Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.8Red Hat

High [CVE-2026-26200] Denial of Service due to heap buffer overflow when parsing a crafted h5 file

Denial of Service due to heap buffer overflow when parsing a crafted h5 file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-26200
Unclassified
Feb 19, 2026
High7.5Red Hat

High [CVE-2026-25535] denial of service via malicious GIF dimensions

denial of service via malicious GIF dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.

CVE-2026-25535
Unclassified
Feb 19, 2026
High7.5Red Hat

High [CVE-2026-22860] Rack Directory Traversal via Rack:Directory

Rack Directory Traversal via Rack:Directory. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat 3scale API Management Platform 2.

CVE-2026-22860
Unclassified
Feb 18, 2026
High8.8Red Hat

High [CVE-2025-14009] Zip Slip Vulnerability in nltk Leading to Code Execution

Zip Slip Vulnerability in nltk Leading to Code Execution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1775144403, rhoai/odh-ta-lmes-job-rhel9:1776271296. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; OpenShift Lightspeed; Red Hat OpenShift AI (RHOAI).

CVE-2025-14009
Unclassified
Feb 18, 2026
High8.8Red Hat

High [CVE-2026-2648] Heap buffer overflow in PDFium

Heap buffer overflow in PDFium. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2648
Unclassified
Feb 18, 2026
High8.8Red Hat

High [CVE-2026-2649] Integer overflow in V8

Integer overflow in V8. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2649
Unclassified
Feb 18, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-23216] Fix use-after-free in iscsit_dec_conn_usage_count()

Fix use-after-free in iscsit_dec_conn_usage_count(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-413. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:9870 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23216
Unclassified
Feb 18, 2026
High7.4Red Hat

High [CVE-2026-24734] Certificate revocation bypass due to improper OCSP response validation

Certificate revocation bypass due to improper OCSP response validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected package(s): jws6-tomcat-native, tomcat, tomcat10-main, jws6-tomcat, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:5612 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 6.2 on RHEL 10; Red Hat JBoss Web Server 6.2 on RHEL 8; and 3 more.

CVE-2026-24734
Unclassified
Feb 17, 2026
High7.1Red Hat

High [CVE-2026-24708] Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova

Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova. Red Hat rates this important (CVSS 7.1). Weakness: CWE-73. Affected package(s): openstack-nova. Resolved in Red Hat advisory RHSA-2026:7884 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenStack Services on OpenShift 18.0; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more.

CVE-2026-24708
Unclassified
Feb 17, 2026
High7.5Red Hat

High [CVE-2026-2447] Heap buffer overflow in libvpx

Heap buffer overflow in libvpx. Red Hat rates this important (CVSS 7.5). Affected package(s): libvpx, thunderbird, rhaiis/vllm-rocm-rhel9:1775680262, firefox, rhaiis/vllm-cuda-rhel9:1775680192, rhaiis/vllm-spyre-rhel9:1778244546. Resolved in Red Hat advisory RHSA-2026:3967 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 11 more.

CVE-2026-2447
Unclassified
Feb 16, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-23171] Linux kernel: Use-after-free in bonding module can cause system crash or arbitrary code execution

Linux kernel: Use-after-free in bonding module can cause system crash or arbitrary code execution. Red Hat rates this moderate (CVSS 7). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:8342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23171
Unclassified
Feb 14, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-23210] Linux kernel: Denial of Service in ice driver due to race condition during VSI rebuild

Linux kernel: Denial of Service in ice driver due to race condition during VSI rebuild. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:6570 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-23210
Unclassified
Feb 14, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-23209] fix error recovery in macvlan_common_newlink()

fix error recovery in macvlan_common_newlink(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:6954 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-23209
Unclassified
Feb 14, 2026
High7.6Vendor: MediumRed Hat

High [CVE-2026-23136] Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state

Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-440. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27708 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23136
Unclassified
Feb 14, 2026
High7.3Vendor: MediumRed Hat

High [CVE-2026-23144] Linux kernel: Local denial of service and memory leak in DAMON sysfs via setup failure

Linux kernel: Local denial of service and memory leak in DAMON sysfs via setup failure. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-772. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:8342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23144
Unclassified
Feb 14, 2026
High7.6Vendor: MediumRed Hat

High [CVE-2026-23139] update last_gc only when GC has been performed

update last_gc only when GC has been performed. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-400. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:15883 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-23139
Unclassified
Feb 14, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-23193] Fix use-after-free in iscsit_dec_session_usage_count()

Fix use-after-free in iscsit_dec_session_usage_count(). Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-364. Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23193
Unclassified
Feb 14, 2026
High7.3Vendor: MediumRed Hat

High [CVE-2026-23204] use skb_header_pointer_careful()

use skb_header_pointer_careful(). Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-1285. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:10756 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9.

CVE-2026-23204
Unclassified
Feb 14, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-23191] Fix racy access at PCM trigger

Fix racy access at PCM trigger. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-367. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-23191
Unclassified
Feb 14, 2026
High7.3Vendor: MediumRed Hat

High [CVE-2026-23156] Linux kernel: Information disclosure in efivarfs via incorrect error propagation

Linux kernel: Information disclosure in efivarfs via incorrect error propagation. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-390. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:9095 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-23156
Unclassified
Feb 14, 2026

← All vendors