Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.8Red Hat

High [CVE-2026-6358] Use after free in XR

Use after free in XR. Red Hat rates this important (CVSS 8.8). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6358
Unclassified
Apr 15, 2026
High8.8Red Hat

High [CVE-2026-6300] Use after free in CSS

Use after free in CSS. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6300
Unclassified
Apr 15, 2026
High8.0Red Hat

High [CVE-2026-6314] Out of bounds write in GPU

Out of bounds write in GPU. Red Hat rates this important (CVSS 8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6314
Unclassified
Apr 15, 2026
High8.8Red Hat

High [CVE-2026-6302] Use after free in Video

Use after free in Video. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6302
Unclassified
Apr 15, 2026
High8.3Red Hat

High [CVE-2026-6297] Use after free in Proxy

Use after free in Proxy. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6297
Unclassified
Apr 15, 2026
High7.4Red Hat

High [CVE-2026-6298] Heap buffer overflow in Skia

Heap buffer overflow in Skia. Red Hat rates this important (CVSS 7.4). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6298
Unclassified
Apr 15, 2026
High8.8Red Hat

High [CVE-2026-6307] Type Confusion in Turbofan

Type Confusion in Turbofan. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6307
Unclassified
Apr 15, 2026
High8.8Red Hat

High [CVE-2026-6361] Heap buffer overflow in PDFium

Heap buffer overflow in PDFium. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6361
Unclassified
Apr 15, 2026
High8.8Red Hat

High [CVE-2026-6859] Arbitrary code execution due to hardcoded `trust_remote_code=True`

Arbitrary code execution due to hardcoded `trust_remote_code=True`. Red Hat rates this important (CVSS 8.8). Weakness: CWE-829. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-6859
Unclassified
Apr 15, 2026
High8.8Red Hat

High [CVE-2026-33414] Arbitrary code execution via command injection in HyperV backend

Arbitrary code execution via command injection in HyperV backend. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): podman-main. Resolved in Red Hat advisory RHSA-2026:8211 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images.

CVE-2026-33414
Unclassified
Apr 14, 2026
High7.8Red Hat

High [CVE-2026-33023] Code execution via crafted image due to use-after-free vulnerability

Code execution via crafted image due to use-after-free vulnerability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33023
Unclassified
Apr 14, 2026
High7.5Red Hat

High [CVE-2026-32178] SMTP Command Injection and Header Injection via MailAddress parsing flaw

SMTP Command Injection and Header Injection via MailAddress parsing flaw. Red Hat rates this important (CVSS 7.5). Weakness: CWE-138. Affected package(s): dotnet8.0, dotnet10.0, dotnet8, dotnet9.0, dotnet9, dotnet10. Resolved in Red Hat advisory RHSA-2026:9080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2026-32178
Unclassified
Apr 14, 2026
High7.5Red Hat

High [CVE-2026-26171] .NET: Security Bypass and Denial of Service Vulnerability

.NET: Security Bypass and Denial of Service Vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected package(s): dotnet8.0, dotnet10.0, dotnet8, dotnet9.0, dotnet9, dotnet10. Resolved in Red Hat advisory RHSA-2026:9080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2026-26171
Unclassified
Apr 14, 2026
High7.5Red Hat

High [CVE-2026-32203] .NET: Denial of Service via stack overflow

.NET: Denial of Service via stack overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): dotnet8.0, dotnet10.0, dotnet8, dotnet9.0, dotnet9, dotnet10. Resolved in Red Hat advisory RHSA-2026:9080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2026-32203
Unclassified
Apr 14, 2026
High7.5Red Hat

High [CVE-2026-33116] .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform

.NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected package(s): dotnet8.0, dotnet10.0, dotnet8, dotnet9.0, dotnet9, dotnet10. Resolved in Red Hat advisory RHSA-2026:9080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2026-33116
Unclassified
Apr 14, 2026
High7.5Red Hat

High [CVE-2026-23666] .NET Framework: Denial of Service via Race Condition

.NET Framework: Denial of Service via Race Condition. Red Hat rates this important (CVSS 7.5). Weakness: CWE-366. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23666
Unclassified
Apr 14, 2026
High7.4Red Hat

High [CVE-2026-2332] HTTP request smuggling via chunked extension quoted-string parsing

HTTP request smuggling via chunked extension quoted-string parsing. Red Hat rates this important (CVSS 7.4). Weakness: CWE-444. Affected package(s): offline-knowledge-portal/rhokp-rhel9:1779996999, devspaces/pluginregistry-rhel9:1776717247, jmc, jetty-http, devspaces/openvsx-rhel9:1776716842. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Offline Knowledge Portal 1.2.7; Red Hat OpenShift Dev Spaces 3.27; OpenShift Developer Tools and Services; and 16 more.

CVE-2026-2332
Unclassified
Apr 14, 2026
High7.5Red Hat

High [CVE-2026-40164] Denial of Service via crafted JSON object causing hash collisions

Denial of Service via crafted JSON object causing hash collisions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-341. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, jq, rhcos, rhaiis/model-opt-cuda-rhel9:1780681984, rhaiis/vllm-rocm-rhel9:1782353093. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 19 more.

CVE-2026-40164
Unclassified
Apr 13, 2026
High8.2Red Hat

High [CVE-2026-39979] out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers

out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, jq, rhcos, rhaiis/model-opt-cuda-rhel9:1780681984, rhaiis/vllm-rocm-rhel9:1782353093. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 21 more.

CVE-2026-39979
Unclassified
Apr 13, 2026
High7.1Red Hat

High [CVE-2026-4786] Arbitrary code execution via command injection in webbrowser.open() API

Arbitrary code execution via command injection in webbrowser.open() API. Red Hat rates this important (CVSS 7.1). Weakness: CWE-88. Affected package(s): python3.11, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, rhpam, python3.9, python3.12. Resolved in Red Hat advisory RHSA-2026:35838 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 16 more.

CVE-2026-4786
Unclassified
Apr 13, 2026

← All vendors