Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Vendor: MediumRed Hat

High [CVE-2026-27628] possible infinite loop when loading circular /Prev entries in cross-reference streams

possible infinite loop when loading circular /Prev entries in cross-reference streams. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-835. Affected package(s): quay/quay-rhel9:1775069491, rhoai/odh-llama-stack-core-rhel9:1775144403, quay/quay-rhel8:1773771962, quay/quay-rhel8:1773971077, quay/quay-rhel9:1775169226, quay/quay-rhel8:1773936323. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27628
Unclassified
Feb 25, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-27571] WebSockets pre-auth memory DoS

WebSockets pre-auth memory DoS. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1773650060, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1773650767. Resolved in Red Hat advisory RHSA-2026:6226 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27571
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2807] Memory safety bugs fixed in Firefox 148 and Thunderbird 148

Memory safety bugs fixed in Firefox 148 and Thunderbird 148. Red Hat rates this important (CVSS 7.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2807
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2799] Use-after-free in the DOM: Core & HTML component

Use-after-free in the DOM: Core & HTML component. Red Hat rates this important (CVSS 7.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2799
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2797] Use-after-free in the JavaScript: GC component

Use-after-free in the JavaScript: GC component. Red Hat rates this important (CVSS 7.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2797
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2796] JIT miscompilation in the JavaScript: WebAssembly component

JIT miscompilation in the JavaScript: WebAssembly component. Red Hat rates this important (CVSS 7.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2796
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2794] Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android

Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. Red Hat rates this important (CVSS 7.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2794
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2793] Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148

Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2793
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2792] Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148

Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2792
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2778] Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component

Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2778
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2776] Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software

Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2776
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2777] Privilege escalation in the Messaging System component

Privilege escalation in the Messaging System component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2777
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2775] Mitigation bypass in the DOM: HTML Parser component

Mitigation bypass in the DOM: HTML Parser component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2775
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2774] Integer overflow in the Audio/Video component

Integer overflow in the Audio/Video component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2774
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2773] Incorrect boundary conditions in the Web Audio component

Incorrect boundary conditions in the Web Audio component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2773
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2772] Use-after-free in the Audio/Video: Playback component

Use-after-free in the Audio/Video: Playback component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2772
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2771] Undefined behavior in the DOM: Core & HTML component

Undefined behavior in the DOM: Core & HTML component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2771
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2770] Use-after-free in the DOM: Bindings (WebIDL) component

Use-after-free in the DOM: Bindings (WebIDL) component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2770
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2769] Use-after-free in the Storage: IndexedDB component

Use-after-free in the Storage: IndexedDB component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2769
Unclassified
Feb 24, 2026
High7.5Red Hat

High [CVE-2026-2768] Sandbox escape in the Storage: IndexedDB component

Sandbox escape in the Storage: IndexedDB component. Red Hat rates this important (CVSS 7.5). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:3984 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-2768
Unclassified
Feb 24, 2026

← All vendors