Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4712 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.2Red Hat

High [CVE-2026-19143] Google Chrome on Android: Sandbox escape via malicious WebAPK input

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) By crafting and using a malicious file, an attacker can bypass security restrictions designed to isolate applications, potentially leading to unauthorized access or control over the device. This is an Important vulnerability. While the original report references Google Chrome on Android, the underlying flaw affects the Chromium package in Red Hat Community Projects, potentially leading to a compromise of the system beyond the browser's security boundaries. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-1286.

CVE-2026-19143
Unclassified
Aug 6, 2026
High8.2Red Hat

High [CVE-2026-19140] Sandbox escape via use after free vulnerability in crafted HTML.

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) This escape can be achieved by tricking a user into visiting a specially crafted HTML page. Successful exploitation could lead to arbitrary code execution outside the browser's security sandbox. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19140
Unclassified
Aug 6, 2026
High8.2Red Hat

High [CVE-2026-19141] Sandbox escape due to use-after-free vulnerability

Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) A flaw was found in Chromium. This could be achieved by enticing a user to visit a specially crafted HTML page, leading to a higher level of system access. This vulnerability, triggered by user interaction with a crafted HTML page, could lead to further system compromise by bypassing a critical security boundary. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19141
Unclassified
Aug 6, 2026
High8.3Red Hat

High [CVE-2026-19138] Sandbox escape via heap buffer overflow in CrashReporting

Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) This could lead to further compromise of the user's system. After an initial compromise of the renderer process, typically through user interaction with a crafted HTML page, a heap buffer overflow can be exploited to bypass the browser's security sandbox. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-120.

CVE-2026-19138
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19168] Arbitrary Code Execution via crafted HTML page

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) This can be achieved by enticing a user to visit a specially crafted HTML page, leading to unauthorized code execution. This Important vulnerability in the V8 engine of Chromium-based browsers allows for arbitrary code execution within the browser's sandbox. Exploitation requires a user to visit a specially crafted HTML page, making it a client-side attack that could lead to system compromise if the sandbox is bypassed. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-823.

CVE-2026-19168
Unclassified
Aug 6, 2026
High8.3Red Hat

High [CVE-2026-19169] Privilege escalation via crafted HTML page in Contextual Tasks

Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) This can be achieved by enticing a user to visit a crafted HTML page, leading to an attacker gaining elevated permissions within the browser. The vulnerability is triggered by insufficient validation of untrusted input when a user visits a specially crafted HTML page, posing a significant risk to the confidentiality and integrity of user data for Red Hat users of the Chromium browser. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L). Weakness: CWE-79.

CVE-2026-19169
Unclassified
Aug 6, 2026
High8.2Red Hat

High [CVE-2026-19172] Sandbox escape via use after free in Views

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) A flaw was found in Chromium's Views component. This could potentially lead to a sandbox escape, allowing the attacker to execute code outside the confined environment. Exploiting a use-after-free flaw in the Views component with a crafted HTML page could bypass a critical security boundary, potentially leading to further system compromise beyond the browser's sandboxed environment. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19172
Unclassified
Aug 6, 2026
High8.8Red Hat

High [CVE-2026-19170] Sandbox escape via use after free in WebGL

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) This could potentially allow the attacker to perform a sandbox escape, breaking out of the browser's security protections and gaining further access to the system. This flaw allows a remote attacker to execute arbitrary code outside the browser's security sandbox by enticing a user to visit a specially crafted HTML page. While requiring user interaction, the ability to bypass browser security protections makes this an Important concern for Red Hat users of Chromium. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19170
Unclassified
Aug 6, 2026
High8.4Red Hat

High [CVE-2026-19157] Sandbox escape via out-of-bounds write in Google Chrome on Android

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) A flaw was found in ANGLE, a component within Google Chrome on Android. This could lead to an attacker executing arbitrary code outside the browser's security sandbox. This bypasses security boundaries, leading to potential compromise of the underlying system. Red Hat severity: Important — CVSS 8.4 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-787.

CVE-2026-19157
Unclassified
Aug 6, 2026
High8.3Red Hat

High [CVE-2026-19149] Sandbox escape via use-after-free vulnerability in Aura

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) A flaw was found in the Aura component of Google Chrome. This could allow the attacker to bypass security restrictions (sandbox escape) and execute unauthorized code on the affected system, posing a critical risk to data and system integrity. An Important vulnerability exists in the Aura component of Chromium, as distributed in Fedora and EPEL. Successful exploitation could lead to arbitrary code execution outside the browser's security sandbox, significantly compromising system integrity and confidentiality. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-19149
Unclassified
Aug 6, 2026
High7.5Red Hat

High [CVE-2026-67422] Denial of Service via Regular Expression Vulnerability

Denial of Service via Regular Expression Vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Hardened Images; Self-service automation portal 2.

CVE-2026-67422
Unclassified
Aug 6, 2026
High8.7Red Hat

High [CVE-2026-66808] unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)

unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection). Red Hat rates this important (CVSS 8.7). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:54432 with package multicluster-engine/hypershift-addon-rhel9-operator:1786912006, multicluster-engine/hypershift-addon-rhel9-operator:1786548381, multicluster-engine/hypershift-addon-rhel9-operator:1787259113, multicluster-engine/hypershift-addon-rhel9-operator:1787264068. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-66808
Unclassified
Aug 6, 2026
High7.5Red Hat

High [CVE-2026-71436] Denial of Service via invalid X-Axis parameters

Denial of Service via invalid X-Axis parameters. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.

