Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4700 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.8Red Hat

High [CVE-2026-19151] Arbitrary code execution via use-after-free in V8

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) A flaw was found in chromium-browser. A remote attacker could exploit a use-after-free vulnerability in the V8 JavaScript engine by crafting a malicious HTML page. This could allow the attacker to execute arbitrary code within the browser's sandbox, potentially leading to further system compromise. While execution is initially contained within the browser's sandbox, the potential for further system compromise elevates the risk to Important, as it bypasses typical browser security mechanisms. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19151
Unclassified
Aug 6, 2026
High8.2Red Hat

High [CVE-2026-19152] Sandbox escape via insufficient policy enforcement in Navigation

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) A flaw was found in Chromium. This vulnerability can be exploited via a specially crafted HTML page, leading to a bypass of security boundaries. Exploitation requires a prior compromise of the renderer process, typically through a crafted HTML page, enabling the attacker to bypass security boundaries and potentially gain further system access. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-266.

CVE-2026-19152
Unclassified
Aug 6, 2026
High8.2Red Hat

High [CVE-2026-19148] Sandbox escape via out-of-bounds write in GPU

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) This could potentially allow the attacker to escape the browser's sandbox, leading to further system compromise. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-19148
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19150] Google Chrome (V8): Arbitrary code execution via crafted HTML page

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) A flaw was found in V8, the JavaScript engine used in Google Chrome. This could be achieved by enticing a user to visit a specially crafted HTML page. The primary impact is arbitrary code execution, which could lead to further system compromise. This vulnerability is rated as Important. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-843.

CVE-2026-19150
Unclassified
Aug 6, 2026
High8.2Red Hat

High [CVE-2026-19147] Sandbox escape via use-after-free vulnerability in Aura

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) This could potentially allow the attacker to perform a sandbox escape, bypassing security mechanisms and gaining further access to the system. Exploitation requires a prior compromise of the browser's renderer process, which could then be leveraged via a crafted HTML page to bypass security boundaries. This poses a significant risk for Red Hat platforms such as Fedora and EPEL, as it could lead to further system compromise beyond the browser's sandbox. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L). Weakness: CWE-787.

CVE-2026-19147
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19145] Arbitrary code execution via use-after-free in Translate component

Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) A flaw was found in the Translate component of Chromium. This could lead to arbitrary code execution within the sandbox environment, potentially compromising the affected system. The vulnerability is triggered by user interaction with a specially crafted HTML page, posing a significant risk due to the common exposure to untrusted web content. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19145
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19144] Arbitrary code execution via crafted HTML page

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) This vulnerability, known as a use-after-free, occurs when the program attempts to use memory that has already been deallocated. Successful exploitation could lead to heap corruption, potentially allowing the attacker to execute arbitrary code. This Important flaw in Chromium allows a remote attacker to execute arbitrary code by tricking a user into visiting a malicious HTML page. The use-after-free vulnerability in the HTML component can lead to heap corruption, making it a significant risk for users of Red Hat-supported systems running Chromium, particularly when browsing untrusted web content. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19144
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19142] Remote code execution via use after free in Views

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) This could lead to heap corruption, potentially allowing the attacker to execute arbitrary code on the affected system. This Important vulnerability in Chromium's Views component allows a remote attacker to achieve code execution. Exploitation requires a user to interact with a specially crafted HTML page, which could lead to heap corruption. This risk is elevated due to the potential for arbitrary code execution within the browser's context. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19142
Unclassified
Aug 6, 2026
High8.2Red Hat

High [CVE-2026-19143] Google Chrome on Android: Sandbox escape via malicious WebAPK input

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) By crafting and using a malicious file, an attacker can bypass security restrictions designed to isolate applications, potentially leading to unauthorized access or control over the device. This is an Important vulnerability. While the original report references Google Chrome on Android, the underlying flaw affects the Chromium package in Red Hat Community Projects, potentially leading to a compromise of the system beyond the browser's security boundaries. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-1286.

CVE-2026-19143
Unclassified
Aug 6, 2026
High8.2Red Hat

High [CVE-2026-19140] Sandbox escape via use after free vulnerability in crafted HTML.

