CVE-2026-104988Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allows certificate mis-issuance with arbitrary subject Exploitation status Not confirmed Fix Not confirmed Published 10/02/2026 Severity High CVE-2026-94422xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape Exploitation status Not known exploited Fix YesPublished 10/02/2026 Severity High CVE-2026-95512Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader Exploitation status Not confirmed Fix Not confirmed Published 10/02/2026 Severity Medium CVE-2026-86345389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result Exploitation status Not confirmed Fix Not confirmed Published 10/01/2026 Severity Critical CVE-2026-86344389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue Exploitation status Not known exploited Fix Not confirmed Published 10/01/2026 Severity High CVE-2026-103641Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder Exploitation status Not known exploited Fix Not confirmed Published 10/01/2026 Severity Medium CVE-2026-103399Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body Exploitation status Not known exploited Fix Not confirmed Published 09/30/2026 Severity Medium CVE-2026-103242Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag Exploitation status Not known exploited Fix Not confirmed Published 09/30/2026 Severity High CVE-2026-102560Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-102559Libsoup: libsoup: heap buffer overflow during websocket client-frame masking Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-102558Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-102555Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-102557Libsoup: libsoup: heap buffer overflow during websocket message reassembly Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-102556Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-95520Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-97029Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity Medium CVE-2026-97024Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-97027Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus service files Exploitation status Not known exploited Fix Not confirmed Published 09/28/2026 Severity Low CVE-2026-97026Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path Exploitation status Not known exploited Fix Not confirmed Published 09/28/2026 Severity Low CVE-2026-97025Flatpak: flatpak: world-readable oci authentication token in system-helper cache path Exploitation status Not known exploited Fix Not confirmed Published 09/28/2026 Severity Low CVE-2026-102010Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in binary heap erase_if Exploitation status Not known exploited Fix Not confirmed Published 09/28/2026 Severity High CVE-2026-97023Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy directory export/bin Exploitation status Not known exploited Fix Not confirmed Published 09/28/2026 Severity High CVE-2026-96284Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following Exploitation status Not known exploited Fix Not confirmed Published 09/27/2026 Severity Low CVE-2026-96282Flatpak: flatpak: extension metadata path traversal file existence oracle Exploitation status Not known exploited Fix Not confirmed Published 09/27/2026 Severity Low CVE-2026-96283Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pull Exploitation status Not known exploited Fix Not confirmed Published 09/27/2026 Severity Low CVE-2026-96281Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes Exploitation status Not known exploited Fix Not confirmed Published 09/27/2026 Severity Medium CVE-2026-96280Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems Exploitation status Not known exploited Fix Not confirmed Published 09/27/2026 Severity High CVE-2026-96279Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks Exploitation status Not known exploited Fix Not confirmed Published 09/27/2026 Severity Medium CVE-2026-93834Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape Exploitation status Public exploit Fix Not confirmed Published 09/25/2026 Severity High CVE-2026-95521Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm Exploitation status Not known exploited Fix Not confirmed Published 09/24/2026 Severity High CVE-2026-95519Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows) Exploitation status Not known exploited Fix Not confirmed Published 09/24/2026 Severity High CVE-2026-97185Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file Exploitation status Not known exploited Fix Not confirmed Published 09/24/2026 Severity High CVE-2026-96889Librsvg: use-after-free when xml includes have duplicated entities Exploitation status Public exploit Fix Not confirmed Published 09/23/2026 Severity High CVE-2026-96546Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader Exploitation status Public exploit Fix Not confirmed Published 09/23/2026 Severity Low CVE-2026-96545Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader Exploitation status Public exploit Fix Not confirmed Published 09/23/2026 Severity Medium CVE-2026-96541Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline Exploitation status Public exploit Fix Not confirmed