Skip to main content

Threats Tagged 'red-hat-product-security'

View all threats tagged with 'red-hat-product-security'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: red-hat-product-security

Threats Tagged 'red-hat-product-security'

Click on any threat for detailed analysis and mitigation recommendations

0

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (CVE-2026-64320) * kernel: udp: fix potential use-after-free in tunnel segmentation (CVE-2026-74705) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: Linux kernel: xfrm single-frag length not properly limited () * kernel: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (CVE-2026-46149) * kernel: blk-cgroup: fix UAF in __blkcg_rstat_flush() (CVE-2026-63802) * kernel: udp: fix potential use-after-free in tunnel segmentation (CVE-2026-74705) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Red Hat has issued a critical security advisory for Red Hat Ansible Automation Platform 2.7 Container Release. This update addresses multiple security vulnerabilities affecting the platform, which provides an enterprise framework for IT automation. The advisory includes fixes for several CVEs and related bugs. Users are advised to apply the update after ensuring all previous errata are applied. No specific affected versions are detailed in the advisory.

Join the discussion

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ipvlan: Make the addrs_lock be per port (CVE-2026-23103) * kernel: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (CVE-2026-53360) * kernel: vsock/virtio: fix zerocopy completion for multi-skb sends (CVE-2026-53365) * kernel: NFSD: Fix SECINFO_NO_NAME decode error cleanup (CVE-2026-53398) * kernel: vsock/virtio: bind uarg before filling zerocopy skb (CVE-2026-63970) * kernel: igc: set tx buffer type for SMD frames (CVE-2026-64035) * kernel: vsock/vmci: fix UAF when peer resets connection during handshake (CVE-2026-64115) * kernel: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (CVE-2026-72317) * kernel: udp: fix potential use-after-free in tunnel segmentation (CVE-2026-74705) * kernel: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev (CVE-2026-74744) * kernel: nfsd: defer vfree of compound ops to fix rpc_status UAF (CVE-2026-89690) * kernel: nfsd: initialize copy-notify stateid before publishing it (CVE-2026-89669) * kernel: svcrdma: Reject inline replies that overflow the pull-up buffer (CVE-2026-89530) * kernel: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY (CVE-2026-89676) * kernel: nfsd: revoke copy-notify stateids before dropping their reference (CVE-2026-89663) * kernel: nfsd: fix UAF in async copy cancel and shutdown (CVE-2026-89675) Bug Fix(es) and Enhancement(s): * mlxbf_bootctl: driver update to Linux v6.16 [Nvidia 10.2.z FEAT] (JIRA:RHEL-212709) * [GNR-D] missing interfaces tspll_cfg [rhel-10.2] (JIRA:RHEL-273805) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

A security vulnerability (CVE-2026-49825) affecting the lxml HTML cleaner component used in Python environments has been identified and addressed by Red Hat. The issue involves a URL bypass vulnerability in the Cleaner due to a missing xlink:href attribute. This vulnerability affects multiple specific versions of Red Hat Quay and related Python lxml packages. Red Hat has issued an important security advisory with updated packages to remediate this issue.

Join the discussion

A security update for PostgreSQL 12 addresses a vulnerability (CVE-2026-18408) that allows arbitrary code execution via untrusted data inclusion in the pg_dump utility. This vulnerability affects Red Hat Enterprise Linux 8.4 Extended Life Cycle Long Life versions. The issue is rated as important by Red Hat Product Security. A security fix is available and should be applied to affected systems to mitigate the risk.

Join the discussion

The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix.

Join the discussion

This update includes the following RPMs: nodejs24: * nodejs24-24.18.1-0.1.hum1 (aarch64, x86_64) * nodejs24-bin-24.18.1-0.1.hum1 (noarch) * nodejs24-devel-24.18.1-0.1.hum1 (aarch64, x86_64) * nodejs24-docs-24.18.1-0.1.hum1 (noarch) * nodejs24-full-i18n-24.18.1-0.1.hum1 (aarch64, x86_64) * nodejs24-libs-24.18.1-0.1.hum1 (aarch64, x86_64) * nodejs24-npm-11.16.0-1.24.18.1.0.1.hum1 (noarch) * nodejs24-npm-bin-24.18.1-0.1.hum1 (noarch) * v8-13.6-devel-13.6.233.17-1.24.18.1.0.1.hum1 (aarch64, x86_64) * nodejs24-24.18.1-0.1.hum1.src (src)

Join the discussion

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.22.15. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:68550 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/

Join the discussion

This security update provides a functional equivalent of RHSA-2026:45114. The original Red Hat(R) advisory is available from the Red Hat web site at https://access.redhat.com/errata/RHSA-2026:45114.

Join the discussion

Showing 1 to 10 of 4050 results

Filters:Tag: red-hat-product-security
Page 1 of 405
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses