Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.2Red Hat

Medium [CVE-2026-33947] unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted()

unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted(). Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-674. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:8579 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33947
Unclassified
Apr 13, 2026
Medium6.8Red Hat

Medium [CVE-2026-32316] Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow

Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:8579 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32316
Unclassified
Apr 13, 2026
Medium4.0Red Hat

Medium [CVE-2026-33555] Request smuggling via HTTP/3 parser desynchronization

Request smuggling via HTTP/3 parser desynchronization. Red Hat rates this moderate (CVSS 4). Weakness: CWE-130. Affected package(s): haproxy-main. Resolved in Red Hat advisory RHSA-2026:8749 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33555
Unclassified
Apr 13, 2026
Medium5.0Red Hat

Medium [CVE-2026-6845] Denial of Service via crafted ELF file

Denial of Service via crafted ELF file. Red Hat rates this moderate (CVSS 5). Weakness: CWE-476. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:34924 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more.

CVE-2026-6845
Unclassified
Apr 13, 2026
Medium4.0Red Hat

Medium [CVE-2026-40386] Denial of Service and information disclosure via integer underflow in MakerNote decoding

Denial of Service and information disclosure via integer underflow in MakerNote decoding. Red Hat rates this moderate (CVSS 4). Weakness: CWE-191. Affected package(s): libexif. Resolved in Red Hat advisory RHSA-2026:26276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-40386
Unclassified
Apr 12, 2026
Medium4.0Red Hat

Medium [CVE-2026-40385] Information disclosure and crashes via integer overflow in Nikon MakerNote handling

Information disclosure and crashes via integer overflow in Nikon MakerNote handling. Red Hat rates this moderate (CVSS 4). Weakness: CWE-190. Affected package(s): libexif. Resolved in Red Hat advisory RHSA-2026:26276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7.

CVE-2026-40385
Unclassified
Apr 12, 2026
Medium5.3Red Hat

Medium [CVE-2026-3446] Python base64: Incomplete data decoding due to premature stop at padding

Python base64: Incomplete data decoding due to premature stop at padding. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1286. Affected package(s): python3. Resolved in Red Hat advisory RHSA-2026:10118 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3446
Unclassified
Apr 10, 2026
Medium4.5Red Hat

Medium [CVE-2026-1502] HTTP header injection via CR/LF in proxy tunnel headers

HTTP header injection via CR/LF in proxy tunnel headers. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-93. Affected package(s): python3, python3.12, python3.14, rhui5/rhua-rhel9:1779798222, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:19019 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-1502
Unclassified
Apr 10, 2026
Medium6.5Red Hat

Medium [CVE-2026-34481] Denial of Service via invalid JSON output

Denial of Service via invalid JSON output. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-241. Affected package(s): log4j-layout-template-json, offline-knowledge-portal/rhokp-rhel9:1779996999. Resolved in Red Hat advisory RHSA-2026:22619 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34481
Unclassified
Apr 10, 2026
Medium5.3Red Hat

Medium [CVE-2026-34480] Invalid XML output causes denial of service in logging

Invalid XML output causes denial of service in logging. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-168. Affected package(s): log4j-core-test, offline-knowledge-portal/rhokp-rhel9:1779996999, log4j-core. Resolved in Red Hat advisory RHSA-2026:22619 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34480
Unclassified
Apr 10, 2026
Medium5.3Red Hat

Medium [CVE-2026-34479] Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping

Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-91. Affected package(s): offline-knowledge-portal/rhokp-rhel9:1779996999. Resolved in Red Hat advisory RHSA-2026:21773 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34479
Unclassified
Apr 10, 2026
Medium5.8Red Hat

Medium [CVE-2026-34478] Log injection via CRLF sequences due to configuration attribute renames

Log injection via CRLF sequences due to configuration attribute renames. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-93. Affected package(s): log4j-core-test, offline-knowledge-portal/rhokp-rhel9:1779996999, log4j-core. Resolved in Red Hat advisory RHSA-2026:22619 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34478
Unclassified
Apr 10, 2026
Medium6.8Red Hat

Medium [CVE-2026-34477] Man-in-the-middle attack due to incomplete hostname verification

Man-in-the-middle attack due to incomplete hostname verification. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-295. Affected package(s): offline-knowledge-portal/rhokp-rhel9:1779996999. Resolved in Red Hat advisory RHSA-2026:21773 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34477
Unclassified
Apr 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-40227] Denial of Service via malicious IPC API call with null element

Denial of Service via malicious IPC API call with null element. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40227
Unclassified
Apr 10, 2026
Medium6.4Red Hat

Medium [CVE-2026-40226] systemd nspawn: Escape-to-host action via crafted config file

systemd nspawn: Escape-to-host action via crafted config file. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-348. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40226
Unclassified
Apr 10, 2026
Medium6.4Red Hat

Medium [CVE-2026-40225] udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-250. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40225
Unclassified
Apr 10, 2026
Medium6.7Red Hat

Medium [CVE-2026-40224] Local privilege escalation via varlink

Local privilege escalation via varlink. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-266. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40224
Unclassified
Apr 10, 2026
Medium4.7Red Hat

Medium [CVE-2026-40223] Local unprivileged user can cause Denial of Service

Local unprivileged user can cause Denial of Service. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-617. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40223
Unclassified
Apr 10, 2026
Medium4.4Red Hat

Medium [CVE-2026-35206] Files written to unexpected directory via specially crafted Chart

Files written to unexpected directory via specially crafted Chart. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-22. Affected package(s): helm-cli, rhacm2/multicloud-integrations-rhel9:1782256081, multicluster-engine/backplane-rhel9-operator:1782476869. Resolved in Red Hat advisory RHSA-2026:26441 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-35206
Unclassified
Apr 9, 2026
Medium5.9Red Hat

Medium [CVE-2026-34500] Authentication bypass via client certificate misconfiguration

Authentication bypass via client certificate misconfiguration. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-34500
Unclassified
Apr 9, 2026

← All vendors