Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.9Red Hat

Medium [CVE-2026-28386] Denial of Service due to out-of-bounds read in AES-CFB128

Denial of Service due to out-of-bounds read in AES-CFB128. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-805. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-28386
Unclassified
Apr 7, 2026
Medium5.5Red Hat

Medium [CVE-2026-5745] A NULL pointer dereference vulnerability exists in the ACL parser of libarchive

A NULL pointer dereference vulnerability exists in the ACL parser of libarchive. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected package(s): libarchive-main. Resolved in Red Hat advisory RHSA-2026:8944 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more.

CVE-2026-5745
Unclassified
Apr 7, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-5864] Heap buffer overflow in WebAudio

Heap buffer overflow in WebAudio. Red Hat rates this important (CVSS 6.5). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5864
Unclassified
Apr 7, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-5867] Heap buffer overflow in WebML

Heap buffer overflow in WebML. Red Hat rates this important (CVSS 6.5). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5867
Unclassified
Apr 7, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-5869] Heap buffer overflow in WebML

Heap buffer overflow in WebML. Red Hat rates this important (CVSS 6.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5869
Unclassified
Apr 7, 2026
Medium4.1Red Hat

Medium [CVE-2026-35177] Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass

Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-22. Affected package(s): vim, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, rhui5/rhua-rhel9:1781525739, insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671. Resolved in Red Hat advisory RHSA-2026:28049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-35177
Unclassified
Apr 6, 2026
Medium4.6Red Hat

Medium [CVE-2026-35166] Information disclosure and content manipulation via improper markdown link escaping

Information disclosure and content manipulation via improper markdown link escaping. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-79. Affected package(s): hugo-main. Resolved in Red Hat advisory RHSA-2026:7848 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-35166
Unclassified
Apr 6, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-34756] Denial of Service via excessively large 'n' parameter in OpenAI-compatible API

Denial of Service via excessively large 'n' parameter in OpenAI-compatible API. Red Hat rates this important (CVSS 6.5). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat AI Inference Server 3.4.

CVE-2026-34756
Unclassified
Apr 6, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-34755] Denial of Service due to excessive video frame processing

Denial of Service due to excessive video frame processing. Red Hat rates this important (CVSS 6.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat AI Inference Server 3.4.

CVE-2026-34755
Unclassified
Apr 6, 2026
Medium5.0Red Hat

Medium [CVE-2026-5704] hidden file injection via crafted archives

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N). Weakness: CWE-434. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-5704
Red Hat Enterprise Linux
Apr 6, 2026
Medium6.7Vendor: HighRed Hat

Medium [CVE-2026-4878] Privilege escalation via TOCTOU race condition in cap_set_file()

Privilege escalation via TOCTOU race condition in cap_set_file(). Red Hat rates this important (CVSS 6.7). Weakness: CWE-367. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, libcap, rhui5/haproxy-rhel9:1779798164, rhcos, libcap-main. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 40 more.

CVE-2026-4878
Unclassified
Apr 6, 2026
Medium6.5Red Hat

Medium [CVE-2026-5265] Heap Over-Read in ICMP Error Response Generation

Heap Over-Read in ICMP Error Response Generation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-130. Affected package(s): ovn25.03, ovn25.09, ovn, ovn23.09, ovn24.03, ovn23.06. Resolved in Red Hat advisory RHSA-2026:11702 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-5265
Unclassified
Apr 6, 2026
Medium5.5Red Hat

Medium [CVE-2026-34933] Denial of Service via D-Bus method call

Denial of Service via D-Bus method call. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1288. Affected package(s): avahi-main. Resolved in Red Hat advisory RHSA-2026:11316 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34933
Unclassified
Apr 3, 2026
Medium4.7Red Hat

Medium [CVE-2026-27456] TOCTOU in the mount program when setting up loop devices

TOCTOU in the mount program when setting up loop devices. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-367. Affected package(s): util-linux-main. Resolved in Red Hat advisory RHSA-2026:7180 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27456
Unclassified
Apr 3, 2026
Medium6.4Red Hat

Medium [CVE-2026-34980] Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network

Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-78. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34980
Unclassified
Apr 3, 2026
Medium5.3Red Hat

Medium [CVE-2026-34979] Denial of Service via heap-based buffer overflow in job attribute processing

Denial of Service via heap-based buffer overflow in job attribute processing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-120. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34979
Unclassified
Apr 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-34978] Denial of Service via path traversal in RSS notifier

Denial of Service via path traversal in RSS notifier. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34978
Unclassified
Apr 3, 2026
Medium5.2Red Hat

Medium [CVE-2026-34990] Privilege escalation via arbitrary file overwrite due to coerced authentication

Privilege escalation via arbitrary file overwrite due to coerced authentication. Red Hat rates this moderate (CVSS 5.2). Weakness: CWE-73. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34990
Unclassified
Apr 3, 2026
Medium6.4Red Hat

Medium [CVE-2026-27447] Authorization bypass via case-insensitive username comparison

Authorization bypass via case-insensitive username comparison. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-178. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27447
Unclassified
Apr 3, 2026
Medium5.4Red Hat

Medium [CVE-2026-35536] Cookie attribute injection due to improper handling of cookie arguments

Cookie attribute injection due to improper handling of cookie arguments. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-88. Affected package(s): python-tornado. Resolved in Red Hat advisory RHSA-2026:24342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-35536
Unclassified
Apr 3, 2026

← All vendors