Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.2Red Hat

High [CVE-2026-7911] Use after free in Aura

Use after free in Aura. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7911
Unclassified
May 5, 2026
High7.7Red Hat

High [CVE-2026-7910] Use after free in Views

Use after free in Views. Red Hat rates this important (CVSS 7.7). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7910
Unclassified
May 5, 2026
High8.8Red Hat

High [CVE-2026-7903] Integer overflow in ANGLE

Integer overflow in ANGLE. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7903
Unclassified
May 5, 2026
High8.8Red Hat

High [CVE-2026-7899] Out of bounds read and write in V8

Out of bounds read and write in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7899
Unclassified
May 5, 2026
High8.8Red Hat

High [CVE-2026-7896] Integer overflow in Blink

Integer overflow in Blink. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7896
Unclassified
May 5, 2026
High8.8Red Hat

High [CVE-2026-7929] Use after free in MediaRecording

Use after free in MediaRecording. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7929
Unclassified
May 5, 2026
High8.8Red Hat

High [CVE-2026-7926] Use after free in PresentationAPI

Use after free in PresentationAPI. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7926
Unclassified
May 5, 2026
High7.3Red Hat

High [CVE-2026-7913] Insufficient policy enforcement in DevTools

Insufficient policy enforcement in DevTools. Red Hat rates this important (CVSS 7.3). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7913
Unclassified
May 5, 2026
High8.2Red Hat

High [CVE-2026-7916] Insufficient data validation in InterestGroups

Insufficient data validation in InterestGroups. Red Hat rates this important (CVSS 8.2). Weakness: CWE-501. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7916
Unclassified
May 5, 2026
High8.0Red Hat

High [CVE-2026-7919] Use after free in Aura

Use after free in Aura. Red Hat rates this important (CVSS 8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7919
Unclassified
May 5, 2026
High8.2Red Hat

High [CVE-2026-7925] Use after free in Chromoting

Use after free in Chromoting. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7925
Unclassified
May 5, 2026
High8.0Red Hat

High [CVE-2026-7912] Integer overflow in GPU

Integer overflow in GPU. Red Hat rates this important (CVSS 8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7912
Unclassified
May 5, 2026
High8.8Red Hat

High [CVE-2026-7927] Type Confusion in Runtime

Type Confusion in Runtime. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7927
Unclassified
May 5, 2026
High7.5Red Hat

High [CVE-2026-6321] Path traversal vulnerability allows bypass of security policies

Path traversal vulnerability allows bypass of security policies. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected package(s): odf4/odf-multicluster-rhel9-operator:1778577548, network-observability/network-observability-console-plugin-rhel9:1780556069, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9:1782840519, odf4/odf-cli-rhel9:1781557189, satellite/iop-advisor-frontend-rhel9:1781181673. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; Red Hat Discovery 2; and 17 more.

CVE-2026-6321
Unclassified
May 4, 2026
High7.5Red Hat

High [CVE-2026-42154] Denial of Service via uncontrolled memory allocation in remote read endpoint

Denial of Service via uncontrolled memory allocation in remote read endpoint. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): opentelemetry-collector, jaeger-main, rhacm2/prometheus-rhel9:1782374537, opentelemetry-collector-main, openshift-logging/logging-loki-rhel9:1782405469, opentelemetry-collector-contrib-main. Resolved in Red Hat advisory RHSA-2026:29770 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: RHEM 1.0 for RHEL 9; Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 9); Logging Subsystem for Red Hat OpenShift 6.4; and 45 more.

CVE-2026-42154
Unclassified
May 4, 2026
High7.5Red Hat

High [CVE-2026-42151] Information disclosure of Azure OAuth client secret via config API

Information disclosure of Azure OAuth client secret via config API. Red Hat rates this important (CVSS 7.5). Weakness: CWE-256. Affected package(s): opentelemetry-collector, opentelemetry-collector-contrib-main, jaeger-main, opentelemetry-collector-main. Resolved in Red Hat advisory RHSA-2026:25504 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: RHEM 1.0 for RHEL 9; Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 9); Red Hat Edge Manager 1.0; and 42 more.

CVE-2026-42151
Unclassified
May 4, 2026
High7.5Red Hat

High [CVE-2026-43964] buffer over-read via malformed enhanced status code

buffer over-read via malformed enhanced status code. Red Hat rates this important (CVSS 7.5). Weakness: CWE-193. Affected package(s): postfix. Resolved in Red Hat advisory RHSA-2026:25932 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 5 more.

CVE-2026-43964
Unclassified
May 4, 2026
High8.8Red Hat

High [CVE-2026-29004] Arbitrary Code Execution via DHCPv6 Client Heap Buffer Overflow

Arbitrary Code Execution via DHCPv6 Client Heap Buffer Overflow. Red Hat rates this important (CVSS 8.8). Weakness: CWE-131. Affected package(s): busybox-main. Resolved in Red Hat advisory RHSA-2026:30652 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-29004
Unclassified
May 4, 2026
High7.5Red Hat

High [CVE-2026-40682] XML External Entity (XXE) vulnerability via crafted dictionary parsing

XML External Entity (XXE) vulnerability via crafted dictionary parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-611. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40682
Unclassified
May 4, 2026
High7.5Red Hat

High [CVE-2026-42027] Arbitrary Class Loading via Model Manifest

Arbitrary Class Loading via Model Manifest. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI).

CVE-2026-42027
Unclassified
May 4, 2026

← All vendors