Red Hat Directory Server 12,Red Hat Directory Server 13,Red Hat Enterprise Linux 6,
Full Details
CVE document


CVE-2026-18453
Severity: important
Released on: 07/09/2026
Advisory: RHSA-2026:64783, RHSA-2026:64784, RHSA-2026:64785, RHSA-2026:64790, RHSA-2026:64780, RHSA-2026:64791, RHSA-2026:64792, RHSA-2026:64781, RHSA-2026:64793, RHSA-2026:64771, RHSA-2026:64804, RHSA-2026:64776, RHSA-2026:64789, RHSA-2026:64778, RHSA-2026:64779, RHSA-2026:65119,
Bugzilla: 2509696
Bugzilla Description: 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-476
Affected Packages: 389-ds-base-0:2.4.5-29.el9_4,389-ds-base-0:2.6.1-24.el9_6,389-ds-base-0:3.0.6-21.el10_0,redhat-ds:12-9020020260903155914.1674d574,389-ds:1.4-8040020260901171549.96015a92,389-ds-base-0:2.8.0-10.el9_8,389-ds-base-0:3.2.0-10.el10_2,redhat-ds:11-8080020260903102346.f969626e,redhat-ds:11-8100020260904171440.37ed7c03,redhat-ds:12-9040020260903102623.1674d574,389-ds:1.4-8080020260831180218.6dbb3803,389-ds:1.4-8100020260904155442.25e700aa,dirsrv/dirsrv-container-rhel10:1788851765,389-ds-base-0:1.3.11.1-15.el7_9,389-ds:1.4-8060020260901145727.824efc52,389-ds-base-0:2.2.4-22.el9_2,
Package States: Red Hat Directory Server 12,Red Hat Directory Server 13,Red Hat Enterprise Linux 6,
Full Details
CVE document


CVE-2026-84732
Severity: important
Released on: 07/09/2026
Advisory:
Bugzilla: 2529320
Bugzilla Description: openvpn: OpenVPN: Remote Denial of Service via crafted ACK packets
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-190
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-84256
Severity: important
Released on: 07/09/2026
Advisory:
Bugzilla: 2529309
Bugzilla Description: OpenVPN: OpenVPN: Arbitrary command execution via crafted certificate subject
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-88
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-84226
Severity: important
Released on: 07/09/2026
Advisory:
Bugzilla: 2529304
Bugzilla Description: OpenVPN: OpenVPN: Arbitrary Code Execution via Binary Planting on Windows
CVSS Score:
CVSSv3 Score: 7.8
Vector:
CWE: CWE-426
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-78254
Severity: moderate
Released on: 07/09/2026
Advisory:
Bugzilla: 2529299
Bugzilla Description: org.apache.ant/ant: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks
CVSS Score:
CVSSv3 Score: 6.8
Vector:
CWE: CWE-22
Affected Packages:
Package States: Migration Toolkit for Applications 8,Migration Toolkit for Applications 8,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,OpenShift Developer Tools and Services,Red Hat build of Apicurio Registry 3,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Fuse 7,Red Hat JBoss Web Server 6,Red Hat JBoss Web Server 6,Red Hat JBoss Web Server 7,Red Hat Single Sign-On 7,
Full Details
CVE document


CVE-2026-82312
Severity: moderate
Released on: 07/09/2026
Advisory:
Bugzilla: 2529300
Bugzilla Description: openvpn: OpenVPN: Denial of service via NULL DACL on named IPC objects
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-279
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-81830
Severity: moderate
Released on: 07/09/2026
Advisory:
Bugzilla: 2529302
Bugzilla Description: OpenVPN: OpenVPN: Security Bypass via incorrect file path validation
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-22
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-81738
Severity: low
Released on: 07/09/2026
Advisory:
Bugzilla: 2529301
Bugzilla Description: openvpn: OpenVPN: Out-of-bounds write via crafted DOMAIN-SEARCH entries
CVSS Score:
CVSSv3 Score: 4.2
Vector:
CWE: CWE-787
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-78221
Severity: important
Released on: 07/09/2026
Advisory:
Bugzilla: 2529297
Bugzilla Description: OpenVPN: OpenVPN: Memory corruption and information disclosure vulnerability
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-120
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-78043
Severity: moderate
Released on: 07/09/2026
Advisory:
Bugzilla: 2529298
Bugzilla Description: OpenVPN: OpenVPN: Privilege Escalation via Arbitrary Configuration File Loading
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-22
Affected Packages:
Package States:
Full Details
CVE document


