Red Hat Enterprise Linux 9.4 Extended Update Support
118 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Red Hat Enterprise Linux 9.4 Extended Update Support, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Red Hat Enterprise Linux 9.4 Extended Update Support CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 6 |
| 2024-11 | 2 |
| 2024-12 | 1 |
| 2025-01 | 3 |
| 2025-02 | 13 |
| 2025-03 | 2 |
| 2025-04 | 17 |
| 2025-05 | 7 |
| 2025-06 | 15 |
| 2025-07 | 7 |
| 2025-08 | 2 |
| 2025-09 | 4 |
| 2025-10 | 5 |
| 2025-11 | 6 |
| 2025-12 | 5 |
| 2026-01 | 2 |
| 2026-02 | 3 |
| 2026-03 | 6 |
| 2026-04 | 6 |
| 2026-05 | 3 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 118 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical5
- High74
- Medium38
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Red Hat Enterprise Linux 9.4 Extended Update Support.
- CVE-2026-4802Cockpit: cockpit: arbitrary command execution via crafted links in system logs ui8.0
- CVE-2026-34002Xorg: xwayland: x.org x server: information disclosure or denial of service via out-of-bounds read in xkb modifier map handling6.1
- CVE-2026-34000Xwayland: xorg: x.org x server: information disclosure and denial of service via out-of-bounds read in xkb geometry processing.6.1
- CVE-2026-34003Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access7.8
- CVE-2026-34001Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption7.8
- CVE-2026-33999Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling7.8
- CVE-2026-4878Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()6.7
- CVE-2026-35092Corosync: corosync: denial of service via integer overflow in join message validation7.5
- CVE-2026-35091Corosync: corosync: denial of service and information disclosure via crafted udp packet8.2
- CVE-2026-5201Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image7.5
- CVE-2026-5121Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing7.5
- CVE-2026-4775Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing7.8
- CVE-2026-4424Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing7.5
- CVE-2026-4111Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive7.5
- CVE-2025-12801Nfs-utils: rpc.mountd in the nfs-utils privilege escalation6.5
Product grouping is registry-driven, with AI assist and human review. How it works