Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

284 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Low3.7Red Hat

Low [CVE-2026-28753] NGINX Plus and NGINX Open Source: Request manipulation via header injection in SMTP upstream requests

NGINX Plus and NGINX Open Affected products named by the advisory: nginx-main; Red Hat Enterprise Linux.

CVE-2026-28753
Unclassified
Mar 24, 2026
Low3.4Red Hat

Low [CVE-2026-4718] Undefined behavior in the WebRTC: Signaling component

Undefined behavior in the WebRTC: Signaling component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-475. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4718
Unclassified
Mar 24, 2026
Low3.4Red Hat

Low [CVE-2026-4719] Incorrect boundary conditions in the Graphics: Text component

Incorrect boundary conditions in the Graphics: Text component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-805. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4719
Unclassified
Mar 24, 2026
Low3.3Red Hat

Low [CVE-2026-3479] Python pkgutil.get_data(): Path Traversal via improper resource argument validation

Python pkgutil.get_data(): Path Traversal via improper resource argument validation. Red Hat rates this low (CVSS 3.3). Weakness: CWE-22. Affected package(s): python3. Resolved in Red Hat advisory RHSA-2026:10118 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3479
Unclassified
Mar 18, 2026
Low2.5Red Hat

Low [CVE-2025-13462] `tarfile` module misinterprets crafted tar archives leading to data integrity issues

`tarfile` module misinterprets crafted tar archives leading to data integrity issues. Red Hat rates this low (CVSS 2.5). Weakness: CWE-237. Affected package(s): python3. Resolved in Red Hat advisory RHSA-2026:10118 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-13462
Unclassified
Mar 12, 2026
Low3.3Red Hat

Low [CVE-2025-70873] Information Disclosure via Crafted ZIP File

Information Disclosure via Crafted ZIP File. Red Hat rates this low (CVSS 3.3). Weakness: CWE-908. Affected package(s): sqlite-main. Resolved in Red Hat advisory RHSA-2026:7656 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-70873
Unclassified
Mar 12, 2026
Low2.7Red Hat

Low [CVE-2026-3911] org.keycloak.services.resources.admin.UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint

org.keycloak.services.resources.admin. UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint. Red Hat rates this low (CVSS 2.7). Weakness: CWE-359. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3911
Red Hat Enterprise Linux
Mar 11, 2026
Low3.3Red Hat

Low [CVE-2025-69647] infinite loop in readelf via crafted binary with malformed DWARF loclists data

infinite loop in readelf via crafted binary with malformed DWARF loclists data. Red Hat rates this low (CVSS 3.3). Weakness: CWE-835. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69647
Unclassified
Mar 9, 2026
Low3.3Red Hat

Low [CVE-2025-69648] infinite loop in readelf via crafted binary with malformed DWARF .debug_rnglists data

infinite loop in readelf via crafted binary with malformed DWARF.debug_rnglists data. Red Hat rates this low (CVSS 3.3). Weakness: CWE-835. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69648
Unclassified
Mar 9, 2026
Low3.3Vendor: HighRed Hat

Low [CVE-2026-24308] Information disclosure via improper handling of configuration values

Information disclosure via improper handling of configuration values. Red Hat rates this important (CVSS 3.3). Weakness: CWE-117. Affected package(s): zookeeper, rhoai/odh-modelmesh-rhel9:1776756834. Resolved in Red Hat advisory RHSA-2026:14276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat build of Debezium 2; Red Hat build of Debezium 3; Red Hat Fuse 7; and 3 more.

CVE-2026-24308
Unclassified
Mar 7, 2026
Low2.5Red Hat

Low [CVE-2026-27139] FileInfo can escape from a Root in golang os module

FileInfo can escape from a Root in golang os module. Red Hat rates this low (CVSS 2.5). Weakness: CWE-22. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27139
Unclassified
Mar 6, 2026
Low3.7Red Hat

Low [CVE-2026-27138] Panic in name constraint checking for malformed certificates in crypto/x509

Panic in name constraint checking for malformed certificates in crypto/x509. Red Hat rates this low (CVSS 3.7). Weakness: CWE-295. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7291 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27138
Unclassified
Mar 6, 2026
Low2.8Red Hat

Low [CVE-2025-69645] Binutils objdump: Denial of Service via crafted DWARF debug information

Binutils objdump: Denial of Service via crafted DWARF debug information. Red Hat rates this low (CVSS 2.8). Weakness: CWE-1285. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69645
Unclassified
Mar 6, 2026
Low2.8Red Hat

Low [CVE-2025-69644] Denial of Service via crafted binary with malformed DWARF debug information

Denial of Service via crafted binary with malformed DWARF debug information. Red Hat rates this low (CVSS 2.8). Weakness: CWE-606. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69644
Unclassified
Mar 6, 2026
Low2.8Red Hat

Low [CVE-2025-69646] Denial of Service via malformed DWARF debug_rnglists data

Denial of Service via malformed DWARF debug_rnglists data. Red Hat rates this low (CVSS 2.8). Weakness: CWE-606. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69646
Unclassified
Mar 6, 2026
Low3.3Red Hat

Low [CVE-2025-69650] double free in readelf via crafted ELF binary with malformed relocation data

double free in readelf via crafted ELF binary with malformed relocation data. Red Hat rates this low (CVSS 3.3). Weakness: CWE-415. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69650
Unclassified
Mar 6, 2026
Low3.3Red Hat

Low [CVE-2025-69652] abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information

abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information. Red Hat rates this low (CVSS 3.3). Weakness: CWE-617. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69652
Unclassified
Mar 6, 2026
Low3.3Red Hat

Low [CVE-2025-69649] NULL pointer dereference in readelf via crafted ELF binary with malformed header fields

NULL pointer dereference in readelf via crafted ELF binary with malformed header fields. Red Hat rates this low (CVSS 3.3). Weakness: CWE-476. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69649
Unclassified
Mar 6, 2026
Low2.8Red Hat

Low [CVE-2025-69651] Denial of Service via crafted ELF binary processing

Denial of Service via crafted ELF binary processing. Red Hat rates this low (CVSS 2.8). Weakness: CWE-824. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:7098 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69651
Unclassified
Mar 6, 2026
Low3.7Red Hat

Low [CVE-2025-11143] Security bypass due to differential URI parsing

Security bypass due to differential URI parsing. Red Hat rates this low (CVSS 3.7). Weakness: CWE-444. Affected package(s): offline-knowledge-portal/rhokp-rhel9:1779996999. Resolved in Red Hat advisory RHSA-2026:21773 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-11143
Unclassified
Mar 5, 2026

← All vendors