Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.1Vendor: MediumRed Hat

High [CVE-2026-43077] algif_aead - Fix minimum RX size check for decryption

algif_aead - Fix minimum RX size check for decryption. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-131. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-43077
Unclassified
May 6, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-43190] check remaining length before reading optlen

check remaining length before reading optlen. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-125. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-43190
Unclassified
May 6, 2026
High7.9Red Hat

High [CVE-2026-43133] Always use vmcb01 in VMLOAD/VMSAVE emulation

Always use vmcb01 in VMLOAD/VMSAVE emulation. Red Hat rates this important (CVSS 7.9). Weakness: CWE-628. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-43133
Unclassified
May 6, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-43128] Fix double dma_buf_unpin in failure path

Fix double dma_buf_unpin in failure path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:19569 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-43128
Unclassified
May 6, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-43158] fix freemap adjustments when adding xattrs to leaf blocks

fix freemap adjustments when adding xattrs to leaf blocks. Red Hat rates this moderate (CVSS 7). Weakness: CWE-617. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-43158
Unclassified
May 6, 2026
High7.0Red Hat

High [CVE-2026-43125] validate length in dlm_search_rsb_tree

validate length in dlm_search_rsb_tree. Red Hat rates this important (CVSS 7). Weakness: CWE-130. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 4 more.

CVE-2026-43125
Unclassified
May 6, 2026
High8.1Red Hat

High [CVE-2026-28780] Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow

Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Affected package(s): httpd, httpd:2.4, jbcs-httpd24-httpd. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: JBoss Core Services for RHEL 8; JBoss Core Services on RHEL 7; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-28780
Unclassified
May 5, 2026
High7.1Red Hat

High [CVE-2026-40110] Cross-Origin Resource Sharing (CORS) bypass via improper Origin header validation

Cross-Origin Resource Sharing (CORS) bypass via improper Origin header validation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-625. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat Migration Toolkit for Applications 8.2.

CVE-2026-40110
Unclassified
May 5, 2026
High7.5Red Hat

High [CVE-2026-35579] Authentication bypass allows unauthorized access to TSIG-protected functionalities

Authentication bypass allows unauthorized access to TSIG-protected functionalities. Red Hat rates this important (CVSS 7.5). Weakness: CWE-303. Affected package(s): rhacm2/lighthouse-coredns-rhel9:1780204249. Resolved in Red Hat advisory RHSA-2026:25127 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14.

CVE-2026-35579
Unclassified
May 5, 2026
High7.1Red Hat

High [CVE-2026-35397] Unauthorized File Access via Path Traversal Vulnerability

Unauthorized File Access via Path Traversal Vulnerability. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat Migration Toolkit for Applications 8.2.

CVE-2026-35397
Unclassified
May 5, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-32936] Denial of Service via oversized DNS-over-HTTPS GET requests

Denial of Service via oversized DNS-over-HTTPS GET requests. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1284. Affected package(s): rhacm2/lighthouse-agent-rhel9:1780204232, rhacm2/lighthouse-coredns-rhel9:1780204249. Resolved in Red Hat advisory RHSA-2026:25127 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32936
Unclassified
May 5, 2026
High8.8Red Hat

High [CVE-2026-25243] RESTORE invalid memory access may allow remote code execution

RESTORE invalid memory access may allow remote code execution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Affected package(s): redis, valkey, redis:6, redis:7. Resolved in Red Hat advisory RHSA-2026:26540 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 7 more.

CVE-2026-25243
Unclassified
May 5, 2026
High8.8Red Hat

High [CVE-2026-23631] Remote code execution via use-after-free in Lua scripting

Remote code execution via use-after-free in Lua scripting. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Affected package(s): redis:7, valkey. Resolved in Red Hat advisory RHSA-2026:26540 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images.

CVE-2026-23631
Unclassified
May 5, 2026
High7.5Red Hat

High [CVE-2026-23479] use-after-free in unblock client flow may allow remote code execution

use-after-free in unblock client flow may allow remote code execution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-416. Affected package(s): redis:7, valkey. Resolved in Red Hat advisory RHSA-2026:26540 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Hardened Images.

CVE-2026-23479
Unclassified
May 5, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-29168] unrestricted OCSP response leads to resource exhaustion

unrestricted OCSP response leads to resource exhaustion. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Affected package(s): mod_md, jbcs-httpd24-httpd, jbcs-httpd24-mod_md. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-29168
Unclassified
May 5, 2026
High7.5Red Hat

High [CVE-2026-6918] Denial of Service in JITServer via crafted TCP message

Denial of Service in JITServer via crafted TCP message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:22328 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 10.2 Extended Update Support.

CVE-2026-6918
Unclassified
May 5, 2026
High7.5Red Hat

High [CVE-2026-6322] URI authority bypass due to improper delimiter handling

URI authority bypass due to improper delimiter handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-140. Affected package(s): cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9:1782839981, cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9:1782840519, openshift4/ose-monitoring-plugin-rhel9:1782313844, quay/quay-rhel8:1781878070, rhacm2/console-rhel9:1780600823. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Enterprise Linux Extensions Channel (v. 10); Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9; and 36 more.

CVE-2026-6322
Unclassified
May 5, 2026
High7.5Red Hat

High [CVE-2026-43868] Denial of Service via excessive memory allocation

Denial of Service via excessive memory allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. Affected package(s): libthrift. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); and 1 more.

CVE-2026-43868
Unclassified
May 5, 2026
High7.3Red Hat

High [CVE-2026-43869] Security bypass due to improper certificate validation

Security bypass due to improper certificate validation. Red Hat rates this important (CVSS 7.3). Weakness: CWE-295. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, cryostat/cryostat-storage-rhel9:4.2.0, libthrift, rhosdt/tempo-rhel9:1781589494. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 17 more.

CVE-2026-43869
Unclassified
May 5, 2026
High7.7Red Hat

High [CVE-2026-42997] Information disclosure via credential forwarding during mold import

Information disclosure via credential forwarding during mold import. Red Hat rates this important (CVSS 7.7). Weakness: CWE-201. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

CVE-2026-42997
Unclassified
May 5, 2026

← All vendors