Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4699 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-19015] Uncontrolled resource consumption leading to denial of service

Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-19015, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3. A flaw was found in Consul. This allows the attacker to continuously grow the agent's Connect CA roots cache, bypassing configured cache limits. The consequence is a denial of service (DoS) due to excessive memory usage, impacting the availability of the service. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.

CVE-2026-19015
Unclassified
Aug 7, 2026
High7.1Red Hat

High [CVE-2026-71556] Arbitrary file read/write via symbolic link resolution

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. This could result in information disclosure or arbitrary file modification. Exploitation requires the application to clone an attacker-controlled repository and then perform worktree operations against it; applications that only process trusted repositories are not exposed. Red Hat rates the impact of this flaw as Important. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L). Weakness: CWE-59. Affected products named by the advisory: external secrets operator for Red Hat OpenShift 1.2; Red Hat Hardened Images; Assisted Installer for Red Hat OpenShift Container Platform 2; Builds for Red Hat OpenShift; and 38 more. Affected products named by the advisory: Compliance Operator; Confidential Compute Attestation; Custom Metric Autoscaler operator for Red Hat Openshift; DPU kit for NVIDIA; and 34 more.

CVE-2026-71556
Unclassified
Aug 7, 2026
High7.5Red Hat

High [CVE-2026-15816] root code execution via unescaped error message written to sourced emergency hook script in die

root code execution via unescaped error message written to sourced emergency hook script in die(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:54575 with package dracut-0:057-54.git20250423.el9_4.3, dracut-0:057-25.git20250717.el9_2.2, dracut-0:057-89.git20250311.el9_6.1, dracut-0:105-4.el10_0.1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 18 more.

CVE-2026-15816
Unclassified
Aug 7, 2026
High7.5Red Hat

High [CVE-2025-63235] codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets

codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772.

CVE-2025-63235
Unclassified
Aug 7, 2026
High7.8Red Hat

High [CVE-2026-70632] Arbitrary Code Execution in CFHD Decoder via Crafted AVI File

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer. A flaw was found in FFmpeg. A remote attacker can exploit this by providing a specially crafted AVI (Audio Video Interleave) file during stream analysis. This can lead to memory corruption and may be escalated to arbitrary code execution, allowing the attacker to run malicious code on the affected system. Exploitation requires a local attacker to entice a user into processing a specially crafted AVI file, which triggers an out-of-bounds write in the FFmpeg CineForm HD (CFHD) decoder. This user interaction and local attack vector reduce the overall risk compared to remotely exploitable flaws. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-70632
Unclassified
Aug 6, 2026
High7.8Red Hat

High [CVE-2026-70628] Arbitrary code execution via crafted WTV file in DVB subtitle parser

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution. A flaw was found in FFmpeg. An attacker could exploit a signed integer overflow vulnerability within the DVB subtitle parser by providing a specially crafted WTV (Windows Recorded TV Show) file. While exploitation requires a local attacker to entice a user into processing a specially crafted WTV file, successful exploitation could lead to arbitrary code execution. This risk is elevated due to FFmpeg's common use in multimedia processing within Red Hat environments. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-805. Affected Red Hat products: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-70628
Unclassified
Aug 6, 2026
High7.5Red Hat

High [CVE-2026-71430] Denial of Service due to excessive string length in replacements

Denial of Service due to excessive string length in replacements. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131.

CVE-2026-71430
Unclassified
Aug 6, 2026
High8.0Red Hat

High [CVE-2026-19177] Sandbox escape via crafted HTML page

Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) A flaw was found in Chromium. This could potentially allow the attacker to escape the browser's security sandbox, leading to further system compromise. While exploitation requires a prior compromise of the renderer process and user interaction with a specially crafted HTML page, a successful attack could lead to significant impact on the system's confidentiality, integrity, and availability. The high attack complexity and user interaction prevent this flaw from being rated Critical. Red Hat severity: Important — CVSS 8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-1289.

CVE-2026-19177
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19175] Remote sandbox escape via use-after-free in Payments

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) This could potentially allow the attacker to escape the browser's security sandbox, gaining unauthorized access to the underlying system. This Important vulnerability in the Chromium browser's Payments component allows a remote attacker to escape the browser's sandbox by enticing a user to visit a specially crafted HTML page. This flaw could lead to further compromise of the user's system beyond the browser's security boundaries. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H). Weakness: CWE-825.