CVE-2026-71436
Unclassified
Aug 6, 2026
High8.5Red Hat

High [CVE-2026-71327] Cross-namespace backend hijacking due to Gateway API identity collision

Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10. Its Kubernetes Gateway API provider incorrectly generates unique identifiers for routes and services. This vulnerability allows an attacker to create conflicting routes, which can then overwrite the backend services of another isolated environment (namespace). This could lead to unauthorized control over services in different namespaces. A flaw in Traefik's Kubernetes Gateway API provider allows a lower-privileged tenant to overwrite backend routing rules across namespace boundaries. Due to deterministic route identity generation concatenating namespace, route name, Gateway identity, entry point, and rule index using hyphens, identical generated string identifiers result in name collisions. Affected product named by the advisory: Red Hat OpenShift Dev Spaces.

CVE-2026-71327
Unclassified
Aug 6, 2026
High8.7Red Hat

High [CVE-2026-71325] Namespace isolation bypass via TraefikService backendRef

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10. A flaw was found in Traefik. This flaw allows a tenant, even when restricted by Role-Based Access Control (RBAC) to a single namespace, to bypass namespace isolation. This defeats the intended `allowCrossNamespace=false` enforcement, leading to unauthorized access or manipulation of services across namespaces. A flaw in Traefik's service resolver allows a lower-privileged tenant to reference and bind cross-namespace TraefikService objects via @kubernetescrd, even when allowCrossNamespace=false is configured. By creating a custom router targeting an isolated TraefikService CRD in a separate namespace, an authenticated attacker can bypass namespace isolation controls, intercepting or rerouting backend service traffic across multi-tenant boundaries.

CVE-2026-71325
Unclassified
Aug 6, 2026
High8.1Red Hat

High [CVE-2026-43632] Potential code execution via a race condition in tokenization endpoints

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task queue and access ctx_server.vocab directly on HTTP worker threads. Attackers can exploit a time-of-check-time-of-use race condition where the main thread destroys and frees vocab after the synchronization lock is released but before the handler finishes using it, causing a crash or potential code execution when --sleep-idle-seconds is configured. Successful exploitation could lead to a system crash or potentially arbitrary code execution. This occurs when the main thread releases synchronization locks and destroys the vocabulary structure while an HTTP worker thread is still actively processing a request. An unauthenticated remote attacker sending concurrent HTTP requests can trigger heap corruption, leading to a service crash (Denial of Service) or potential arbitrary code execution within the security context of the llama-server process. Because exploitation relies on tight timing windows during idle cleanup cycles and impact is contained within the process boundaries without inherent host privilege escalation or OS isolation bypass, this vulnerability has been rated with an Important severity.

CVE-2026-43632
Unclassified
Aug 6, 2026
High8.1Red Hat

High [CVE-2026-43631] Remote code execution via use-after-free vulnerability in llama-server

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the vulnerability by sending requests to affected endpoints while the server transitions to sleep mode, causing concurrent worker threads to dereference a freed vocab pointer that can be reclaimed with attacker-controlled data to achieve remote code execution. Exploitation requires sending network requests to the HTTP server during the specific, narrow window when the service transitions into an idle sleep state. If successfully timing the race condition, an unauthenticated attacker could corrupt server memory to achieve full compromise across Confidentiality, Integrity, and Availability (C:H, I:H, A:H) within the process privilege context. Deployments operating without automated idle-sleep timeouts enabled, CLI tool invocations, or non-server API environments are completely unaffected by this flaw. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-43631
Unclassified
Aug 6, 2026
High8.1Red Hat

High [CVE-2026-43629] Arbitrary code execution via crafted KV cache state files

llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write access to the slot_save_path directory to corrupt heap memory. Attackers can craft malicious state files where cell_count multiplication overflows or exceeds tensor buffer allocation to write attacker-controlled bytes past buffer boundaries, potentially resulting in heap metadata corruption, model weight corruption, or arbitrary code execution via function pointer overwrite. An attacker with local write access to specific directories can exploit a heap buffer overflow vulnerability. By crafting malicious data files, the attacker can cause the system to write beyond intended memory boundaries. This could lead to data corruption or, in severe cases, allow the attacker to execute unauthorized code, potentially compromising the system. Exploitation requires an attacker to possess write access to the slot storage location and plant a maliciously crafted key-value cache state file prior to a restoration operation. If successfully processed, the heap memory corruption can grant complete compromise of Confidentiality, Integrity, and Availability (C:H, I:H, A:H) within the context of the running application process.

CVE-2026-43629
Unclassified
Aug 6, 2026
High7.8Red Hat

High [CVE-2026-43627] Arbitrary Code Execution via Integer Overflow in Memory Allocation

llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers can pass specially crafted parameters to trigger integer overflow, causing heap corruption and potentially achieving arbitrary code execution through subsequent batch operations that write past allocated buffer boundaries. Exploitation requires convincing a user or local process to execute inference workloads using maliciously oversized batch sizing parameters, leading to an arithmetic overflow during memory allocation and subsequent heap corruption. Full impact across Confidentiality, Integrity, and Availability (C:H, I:H, A:H) is possible if local memory execution controls fail, potentially resulting in arbitrary code execution within the application context. Deployments operating strictly with validated, bounded batch size inputs or running non-interactive server pipelines where batch parameters are hard-coded or strictly validated are unaffected. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-805. Affected Red Hat products: Red Hat Enterprise Linux AI (RHEL AI) 3. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-43627
Unclassified
Aug 6, 2026
High7.8Red Hat

High [CVE-2026-7867] Local Privilege Escalation via as-user option spoofing

Local Privilege Escalation via as-user option spoofing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:53435 with package udisks2-0:2.11.0-2.el10_2.1. Affected product named by the advisory: Red Hat Enterprise Linux 10. Affected product named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support.

CVE-2026-7867
Unclassified
Aug 6, 2026

← All vendors