CVE Tools

Red Hat Enterprise Linux 9.4 Extended Update Support

118 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Red Hat Enterprise Linux 9.4 Extended Update Support, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Enterprise Linux 9.4 Extended Update Support CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Enterprise Linux 9.4 Extended Update Support CVEs per month
MonthCVEs
2024-106
2024-112
2024-121
2025-013
2025-0213
2025-032
2025-0417
2025-057
2025-0615
2025-077
2025-082
2025-094
2025-105
2025-116
2025-125
2026-012
2026-023
2026-036
2026-046
2026-053
2026-060
2026-070
2026-080
2026-090

Severity

How the 118 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical54%
  • High7463%
  • Medium3832%
  • Low11%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Enterprise Linux 9.4 Extended Update Support.

  1. CVE-2026-4802Cockpit: cockpit: arbitrary command execution via crafted links in system logs ui8.0
  2. CVE-2026-34002Xorg: xwayland: x.org x server: information disclosure or denial of service via out-of-bounds read in xkb modifier map handling6.1
  3. CVE-2026-34000Xwayland: xorg: x.org x server: information disclosure and denial of service via out-of-bounds read in xkb geometry processing.6.1
  4. CVE-2026-34003Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access7.8
  5. CVE-2026-34001Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption7.8
  6. CVE-2026-33999Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling7.8
  7. CVE-2026-4878Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()6.7
  8. CVE-2026-35092Corosync: corosync: denial of service via integer overflow in join message validation7.5
  9. CVE-2026-35091Corosync: corosync: denial of service and information disclosure via crafted udp packet8.2
  10. CVE-2026-5201Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image7.5
  11. CVE-2026-5121Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing7.5
  12. CVE-2026-4775Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing7.8
  13. CVE-2026-4424Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing7.5
  14. CVE-2026-4111Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive7.5
  15. CVE-2025-12801Nfs-utils: rpc.mountd in the nfs-utils privilege escalation6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store