CVE Tools

Red Hat Enterprise Linux

1,104 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Red Hat Enterprise Linux, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Enterprise Linux CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Enterprise Linux CVEs per month
MonthCVEs
2024-1011
2024-1119
2024-121
2025-0111
2025-0225
2025-0318
2025-0429
2025-0518
2025-0629
2025-0719
2025-088
2025-0913
2025-1010
2025-1117
2025-128
2026-0118
2026-0220
2026-0338
2026-0445
2026-0525
2026-0686
2026-0793
2026-08100
2026-09114

Severity

How the 1,104 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical232%
  • High40236%
  • Medium59654%
  • Low838%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Enterprise Linux.

  1. CVE-2026-93834Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape8.8
  2. CVE-2026-95521Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm7.8
  3. CVE-2026-95519Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows)7.8
  4. CVE-2026-97185Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file7.8
  5. CVE-2026-96889Librsvg: use-after-free when xml includes have duplicated entities7.8
  6. CVE-2026-96546Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader2.5
  7. CVE-2026-96545Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader4.4
  8. CVE-2026-96541Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline7.5
  9. CVE-2026-96276Flatpak: flatpak: arbitrary write in host context via flatpak build-init9.8
  10. CVE-2026-96275Flatpak: flatpak: arbitrary write access as root via extra-data extraction8.8
  11. CVE-2026-96512Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization7.8
  12. CVE-2026-96442Emacs: emacs: arbitrary code execution in flymake mode7.8
  13. CVE-2026-13087Kernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path...8.8
  14. CVE-2026-90462Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization5.4
  15. CVE-2026-94640Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store