Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium4.1Red Hat

Medium [CVE-2026-47131] Arbitrary code execution via sandbox escape vulnerability

Arbitrary code execution via sandbox escape vulnerability. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-843. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47131
Unclassified
Jun 12, 2026
Medium6.7Red Hat

Medium [CVE-2026-48914] heap buffer overflow in virtio-blk scsi request handling

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux for NVIDIA 26; and 1 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-48914
Red Hat Enterprise Linux
Jun 12, 2026
Medium4.9Red Hat

Medium [CVE-2026-11986] authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloak

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control. Affected product named by the advisory: Red Hat build of Keycloak 26.6.

CVE-2026-11986
Unclassified
Jun 11, 2026
Medium5.9Red Hat

Medium [CVE-2026-46692] Heap buffer over-write via `magick -distribute-cache` service connection

Heap buffer over-write via `magick -distribute-cache` service connection. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-787. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7.

CVE-2026-46692
Unclassified
Jun 10, 2026
Medium5.0Red Hat

Medium [CVE-2026-11850] integer underflow in berval2tl_data() leads to heap out-of-bounds read

integer underflow in berval2tl_data() leads to heap out-of-bounds read. Red Hat rates this moderate (CVSS 5). Weakness: CWE-191. Affected package(s): krb5-main. Resolved in Red Hat advisory RHSA-2026:25520 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more.

CVE-2026-11850
Unclassified
Jun 10, 2026
Medium6.2Red Hat

Medium [CVE-2026-45491] .NET: Local file tampering via link following vulnerability

.NET: Local file tampering via link following vulnerability. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-59. Affected package(s): dotnet8, dotnet8.0, dotnet9.0, dotnet9, dotnet10.0, dotnet10. Resolved in Red Hat advisory RHSA-2026:25110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-45491
Unclassified
Jun 9, 2026
Medium4.9Vendor: LowRed Hat

Medium [CVE-2026-11793] stack buffer overflow in checkprefix algorithm id parsing

A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only. Red Hat severity: Low — CVSS 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-121. Affected Red Hat products: Red Hat Directory Server 11; Red Hat Directory Server 12; Red Hat Directory Server 13; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-11793
Red Hat Enterprise Linux
Jun 9, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-7383] Heap buffer overflow due to signed integer overflow in Unicode output sizing

Heap buffer overflow due to signed integer overflow in Unicode output sizing. Red Hat rates this low (CVSS 5.5). Weakness: CWE-190. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-7383
Unclassified
Jun 9, 2026
Medium5.9Vendor: LowRed Hat

Medium [CVE-2026-9076] Denial of Service due to heap out-of-bounds read in CMS password-based decryption

Denial of Service due to heap out-of-bounds read in CMS password-based decryption. Red Hat rates this low (CVSS 5.9). Weakness: CWE-131. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-9076
Unclassified
Jun 9, 2026
Medium5.0Vendor: LowRed Hat

Medium [CVE-2026-34180] Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.

Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.. Red Hat rates this low (CVSS 5). Weakness: CWE-190. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-34180
Unclassified
Jun 9, 2026
Medium6.3Vendor: LowRed Hat

Medium [CVE-2026-34181] PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys

PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys. Red Hat rates this low (CVSS 6.3). Weakness: CWE-347. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-34181
Unclassified
Jun 9, 2026
Medium5.9Red Hat

Medium [CVE-2026-42764] NULL pointer dereference in QUIC server initial packet handling

NULL pointer dereference in QUIC server initial packet handling. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-476. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-42764
Unclassified
Jun 9, 2026
Medium5.3Vendor: LowRed Hat

Medium [CVE-2026-42766] Possible NULL Dereference in Password-Based CMS Decryption

Possible NULL Dereference in Password-Based CMS Decryption. Red Hat rates this low (CVSS 5.3). Weakness: CWE-476. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-42766
Unclassified
Jun 9, 2026
Medium5.3Vendor: LowRed Hat

Medium [CVE-2026-42767] NULL Pointer Dereference in CRMF EncryptedValue Decryption

NULL Pointer Dereference in CRMF EncryptedValue Decryption. Red Hat rates this low (CVSS 5.3). Weakness: CWE-476. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-42767
Unclassified
Jun 9, 2026
Medium6.3Vendor: LowRed Hat

Medium [CVE-2026-42768] Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()

Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt(). Red Hat rates this low (CVSS 6.3). Weakness: CWE-205. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-42768
Unclassified
Jun 9, 2026
Medium5.9Vendor: LowRed Hat

Medium [CVE-2026-42769] Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate

Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate. Red Hat rates this low (CVSS 5.9). Weakness: CWE-295. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-42769
Unclassified
Jun 9, 2026
Medium5.9Vendor: LowRed Hat

Medium [CVE-2026-42770] FFC-DH Peer Validation Uses Attacker-Supplied q

FFC-DH Peer Validation Uses Attacker-Supplied q. Red Hat rates this low (CVSS 5.9). Weakness: CWE-354. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-42770
Unclassified
Jun 9, 2026
Medium6.5Red Hat

Medium [CVE-2026-43951] Out-of-bounds Read in mod_headers and mod_mime

Out-of-bounds Read in mod_headers and mod_mime. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected package(s): mod_http2. Resolved in Red Hat advisory RHSA-2026:34355 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-43951
Unclassified
Jun 8, 2026
Medium5.0Vendor: HighRed Hat

Medium [CVE-2026-11678] Integer overflow in libyuv

Integer overflow in libyuv. Red Hat rates this important (CVSS 5). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11678
Unclassified
Jun 8, 2026
Medium6.6Vendor: HighRed Hat

Medium [CVE-2026-11628] Use after free in Ozone

Use after free in Ozone. Red Hat rates this important (CVSS 6.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11628
Unclassified
Jun 8, 2026

← All vendors