Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1267 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 807 high, 402 medium, 27 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High7.5Linux

High [CVE-2026-29146] Information disclosure via Padding Oracle vulnerability in EncryptInterceptor

Information disclosure via Padding Oracle vulnerability in EncryptInterceptor. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1240. Affected package(s): jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; and 10 more.

CVE-2026-29146
Red Hat Enterprise Linux
Apr 9, 2026
High7.8Linux

High [CVE-2026-34734] HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file

HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-34734
Red Hat Enterprise Linux
Apr 9, 2026
High7.0Linux

High [CVE-2025-62718] Server-Side Request Forgery and proxy bypass due to improper hostname normalization

Server-Side Request Forgery and proxy bypass due to improper hostname normalization. Red Hat rates this important (CVSS 7). Weakness: CWE-1289. Affected package(s): openshift-service-mesh/kiali-rhel9:1776149682, openshift-service-mesh/kiali-ossmc-rhel9:1776151134, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, devspaces/dashboard-rhel9:1776795511, openshift-service-mesh/kiali-ossmc-rhel8:1776202125, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 35 more.

CVE-2025-62718
Red Hat Enterprise Linux
Apr 9, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-27140] Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names

Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names. Red Hat rates this important (CVSS 9). Weakness: CWE-641. Affected package(s): openshift4/cloud-network-config-controller-rhel9:1780040126, openshift4/ose-agent-installer-utils-rhel9:1780044523, openshift4/ose-vsphere-csi-driver-rhel9-operator:1780040095, openshift4/ose-aws-cloud-controller-manager-rhel9:1780040386, openshift4/ose-aws-cluster-api-controllers-rhel9:1780040551, openshift4/ose-ironic-machine-os-downloader-rhel9:1780365576. Resolved in Red Hat advisory RHSA-2026:10704 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 12 more.

CVE-2026-27140
Red Hat Enterprise Linux
Apr 8, 2026
High7.3Linux

High [CVE-2026-39892] Buffer overflow via non-contiguous buffer in API

Buffer overflow via non-contiguous buffer in API. Red Hat rates this important (CVSS 7.3). Weakness: CWE-131. Affected package(s): ansible-automation-platform, quay/quay-rhel8:1779811473, quay/quay-rhel8:1779689392, ansible-automation-platform-tech-preview/metrics-service-rhel9:1779760844, automation-controller, python3.12-cryptography. Resolved in Red Hat advisory RHSA-2026:23361 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat AI Inference Server 3.3; and 20 more.

CVE-2026-39892
Red Hat Enterprise Linux
Apr 8, 2026
High7.5Linux

High [CVE-2026-32280] Denial of Service vulnerability in certificate chain building

Denial of Service vulnerability in certificate chain building. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): rhc, openshift-service-mesh/pilot-rhel8:1777319850, openshift-service-mesh/istio-rhel9-operator:1778149657, grafana-pcp, openshift-service-mesh/istio-cni-rhel8:1777374598, rhtas/client-server-rhel9:1780399582. Resolved in Red Hat advisory RHSA-2026:11507 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 10; Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat OpenShift Container Platform 4.14; and 114 more.

CVE-2026-32280
Red Hat Enterprise Linux
Apr 8, 2026
High7.5Linux

High [CVE-2026-32283] Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages

Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-764. Affected package(s): rhc, grafana-pcp, skopeo, host-metering, container-tools:rhel8, git-lfs. Resolved in Red Hat advisory RHSA-2026:11507 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 10; and 78 more.

CVE-2026-32283
Red Hat Enterprise Linux
Apr 8, 2026
High8.8Linux

High [CVE-2026-33810] Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application

Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1289. Affected package(s): rhtas/client-server-rhel9:1780399582, golang1, cryostat/cryostat-storage-rhel9:4.1.1, opentelemetry-collector, hawtio-operator-container, web-terminal/web-terminal-exec-rhel9:1780425077. Resolved in Red Hat advisory RHSA-2026:28047 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; RHEM 1.0 for RHEL 9; Red Hat Satellite 6.19 for RHEL 9; Red Hat Enterprise Linux AppStream EUS (v. 10.0); and 72 more.

CVE-2026-33810
Red Hat Enterprise Linux
Apr 8, 2026
High7.8Linux

High [CVE-2026-6846] Arbitrary code execution via malformed XCOFF object file processing

Arbitrary code execution via malformed XCOFF object file processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:33527 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-6846
Red Hat Enterprise Linux
Apr 8, 2026
High7.5Linux

High [CVE-2026-58016] integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"

integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml". Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more.