Published 09/23/2026 Severity High CVE-2026-96276Flatpak: flatpak: arbitrary write in host context via flatpak build-init Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity Critical CVE-2026-96275Flatpak: flatpak: arbitrary write access as root via extra-data extraction Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity High CVE-2026-96512Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity High CVE-2026-96442Emacs: emacs: arbitrary code execution in flymake mode Exploitation status Not known exploited Fix YesPublished 09/23/2026 Severity High CVE-2026-13087Exploitation status Not confirmed Fix Not confirmed Published 09/22/2026 Severity Unknown CVE-2026-90462Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization Exploitation status Public exploit Fix Not confirmed Published 09/22/2026 Severity Medium CVE-2026-94640Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service Exploitation status Not known exploited Fix Not confirmed Published 09/22/2026 Severity High CVE-2026-95619Gcc: libstdc++ integer overflow in `new` operator Exploitation status Not known exploited Fix Not confirmed Published 09/22/2026 Severity High CVE-2026-95508Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu Exploitation status Not known exploited Fix Not confirmed Published 09/22/2026 Severity High CVE-2026-95511Exploitation status Not confirmed Fix Not confirmed Published 09/22/2026 Severity Unknown CVE-2026-93433Libstoragemgmt: libstoragemgmt: denial of service via stack buffer overflow in scsi vpd page parsing Exploitation status Not known exploited Fix Not confirmed Published 09/21/2026 Severity Medium CVE-2026-92382Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write Exploitation status Not known exploited Fix Not confirmed Published 09/21/2026 Severity Medium CVE-2026-94184Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01) Exploitation status Not known exploited Fix Not confirmed Published 09/21/2026 Severity High CVE-2026-80110Pki-core: dogtag pki v2 rest acl filter's reverse-lexicographic tie-break lets a ca agent invoke the admin-only raw profile creation endpoint Exploitation status Not known exploited Fix Not confirmed Published 09/21/2026 Severity High CVE-2026-92574Cri-o: cri-o checkpoint restore bypasses destination security context Exploitation status Not known exploited Fix YesPublished 09/21/2026 Severity High CVE-2026-91202Cockpit-files: cockpit-files: arbitrary file ownership change via symlink following in privileged paste Exploitation status Not known exploited Fix Not confirmed Published 09/18/2026 Severity Medium CVE-2026-91203Cockpit-files: cockpit-files: arbitrary file ownership and permission modification via symlink race condition Exploitation status Public exploit Fix Not confirmed Published 09/18/2026 Severity Medium CVE-2026-91205Cockpit-files: cockpit-files: local attacker can hijack file ownership via symlink race Exploitation status Not known exploited Fix Not confirmed Published 09/18/2026 Severity Medium CVE-2026-92768Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments Exploitation status Public exploit Fix Not confirmed Published 09/18/2026 Severity Medium CVE-2026-92747Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process list Exploitation status Public exploit Fix Not confirmed Published 09/18/2026 Severity Medium CVE-2026-92745Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via process arguments Exploitation status Not known exploited Fix Not confirmed Published 09/18/2026 Severity Medium CVE-2026-91142Cockpit: integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 builds Exploitation status Not known exploited Fix Not confirmed Published 09/18/2026 Severity Low CVE-2026-91147Cockpit: cockpit: denial of service in `cockpit-ws` due to url-root handling without a trailing slash Exploitation status Public exploit Fix Not confirmed Published 09/18/2026 Severity Medium CVE-2026-91149Cockpit: cockpit: denial of service via unbounded connection thread spawning Exploitation status Not known exploited Fix Not confirmed Published 09/18/2026 Severity High CVE-2026-93676Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks Exploitation status Not known exploited Fix Not confirmed Published 09/18/2026 Severity Low CVE-2026-93653Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill via unvalidated tiling-pattern repeat count (denial of service) Exploitation status Not known exploited Fix Not confirmed Published 09/18/2026 Severity Medium CVE-2026-81627Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram Exploitation status Public exploit Fix Not confirmed Published 09/18/2026 Severity High CVE-2026-89058Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard config Exploitation status Public exploit Fix YesPublished 09/18/2026 Severity High CVE-2026-89059Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos) Exploitation status Public exploit Fix YesPublished 09/18/2026 Severity High CVE-2026-76781Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute Exploitation status Not known exploited Fix Not confirmed Published 09/17/2026 Severity Medium CVE-2026-92925Redis: redis: out-of-bounds read via crafted cluster bus packets Exploitation status Not known exploited