Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11617 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.4Red Hat

Medium [CVE-2026-91991] Cookie attribute injection via capitalized keyword arguments

Cookie attribute injection via capitalized keyword arguments. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-915. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 2 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4.

CVE-2026-91991
Unclassified
Sep 15, 2026
Medium5.4Red Hat

Medium [CVE-2026-91986] Information disclosure and virtual host spoofing via control character injection

Information disclosure and virtual host spoofing via control character injection. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 2 more. Affected products named by the advisory: Red Hat package: igvm; Red Hat package: rust.

CVE-2026-91986
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.3Red Hat

Medium [CVE-2026-91962] Remote out-of-bounds access via integer overflow in audin Apple backends

Remote out-of-bounds access via integer overflow in audin Apple backends. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-91962
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91961] Denial of Service via URBDRC control-transfer request with invalid OutputBufferSize

Denial of Service via URBDRC control-transfer request with invalid OutputBufferSize. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-91961
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91960] Denial of Service via integer overflow and double free in WinPR

Denial of Service via integer overflow and double free in WinPR. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-91960
Unclassified
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91959] Denial of Service due to buffer over-read in RPC gateway

Denial of Service due to buffer over-read in RPC gateway. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-91959
Unclassified
Sep 15, 2026
Medium6.6Red Hat

Medium [CVE-2026-91958] Denial of service and potential code execution via malicious RDP file

Denial of service and potential code execution via malicious RDP file. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.

CVE-2026-91958
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91956] Denial of Service via out-of-bounds read in URBDRC channel

Denial of Service via out-of-bounds read in URBDRC channel. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-91956
Unclassified
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91954] Denial of Service via crafted Surface Bits command

Denial of Service via crafted Surface Bits command. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-91954
Unclassified
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91952] Denial of Service via crafted AVC444 graphics updates

Denial of Service via crafted AVC444 graphics updates. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-91952
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91953] Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption.

Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-91953
Unclassified
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91951] Denial of Service via out-of-bounds write in urbdrc client channel

Denial of Service via out-of-bounds write in urbdrc client channel. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.

CVE-2026-91951
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91946] Information Disclosure via RDPGFX ResetGraphics PDU

Information Disclosure via RDPGFX ResetGraphics PDU. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-824. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-91946
Unclassified
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91945] Denial of Service due to out-of-bounds read in smartcard response processing

Denial of Service due to out-of-bounds read in smartcard response processing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.

CVE-2026-91945
Red Hat Enterprise Linux
Sep 15, 2026
Medium5.4Red Hat

Medium [CVE-2024-58384] CRLF injection in CurlAsyncHTTPClient allows arbitrary header injection or new HTTP requests.

CRLF injection in CurlAsyncHTTPClient allows arbitrary header injection or new HTTP requests. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-93. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 11 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more.

CVE-2024-58384
Red Hat Enterprise Linux
Sep 15, 2026
Medium5.3Red Hat

Medium [CVE-2026-55701] github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver: OpenTelemetry Collector Contrib githubreceiver: Unauthorized data injection via authentication bypass

github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver: OpenTelemetry Collector Contrib githubreceiver: Unauthorized data injection via authentication bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:63152 with package opentelemetry-collector-contrib-main-0.160.0-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-55701
Unclassified
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-54168] github.com/openshift-pipelines/pipelines-as-code: Pipelines-as-Code: Information disclosure via unscoped GitHub App installation token

github.com/openshift-pipelines/pipelines-as-code: Pipelines-as-Code: Information disclosure via unscoped GitHub App installation token. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862.

CVE-2026-54168
Unclassified
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-90439] NGINX ngx_http_v3_module: Denial of Service via TLS handshake heap buffer overflow

NGINX ngx_http_v3_module: Denial of Service via TLS handshake heap buffer overflow. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:67977 with package nginx-main-1.30.5-4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.

CVE-2026-90439
Unclassified
Sep 15, 2026
Medium6.1Red Hat

Medium [CVE-2026-92059] Incorrect boundary conditions in the DOM: Editor component

Incorrect boundary conditions in the DOM: Editor component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787.

CVE-2026-92059
Unclassified
Sep 15, 2026
Medium6.1Red Hat

Medium [CVE-2026-92058] Use-after-free in the Graphics component

Use-after-free in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825.

CVE-2026-92058
Unclassified
Sep 15, 2026

← All vendors