Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.6Red Hat

Medium [CVE-2026-7261] Memory corruption and information disclosure via incorrect persistence handling

Memory corruption and information disclosure via incorrect persistence handling. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-825. Affected package(s): php, php:7.4. Resolved in Red Hat advisory RHSA-2026:33449 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-7261
Unclassified
May 10, 2026
Medium5.4Red Hat

Medium [CVE-2026-6735] Cross-Site Scripting vulnerability via improper URL sanitation

Cross-Site Scripting vulnerability via improper URL sanitation. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected package(s): php, php8.4, php:8.2, php:7.4, php:8.3, php-main. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-6735
Unclassified
May 10, 2026
Medium6.5Red Hat

Medium [CVE-2026-42256] Net::IMAP: Denial of Service via large iteration count in SCRAM authentication

Net::IMAP: Denial of Service via large iteration count in SCRAM authentication. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected package(s): ruby3, ruby4. Resolved in Red Hat advisory RHSA-2026:33552 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-42256
Unclassified
May 9, 2026
Medium6.5Red Hat

Medium [CVE-2026-42245] Net::IMAP: Denial of Service via crafted IMAP responses

Net::IMAP: Denial of Service via crafted IMAP responses. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected package(s): ruby3, ruby:3.3, ruby4, ruby4.0, ruby, ruby:4.0. Resolved in Red Hat advisory RHSA-2026:33515 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-42245
Unclassified
May 9, 2026
Medium4.0Red Hat

Medium [CVE-2026-42310] Denial of Service via malicious PDF processing

Denial of Service via malicious PDF processing. Red Hat rates this moderate (CVSS 4). Weakness: CWE-835. Affected package(s): rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1778274666, rhaiis/model-opt-cuda-rhel9:1778244559. Resolved in Red Hat advisory RHSA-2026:16030 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-42310
Unclassified
May 9, 2026
Medium5.1Red Hat

Medium [CVE-2026-42309] Denial of Service via specially crafted coordinate input

Denial of Service via specially crafted coordinate input. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-131. Affected package(s): rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1778274666, rhaiis/model-opt-cuda-rhel9:1778244559. Resolved in Red Hat advisory RHSA-2026:16030 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-42309
Unclassified
May 9, 2026
Medium6.5Red Hat

Medium [CVE-2026-2291] heap buffer overflow in cache via NAME_ESCAPE expansion

heap buffer overflow in cache via NAME_ESCAPE expansion. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-131. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-2291
Unclassified
May 9, 2026
Medium6.5Red Hat

Medium [CVE-2026-4893] Broken ECS source validation bypass

Broken ECS source validation bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-20. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-4893
Unclassified
May 9, 2026
Medium5.9Red Hat

Medium [CVE-2026-41889] SQL injection via specific SQL query conditions

SQL injection via specific SQL query conditions. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-89. Affected package(s): caddy-main, cosign-main, go-fdo-server-main. Resolved in Red Hat advisory RHSA-2026:16133 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41889
Unclassified
May 8, 2026
Medium6.5Red Hat

Medium [CVE-2026-41506] Information disclosure of HTTP authentication credentials via redirects

Information disclosure of HTTP authentication credentials via redirects. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-601. Affected package(s): syft-main. Resolved in Red Hat advisory RHSA-2026:17669 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41506
Unclassified
May 8, 2026
Medium5.3Red Hat

Medium [CVE-2026-44928] Incorrect URI comparison leading to integrity issues

Incorrect URI comparison leading to integrity issues. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1025. Affected package(s): uriparser-main. Resolved in Red Hat advisory RHSA-2026:16341 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-44928
Unclassified
May 8, 2026
Medium5.4Red Hat

Medium [CVE-2026-39823] Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content

Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:23262 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-39823
Unclassified
May 7, 2026
Medium5.4Red Hat

Medium [CVE-2026-39826] Cross-site scripting due to incorrect script tag escaping

Cross-site scripting due to incorrect script tag escaping. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-1289. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:23262 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-39826
Unclassified
May 7, 2026
Medium6.5Red Hat

Medium [CVE-2026-39825] ReverseProxy forwards hidden query parameters, potentially bypassing security controls

ReverseProxy forwards hidden query parameters, potentially bypassing security controls. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-472. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:23262 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-39825
Unclassified
May 7, 2026
Medium6.8Red Hat

Medium [CVE-2026-13595] heap use-after-free in libblkid nested partition probing

heap use-after-free in libblkid nested partition probing. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-416. Affected package(s): util-linux-main. Resolved in Red Hat advisory RHSA-2026:26573 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more.

CVE-2026-13595
Unclassified
May 7, 2026
Medium6.3Red Hat

Medium [CVE-2026-6420] Security bypass due to hardcoded TPM quote nonce

Security bypass due to hardcoded TPM quote nonce. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-1241. Affected package(s): keylime. Resolved in Red Hat advisory RHSA-2026:28582 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-6420
Unclassified
May 6, 2026
Medium5.3Red Hat

Medium [CVE-2026-6860] Denial of Service via TLS handshake with wildcard server name

Denial of Service via TLS handshake with wildcard server name. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator, rhbk/keycloak-rhel9:26.6, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6860
Unclassified
May 6, 2026
Medium4.7Red Hat

Medium [CVE-2026-43163] fix GPF in write_page caused by resize race

fix GPF in write_page caused by resize race. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:21745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-43163
Unclassified
May 6, 2026
Medium6.7Red Hat

Medium [CVE-2026-43205] Linux kernel dpaa2-switch: Kernel memory corruption via out-of-bounds write

Linux kernel dpaa2-switch: Kernel memory corruption via out-of-bounds write. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-787. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:21557 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-43205
Unclassified
May 6, 2026
Medium5.8Red Hat

Medium [CVE-2026-43279] Add sanity check for OOB writes at silencing

Add sanity check for OOB writes at silencing. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-787. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-43279
Unclassified
May 6, 2026

← All vendors