CVE-2026-86332
Severity: moderate
Released on: 07/09/2026
Advisory:
Bugzilla: 2529287
Bugzilla Description: odh-dashboard: odh-dashboard: NIM credential Secret readable by any authenticated user
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-862
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-86315
Severity: moderate
Released on: 07/09/2026
Advisory:
Bugzilla: 2529280
Bugzilla Description: Escargot: Escargot: Out-of-bounds write leads to Denial of Service
CVSS Score:
CVSSv3 Score: 6.2
Vector:
CWE: CWE-787
Affected Packages:
Package States: OpenShift Lightspeed,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Update Service,
Full Details
CVE document


CVE-2026-82209
Severity: low
Released on: 06/09/2026
Advisory:
Bugzilla: 2529207
Bugzilla Description: curl: libcurl: Information disclosure via improper Public Suffix List boundary check
CVSS Score:
CVSSv3 Score: 3.1
Vector:
CWE: CWE-501
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-19931
Severity: moderate
Released on: 06/09/2026
Advisory:
Bugzilla: 2529199
Bugzilla Description: curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-488
Affected Packages:
Package States: Confidential Compute Attestation,Confidential Compute Attestation,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-18924
Severity: low
Released on: 06/09/2026
Advisory:
Bugzilla: 2529201
Bugzilla Description: curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-416
Affected Packages:
Package States: Confidential Compute Attestation,Confidential Compute Attestation,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-13608
Severity: low
Released on: 06/09/2026
Advisory:
Bugzilla: 2529198
Bugzilla Description: curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-347
Affected Packages:
Package States: Confidential Compute Attestation,Confidential Compute Attestation,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Dev Spaces,Red Hat Satellite 6,Red Hat Satellite 6,Red Hat Satellite 6,
Full Details
CVE document


