Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-3608] Denial of Service via maliciously crafted message

Denial of Service via maliciously crafted message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Affected package(s): kea. Resolved in Red Hat advisory RHSA-2026:7342 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support.

CVE-2026-3608
Unclassified
Mar 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-23375] deny THP for files on anonymous inodes

deny THP for files on anonymous inodes. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:21557 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-23375
Unclassified
Mar 25, 2026
High8.3Red Hat

High [CVE-2025-67030] org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method

org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method. Red Hat rates this important (CVSS 8.3). Weakness: CWE-22. Affected package(s): eap8-jboss-logging, eap8-guava-failureaccess, eap8-activemq-artemis, eap8-netty-transport-native-epoll, eap8-reactivex-rxjava, eap8-wildfly-javadocs. Resolved in Red Hat advisory RHSA-2026:7109 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss EAP 8.1 for RHEL 8; Red Hat JBoss EAP 8.1 for RHEL 9; Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); and 32 more.

CVE-2025-67030
Unclassified
Mar 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-23392] release flowtable after rcu grace period on error

release flowtable after rcu grace period on error. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23392
Unclassified
Mar 25, 2026
High8.2Red Hat

High [CVE-2026-4371] Out of bounds read in IMAP parsing

Out of bounds read in IMAP parsing. Red Hat rates this important (CVSS 8.2). Weakness: CWE-130. Affected package(s): thunderbird. Resolved in Red Hat advisory RHSA-2026:8286 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 9 more.

CVE-2026-4371
Unclassified
Mar 24, 2026
High7.3Red Hat

High [CVE-2026-33412] Arbitrary code execution via command injection in glob() function

Arbitrary code execution via command injection in glob() function. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/cds-kubernetes-tp-rhel9:1777459441, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim. Resolved in Red Hat advisory RHSA-2026:6915 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 23 more.

CVE-2026-33412
Unclassified
Mar 24, 2026
High7.8Red Hat

High [CVE-2026-32647] Denial of Service or Code Execution via specially crafted MP4 files

Denial of Service or Code Execution via specially crafted MP4 files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-125. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Open Source; NGINX Plus; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 7 more.

CVE-2026-32647
Unclassified
Mar 24, 2026
High7.8Red Hat

High [CVE-2026-4775] Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing

Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): libtiff-main, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, compat-libtiff3, libtiff, mingw-libtiff. Resolved in Red Hat advisory RHSA-2026:30349 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 13 more.

CVE-2026-4775
Unclassified
Mar 24, 2026
High7.5Red Hat

High [CVE-2026-27651] Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled

Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Open Source; NGINX Plus; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 6 more.

CVE-2026-27651
Unclassified
Mar 24, 2026
High8.2Red Hat

High [CVE-2026-27654] Denial of Service or file modification via buffer overflow in ngx_http_dav_module

Denial of Service or file modification via buffer overflow in ngx_http_dav_module. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Open Source; NGINX Plus; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 6 more.

CVE-2026-27654
Unclassified
Mar 24, 2026
High7.5Red Hat

High [CVE-2026-27784] Denial of Service due to memory corruption via crafted MP4 file

Denial of Service due to memory corruption via crafted MP4 file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Open Source; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; and 5 more.

CVE-2026-27784
Unclassified
Mar 24, 2026
High7.5Red Hat

High [CVE-2026-4721] Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149

Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-4721
Unclassified
Mar 24, 2026
High7.5Red Hat

High [CVE-2026-4729] Memory safety bugs fixed in Firefox 149 and Thunderbird 149

Memory safety bugs fixed in Firefox 149 and Thunderbird 149. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4729
Unclassified
Mar 24, 2026
High7.5Red Hat

High [CVE-2026-4720] Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149

Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-4720
Unclassified
Mar 24, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-4704] Denial-of-service in the WebRTC: Signaling component

Denial-of-service in the WebRTC: Signaling component. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4704
Unclassified
Mar 24, 2026
High7.5Red Hat

High [CVE-2026-4699] Incorrect boundary conditions in the Layout: Text and Fonts component

Incorrect boundary conditions in the Layout: Text and Fonts component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-4699
Unclassified
Mar 24, 2026
High7.5Red Hat

High [CVE-2026-4700] Mitigation bypass in the Networking: HTTP component

Mitigation bypass in the Networking: HTTP component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-444. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-4700
Unclassified
Mar 24, 2026
High7.5Red Hat

High [CVE-2026-4698] JIT miscompilation in the JavaScript Engine: JIT component

JIT miscompilation in the JavaScript Engine: JIT component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-733. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-4698
Unclassified
Mar 24, 2026
High7.5Red Hat

High [CVE-2026-4697] Incorrect boundary conditions in the Audio/Video: Web Codecs component

Incorrect boundary conditions in the Audio/Video: Web Codecs component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-4697
Unclassified
Mar 24, 2026
High7.5Red Hat

High [CVE-2026-4695] Incorrect boundary conditions in the Audio/Video: Web Codecs component

Incorrect boundary conditions in the Audio/Video: Web Codecs component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-4695
Unclassified
Mar 24, 2026

← All vendors