Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.2Red Hat

High [CVE-2026-9117] Type Confusion in GFX

Type Confusion in GFX. Red Hat rates this important (CVSS 8.2). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9117
Unclassified
May 19, 2026
High8.8Red Hat

High [CVE-2026-9112] Use after free in GPU

Use after free in GPU. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9112
Unclassified
May 19, 2026
High8.1Red Hat

High [CVE-2026-9800] Authorization bypass via incorrect URI comparison

Authorization bypass via incorrect URI comparison. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1025. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.6, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.4. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6; Red Hat JBoss Enterprise Application Platform Expansion Pack.

CVE-2026-9800
Unclassified
May 19, 2026
High7.8Red Hat

High [CVE-2026-46323] Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs

Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs. Red Hat rates this important (CVSS 7.8). Weakness: CWE-123. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27708 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux for NVIDIA 26; and 5 more.

CVE-2026-46323
Unclassified
May 19, 2026
High8.0Red Hat

High [CVE-2026-25244] Remote Code Execution via command injection in Git branch name processing

Remote Code Execution via command injection in Git branch name processing. Red Hat rates this important (CVSS 8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-25244
Unclassified
May 18, 2026
High8.3Red Hat

High [CVE-2026-44774] Privilege escalation via Kubernetes Gateway API provider configuration bypass

Privilege escalation via Kubernetes Gateway API provider configuration bypass. Red Hat rates this important (CVSS 8.3). Weakness: CWE-15. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.29.

CVE-2026-44774
Unclassified
May 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-46483] command injection when decompressing .tgz archives

command injection when decompressing.tgz archives. Red Hat rates this moderate (CVSS 7). Weakness: CWE-78. Affected package(s): vim. Resolved in Red Hat advisory RHSA-2026:28049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-46483
Unclassified
May 15, 2026
High7.5Red Hat

High [CVE-2026-45736] Uninitialized memory disclosure via `websocket.close()` with `TypedArray`

Uninitialized memory disclosure via `websocket.close()` with `TypedArray`. Red Hat rates this important (CVSS 7.5). Weakness: CWE-824. Affected package(s): dotnet8, ansible-automation-platform, rhdh/rhdh-hub-rhel9:1782761244, dotnet10, discovery/discovery-ui-rhel9:1782166952, dotnet9. Resolved in Red Hat advisory RHSA-2026:34374 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9; Red Hat Discovery 2; and 30 more.

CVE-2026-45736
Unclassified
May 15, 2026
High7.8Red Hat

High [CVE-2026-46333] Read root-owned files as an unprivileged user

Read root-owned files as an unprivileged user. Red Hat rates this important (CVSS 7.8). Weakness: CWE-269. Affected package(s): kernel, rhcos, kernel-rt, openshift, kpatch-patch, cri-o. Resolved in Red Hat advisory RHSA-2026:23470 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NVIDIA for RHEL 10; Red Hat OpenShift Container Platform 4.20; Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); and 55 more.

CVE-2026-46333
Unclassified
May 15, 2026
High7.0Red Hat

High [CVE-2025-54518] Privilege escalation via improper CPU cache isolation

Privilege escalation via improper CPU cache isolation. Red Hat rates this important (CVSS 7). Weakness: CWE-1220. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; and 5 more.

CVE-2025-54518
Unclassified
May 15, 2026
High8.2Red Hat

High [CVE-2026-34253] vorbis-tools ogg123: Arbitrary code execution via buffer underflow in remote control functionality

vorbis-tools ogg123: Arbitrary code execution via buffer underflow in remote control functionality. Red Hat rates this important (CVSS 8.2). Weakness: CWE-124. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34253
Unclassified
May 15, 2026
High7.5Red Hat

High [CVE-2026-44673] Denial of Service or arbitrary code execution via maliciously crafted LYB binary blob

Denial of Service or arbitrary code execution via maliciously crafted LYB binary blob. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): libyang. Resolved in Red Hat advisory RHSA-2026:24758 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 2 more.

CVE-2026-44673
Unclassified
May 14, 2026
High8.8Red Hat

High [CVE-2026-8559] Integer overflow in Internationalization

Integer overflow in Internationalization. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8559
Unclassified
May 14, 2026
High8.8Red Hat

High [CVE-2026-8555] Use after free in GTK

Use after free in GTK. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8555
Unclassified
May 14, 2026
High8.8Red Hat

High [CVE-2026-8551] Use after free in Downloads

Use after free in Downloads. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8551
Unclassified
May 14, 2026
High8.8Red Hat

High [CVE-2026-8552] Heap buffer overflow in GPU

Heap buffer overflow in GPU. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8552
Unclassified
May 14, 2026
High8.0Red Hat

High [CVE-2026-8542] Use after free in Core

Use after free in Core. Red Hat rates this important (CVSS 8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8542
Unclassified
May 14, 2026
High8.1Red Hat

High [CVE-2026-8539] Script injection in SanitizerAPI

Script injection in SanitizerAPI. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8539
Unclassified
May 14, 2026
High8.7Red Hat

High [CVE-2026-8536] Insufficient validation of untrusted input in ReadingMode

Insufficient validation of untrusted input in ReadingMode. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1289. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8536
Unclassified
May 14, 2026
High7.4Red Hat

High [CVE-2026-8537] Insufficient policy enforcement in ViewTransitions

Insufficient policy enforcement in ViewTransitions. Red Hat rates this important (CVSS 7.4). Weakness: CWE-368. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8537
Unclassified
May 14, 2026

← All vendors