CVE-2026-86253
Severity: moderate
Released on: 06/09/2026
Advisory:
Bugzilla: 2529156
Bugzilla Description: h3: h3: Arbitrary File Read via Path Traversal
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-86252
Severity: moderate
Released on: 06/09/2026
Advisory:
Bugzilla: 2529158
Bugzilla Description: h3: h3: Server-Sent Events (SSE) injection via carriage return
CVSS Score:
CVSSv3 Score: 5.3
Vector:
CWE: CWE-93
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-86251
Severity: moderate
Released on: 06/09/2026
Advisory:
Bugzilla: 2529161
Bugzilla Description: h3: h3: Information disclosure via path traversal due to double-decoding flaw
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-22
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-86250
Severity: important
Released on: 06/09/2026
Advisory:
Bugzilla: 2529162
Bugzilla Description: h3: h3: Denial of Service via unbounded chunked cookie processing
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-606
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-86205
Severity: moderate
Released on: 06/09/2026
Advisory:
Bugzilla: 2529167
Bugzilla Description: h3: h3: Open Redirect vulnerability via unsanitized Referer header
CVSS Score:
CVSSv3 Score: 5.4
Vector:
CWE: CWE-601
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-18238
Severity: moderate
Released on: 05/09/2026
Advisory:
Bugzilla: 2529090
Bugzilla Description: libpcap: libpcap: Information disclosure via out-of-bounds read in rpcap client
CVSS Score:
CVSSv3 Score: 5.0
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-18313
Severity: moderate
Released on: 05/09/2026
Advisory:
Bugzilla: 2529092
Bugzilla Description: libpcap: libpcap: Denial of Service via memory leak in rpcapd
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-772
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-6554
Severity: moderate
Released on: 05/09/2026
Advisory:
Bugzilla: 2529091
Bugzilla Description: libpcap: libpcap: Denial of Service via infinite loop in BPF interpreter
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-6244
Severity: moderate
Released on: 05/09/2026
Advisory:
Bugzilla: 2529094
Bugzilla Description: libpcap: libpcap: Denial of Service via crafted BPF filter program
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-369
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-31911
Severity: moderate
Released on: 05/09/2026
Advisory:
Bugzilla: 2529089
Bugzilla Description: libpcap: libpcap: Denial of Service via crafted BPF opcode
CVSS Score:
CVSSv3 Score: 5.5
Vector:
CWE: CWE-617
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-31912
Severity: moderate
Released on: 05/09/2026
Advisory:
Bugzilla: 2529088
Bugzilla Description: libpcap: libpcap: Denial of service via crafted BPF filter program
CVSS Score:
CVSSv3 Score: 6.1
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-0799
Severity: important
Released on: 05/09/2026
Advisory:
Bugzilla: 2529093
Bugzilla Description: libpcap: libpcap: Out-of-bounds read and write vulnerability allows arbitrary memory access
CVSS Score:
CVSSv3 Score: 8.7
Vector:
CWE: CWE-125
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-86145
Severity: important
Released on: 05/09/2026
Advisory: RHSA-2026:67534,
Bugzilla: 2528993
Bugzilla Description: pcre2: PCRE2: Out-of-bounds write allows arbitrary code execution via crafted regular expressions
CVSS Score:
CVSSv3 Score: 8.2
Vector:
CWE: CWE-787
Affected Packages: pcre2-main-10.48-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-86144
Severity: moderate
Released on: 05/09/2026
Advisory: RHSA-2026:64463,
Bugzilla: 2528992
Bugzilla Description: libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation.
CVSS Score:
CVSSv3 Score: 5.6
Vector:
CWE: CWE-669
Affected Packages: libxml2-main-2.15.4-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-86143
Severity: moderate
Released on: 05/09/2026
Advisory: RHSA-2026:64463,
Bugzilla: 2528987
Bugzilla Description: libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks
CVSS Score:
CVSSv3 Score: 6.9
Vector:
CWE: CWE-192
Affected Packages: libxml2-main-2.15.4-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-86142
Severity: moderate
Released on: 05/09/2026
Advisory: RHSA-2026:64463,
Bugzilla: 2528990
Bugzilla Description: libxml2: libxml2: Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturation
CVSS Score:
CVSSv3 Score: 6.9
Vector:
CWE: CWE-805
Affected Packages: libxml2-main-2.15.4-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-86141
Severity: low
Released on: 05/09/2026
Advisory: RHSA-2026:64463,
Bugzilla: 2528988
Bugzilla Description: libxml2: libxml2: Denial of Service due to NULL pointer dereference in xmlRegNewParserCtxt
CVSS Score:
CVSSv3 Score: 2.9
Vector:
CWE: CWE-252
Affected Packages: libxml2-main-2.15.4-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-86140
Severity: important
Released on: 05/09/2026
Advisory: RHSA-2026:64463,
Bugzilla: 2528989
Bugzilla Description: libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-120
Affected Packages: libxml2-main-2.15.4-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-86139
Severity: moderate
Released on: 05/09/2026
Advisory: RHSA-2026:64463,
Bugzilla: 2528991
Bugzilla Description: libxml2: libxml2: Integer overflow in xmlURIEscapeStr may lead to arbitrary code execution
CVSS Score:
CVSSv3 Score: 6.9
Vector:
CWE: CWE-190
Affected Packages: libxml2-main-2.15.4-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-86138
Severity: moderate
Released on: 05/09/2026
Advisory: RHSA-2026:64463,
Bugzilla: 2528986
Bugzilla Description: libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow
CVSS Score:
CVSSv3 Score: 6.9
Vector:
CWE: CWE-190
Affected Packages: libxml2-main-2.15.4-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-86137
Severity: low
Released on: 05/09/2026
Advisory: RHSA-2026:64463,
Bugzilla: 2528985
Bugzilla Description: libxml2: libxml2: Denial of Service via out-of-bounds read in xmlFAParsePosCharGroup
CVSS Score:
CVSSv3 Score: 2.9
Vector:
CWE: CWE-125
Affected Packages: libxml2-main-2.15.4-0.1.hum1,
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-53769
Severity: moderate
Released on: 04/09/2026
Advisory:
Bugzilla: 2528883
Bugzilla Description: avo: Avo: Unauthorized attachment modification via authorization bypass
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-639
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-85781
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2528853