CVE-2026-58016
Red Hat Enterprise Linux
Apr 8, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-34078] Arbitrary code execution via crafted symlinks in sandbox-expose options

Arbitrary code execution via crafted symlinks in sandbox-expose options. Red Hat rates this important (CVSS 9). Weakness: CWE-59. Affected package(s): flatpak. Resolved in Red Hat advisory RHSA-2026:21757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-34078
Red Hat Enterprise Linux
Apr 7, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-34582] Client authentication bypass in TLS 1.3 implementation

Client authentication bypass in TLS 1.3 implementation. Red Hat rates this important (CVSS 9.1). Weakness: CWE-166. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-34582
Red Hat Enterprise Linux
Apr 7, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-34580] Certificate validation bypass due to incorrect certificate matching

Certificate validation bypass due to incorrect certificate matching. Red Hat rates this important (CVSS 9.1). Weakness: CWE-295. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-34580
Red Hat Enterprise Linux
Apr 7, 2026
Critical9.8Linux

Critical [CVE-2026-4631] Unauthenticated remote code execution due to SSH command-line argument injection

Unauthenticated remote code execution due to SSH command-line argument injection. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-78. Affected package(s): cockpit. Resolved in Red Hat advisory RHSA-2026:7383 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.

CVE-2026-4631
Red Hat Enterprise Linux
Apr 7, 2026
High8.2Linux

High [CVE-2026-34045] Denial of Service and Information Disclosure via unauthenticated HTTP server

Denial of Service and Information Disclosure via unauthenticated HTTP server. Red Hat rates this important (CVSS 8.2). Weakness: CWE-770. Affected package(s): rh-podman-desktop. Resolved in Red Hat advisory RHSA-2026:13867 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34045
Red Hat Enterprise Linux
Apr 7, 2026
High7.5Linux

High [CVE-2026-39363] Information disclosure via WebSocket connection bypasses access control

Information disclosure via WebSocket connection bypasses access control. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1220. Affected package(s): ansible-automation-platform-tech-preview/mcp-server-rhel9:1779783248, automation-platform-ui, automation-gateway. Resolved in Red Hat advisory RHSA-2026:24866 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Build of Keycloak; and 2 more.

CVE-2026-39363
Red Hat Enterprise Linux
Apr 7, 2026
High8.3Linux

High [CVE-2026-33816] Memory-safety vulnerability

Memory-safety vulnerability. Red Hat rates this important (CVSS 8.3). Weakness: CWE-787. Affected package(s): advanced-cluster-security/rhacs-scanner-v4-rhel8:1777986630, rhtas/updatetree-rhel9:1780053572, rhtas/createtree-rhel9:1780053572, advanced-cluster-security/rhacs-scanner-v4-rhel8:1777307791, custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator:1779953535, go-fdo-server. Resolved in Red Hat advisory RHSA-2026:13907 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Enterprise Linux 10; RHEM 1.0 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 16 more.

CVE-2026-33816
Red Hat Enterprise Linux
Apr 7, 2026
High8.3Linux

High [CVE-2026-33815] Memory-safety vulnerability

Memory-safety vulnerability. Red Hat rates this important (CVSS 8.3). Weakness: CWE-787. Affected package(s): advanced-cluster-security/rhacs-scanner-v4-rhel8:1777986630, rhtas/updatetree-rhel9:1780053572, rhtas/createtree-rhel9:1780053572, advanced-cluster-security/rhacs-scanner-v4-rhel8:1777307791, custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator:1779953535, rhtas/trillian-logserver-rhel9:1780053572. Resolved in Red Hat advisory RHSA-2026:24482 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; RHEM 1.0 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 16 more.

CVE-2026-33815
Red Hat Enterprise Linux
Apr 7, 2026
High7.5Linux

High [CVE-2026-20911] Arbitrary Code Execution via specially crafted file

Arbitrary Code Execution via specially crafted file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.

CVE-2026-20911
Red Hat Enterprise Linux
Apr 7, 2026
High7.5Linux

High [CVE-2026-21413] Arbitrary code execution via heap-based buffer overflow in lossless JPEG loading

Arbitrary code execution via heap-based buffer overflow in lossless JPEG loading. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): LibRaw. Resolved in Red Hat advisory RHSA-2026:11360 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; and 8 more.

CVE-2026-21413
Red Hat Enterprise Linux
Apr 7, 2026

← All Linux advisories