Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5545 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium4.3Linux Updated

Medium [CVE-2026-67303] Denial of Service via unsupported serial device control request

Denial of Service via unsupported serial device control request. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-617.

CVE-2026-67303
Unclassified
Aug 1, 2026
Medium5.3Linux Updated

Medium [CVE-2026-66402] Server Identity Verification Bypass via TLS Certificate Validation Weaknesses

Server Identity Verification Bypass via TLS Certificate Validation Weaknesses. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-222.

CVE-2026-66402
Unclassified
Aug 1, 2026
Medium6.1Linux Updated

Medium [CVE-2026-67338] Stored cross-site scripting in Extension Manager allows arbitrary code execution

Stored cross-site scripting in Extension Manager allows arbitrary code execution. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-79.

CVE-2026-67338
Unclassified
Aug 1, 2026
Medium6.5Linux Updated

Medium [CVE-2026-67296] Denial of Service due to RDPEI message processing

Denial of Service due to RDPEI message processing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-20.

CVE-2026-67296
Unclassified
Aug 1, 2026
Medium6.5Linux Updated

Medium [CVE-2026-67304] Denial of Service via null pointer dereference in smartcard cleanup

Denial of Service via null pointer dereference in smartcard cleanup. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476.

CVE-2026-67304
Unclassified
Aug 1, 2026
Medium4.2Linux Updated

Medium [CVE-2026-67293] Weakens TLS server authentication due to improper wildcard certificate hostname validation

Weakens TLS server authentication due to improper wildcard certificate hostname validation. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-295.

CVE-2026-67293
Unclassified
Aug 1, 2026
Medium5.3Linux Updated

Medium [CVE-2026-67317] Denial of Service via maxBodyLength bypass with ReadableStream

Denial of Service via maxBodyLength bypass with ReadableStream. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.

CVE-2026-67317
Unclassified
Aug 1, 2026
Medium6.5Linux Updated

Medium [CVE-2026-67297] Resource exhaustion due to oversized chunked HTTP responses

Resource exhaustion due to oversized chunked HTTP responses. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.

CVE-2026-67297
Unclassified
Aug 1, 2026
Medium5.9Linux Updated

Medium [CVE-2026-67301] Memory disclosure or denial of service via crafted RDP update orders

Memory disclosure or denial of service via crafted RDP update orders. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-125.

CVE-2026-67301
Unclassified
Aug 1, 2026
Medium6.5Linux

Medium [CVE-2026-67290] Denial of Service via malformed media data

Denial of Service via malformed media data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125.

CVE-2026-67290
Unclassified
Aug 1, 2026
Low2.1Linux Updated

Low [CVE-2026-66401] Denial of Service via out-of-bounds read in UVC H.264 parser

Denial of Service via out-of-bounds read in UVC H.264 parser. Red Hat rates this low (CVSS 2.1). Weakness: CWE-125.

CVE-2026-66401
Unclassified
Aug 1, 2026
Low3.7Linux Updated

Low [CVE-2026-67316] Prototype Pollution allows unauthorized data transmission and network redirection

Prototype Pollution allows unauthorized data transmission and network redirection. Red Hat rates this low (CVSS 3.7). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.

CVE-2026-67316
Unclassified
Aug 1, 2026
Low3.7Linux Updated

Low [CVE-2026-67294] Server certificate validation bypass via improper Extended Key Usage (EKU) validation

Server certificate validation bypass via improper Extended Key Usage (EKU) validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295.

CVE-2026-67294
Unclassified
Aug 1, 2026
Critical9.9Linux

Critical [CVE-2026-17566] pgAdmin 4: pgAdmin 4: Remote Code Execution via backslash-escape mismatch in Import/Export Data tool

pgAdmin 4: pgAdmin 4: Remote Code Execution via backslash-escape mismatch in Import/Export Data tool. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-78.

CVE-2026-17566
Unclassified
Jul 31, 2026
High7.4Linux Updated

High [CVE-2026-68770] Remote Code Execution via Security Control Bypass

Remote Code Execution via Security Control Bypass. Red Hat rates this important (CVSS 7.4). Weakness: CWE-454.

CVE-2026-68770
Unclassified
Jul 31, 2026
High8.2Linux

High [CVE-2026-18141] Authentication bypass in Event-Driven Ansible via forged HTTP header

Authentication bypass in Event-Driven Ansible via forged HTTP header. Red Hat rates this important (CVSS 8.2). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:50340 with package automation-eda-controller-0:1.2.11-1.el9ap, ansible-automation-platform-27/gateway-rhel9:1785435970, ansible-automation-platform-26/gateway-rhel9:1785780020. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-18141
Red Hat Enterprise Linux
Jul 31, 2026
High7.5Linux Updated

High [CVE-2026-18446] Host confusion vulnerability via backslash in URI authority

Host confusion vulnerability via backslash in URI authority. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1289. Red Hat lists fixing advisory RHSA-2026:49387 with package grafana13-1-main-13.1.1-0.4.hum1, grafana12-4-main-12.4.6-0.3.hum1.

CVE-2026-18446
Unclassified
Jul 31, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-18358] gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service

gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-400.

CVE-2026-18358
Unclassified
Jul 31, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-11770] pre-auth LDAP filter injection in CleanAllRUV status check

pre-auth LDAP filter injection in CleanAllRUV status check. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-90.

CVE-2026-11770
Unclassified
Jul 31, 2026
High7.5Linux

High [CVE-2026-15722] pre-authentication stack buffer overflow in get_ruvelement_from_berval via unbounded replica ID parsing

pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-121.

CVE-2026-15722
Unclassified
Jul 31, 2026

← All vendors