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) This escape can be achieved by tricking a user into visiting a specially crafted HTML page. Successful exploitation could lead to arbitrary code execution outside the browser's security sandbox. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19140
Unclassified
Aug 6, 2026
High8.2Red Hat

High [CVE-2026-19141] Sandbox escape due to use-after-free vulnerability

Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) A flaw was found in Chromium. This could be achieved by enticing a user to visit a specially crafted HTML page, leading to a higher level of system access. This vulnerability, triggered by user interaction with a crafted HTML page, could lead to further system compromise by bypassing a critical security boundary. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19141
Unclassified
Aug 6, 2026
High8.3Red Hat

High [CVE-2026-19138] Sandbox escape via heap buffer overflow in CrashReporting

Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) This could lead to further compromise of the user's system. After an initial compromise of the renderer process, typically through user interaction with a crafted HTML page, a heap buffer overflow can be exploited to bypass the browser's security sandbox. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-120.

CVE-2026-19138
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19168] Arbitrary Code Execution via crafted HTML page

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) This can be achieved by enticing a user to visit a specially crafted HTML page, leading to unauthorized code execution. This Important vulnerability in the V8 engine of Chromium-based browsers allows for arbitrary code execution within the browser's sandbox. Exploitation requires a user to visit a specially crafted HTML page, making it a client-side attack that could lead to system compromise if the sandbox is bypassed. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-823.

CVE-2026-19168
Unclassified
Aug 6, 2026
High8.3Red Hat

High [CVE-2026-19169] Privilege escalation via crafted HTML page in Contextual Tasks

Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) This can be achieved by enticing a user to visit a crafted HTML page, leading to an attacker gaining elevated permissions within the browser. The vulnerability is triggered by insufficient validation of untrusted input when a user visits a specially crafted HTML page, posing a significant risk to the confidentiality and integrity of user data for Red Hat users of the Chromium browser. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L). Weakness: CWE-79.

CVE-2026-19169
Unclassified
Aug 6, 2026
High8.2Red Hat

High [CVE-2026-19172] Sandbox escape via use after free in Views

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) A flaw was found in Chromium's Views component. This could potentially lead to a sandbox escape, allowing the attacker to execute code outside the confined environment. Exploiting a use-after-free flaw in the Views component with a crafted HTML page could bypass a critical security boundary, potentially leading to further system compromise beyond the browser's sandboxed environment. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19172
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19170] Sandbox escape via use after free in WebGL

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) This could potentially allow the attacker to perform a sandbox escape, breaking out of the browser's security protections and gaining further access to the system. This flaw allows a remote attacker to execute arbitrary code outside the browser's security sandbox by enticing a user to visit a specially crafted HTML page. While requiring user interaction, the ability to bypass browser security protections makes this an Important concern for Red Hat users of Chromium. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19170
Unclassified
Aug 6, 2026
High8.4Red Hat

High [CVE-2026-19157] Sandbox escape via out-of-bounds write in Google Chrome on Android

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) A flaw was found in ANGLE, a component within Google Chrome on Android. This could lead to an attacker executing arbitrary code outside the browser's security sandbox. This bypasses security boundaries, leading to potential compromise of the underlying system. Red Hat severity: Important — CVSS 8.4 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-19157
Unclassified
Aug 6, 2026
High8.3Red Hat

High [CVE-2026-19149] Sandbox escape via use-after-free vulnerability in Aura

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) A flaw was found in the Aura component of Google Chrome. This could allow the attacker to bypass security restrictions (sandbox escape) and execute unauthorized code on the affected system, posing a critical risk to data and system integrity. An Important vulnerability exists in the Aura component of Chromium, as distributed in Fedora and EPEL. Successful exploitation could lead to arbitrary code execution outside the browser's security sandbox, significantly compromising system integrity and confidentiality. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19149
Unclassified
Aug 6, 2026
High7.5Red Hat

High [CVE-2026-67422] Denial of Service via Regular Expression Vulnerability

Denial of Service via Regular Expression Vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Hardened Images; Self-service automation portal 2.

CVE-2026-67422
Unclassified
Aug 6, 2026
High8.7Red Hat

High [CVE-2026-66808] unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)

unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection). Red Hat rates this important (CVSS 8.7). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:54432 with package multicluster-engine/hypershift-addon-rhel9-operator:1786912006, multicluster-engine/hypershift-addon-rhel9-operator:1786548381, multicluster-engine/hypershift-addon-rhel9-operator:1787259113, multicluster-engine/hypershift-addon-rhel9-operator:1787264068. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-66808
Unclassified
Aug 6, 2026

← All vendors