Technology · Red Hat
Red Hat Enterprise Linux 6 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 55 vulnerabilities in Red Hat Enterprise Linux 6: 0 in the last 7 days and 20 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-58222, was published on 30 July 2026.
- Last 7 days
- 0
- Last 90 days
- 20
- Critical, all time
- 3
- Exploited in the wild
- 0
About Red Hat Enterprise Linux 6
A commercial Linux distribution based on the open-source Linux kernel and designed for enterprise environments.
Latest Red Hat Enterprise Linux 6 vulnerabilities
- CVE-2026-58222: Samba AD DC LDAP filter injection and ACL bypass in Compare requestshighCVSS 8.8
- CVE-2026-58216: Samba KDC out-of-bounds read in kpasswd servicemediumCVSS 5.3
- CVE-2026-58218: Samba internal DNS server denial of service via TKEY cache exhaustionmediumCVSS 5.3
- CVE-2026-17072: GStreamer gst-plugins-good heap out-of-bounds read in Matroska demuxerlowCVSS 3.3
- CVE-2026-66759: GNOME GIMP out-of-bounds read in file-icns pluginhighCVSS 7.1
- CVE-2026-15003: GNU Binutils heap overflow in linker XCOFF processingmediumCVSS 5.6
- CVE-2026-6390: GNU nano format string vulnerability in multi-buffer error handlingmediumCVSS 6.8
- CVE-2026-16517: libarchive signed integer overflow in ZIP writerlowCVSS 2.9
- CVE-2026-15588: GNOME GLib denial of service in GDBus authenticationmediumCVSS 5.3
- CVE-2026-3842: QEMU out-of-bounds write in hyperv/syndbg memory mappinghighCVSS 7.8
- CVE-2026-58016: GNOME GLib out-of-bounds read in D-Bus introspection XML parsinghighCVSS 7.5
- CVE-2026-58015: GLib path traversal in GDBus DBUS_COOKIE_SHA1 authenticationmediumCVSS 5.9
- CVE-2026-58014: GNOME GLib off-by-one error in g_key_file_get_locale_string_listhighCVSS 7.3
- CVE-2026-58013: GNOME GLib buffer over-read in g_io_channel_read_line_backendmediumCVSS 6.5
- CVE-2026-58012: GNOME GLib buffer over-read in g_regex_replacemediumCVSS 6.5
- CVE-2026-58011: GNOME GLib out-of-bounds read in g_date_time_get_ymdmediumCVSS 6.5
- CVE-2026-58010: GLib off-by-one error in GVariant serializermediumCVSS 6.5
- CVE-2026-13757: p11-kit stack exhaustion via uncontrolled recursion in RPC attribute parsingmediumCVSS 6.2
- CVE-2026-57966: Red Hat spice-vdagent path traversal in file transfermediumCVSS 4.4
- CVE-2026-57965: Red Hat spice-vdagent integer overflow in udscs_writemediumCVSS 5.1
- CVE-2026-55655: OpenSSH X11 forwarding connection hijack via abstract UNIX socketmediumCVSS 5
- CVE-2026-55654: OpenSSH heap out-of-bounds read in GSSAPI indicator cleanuplowCVSS 3.7
- CVE-2026-55653: OpenSSH double free in DH-GEX client during FIPS validationmediumCVSS 4.3
- CVE-2026-3195: QEMU heap overflow in virtio-snd devicehighCVSS 7.4
- CVE-2026-2604: GNOME Evolution Data Server arbitrary file deletion in addressbook backendmediumCVSS 5.6EPSS 0.2%
Most severe Red Hat Enterprise Linux 6 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-20911: LibRaw heap buffer overflow in HuffTable::initvalcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-22853: FreeRDP heap buffer overflow in RDPEAR NDR array readercriticalCVSS 9.8EPSS 0.5%
- CVE-2026-42216: AcademySoftwareFoundation OpenEXR out-of-bounds read in IDManifestcriticalCVSS 9.1EPSS 0.4%
- CVE-2026-58222: Samba AD DC LDAP filter injection and ACL bypass in Compare requestshighCVSS 8.8
- CVE-2026-25965: ImageMagick path traversal policy bypass in path security policyhighCVSS 8.6EPSS 0.8%
- CVE-2016-7543: GNU Bash privilege escalation via SHELLOPTS and PS4 variableshighCVSS 8.4
- CVE-2026-25794: ImageMagick heap overflow in WriteUHDRImagehighCVSS 8.2EPSS 0.3%
- CVE-2026-26740: giflib buffer overflow in EGifGCBToExtensionhighCVSS 8.2EPSS 0.3%
- CVE-2026-23876: ImageMagick heap buffer overflow in XBM image decoderhighCVSS 8.1EPSS 0.5%
- CVE-2026-24660: LibRaw heap buffer overflow in x3f_load_huffmanhighCVSS 8.1EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 10 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 3 | 0 | |
| 27 Jul 2026 | 6 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/enterprise-linux-6.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Red Hat Enterprise Linux 6 vulnerabilities", https://junglewise.ai/threats/technologies/enterprise-linux-6, 26 September 2026.