Bugzilla Description: github.com/kubernetes-sigs/aws-efs-csi-driver: Amazon EFS CSI Driver: Unauthorized directory deletion via unverified access point ownership
CVSS Score:
CVSSv3 Score: 7.7
Vector:
CWE: CWE-639
Affected Packages:
Package States: Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-18149
Severity: moderate
Released on: 04/09/2026
Advisory: RHSA-2026:54389, RHSA-2026:54438, RHSA-2026:66008,
Bugzilla: 2528802
Bugzilla Description: undici: undici: Denial of Service due to orphaned response body in retry handler
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-911
Affected Packages: nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1,grafana12-4-main-12.4.10-0.2.hum1,nodejs26-main-26.7.0-1.5.2.hum1,
Package States: Exploit Intelligence,OpenShift Pipelines,OpenShift Pipelines,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-18540
Severity: low
Released on: 04/09/2026
Advisory: RHSA-2026:66008, RHSA-2026:66605,
Bugzilla: 2528783
Bugzilla Description: undici: undici: HTTP response splitting via retry interceptor
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-444
Affected Packages: nodejs26-main-26.8.2-0.1.hum1,grafana12-4-main-12.4.10-0.2.hum1,
Package States: Exploit Intelligence,OpenShift Pipelines,OpenShift Pipelines,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-19534
Severity: important
Released on: 04/09/2026
Advisory: RHSA-2026:69248, RHSA-2026:66008, RHSA-2026:66605,
Bugzilla: 2528759
Bugzilla Description: undici: undici: Denial of Service via unrequested WebSocket subprotocol
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-476
Affected Packages: nodejs26-main-26.8.2-0.1.hum1,grafana12-4-main-12.4.10-0.2.hum1,rhdh/rhdh-hub-rhel9:1789554285,
Package States: Exploit Intelligence,OpenShift Pipelines,OpenShift Pipelines,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-84890
Severity: moderate
Released on: 04/09/2026
Advisory: RHSA-2026:54389, RHSA-2026:54438, RHSA-2026:66008,
Bugzilla: 2528772
Bugzilla Description: undici: undici: Denial of Service via unbounded decompression of compressed responses
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-409
Affected Packages: nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1,grafana12-4-main-12.4.10-0.2.hum1,nodejs26-main-26.7.0-1.5.2.hum1,
Package States: Exploit Intelligence,OpenShift Pipelines,OpenShift Pipelines,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-84933
Severity: moderate
Released on: 04/09/2026
Advisory: RHSA-2026:54389, RHSA-2026:54438, RHSA-2026:66008,
Bugzilla: 2528756
Bugzilla Description: undici: undici: Cross-user cookie disclosure via Set-Cookie caching
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-524
Affected Packages: nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1,grafana12-4-main-12.4.10-0.2.hum1,nodejs26-main-26.7.0-1.5.2.hum1,
Package States: Exploit Intelligence,OpenShift Pipelines,OpenShift Pipelines,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-84947
Severity: moderate
Released on: 04/09/2026
Advisory: RHSA-2026:54389, RHSA-2026:54438, RHSA-2026:66008,
Bugzilla: 2528754
Bugzilla Description: undici: Undici: Response truncation and connection termination
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-130
Affected Packages: nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1,grafana12-4-main-12.4.10-0.2.hum1,nodejs26-main-26.7.0-1.5.2.hum1,
Package States: Exploit Intelligence,OpenShift Pipelines,OpenShift Pipelines,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-84961
Severity: important
Released on: 04/09/2026
Advisory: RHSA-2026:69248, RHSA-2026:54438, RHSA-2026:66008, RHSA-2026:66605,
Bugzilla: 2528735
Bugzilla Description: undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-295
Affected Packages: nodejs26-main-26.8.2-0.1.hum1,nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1,grafana12-4-main-12.4.10-0.2.hum1,rhdh/rhdh-hub-rhel9:1789554285,
Package States: Exploit Intelligence,OpenShift Pipelines,OpenShift Pipelines,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-85008
Severity: low
Released on: 04/09/2026
Advisory: RHSA-2026:54389, RHSA-2026:54438, RHSA-2026:66008,
Bugzilla: 2528747
Bugzilla Description: undici: undici: Integrity failure due to caching of unsafe HTTP method responses
CVSS Score:
CVSSv3 Score: 3.7
Vector:
CWE: CWE-444
Affected Packages: nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1,grafana12-4-main-12.4.10-0.2.hum1,nodejs26-main-26.7.0-1.5.2.hum1,
Package States: Exploit Intelligence,OpenShift Pipelines,OpenShift Pipelines,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-85152
Severity: important
Released on: 04/09/2026
Advisory: RHSA-2026:63782, RHSA-2026:54389, RHSA-2026:54438,
Bugzilla: 2528717
Bugzilla Description: undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-346
Affected Packages: grafana12-4-main-12.4.9-0.6.hum1,nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1,nodejs26-main-26.7.0-1.5.2.hum1,
Package States: Exploit Intelligence,OpenShift Pipelines,OpenShift Pipelines,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-85014
Severity: moderate
Released on: 04/09/2026
Advisory: RHSA-2026:54389, RHSA-2026:54438, RHSA-2026:66008,
Bugzilla: 2528712
Bugzilla Description: undici: undici: Denial of Service via WebSocketStream unclean close
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-390
Affected Packages: nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1,grafana12-4-main-12.4.10-0.2.hum1,nodejs26-main-26.7.0-1.5.2.hum1,
Package States: Exploit Intelligence,OpenShift Pipelines,OpenShift Pipelines,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-85024
Severity: moderate
Released on: 04/09/2026
Advisory: RHSA-2026:63782, RHSA-2026:66605,
Bugzilla: 2528707
Bugzilla Description: undici: undici: Denial of Service via unhandled error in WebSocket permessage-deflate decompression
CVSS Score:
CVSSv3 Score: 5.9
Vector:
CWE: CWE-431
Affected Packages: nodejs26-main-26.8.2-0.1.hum1,grafana12-4-main-12.4.9-0.6.hum1,
Package States: Exploit Intelligence,OpenShift Pipelines,OpenShift Pipelines,Red Hat AMQ Broker 7,Red Hat AMQ Broker 7,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Enterprise Linux 9,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat Openshift Data Foundation 4,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat OpenShift Dev Spaces,Red Hat Trusted Artifact Signer,Secrets Management Console for Red Hat OpenShift,Self-service automation portal 2,Self-service automation portal 2,
Full Details
CVE document


