Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.0Red Hat

High [CVE-2026-4802] Arbitrary command execution via crafted links in system logs UI

Arbitrary command execution via crafted links in system logs UI. Red Hat rates this important (CVSS 8). Weakness: CWE-78. Affected package(s): cockpit. Resolved in Red Hat advisory RHSA-2026:21390 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; and 6 more.

CVE-2026-4802
Unclassified
May 11, 2026
High7.8Red Hat

High [CVE-2026-43500] "Dirty Frag" RxRPC variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel

"Dirty Frag" RxRPC variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel. Red Hat rates this important (CVSS 7.8). Weakness: CWE-123. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-43500
Unclassified
May 11, 2026
High7.5Red Hat

High [CVE-2026-8177] XML::LibXML: Denial of Service via truncated UTF-8 in XML node names

XML::LibXML: Denial of Service via truncated UTF-8 in XML node names. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-8177
Unclassified
May 10, 2026
High7.5Red Hat

High [CVE-2026-45186] denial of service via crafted XML input

denial of service via crafted XML input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-407. Affected package(s): expat, rhui5/haproxy-rhel9:1781525671, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, libexpat, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:22715 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 9); Red Hat Enterprise Linux BaseOS (v. 10); Red Hat Enterprise Linux BaseOS (v. 8); and 9 more.

CVE-2026-45186
Unclassified
May 10, 2026
High7.5Red Hat

High [CVE-2026-7263] denial of service via DOMNode::C14N()

denial of service via DOMNode::C14N(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): php8.4. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-7263
Unclassified
May 10, 2026
High8.2Red Hat

High [CVE-2026-6104] global buffer over-read in mb_convert_encoding() with attacker-supplied encoding

global buffer over-read in mb_convert_encoding() with attacker-supplied encoding. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected package(s): php8.4. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-6104
Unclassified
May 10, 2026
High7.7Red Hat

High [CVE-2026-6722] PHP SOAP extension: Remote Code Execution via use-after-free vulnerability

PHP SOAP extension: Remote Code Execution via use-after-free vulnerability. Red Hat rates this important (CVSS 7.7). Weakness: CWE-825. Affected package(s): php, php:7.4. Resolved in Red Hat advisory RHSA-2026:33449 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7.

CVE-2026-6722
Unclassified
May 10, 2026
High7.5Red Hat

High [CVE-2026-7262] NULL pointer dereference in SOAP apache:Map decoder with missing <value>

NULL pointer dereference in SOAP apache:Map decoder with missing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Affected package(s): php, php8.4, php:8.2, php:7.4, php:8.3. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-7262
Unclassified
May 10, 2026
High8.1Red Hat

High [CVE-2025-14179] SQL injection in pdo_firebird via NUL bytes in quoted strings

SQL injection in pdo_firebird via NUL bytes in quoted strings. Red Hat rates this important (CVSS 8.1). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2025-14179
Unclassified
May 10, 2026
High7.5Red Hat

High [CVE-2026-7568] signed integer overflow in metaphone()

signed integer overflow in metaphone(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): php, php8.4, php:8.2, php:7.4, php:8.3. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-7568
Unclassified
May 10, 2026
High7.1Red Hat

High [CVE-2026-42258] Net::IMAP: IMAP Command Injection via Symbol Arguments

Net::IMAP: IMAP Command Injection via Symbol Arguments. Red Hat rates this important (CVSS 7.1). Weakness: CWE-93. Affected package(s): ruby, ruby4.0, ruby:3.3, ruby:2.5, ruby:4.0. Resolved in Red Hat advisory RHSA-2026:33514 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.

CVE-2026-42258
Unclassified
May 9, 2026
High7.4Red Hat

High [CVE-2026-42246] Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS

Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS. Red Hat rates this important (CVSS 7.4). Weakness: CWE-325. Affected package(s): ruby, ruby4, ruby4.0, ruby:3.3, ruby3, ruby:2.5. Resolved in Red Hat advisory RHSA-2026:33514 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 9 more.

CVE-2026-42246
Unclassified
May 9, 2026
High7.0Red Hat

High [CVE-2026-41163] Privilege escalation via ptrace when installed in setuid mode

Privilege escalation via ptrace when installed in setuid mode. Red Hat rates this important (CVSS 7). Weakness: CWE-269. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41163
Unclassified
May 9, 2026
High8.1Red Hat

High [CVE-2026-42296] Privilege escalation via security control bypass

Privilege escalation via security control bypass. Red Hat rates this important (CVSS 8.1). Weakness: CWE-863. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-42296
Unclassified
May 9, 2026
High7.5Red Hat

High [CVE-2026-42294] Denial of Service via large request body to Webhook Interceptor

Denial of Service via large request body to Webhook Interceptor. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-42294
Unclassified
May 9, 2026
High8.3Red Hat

High [CVE-2026-42297] Unauthorized ConfigMap manipulation due to missing authorization

Unauthorized ConfigMap manipulation due to missing authorization. Red Hat rates this important (CVSS 8.3). Weakness: CWE-425. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-42297
Unclassified
May 9, 2026
High7.5Red Hat

High [CVE-2026-4890] NSEC bitmap parsing infinite loop

NSEC bitmap parsing infinite loop. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.19.

CVE-2026-4890
Unclassified
May 9, 2026
High7.5Red Hat

High [CVE-2026-4891] RRSIG rdlen underflow leading to heap OOB read

RRSIG rdlen underflow leading to heap OOB read. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; and 2 more.

CVE-2026-4891
Unclassified
May 9, 2026
High8.8Red Hat

High [CVE-2026-4892] DHCPv6 CLID buffer overflow in helper process

DHCPv6 CLID buffer overflow in helper process. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; and 2 more.

CVE-2026-4892
Unclassified
May 9, 2026
High7.5Red Hat

High [CVE-2026-5172] extract_addresses() OOB read via malformed rdlen

extract_addresses() OOB read via malformed rdlen. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:19158 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-5172
Unclassified
May 9, 2026

← All vendors