Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

10918 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.8Red Hat

High [CVE-2026-47511] Arbitrary code execution via kernel-mode out-of-bounds write

Arbitrary code execution via kernel-mode out-of-bounds write. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.

CVE-2026-47511
Red Hat Enterprise Linux
Sep 30, 2026
High7.8Red Hat

High [CVE-2026-47510] Arbitrary code execution via integer overflow in kernel mode layer

Arbitrary code execution via integer overflow in kernel mode layer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.

CVE-2026-47510
Red Hat Enterprise Linux
Sep 30, 2026
High7.8Red Hat

High [CVE-2026-47508] Code execution via incorrect numeric type conversion

Code execution via incorrect numeric type conversion. Red Hat rates this important (CVSS 7.8). Weakness: CWE-681. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.

CVE-2026-47508
Red Hat Enterprise Linux
Sep 30, 2026
High7.8Red Hat

High [CVE-2026-47507] Privilege escalation via out-of-bounds array access in the kernel mode layer

Privilege escalation via out-of-bounds array access in the kernel mode layer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.

CVE-2026-47507
Red Hat Enterprise Linux
Sep 30, 2026
High7.8Red Hat

High [CVE-2026-47504] Arbitrary code execution via type confusion in the NGX updater

Arbitrary code execution via type confusion in the NGX updater. Red Hat rates this important (CVSS 7.8). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.

CVE-2026-47504
Red Hat Enterprise Linux
Sep 30, 2026
High7.8Red Hat

High [CVE-2026-47501] Privilege escalation via out-of-bounds write during event buffer setup

Privilege escalation via out-of-bounds write during event buffer setup. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.

CVE-2026-47501
Red Hat Enterprise Linux
Sep 30, 2026
High7.8Red Hat

High [CVE-2026-47494] Arbitrary code execution via format string flaw

Arbitrary code execution via format string flaw. Red Hat rates this important (CVSS 7.8). Weakness: CWE-134. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.

CVE-2026-47494
Red Hat Enterprise Linux
Sep 30, 2026
High7.8Red Hat

High [CVE-2026-47491] Privilege escalation via improper memory release

Privilege escalation via improper memory release. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.

CVE-2026-47491
Red Hat Enterprise Linux
Sep 30, 2026
High7.8Red Hat

High [CVE-2026-47489] Privilege escalation via unpreserved read-only memory permissions

Privilege escalation via unpreserved read-only memory permissions. Red Hat rates this important (CVSS 7.8). Weakness: CWE-281. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.

CVE-2026-47489
Red Hat Enterprise Linux
Sep 30, 2026
High7.7Red Hat

High [CVE-2026-103431] colmux does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances

colmux does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances. Red Hat rates this important (CVSS 7.7). Weakness: CWE-150.

CVE-2026-103431
Unclassified
Sep 30, 2026
High7.8Red Hat

High [CVE-2026-103226] stack-based buffer overflow in pdfwrite via crafted font data

stack-based buffer overflow in pdfwrite via crafted font data. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ghostscript.

CVE-2026-103226
Red Hat Enterprise Linux
Sep 30, 2026
High7.3Vendor: MediumRed Hat

High [CVE-2026-101295] Path traversal / arbitrary file write in operator catalog image extraction

Path traversal / arbitrary file write in operator catalog image extraction. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-22.

CVE-2026-101295
Unclassified
Sep 30, 2026
High8.8Red Hat

High [CVE-2026-15815] PLUGIN ARCHIVE EXTRACTION ESCAPES THE PLUGIN DIRECTORY, ALLOWING CODE EXECUTION

PLUGIN ARCHIVE EXTRACTION ESCAPES THE PLUGIN DIRECTORY, ALLOWING CODE EXECUTION. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22. Affected products named by the advisory: Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: grafana.

CVE-2026-15815
Red Hat Enterprise Linux
Sep 30, 2026
High7.3Red Hat

High [CVE-2026-76154] Stored cross-site scripting in the Geomap panel allows privilege escalation

Stored cross-site scripting in the Geomap panel allows privilege escalation. Red Hat rates this important (CVSS 7.3). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:74164 with package grafana13-1-main-13.1.6-0.5.hum1, grafana12-4-main-12.4.12-0.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Enterprise Linux 10; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: grafana.

CVE-2026-76154
Red Hat Enterprise Linux
Sep 30, 2026
High7.4Red Hat

High [CVE-2026-88920] Authentication bypass via unsigned SAML sender-vouches assertion

Authentication bypass via unsigned SAML sender-vouches assertion. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7.

CVE-2026-88920
Unclassified
Sep 30, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-103242] Heap-based buffer overflow write in hex2binv via a mistyped RPMTAG_FILESIGNATURES header tag

Heap-based buffer overflow write in hex2binv() via a mistyped RPMTAG_FILESIGNATURES header tag. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 16 more. Affected products named by the advisory: Red Hat package: python3-rpm; Red Hat package: rpm-apidocs; Red Hat package: rpm-build-libs; Red Hat package: rpm-cron; and 12 more.

CVE-2026-103242
Red Hat Enterprise Linux
Sep 30, 2026
High7.8Red Hat

High [CVE-2026-62146] Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket

A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape. This affects CRI-O versions that persist reserved sandbox metadata together with untrusted pod annotations/labels without validating or namespacing them separately and that reload this state as trusted after a restart, including products that bundle CRI-O as their runtime (e.g., OpenShift Container Platform nodes); exploitation requires pod-creation access plus a subsequent CRI-O restart/node reboot and container recreate, so affected-version and exposure-window details will be confirmed once upstream triage completes Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-501. Red Hat does not currently list a fixing RHSA for this CVE. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-62146
Unclassified
Sep 30, 2026
High8.1Red Hat

High [CVE-2026-93994] Authentication bypass via duplicate public key presentation

Authentication bypass via duplicate public key presentation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:71541 with package maven3-9-main-3.9.16-0.3.hum1. Affected products named by the advisory: OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Enterprise Linux 10; and 10 more. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 6 more.

CVE-2026-93994
Red Hat Enterprise Linux
Sep 30, 2026
High7.5Red Hat

High [CVE-2026-94002] Denial of Service via unsolicited SFTP replies

Denial of Service via unsolicited SFTP replies. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apicurio Registry 3; Red Hat Fuse 7.

CVE-2026-94002
Unclassified
Sep 30, 2026
High7.5Red Hat

High [CVE-2026-92870] Denial of Service via stack-based buffer overflow

Denial of Service via stack-based buffer overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-92870
Unclassified
Sep 30, 2026

← All vendors