Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.9Red Hat

Medium [CVE-2026-6791] Denial of Service via stack exhaustion during tilde expansion

Denial of Service via stack exhaustion during tilde expansion. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:53069 with package glibc-main-2.43-8.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: glibc; and 1 more.

CVE-2026-6791
Red Hat Enterprise Linux
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-6368] Process abort due to invalid memory in wordexp

Process abort due to invalid memory in wordexp. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341. Red Hat lists fixing advisory RHSA-2026:53069 with package glibc-main-2.43-8.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: glibc; and 1 more.

CVE-2026-6368
Red Hat Enterprise Linux
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-63623] Information disclosure via world-readable storage volume images during clone/convert

Information disclosure via world-readable storage volume images during clone/convert. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-732.

CVE-2026-63623
Unclassified
Aug 10, 2026
Medium6.3Red Hat

Medium [CVE-2026-71577] Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration

Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-522.

CVE-2026-71577
Unclassified
Aug 10, 2026
Medium4.7Red Hat

Medium [CVE-2026-15060] Unprivileged users can terminate arbitrary processes

When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file - versions older than v258 are not affected - unrelated to the systemd service manager (pid 1 or user session managers) - systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container) - terminal-only or remote sessions (e.g.: ssh) are not affected This could lead to a denial of service or potentially allow for privilege escalation. Red Hat products are not affected by this vulnerability. Red Hat Enterprise Linux ships systemd versions well below this threshold (RHEL 7: v219, RHEL 8: v239, RHEL 9: v252, RHEL 10: v257). Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-266. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4 as not affected.

CVE-2026-15060
Unclassified
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-18370] Heap-based buffer overflow leads to denial of service

Heap-based buffer overflow leads to denial of service. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.

CVE-2026-18370
Unclassified
Aug 10, 2026
Medium6.8Red Hat

Medium [CVE-2026-19278] Privilege escalation via unanchored regular expressions in Auth M2M role mappings

Privilege escalation via unanchored regular expressions in Auth M2M role mappings. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-625.

CVE-2026-19278
Unclassified
Aug 10, 2026
Medium6.5Red Hat

Medium [CVE-2026-19429] Arbitrary file read via symlink target validation bypass

Arbitrary file read via symlink target validation bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-59. Affected product named by the advisory: OpenShift Developer Tools and Services.

CVE-2026-19429
Unclassified
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68428] Fix use-after-free on vendor module reload

Fix use-after-free on vendor module reload. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68428
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68425] Drop unmatched RMPP responses before reassembly

Drop unmatched RMPP responses before reassembly. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-179. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68425
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68424] fix use-after-free in mtd_virt_concat_destroy_joins

fix use-after-free in mtd_virt_concat_destroy_joins(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.

CVE-2026-68424
Unclassified
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68423] fix use-after-free in mtd_virt_concat_destroy

fix use-after-free in mtd_virt_concat_destroy(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.

CVE-2026-68423
Unclassified
Aug 10, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68422] fix root leak if its reloc root is unexpected in merge_reloc_roots

fix root leak if its reloc root is unexpected in merge_reloc_roots(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68422
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68421] Don't warn on core-sched forced idle in put_prev_task_scx

Don't warn on core-sched forced idle in put_prev_task_scx(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1288. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.

CVE-2026-68421
Linux Kernel
Aug 10, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68418] Prevent user-triggered null deref on QP create

Prevent user-triggered null deref on QP create. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel-rt.

CVE-2026-68418
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68417] publish QP after initialization

publish QP after initialization. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68417
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68413] memory leak in ipw2100_pci_init_one

memory leak in ipw2100_pci_init_one(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68413
Linux Kernel
Aug 10, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68412] Fix an error handling path in cfg80211_wext_siwscan

Fix an error handling path in cfg80211_wext_siwscan(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68412
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68410] fix memory leak in helper_firmware_cb

fix memory leak in helper_firmware_cb(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68410
Linux Kernel
Aug 10, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68407] free RNR data on MBSSID mismatch

free RNR data on MBSSID mismatch. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772.

CVE-2026-68407
Unclassified
Aug 10, 2026