Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5441 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.3Linux

High [CVE-2026-14363] SQL Injection vulnerability

SQL Injection vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-89.

CVE-2026-14363
Unclassified
Jul 1, 2026
High8.2Linux

High [CVE-2026-53492] Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.

Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. Red Hat rates this important (CVSS 8.2). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:42852 with package multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784061472, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784060681, rhacm2/submariner-rhel9-operator:1782933193, multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784127491.

CVE-2026-53492
Unclassified
Jul 1, 2026
High7.8Linux

High [CVE-2026-46680] Privilege escalation via incorrect user ID handling

Privilege escalation via incorrect user ID handling. Red Hat rates this important (CVSS 7.8). Weakness: CWE-681. Red Hat lists fixing advisory RHSA-2026:35111 with package trivy-main-0.72.0-0.1.hum1.

CVE-2026-46680
Unclassified
Jul 1, 2026
High7.5Linux

High [CVE-2026-54428] org.apache.httpcomponents.core5/httpcore5: org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks

org.apache.httpcomponents.core5/httpcore5: org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-54428
Unclassified
Jul 1, 2026
High7.5Linux

High [CVE-2026-54399] org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers

org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-54399
Unclassified
Jul 1, 2026
High7.5Linux

High [CVE-2026-20243] Denial of Service via crafted ALZ file

Denial of Service via crafted ALZ file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-20243
Unclassified
Jul 1, 2026
High7.5Linux

High [CVE-2026-20244] Denial of Service via crafted DMG file

Denial of Service via crafted DMG file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190.

CVE-2026-20244
Unclassified
Jul 1, 2026
High7.5Linux

High [CVE-2026-20215] Denial of Service via crafted 7z file

Denial of Service via crafted 7z file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-20215
Unclassified
Jul 1, 2026
High7.5Linux

High [CVE-2026-20217] Denial of Service via crafted PESpin file

Denial of Service via crafted PESpin file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-20217
Unclassified
Jul 1, 2026
High7.5Linux

High [CVE-2026-20216] Denial of Service via crafted InstallShield file

Denial of Service via crafted InstallShield file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-20216
Unclassified
Jul 1, 2026
High7.5Linux

High [CVE-2026-20213] Denial of Service via crafted Portable Executable (PE) files

Denial of Service via crafted Portable Executable (PE) files. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-20213
Unclassified
Jul 1, 2026
High7.5Linux

High [CVE-2026-20214] Denial of Service via crafted FSG file parsing

Denial of Service via crafted FSG file parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-20214
Unclassified
Jul 1, 2026
High8.5Linux

High [CVE-2026-24260] Privilege escalation and code execution via race condition

Privilege escalation and code execution via race condition. Red Hat rates this important (CVSS 8.5). Weakness: CWE-367.

CVE-2026-24260
Unclassified
Jul 1, 2026
High8.8Linux

High [CVE-2026-5136] Privilege escalation to administrator-level access via usergroup role assignment manipulation

Privilege escalation to administrator-level access via usergroup role assignment manipulation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:34366 with package foreman-0:3.14.0.17-1.el9sat, foreman-0:3.18.0.7-1.el9sat, foreman-0:3.12.0.17-1.el9sat, foreman-0:3.12.0.17-1.el8sat. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-5136
Red Hat Enterprise Linux
Jul 1, 2026
High7.4Linux

High [CVE-2026-56016] Authentication bypass via predictable session IDs

Authentication bypass via predictable session IDs. Red Hat rates this important (CVSS 7.4). Weakness: CWE-331.

CVE-2026-56016
Unclassified
Jul 1, 2026
High7.5Linux

High [CVE-2026-57963] Chat UI manipulation by injection

An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-79. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-57963
Unclassified
Jul 1, 2026
High8.8Linux

High [CVE-2026-53488] Host-root command execution via unvalidated image config labels in CRI plugin

Host-root command execution via unvalidated image config labels in CRI plugin. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:37252 with package multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784060681, rhacm2/submariner-rhel9-operator:1782933193, multicluster-engine/assisted-service-8-rhel8:1783332008, multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784127491.

CVE-2026-53488
Unclassified
Jul 1, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-53341] fix UAF due to unlocked ->mnt_ns read in may_decode_fh

fix UAF due to unlocked ->mnt_ns read in may_decode_fh(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-364.

CVE-2026-53341
Unclassified
Jul 1, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-53354] Mitigate TLBI errata on various Arm CPUs

Mitigate TLBI errata on various Arm CPUs. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1037.

CVE-2026-53354
Unclassified
Jul 1, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-53355] clear i_sends on setup unwind

clear i_sends on setup unwind. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-53355
Unclassified
Jul 1, 2026

← All vendors