Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.1Red Hat

Medium [CVE-2026-12314] Memory safety bug fixed in Thunderbird ESR 140.12

Memory safety bug fixed in Thunderbird ESR 140.12. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-12314
Unclassified
Jun 16, 2026
Medium6.1Red Hat

Medium [CVE-2026-12313] Information disclosure, sandbox escape in the Security: Process Sandboxing component

Information disclosure, sandbox escape in the Security: Process Sandboxing component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-403. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-12313
Unclassified
Jun 16, 2026
Medium6.1Red Hat

Medium [CVE-2026-12311] Information disclosure, sandbox escape in the Security: Process Sandboxing component

Information disclosure, sandbox escape in the Security: Process Sandboxing component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-243. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-12311
Unclassified
Jun 16, 2026
Medium6.1Red Hat

Medium [CVE-2026-12310] Memory safety bug fixed in Thunderbird ESR 140.12

Memory safety bug fixed in Thunderbird ESR 140.12. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-12310
Unclassified
Jun 16, 2026
Medium6.1Red Hat

Medium [CVE-2026-12308] Memory safety bug fixed in Thunderbird ESR 140.12

Memory safety bug fixed in Thunderbird ESR 140.12. Red Hat rates this moderate (CVSS 6.1). Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-12308
Unclassified
Jun 16, 2026
Medium6.1Red Hat

Medium [CVE-2026-12304] Same-origin policy bypass in the Networking: Cookies component

Same-origin policy bypass in the Networking: Cookies component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-346. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-12304
Unclassified
Jun 16, 2026
Medium6.1Red Hat

Medium [CVE-2026-12302] Mitigation bypass in the DOM: Security component

Mitigation bypass in the DOM: Security component. Red Hat rates this moderate (CVSS 6.1). Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-12302
Unclassified
Jun 16, 2026
Medium5.3Red Hat

Medium [CVE-2026-12087] Information Disclosure due to Out-of-Bounds Read

Information Disclosure due to Out-of-Bounds Read. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125. Affected package(s): perl-socket-main. Resolved in Red Hat advisory RHSA-2026:11342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12087
Unclassified
Jun 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-52718] denial of service via av1 tile_list_obu parser byte/bit confusion

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 10.0 Extended Update Support.

CVE-2026-52718
Red Hat Enterprise Linux
Jun 15, 2026
Medium5.3Red Hat

Medium [CVE-2026-44188] Session hijacking and unauthorized data access due to insufficient session expiration

Session hijacking and unauthorized data access due to insufficient session expiration. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-613. Affected package(s): ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:25928 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat Ansible Automation Platform 2.7.

CVE-2026-44188
Unclassified
Jun 15, 2026
Medium4.8Red Hat

Medium [CVE-2026-54411] Plaintext password recovery via timing discrepancy in pam_userdb module

Plaintext password recovery via timing discrepancy in pam_userdb module. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-208. Affected package(s): pam-main. Resolved in Red Hat advisory RHSA-2026:35016 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-54411
Unclassified
Jun 14, 2026
Medium5.8Red Hat

Medium [CVE-2026-44171] Unauthorized file creation via path traversal

Unauthorized file creation via path traversal. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-22. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-44171
Unclassified
Jun 12, 2026
Medium4.3Red Hat

Medium [CVE-2026-44169] MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check

MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-266. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-44169
Unclassified
Jun 12, 2026
Medium5.3Red Hat

Medium [CVE-2026-50560] Denial of Service due to HTTP/2 max header size handling

Denial of Service due to HTTP/2 max header size handling. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected package(s): netty-codec-http2. Resolved in Red Hat advisory RHSA-2026:26018 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-50560
Unclassified
Jun 12, 2026
Medium5.3Red Hat

Medium [CVE-2026-50020] Data manipulation via request-boundary confusion in HttpObjectDecoder

Data manipulation via request-boundary confusion in HttpObjectDecoder. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected package(s): netty-codec-http. Resolved in Red Hat advisory RHSA-2026:26018 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-50020
Unclassified
Jun 12, 2026
Medium5.3Red Hat

Medium [CVE-2026-47244] Denial of Service via uncontrolled HTTP/2 concurrent streams

Denial of Service via uncontrolled HTTP/2 concurrent streams. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected package(s): netty-codec-http2. Resolved in Red Hat advisory RHSA-2026:26018 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47244
Unclassified
Jun 12, 2026
Medium6.6Red Hat

Medium [CVE-2026-47208] Sandbox Breakout Using Promise Species

Sandbox Breakout Using Promise Species. Red Hat rates this moderate (CVSS 6.6). Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47208
Unclassified
Jun 12, 2026
Medium4.1Red Hat

Medium [CVE-2026-47140] Arbitrary code execution due to incomplete sandbox restrictions

Arbitrary code execution due to incomplete sandbox restrictions. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-184. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47140
Unclassified
Jun 12, 2026
Medium6.8Red Hat

Medium [CVE-2026-45673] Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs

Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-1241. Affected package(s): netty-resolver-dns. Resolved in Red Hat advisory RHSA-2026:26018 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-45673
Unclassified
Jun 12, 2026
Medium4.1Red Hat

Medium [CVE-2026-47137] Sandbox escape leading to arbitrary code execution via security bypass

Sandbox escape leading to arbitrary code execution via security bypass. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-480. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47137
Unclassified
Jun 12, 2026

← All vendors