CVE-2026-85730
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2528569
Bugzilla Description: smol-toml: smol-toml: Denial of Service via malformed TOML documents
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-835
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,Red Hat Ansible Automation Platform 2,Red Hat Build of Podman Desktop,Red Hat Developer Hub,Red Hat Enterprise Linux 10,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat Hardened Images,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-85666
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2533309
Bugzilla Description: ogx: OGX: Information disclosure via Server-Side Request Forgery in MCP tool server_url
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-918
Affected Packages:
Package States: Lightspeed Core,Lightspeed Core,Lightspeed Core,Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-85625
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2533311
Bugzilla Description: sift: sift 17.1.3 Prototype Pollution Remote Code Execution via $where
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-94
Affected Packages:
Package States: Red Hat Ansible Automation Platform 2,
Full Details
CVE document


CVE-2026-85623
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2531504
Bugzilla Description: goose: Goose: Arbitrary Command Execution via Recipe Extensions
CVSS Score:
CVSSv3 Score: 8.8
Vector:
CWE: CWE-78
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 9,
Full Details
CVE document


CVE-2026-85597
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2528835
Bugzilla Description: github.com/traefik/traefik: Traefik: Authentication bypass via TLS option conflict
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-303
Affected Packages:
Package States: Red Hat OpenShift Dev Spaces,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,
Full Details
CVE document


CVE-2026-85596
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2529028
Bugzilla Description: github.com/traefik/traefik: Traefik: Authentication bypass due to TLS configuration conflict
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-305
Affected Packages:
Package States: Red Hat OpenShift Dev Spaces,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,
Full Details
CVE document


CVE-2026-85595
Severity: critical
Released on: 04/09/2026
Advisory:
Bugzilla: 2529027
Bugzilla Description: github.com/traefik/traefik: Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth
CVSS Score:
CVSSv3 Score: 9.1
Vector:
CWE: CWE-305
Affected Packages:
Package States: Red Hat OpenShift Dev Spaces,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,
Full Details
CVE document