CVE-2026-19175
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19174] Arbitrary code execution via crafted HTML page

Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) A flaw was found in V8, the JavaScript engine used in Google Chrome. This integer overflow vulnerability allows a remote attacker to execute arbitrary code within the browser's security sandbox—a protective environment that limits what a program can do. This can occur when a user visits a specially crafted HTML page, potentially leading to unauthorized operations within the sandboxed environment. This is an Important vulnerability in the V8 JavaScript engine, utilized by Chromium-based browsers. The requirement for user interaction to trigger the flaw contributes to its Important severity, as direct network exploitation without user action is not possible. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190.

CVE-2026-19174
Unclassified
Aug 6, 2026
High8.3Red Hat

High [CVE-2026-19171] Sandbox escape via use-after-free in Media component

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) A flaw was found in chromium-browser. Exploitation can occur by enticing a user to visit a specially crafted HTML page. An Important use-after-free vulnerability in the Chromium Media component can lead to a sandbox escape. This affects Chromium as distributed in Red Hat community projects. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19171
Unclassified
Aug 6, 2026
High8.3Red Hat

High [CVE-2026-19166] Sandbox escape due to use-after-free in Web Authentication

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) This could potentially allow the attacker to escape the browser's security sandbox, leading to further system compromise. Exploitation requires user interaction, such as visiting a specially crafted HTML page, but could lead to significant system compromise beyond the browser's confines. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19166
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19164] Sandbox escape via crafted HTML page

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) By crafting a malicious HTML page, an attacker could potentially perform a sandbox escape, leading to the execution of arbitrary code outside the browser's security sandbox. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-1286.

CVE-2026-19164
Unclassified
Aug 6, 2026
High8.0Red Hat

High [CVE-2026-19163] Sandbox escape via use-after-free in Media component

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) This could be achieved by enticing a user to visit a specially crafted HTML page, leading to a higher level of system access. Red Hat severity: Important — CVSS 8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19163
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19162] Arbitrary code execution via out-of-bounds write in V8.

Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) A flaw was found in V8, the JavaScript engine used in Google Chrome. Exploitation occurs when a user visits a specially crafted HTML page. This could lead to unauthorized operations on the affected system. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-19162
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19158] Arbitrary code execution via use-after-free in Views

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) This can occur if a user is convinced to engage in specific user interface (UI) gestures while visiting a specially crafted HTML page, potentially leading to arbitrary code execution. This Important flaw in Chromium's Views component allows arbitrary code execution. This user interaction requirement slightly reduces the immediate risk, but successful exploitation could lead to a complete compromise of the affected system. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19158
Unclassified
Aug 6, 2026
High7.5Red Hat

High [CVE-2026-19159] Arbitrary code execution via use-after-free in Views

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) A flaw was found in chromium-browser. By convincing a user to engage in specific user interface gestures and visit a crafted HTML page, an attacker could achieve arbitrary code execution. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-19159
Unclassified
Aug 6, 2026
High8.7Red Hat

High [CVE-2026-19153] Site isolation bypass via insufficient input validation in Workers

Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) This could enable the attacker to access sensitive information or further compromise the user's system. Exploitation requires a compromised renderer process and a specially crafted HTML page, enabling the attacker to circumvent a critical security boundary designed to protect user data. Red Hat severity: Important — CVSS 8.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-807.

CVE-2026-19153
Unclassified
Aug 6, 2026
High7.8Red Hat

High [CVE-2026-19156] Heap buffer overflow allows heap corruption via malicious extension

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High) This vulnerability allows for potential heap corruption, which could be exploited to impact the integrity and availability of the browser. An Important heap buffer overflow flaw was found in the Base component of Chromium. While user interaction is required, the potential for significant impact on affected systems warrants the Important severity. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-19156
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19151] Arbitrary code execution via use-after-free in V8

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) A flaw was found in chromium-browser. A remote attacker could exploit a use-after-free vulnerability in the V8 JavaScript engine by crafting a malicious HTML page. This could allow the attacker to execute arbitrary code within the browser's sandbox, potentially leading to further system compromise. While execution is initially contained within the browser's sandbox, the potential for further system compromise elevates the risk to Important, as it bypasses typical browser security mechanisms. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19151
Unclassified
Aug 6, 2026

← All vendors