Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1197 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 785 high, 362 medium, 16 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High7.1Vendor: MediumLinux

High [CVE-2026-42012] Certificate validation bypass due to improper handling of URI and SRV SANs

Certificate validation bypass due to improper handling of URI and SRV SANs. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-295. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 12 more.

CVE-2026-42012
Red Hat Enterprise Linux
Apr 29, 2026
High8.2Vendor: MediumLinux

High [CVE-2026-42013] Certificate validation bypass due to oversized Subject Alternative Name

Certificate validation bypass due to oversized Subject Alternative Name. Red Hat rates this moderate (CVSS 8.2). Weakness: CWE-295. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 11 more.

CVE-2026-42013
Red Hat Enterprise Linux
Apr 29, 2026
High7.5Linux

High [CVE-2026-42009] Denial of Service via DTLS packet reordering vulnerability

Denial of Service via DTLS packet reordering vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-475. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:29794 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 40 more.

CVE-2026-42009
Red Hat Enterprise Linux
Apr 29, 2026
High7.1Linux

High [CVE-2026-42010] Authentication Bypass via NUL Character in Username

Authentication Bypass via NUL Character in Username. Red Hat rates this important (CVSS 7.1). Weakness: CWE-170. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 38 more.

CVE-2026-42010
Red Hat Enterprise Linux
Apr 29, 2026
High8.2Vendor: MediumLinux

High [CVE-2026-5260] Information disclosure via heap overread in RSA key exchange

Information disclosure via heap overread in RSA key exchange. Red Hat rates this moderate (CVSS 8.2). Weakness: CWE-126. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-5260
Red Hat Enterprise Linux
Apr 29, 2026
High7.5Linux

High [CVE-2026-7323] Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1

Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1. Red Hat rates this important (CVSS 7.5). Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-7323
Red Hat Enterprise Linux
Apr 28, 2026
High8.8Linux

High [CVE-2026-7322] Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1

Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-7322
Red Hat Enterprise Linux
Apr 28, 2026
High7.5Linux

High [CVE-2026-7320] Information disclosure due to incorrect boundary conditions in the Audio/Video component

Information disclosure due to incorrect boundary conditions in the Audio/Video component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-7320
Red Hat Enterprise Linux
Apr 28, 2026
High7.5Linux

High [CVE-2026-41606] Denial of Service via uncontrolled recursion

Denial of Service via uncontrolled recursion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 8 more.

CVE-2026-41606
Red Hat Enterprise Linux
Apr 28, 2026
High7.7Linux

High [CVE-2026-41605] Integer Overflow or Wraparound Vulnerability

Integer Overflow or Wraparound Vulnerability. Red Hat rates this important (CVSS 7.7). Weakness: CWE-190. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 7 more.

CVE-2026-41605
Red Hat Enterprise Linux
Apr 28, 2026
High8.2Linux

High [CVE-2026-41604] Out-of-bounds Read vulnerability

Out-of-bounds Read vulnerability. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 8 more.

CVE-2026-41604
Red Hat Enterprise Linux
Apr 28, 2026
High8.2Linux

High [CVE-2026-41603] Security Bypass via Improper Certificate Hostname Validation

Security Bypass via Improper Certificate Hostname Validation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-295. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 7 more.

CVE-2026-41603
Red Hat Enterprise Linux
Apr 28, 2026
High7.5Linux

High [CVE-2025-48431] Apache Thrift c_glib: Denial of Service via specially crafted requests

Apache Thrift c_glib: Denial of Service via specially crafted requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-763. Affected package(s): cryostat/cryostat-storage-rhel9:4.2.0, rhosdt/tempo-rhel9:1781589494, rhacm2/acm-grafana-rhel9:1780926805, rhacm2/acm-grafana-rhel9:1780677003. Resolved in Red Hat advisory RHSA-2026:24539 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.10.1; and 5 more.

CVE-2025-48431
Red Hat Enterprise Linux
Apr 28, 2026
High8.8Linux

High [CVE-2026-6951] Remote Code Execution due to incomplete fix bypass

Remote Code Execution due to incomplete fix bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-88. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-6951
Red Hat Enterprise Linux
Apr 25, 2026
High7.5Linux

High [CVE-2026-42039] Denial of Service via unbounded recursion in toFormData with deeply nested request data

Denial of Service via unbounded recursion in toFormData with deeply nested request data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, openshift4/ose-agent-installer-ui-rhel9:1778539338, satellite/iop-advisor-frontend-rhel9:1781181673, openshift-service-mesh/kiali-rhel8:1778191378, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 33 more.

CVE-2026-42039
Red Hat Enterprise Linux
Apr 24, 2026
High8.2Linux

High [CVE-2026-42041] Authentication bypass due to prototype pollution of HTTP error handling

Authentication bypass due to prototype pollution of HTTP error handling. Red Hat rates this important (CVSS 8.2). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, openshift4/ose-agent-installer-ui-rhel9:1778539338, satellite/iop-advisor-frontend-rhel9:1781181673, openshift-service-mesh/kiali-rhel8:1778191378, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 33 more.

CVE-2026-42041
Red Hat Enterprise Linux
Apr 24, 2026
High7.2Linux

High [CVE-2026-42043] NO_PROXY bypass via crafted URL

NO_PROXY bypass via crafted URL. Red Hat rates this important (CVSS 7.2). Weakness: CWE-918. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, openshift4/ose-agent-installer-ui-rhel9:1778539338, satellite/iop-advisor-frontend-rhel9:1781181673, openshift-service-mesh/kiali-rhel8:1778191378, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 32 more.

CVE-2026-42043
Red Hat Enterprise Linux
Apr 24, 2026
High7.4Linux

High [CVE-2026-42044] Invisible JSON Response Tampering via Prototype Pollution Gadget

Invisible JSON Response Tampering via Prototype Pollution Gadget. Red Hat rates this important (CVSS 7.4). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, network-observability/network-observability-console-plugin-rhel9:1780556069, satellite/iop-advisor-frontend-rhel9:1781181673, rhacm2/console-rhel9:1780600823, devspaces/code-rhel9:1779814592, multicluster-engine/console-mce-rhel9:1778383863. Resolved in Red Hat advisory RHSA-2026:26068 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 36 more.

CVE-2026-42044
Red Hat Enterprise Linux
Apr 24, 2026
High7.4Linux

High [CVE-2026-42033] HTTP Transport Hijacking via Prototype Pollution

HTTP Transport Hijacking via Prototype Pollution. Red Hat rates this important (CVSS 7.4). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1778164042, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, openshift4/ose-agent-installer-ui-rhel9:1778539338, satellite/iop-advisor-frontend-rhel9:1781181673, openshift-service-mesh/kiali-rhel8:1778191378, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 35 more.

CVE-2026-42033
Red Hat Enterprise Linux
Apr 24, 2026
High8.1Linux

High [CVE-2026-41316] Arbitrary code execution via deserialization bypass

Arbitrary code execution via deserialization bypass. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. Affected package(s): ruby, ruby4.0, ruby:3.3, ruby:4.0. Resolved in Red Hat advisory RHSA-2026:20614 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 3 more.

CVE-2026-41316
Red Hat Enterprise Linux
Apr 24, 2026

← All Linux advisories