Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5444 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Low3.3Linux

Low [CVE-2026-14650] Denial of Service in UTF-8 Character Handler

Denial of Service in UTF-8 Character Handler. Red Hat rates this low (CVSS 3.3). Weakness: CWE-1050.

CVE-2026-14650
Unclassified
Jul 4, 2026
Critical9.8Vendor: HighLinux

Critical [CVE-2026-14544 +1] Incomplete Fix for CVE-2026-8631

Incomplete Fix for CVE-2026-8631. Red Hat rates this important (CVSS 9.8). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:40894 with package hplip-0:3.23.12-10.el10_2.5, hplip-0:3.21.2-6.el9_8.5, hplip-0:3.18.4-14.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-14544CVE-2026-8631
Red Hat Enterprise Linux
Jul 3, 2026
High8.8Linux

High [CVE-2026-12481] Arbitrary code execution via deserialization vulnerability

Arbitrary code execution via deserialization vulnerability. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502.

CVE-2026-12481
Unclassified
Jul 3, 2026
High7.4Linux

High [CVE-2026-9547] Man-in-the-middle attack via SSH host key bypass

Man-in-the-middle attack via SSH host key bypass. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-9547
Unclassified
Jul 3, 2026
High7.5Linux

High [CVE-2026-9546] Information disclosure due to persistent Referer header

Information disclosure due to persistent Referer header. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-9546
Unclassified
Jul 3, 2026
High7.5Linux

High [CVE-2026-9545] Information disclosure via cached SSL session and early data

Information disclosure via cached SSL session and early data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-295.

CVE-2026-9545
Unclassified
Jul 3, 2026
High7.3Linux

High [CVE-2026-9080] Use-after-free via curl_easy_pause in CURLMOPT_SOCKETFUNCTION callback

Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-9080
Unclassified
Jul 3, 2026
High7.5Linux

High [CVE-2026-9079] Information disclosure due to failure to clear proxy authentication credentials

Information disclosure due to failure to clear proxy authentication credentials. Red Hat rates this important (CVSS 7.5). Weakness: CWE-212. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-9079
Unclassified
Jul 3, 2026
High7.5Linux

High [CVE-2026-8932] Security feature bypass due to improper mTLS connection reuse

Security feature bypass due to improper mTLS connection reuse. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1025. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-8932
Unclassified
Jul 3, 2026
High7.5Linux

High [CVE-2026-8927] Information disclosure due to uncleared proxy authentication state

Information disclosure due to uncleared proxy authentication state. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-8927
Unclassified
Jul 3, 2026
High8.1Linux

High [CVE-2026-8925] Double-free vulnerability in SASL authentication

Double-free vulnerability in SASL authentication. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1341. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-8925
Unclassified
Jul 3, 2026
High8.1Linux

High [CVE-2026-8286] Insecure connection establishment due to TLS configuration mismatch

Insecure connection establishment due to TLS configuration mismatch. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-8286
Unclassified
Jul 3, 2026
High7.5Linux

High [CVE-2026-12064] SSH host verification bypass when using schemeless URLs with SFTP/SCP

SSH host verification bypass when using schemeless URLs with SFTP/SCP. Red Hat rates this important (CVSS 7.5). Weakness: CWE-358. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-12064
Unclassified
Jul 3, 2026
High7.5Linux

High [CVE-2026-11586] Denial of Service via WebSocket PING flood

Denial of Service via WebSocket PING flood. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-11586
Unclassified
Jul 3, 2026
High7.5Linux

High [CVE-2026-11352] Remote denial of service via QUIC UDP receive function vulnerability

Remote denial of service via QUIC UDP receive function vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:29017 with package rust-main-1.96.1-1.hum1, curl-main-8.21.0-0.1.hum1.

CVE-2026-11352
Unclassified
Jul 3, 2026
Medium6.5Linux

Medium [CVE-2026-14604] Denial of Service vulnerability in PLY Model Handler

Denial of Service vulnerability in PLY Model Handler. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1341.

CVE-2026-14604
Unclassified
Jul 3, 2026
Medium4.3Linux

Medium [CVE-2026-14631] Denial of Service via malformed headers

Denial of Service via malformed headers. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-248.

CVE-2026-14631
Unclassified
Jul 3, 2026
Medium4.7Linux

Medium [CVE-2026-14620] Arbitrary file opening and denial of service via exposed developer endpoints

Arbitrary file opening and denial of service via exposed developer endpoints. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-940.

CVE-2026-14620
Unclassified
Jul 3, 2026
Medium4.3Linux

Medium [CVE-2026-14615] FGAP v2 parent group children endpoint bypasses per-child view permission filter

FGAP v2 parent group children endpoint bypasses per-child view permission filter. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-1220.

CVE-2026-14615
Unclassified
Jul 3, 2026
Medium5.4Linux

Medium [CVE-2026-14614] FGAP v2 client scope assignment bypass via ClientResource

FGAP v2 client scope assignment bypass via ClientResource. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-639.

CVE-2026-14614
Unclassified
Jul 3, 2026

← All vendors