Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4712 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.0Red Hat

High [CVE-2026-64582] Fix a use-after-free problem in rxe_mmap

Fix a use-after-free problem in rxe_mmap. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-64582
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-67864] Denial of Service via NodeManagement type-instantiation logic

Denial of Service via NodeManagement type-instantiation logic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287.

CVE-2026-67864
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-56848] Heap-use-after-free in HTTP/2 handling can lead to denial of service

Heap-use-after-free in HTTP/2 handling can lead to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-56848
Unclassified
Aug 4, 2026
High8.8Red Hat

High [CVE-2026-15307] Remote code execution via GeoDjango spatial lookups

Remote code execution via GeoDjango spatial lookups. Red Hat rates this important (CVSS 8.8). Weakness: CWE-434. Red Hat lists fixing advisory RHSA-2026:59153 with package ansible-automation-platform-25/hub-rhel8:1787101922, ansible-automation-platform-26/lightspeed-rhel9:1787244079, python3.12-django-0:5.2.17-1.el8ap, ansible-automation-platform-25/lightspeed-rhel8:1787229385. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 5 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; Red Hat Update Infrastructure 5; and 1 more.

CVE-2026-15307
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-68494] Denial of Service via incomplete fix in async JSON parser

Denial of Service via incomplete fix in async JSON parser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53643 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, jackson-core. Affected products named by the advisory: Cryostat 4; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 28 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel 4 for Quarkus 3; and 24 more.

CVE-2026-68494
Unclassified
Aug 4, 2026
High7.3Vendor: MediumRed Hat

High [CVE-2026-42169] GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c)

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution. This vulnerability in GIMP's APNG loader and DDS plug-in could lead to a heap-buffer-overflow when processing specially crafted image files. Exploitation requires a user to open a malicious APNG or DDS image. Red Hat products shipping GIMP are affected if users are exposed to untrusted image files. Red Hat severity: Moderate — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-131. Affected Red Hat products: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8 as not affected. Red Hat fixing advisory: RHSA-2026:50817, RHSA-2026:73768. Affected products named by the advisory: Red Hat package: gimp.

CVE-2026-42169
Red Hat Enterprise Linux
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-56846] Remote memory exhaustion via HTTP/2 retained header blocks

Remote memory exhaustion via HTTP/2 retained header blocks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:48305 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-56846
Unclassified
Aug 4, 2026
High7.8Red Hat

High [CVE-2026-42170] GIMP DDS plug-in heap-based buffer overflow via BPP mismatch in load_layer (ddsread.c)

GIMP DDS plug-in heap-based buffer overflow via BPP mismatch in load_layer() (ddsread.c). Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.

CVE-2026-42170
Unclassified
Aug 4, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64561] Check for invalid/obsolete root *after* making MMU pages available

Check for invalid/obsolete root *after* making MMU pages available. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:45192 with package kernel-0:5.14.0-687.30.1.el9_8, kernel-0:6.12.0-55.94.1.el10_0, kernel-0:4.18.0-553.147.1.el8_10, kernel-0:5.14.0-427.141.1.el9_4. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.

CVE-2026-64561
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67855] Denial of Service via heap use-after-free

Denial of Service via heap use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.

CVE-2026-67855
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67857] Denial of Service via out-of-bounds read in client-side function

Denial of Service via out-of-bounds read in client-side function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125.

CVE-2026-67857
Unclassified
Aug 4, 2026
High7.8Red Hat

High [CVE-2026-51401] Arbitrary code execution via vms_fixfilename function

Arbitrary code execution via vms_fixfilename() function. Red Hat rates this important (CVSS 7.8). Weakness: CWE-641.

CVE-2026-51401
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67858] Denial of Service via buffer overflow in Local Discovery Server

Denial of Service via buffer overflow in Local Discovery Server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-67858
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67859] Denial of Service via Discovery/LDS handling

Denial of Service via Discovery/LDS handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-67859
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67862] Denial of Service via buffer-overflow

Denial of Service via buffer-overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-67862
Unclassified
Aug 4, 2026
High8.1Red Hat

High [CVE-2026-8400] Arbitrary class loading and instantiation via malicious IIOP server

Arbitrary class loading and instantiation via malicious IIOP server. Red Hat rates this important (CVSS 8.1). Weakness: CWE-470. Red Hat lists fixing advisory RHSA-2026:52949 with package java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-8400
Unclassified
Aug 4, 2026
High7.8Red Hat

High [CVE-2026-64564] don't free the ASCONF's own transport in DEL-IP processing

don't free the ASCONF's own transport in DEL-IP processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825.

CVE-2026-64564
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-67861] Denial of Service via UA_Client_getRemoteDataTypes component

Denial of Service via UA_Client_getRemoteDataTypes component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-67861
Unclassified
Aug 4, 2026
High8.2Red Hat

High [CVE-2026-67860] Heap-based buffer overflow in HistoryRead path

Heap-based buffer overflow in HistoryRead path. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120.

CVE-2026-67860
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-69244] Denial of Service via malformed HTTP responses

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the client. The vulnerable path was error message construction in aiohttp/_http_parser.pyx, where an llhttp error-position pointer was used to build a snippet for malformed chunked responses and malformed request or response bytes at the buffer end. This issue is fixed in version 3.14.3. This is an Important severity flaw in aiohttp that could lead to a denial of service in client applications. A remote, malicious HTTP server could send a specially crafted response, causing an out-of-bounds read in the aiohttp C response parser and resulting in the client application terminating unexpectedly. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Satellite 6.16 for RHEL 8; and 19 more.

CVE-2026-69244
Unclassified
Aug 3, 2026

← All vendors