Fix Not confirmed Published 09/17/2026 Severity High CVE-2026-86320Flatpak-builder: host code execution via `git am` hook execution in patch source extraction (`use-git-am`) Exploitation status Public exploit Fix Not confirmed Published 09/17/2026 Severity High CVE-2026-42784Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion Exploitation status Not known exploited Fix Not confirmed Published 09/16/2026 Severity High CVE-2026-92091Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops array Exploitation status Public exploit Fix Not confirmed Published 09/16/2026 Severity Medium CVE-2025-11395Podman: arbitrary file write when importing oci archive Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity Medium CVE-2026-92248Gimp: integer overflow when generating a thumbnail preview for a psd file Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity High CVE-2026-85234Tftp: tftp-hpa: denial of service due to out-of-bounds read/write in remap engine Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity High CVE-2026-79699Podman: buildah: skopeo: containers/storage: malicious tar whiteout header allows replacement of extraction destination directory Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity Medium CVE-2026-79705Podman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callers Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity Medium CVE-2026-85013Environment-modules: command injection in environment-modules bash completion via malicious module names containing shell metacharacters Exploitation status Public exploit Fix Not confirmed Published 09/15/2026 Severity High CVE-2026-91786Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity Medium CVE-2026-75092Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity High CVE-2026-19816PackageKit: dnf5 backend ignores SIMULATE on RepoRemove Exploitation status Not known exploited Fix YesPublished 09/14/2026 Severity High CVE-2026-90996Sssd: sssd: denial of service in nss responder via crafted zero-length requests Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity Medium CVE-2026-90995Sssd: sssd: local denial of service due to null pointer dereference in pam responder Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity Medium CVE-2026-90994Sssd: sssd: denial of service via malformed pam v1 requests Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity Medium CVE-2026-90463Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`) Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity Medium CVE-2026-90947Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity High CVE-2026-90949Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mismatch Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity High CVE-2026-90948Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png dimensions Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity High CVE-2026-89329Device-mapper-multipath: local denial of service via blocking ipc send operations Exploitation status Not known exploited Fix Not confirmed Published 09/11/2026 Severity Medium CVE-2026-18495Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough Exploitation status Not known exploited Fix Not confirmed Published 09/11/2026 Severity Medium CVE-2026-77159Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file ownership change via symlink Exploitation status Public exploit Fix Not confirmed Published 09/11/2026 Severity Medium CVE-2026-88914Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser Exploitation status Not known exploited Fix Not confirmed Published 09/11/2026 Severity Medium CVE-2026-88924Gvfs: gvfs-admin socket ownership race permits local root Exploitation status Public exploit Fix YesPublished 09/10/2026 Severity High CVE-2026-88859Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction Exploitation status Not known exploited Fix Not confirmed Published 09/10/2026 Severity Medium CVE-2026-84828Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token Exploitation status Not known exploited Fix Not confirmed Published 09/10/2026 Severity Medium CVE-2026-88265Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and chown Exploitation status Not known exploited Fix Not confirmed Published 09/10/2026 Severity Medium CVE-2026-88264Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs Exploitation status Not known exploited Fix YesPublished 09/10/2026 Severity Medium CVE-2026-84042Crun: crun: rootful krun with passt executes container payload as host root Exploitation status Not known exploited Fix Not confirmed Published 09/10/2026 Severity High CVE-2026-18147Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url Exploitation status Not known exploited Fix Not confirmed Published 09/09/2026 Severity High CVE-2026-87876Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up) Exploitation status Public exploit Fix Not confirmed Published 09/09/2026 Severity Low CVE-2026-87875Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound Exploitation status Public exploit Fix Not confirmed Published 09/09/2026 Severity Medium CVE-2026-87853Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation Exploitation status Not known exploited Fix Not confirmed Published 09/09/2026 Severity High