CVE-2026-85594
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2529861
Bugzilla Description: github.com/traefik/traefik: Traefik: Information disclosure via crossProviderNamespaces bypass in Kubernetes Ingress provider
CVSS Score:
CVSSv3 Score: 7.7
Vector:
CWE: CWE-1220
Affected Packages:
Package States: Red Hat OpenShift Dev Spaces,Red Hat OpenShift GitOps,Red Hat OpenShift GitOps,
Full Details
CVE document


CVE-2026-84428
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2528468
Bugzilla Description: fastify: fastify: Header validation bypass via incomplete schema case normalization
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1289
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-84469
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2528458
Bugzilla Description: fastify: Fastify: Request validation bypass allows unauthorized operations
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-1287
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-76169
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2528456
Bugzilla Description: fastify: fastify: Authentication bypass via malformed URLs
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-289
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-84504
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2528450
Bugzilla Description: fastify: fastify: Unauthorized state changes and data disclosure via request body replacement
CVSS Score:
CVSSv3 Score: 8.1
Vector:
CWE: CWE-179
Affected Packages:
Package States: Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat Enterprise Linux AI (RHEL AI) 3,Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift AI (RHOAI),Red Hat OpenShift Dev Spaces,
Full Details
CVE document


CVE-2026-71198
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2524517
Bugzilla Description: openstack-glance: openstack-glance: SSRF via location API missing host validation
CVSS Score:
CVSSv3 Score: 7.7
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-71197
Severity: moderate
Released on: 04/09/2026
Advisory:
Bugzilla: 2524518
Bugzilla Description: openstack-glance: openstack-glance: SSRF blocklist bypass via hostname-to-IP resolution gap in web-download
CVSS Score:
CVSSv3 Score: 4.3
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-81665
Severity: important
Released on: 04/09/2026
Advisory: RHSA-2026:67872, RHSA-2026:67873, RHSA-2026:67881, RHSA-2026:68574, RHSA-2026:67880, RHSA-2026:67878, RHSA-2026:67879,
Bugzilla: 2524910
Bugzilla Description: corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-122
Affected Packages: corosync-0:3.1.9-1.el10_0.3,corosync-0:3.1.10-1.el9_8.2,corosync-0:2.4.5-7.el7_9.4,corosync-0:3.1.10-1.el10_2.2,corosync-0:3.1.7-1.el9_2.2,corosync-0:3.1.8-1.el9_4.2,corosync-0:3.1.9-2.el9_6.2,
Package States: Red Hat Enterprise Linux 8,Red Hat OpenShift Container Platform 4,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-71196
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2524516
Bugzilla Description: openstack-glance: openstack-glance: SSRF via web-download import due to empty default host filters
CVSS Score:
CVSSv3 Score: 7.7
Vector:
CWE: CWE-918
Affected Packages:
Package States: Red Hat OpenStack Platform 13 (Queens),Red Hat OpenStack Platform 16.2,Red Hat OpenStack Platform 17.1,Red Hat OpenStack Platform 18.0,
Full Details
CVE document


CVE-2026-85525
Severity: important
Released on: 04/09/2026
Advisory:
Bugzilla: 2528435
Bugzilla Description: snowflake-connector-python: github.com/snowflakedb/snowflake-go: snowflake-sdk: net.snowflake/snowflake-jdbc: Snowflake Drivers: Data interception via improper OCSP response validation
CVSS Score:
CVSSv3 Score: 7.4
Vector:
CWE: CWE-295
Affected Packages:
Package States: Red Hat OpenShift AI (RHOAI),
Full Details
CVE document


CVE-2026-81666
Severity: moderate
Released on: 04/09/2026
Advisory:
Bugzilla: 2524923
Bugzilla Description: corosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems
CVSS Score:
CVSSv3 Score: 6.5
Vector:
CWE: CWE-190
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,Red Hat OpenShift Container Platform 4,
Full Details
CVE document


CVE-2026-85509
Severity: moderate
Released on: 04/09/2026
Advisory:
Bugzilla: 2528399
Bugzilla Description: FreeIPMI: FreeIPMI: Arbitrary code execution via stack-based buffer overflow
CVSS Score:
CVSSv3 Score: 7.5
Vector:
CWE: CWE-121
Affected Packages:
Package States: Red Hat Enterprise Linux 10,Red Hat Enterprise Linux 6,Red Hat Enterprise Linux 7,Red Hat Enterprise Linux 8,Red Hat Enterprise Linux 9,
Full Details
CVE document