Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.0Red Hat

High [CVE-2026-23868] Double-free vulnerability leading to memory corruption

Double-free vulnerability leading to memory corruption. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected package(s): giflib, rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1779223654, rhaiis/vllm-cuda-rhel9:1778274666, rhaiis/vllm-spyre-rhel9:1778244546, rhaiis/model-opt-cuda-rhel9:1780681984. Resolved in Red Hat advisory RHSA-2026:8859 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 12 more.

CVE-2026-23868
Unclassified
Mar 10, 2026
High8.8Red Hat

High [CVE-2026-28292] Remote Code Execution via bypass of prior security fixes

Remote Code Execution via bypass of prior security fixes. Red Hat rates this important (CVSS 8.8). Weakness: CWE-76. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Logging Subsystem for Red Hat OpenShift.

CVE-2026-28292
Unclassified
Mar 10, 2026
High7.5Red Hat

High [CVE-2026-26130] Denial of Service via uncontrolled resource allocation

Denial of Service via uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dotnet8.0, dotnet9.0, dotnet10.0. Resolved in Red Hat advisory RHSA-2026:4458 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.

CVE-2026-26130
Unclassified
Mar 10, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-26127] .net: .NET: Denial of Service via out-of-bounds read

.net:.NET: Denial of Service via out-of-bounds read. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-125. Affected package(s): dotnet9.0, dotnet10.0. Resolved in Red Hat advisory RHSA-2026:10083 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-26127
Unclassified
Mar 10, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-26131] .NET: Privilege escalation via incorrect default permissions

.NET: Privilege escalation via incorrect default permissions. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-276. Affected package(s): dotnet10. Resolved in Red Hat advisory RHSA-2026:9077 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-26131
Unclassified
Mar 10, 2026
High8.8Red Hat

High [CVE-2026-3918] Use after free in WebMCP

Use after free in WebMCP. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3918
Unclassified
Mar 10, 2026
High8.8Red Hat

High [CVE-2026-3921] Use after free in TextEncoding

Use after free in TextEncoding. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3921
Unclassified
Mar 10, 2026
High8.8Red Hat

High [CVE-2026-3923] Use after free in WebMIDI

Use after free in WebMIDI. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3923
Unclassified
Mar 10, 2026
High8.8Red Hat

High [CVE-2026-3914] Integer overflow in WebML

Integer overflow in WebML. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3914
Unclassified
Mar 10, 2026
High8.8Red Hat

High [CVE-2026-3919] Use after free in Extensions

Use after free in Extensions. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3919
Unclassified
Mar 10, 2026
High8.8Red Hat

High [CVE-2026-3916] Out of bounds read in Web Speech

Out of bounds read in Web Speech. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3916
Unclassified
Mar 10, 2026
High8.8Red Hat

High [CVE-2026-3915] Heap buffer overflow in WebML

Heap buffer overflow in WebML. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3915
Unclassified
Mar 10, 2026
High8.8Red Hat

High [CVE-2026-3917] Use after free in Agents

Use after free in Agents. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3917
Unclassified
Mar 10, 2026
High8.8Red Hat

High [CVE-2026-3920] Out of bounds memory access in WebML

Out of bounds memory access in WebML. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3920
Unclassified
Mar 10, 2026
High8.8Red Hat

High [CVE-2026-3922] Use after free in MediaStream

Use after free in MediaStream. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3922
Unclassified
Mar 10, 2026
High8.8Red Hat

High [CVE-2026-3924] Use after free in WindowDialog

Use after free in WindowDialog. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3924
Unclassified
Mar 10, 2026
High8.1Red Hat

High [CVE-2026-28693] Out-of-bounds read or write due to integer overflow in DIB coder

Out-of-bounds read or write due to integer overflow in DIB coder. Red Hat rates this important (CVSS 8.1). Weakness: CWE-190. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:6713 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-28693
Unclassified
Mar 9, 2026
High7.5Red Hat

High [CVE-2026-28691] Denial of Service via uninitialized pointer dereference in JBIG decoder

Denial of Service via uninitialized pointer dereference in JBIG decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-824. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:6713 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-28691
Unclassified
Mar 9, 2026
High7.1Red Hat

High [CVE-2026-25960] Server-Side Request Forgery bypass via inconsistent URL parsing

Server-Side Request Forgery bypass via inconsistent URL parsing. Red Hat rates this important (CVSS 7.1). Weakness: CWE-474. Affected package(s): rhoai/odh-vllm-gaudi-rhel9:1780069069. Resolved in Red Hat advisory RHSA-2026:24977 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-25960
Unclassified
Mar 9, 2026
High7.5Red Hat

High [CVE-2026-0846] Arbitrary file read via improper path validation in `filestring()` function

Arbitrary file read via improper path validation in `filestring()` function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected package(s): rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1778263054, rhoai/odh-llama-stack-core-rhel9:1775144403, rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1778262893. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more.

CVE-2026-0846
Unclassified
Mar 9, 2026

← All vendors