Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-33908] Denial of Service via deeply nested XML file processing

Denial of Service via deeply nested XML file processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33908
Unclassified
Apr 13, 2026
High7.5Red Hat

High [CVE-2026-33901] Denial of Service due to heap buffer overflow in MVG decoder

Denial of Service due to heap buffer overflow in MVG decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33901
Unclassified
Apr 13, 2026
High8.1Red Hat

High [CVE-2026-6100] Arbitrary code execution or information disclosure via use-after-free in decompression modules

Arbitrary code execution or information disclosure via use-after-free in decompression modules. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825. Affected package(s): python3.11, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, rhpam, python3.9, python3.12. Resolved in Red Hat advisory RHSA-2026:26187 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 16 more.

CVE-2026-6100
Unclassified
Apr 13, 2026
High8.1Red Hat

High [CVE-2026-28291] Command Execution via Option-Parsing Bypass in simple-git

Command Execution via Option-Parsing Bypass in simple-git. Red Hat rates this important (CVSS 8.1). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat Process Automation 7.

CVE-2026-28291
Unclassified
Apr 13, 2026
High7.8Red Hat

High [CVE-2026-1462] Arbitrary Code Execution Vulnerability Bypassing Safe Mode

Arbitrary Code Execution Vulnerability Bypassing Safe Mode. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. Affected package(s): rhoai/odh-modelmesh-runtime-adapter-rhel9:1780394782. Resolved in Red Hat advisory RHSA-2026:24977 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI).

CVE-2026-1462
Unclassified
Apr 13, 2026
High8.6Red Hat

High [CVE-2026-5367] Information disclosure via crafted DHCPv6 packets

Information disclosure via crafted DHCPv6 packets. Red Hat rates this important (CVSS 8.6). Weakness: CWE-130. Affected package(s): ovn25.03, ovn25.09, ovn, ovn23.09, ovn24.03, ovn23.06. Resolved in Red Hat advisory RHSA-2026:11702 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Fast Datapath for Red Hat Enterprise Linux 10; Fast Datapath for Red Hat Enterprise Linux 8; Fast Datapath for Red Hat Enterprise Linux 9; Fast Datapath for RHEL 8; and 2 more.

CVE-2026-5367
Unclassified
Apr 13, 2026
High7.5Red Hat

High [CVE-2026-6857] Remote Code Execution via Unsafe Deserialization

Remote Code Execution via Unsafe Deserialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. Affected package(s): camel-infinispan. Resolved in Red Hat advisory RHSA-2026:22453 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform Expansion Pack.

CVE-2026-6857
Unclassified
Apr 13, 2026
High7.0Red Hat

High [CVE-2026-31419] Linux kernel: Use-after-free in bonding driver leads to denial of service

Linux kernel: Use-after-free in bonding driver leads to denial of service. Red Hat rates this important (CVSS 7). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 2 more.

CVE-2026-31419
Unclassified
Apr 13, 2026
High8.4Red Hat

High [CVE-2019-25695] Arbitrary Code Execution via Local Buffer Overflow

Arbitrary Code Execution via Local Buffer Overflow. Red Hat rates this important (CVSS 8.4). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2019-25695
Unclassified
Apr 12, 2026
High8.6Red Hat

High [CVE-2026-32146] Gleam compiler: Arbitrary file system modification and potential code execution via improper path validation in git dependency handling.

Gleam compiler: Arbitrary file system modification and potential code execution via improper path validation in git dependency handling.. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32146
Unclassified
Apr 11, 2026
High7.8Red Hat

High [CVE-2026-4154] Remote Code Execution via XPM File Parsing Integer Overflow

Remote Code Execution via XPM File Parsing Integer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:17533 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-4154
Unclassified
Apr 11, 2026
High7.8Red Hat

High [CVE-2026-4153] Remote Code Execution via PSP file parsing

Remote Code Execution via PSP file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:17533 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-4153
Unclassified
Apr 11, 2026
High7.8Red Hat

High [CVE-2026-4152] Remote Code Execution via malicious JP2 file parsing

Remote Code Execution via malicious JP2 file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Affected package(s): gimp. Resolved in Red Hat advisory RHSA-2026:25907 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2026-4152
Unclassified
Apr 11, 2026
High7.8Red Hat

High [CVE-2026-4151] Remote Code Execution via ANI File Parsing Integer Overflow

Remote Code Execution via ANI File Parsing Integer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): gimp. Resolved in Red Hat advisory RHSA-2026:16484 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-4151
Unclassified
Apr 11, 2026
High7.8Red Hat

High [CVE-2026-4150] Arbitrary code execution via specially crafted PSD file

Arbitrary code execution via specially crafted PSD file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:17533 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 9 more.

CVE-2026-4150
Unclassified
Apr 11, 2026
High7.3Red Hat

High [CVE-2026-58379] Heap buffer overflow in read_channel_data()

Heap buffer overflow in read_channel_data(). Red Hat rates this important (CVSS 7.3). Weakness: CWE-122. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-58379
Unclassified
Apr 11, 2026
High8.5Red Hat

High [CVE-2026-5483] ODH Dashboard Kubernetes Service Account Exposure

ODH Dashboard Kubernetes Service Account Exposure. Red Hat rates this important (CVSS 8.5). Weakness: CWE-201. Affected package(s): rhoai/odh-dashboard-rhel8:1775230902, rhoai/odh-dashboard-rhel9:1775239958, rhoai/odh-dashboard-rhel9:1775234711, rhoai/odh-dashboard-rhel9:1775523049. Resolved in Red Hat advisory RHSA-2026:7404 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.16; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.2; Red Hat OpenShift AI 3.3.

CVE-2026-5483
Unclassified
Apr 10, 2026
High8.8Red Hat

High [CVE-2026-40217] Arbitrary Code Execution via bytecode rewriting

Arbitrary Code Execution via bytecode rewriting. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1782310008, ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:24866 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat OpenShift AI 3.3.

CVE-2026-40217
Unclassified
Apr 10, 2026
High7.5Red Hat

High [CVE-2026-39304] Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion

Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Fuse 7.

CVE-2026-39304
Unclassified
Apr 10, 2026
High7.8Red Hat

High [CVE-2026-40200] musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort

musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40200
Unclassified
Apr 10, 2026

← All vendors