Red Hat Enterprise Linux 9.2 Extended Update Support
113 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Red Hat Enterprise Linux 9.2 Extended Update Support, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Red Hat Enterprise Linux 9.2 Extended Update Support CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 3 |
| 2024-11 | 1 |
| 2024-12 | 1 |
| 2025-01 | 2 |
| 2025-02 | 10 |
| 2025-03 | 0 |
| 2025-04 | 13 |
| 2025-05 | 1 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 113 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High67
- Medium41
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Red Hat Enterprise Linux 9.2 Extended Update Support.
- CVE-2025-4948Libsoup: integer underflow in soup_multipart_new_from_message() leading to denial of service in libsoup7.5
- CVE-2025-46421Libsoup: information disclosure may leads libsoup client sends authorization header to a different host when being redirected by a server6.8
- CVE-2025-46420Libsoup: memory leak on soup_header_parse_quality_list() via soup-headers.c6.5
- CVE-2025-32911Libsoup: double free on soup_message_headers_get_content_disposition() through "soup-message-headers.c" via "params" ghashtable value9.0
- CVE-2025-32914Libsoup: oob read on libsoup through function "soup_multipart_new_from_message" in soup-multipart.c leads to crash or exit of process7.4
- CVE-2025-32907Libsoup: denial of service in server when client requests a large amount of overlapping ranges with range header5.3
- CVE-2025-32906Libsoup: out of bounds reads in soup_headers_parse_request()7.5
- CVE-2025-32913Libsoup: null pointer dereference in soup_message_headers_get_content_disposition when "filename" parameter is present, but has no value in content-disposition header7.5
- CVE-2025-32053Libsoup: heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space()6.5
- CVE-2025-32052Libsoup: heap buffer overflow in sniff_unknown()6.5
- CVE-2025-32050Libsoup: integer overflow in append_param_quoted5.9
- CVE-2025-32049Libsoup: denial of service attack to websocket server7.5
- CVE-2025-3155Yelp: arbitrary file read7.4
- CVE-2025-2784Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content7.0
- CVE-2025-26601Xorg: xwayland: use-after-free in syncinittrigger()7.8
Product grouping is registry-driven, with AI assist and human review. How it works