CVE Tools

Red Hat Enterprise Linux

10,988 CVEs tracked. 114 of them are in CISA KEV.

This hub aggregates every CVE we track for Red Hat Enterprise Linux, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Enterprise Linux CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Enterprise Linux CVEs per month
MonthCVEs
2024-10184
2024-11128
2024-12183
2025-01107
2025-02288
2025-03149
2025-04126
2025-05254
2025-06259
2025-07282
2025-0869
2025-09377
2025-10346
2025-1175
2025-12199
2026-01107
2026-0245
2026-03118
2026-0488
2026-0558
2026-0698
2026-0793
2026-08100
2026-09114

Severity

How the 10,988 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical9088%
  • High4,29539%
  • Medium5,28848%
  • Low4975%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Enterprise Linux.

  1. CVE-2026-93834Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape8.8
  2. CVE-2026-95521Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm7.8
  3. CVE-2026-95519Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows)7.8
  4. CVE-2026-97185Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file7.8
  5. CVE-2026-96889Librsvg: use-after-free when xml includes have duplicated entities7.8
  6. CVE-2026-96546Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader2.5
  7. CVE-2026-96545Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader4.4
  8. CVE-2026-96541Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline7.5
  9. CVE-2026-96276Flatpak: flatpak: arbitrary write in host context via flatpak build-init9.8
  10. CVE-2026-96275Flatpak: flatpak: arbitrary write access as root via extra-data extraction8.8
  11. CVE-2026-96512Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization7.8
  12. CVE-2026-96442Emacs: emacs: arbitrary code execution in flymake mode7.8
  13. CVE-2026-13087Kernel: heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path...8.8
  14. CVE-2026-90462Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization5.4
  15. CVE-2026-94640Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store