Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5301 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High8.8Linux

High [CVE-2026-52720] Heap buffer overflow via crafted VNC server rectangle in librfb

Heap buffer overflow via crafted VNC server rectangle in librfb. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 7 more.

CVE-2026-52720
Red Hat Enterprise Linux
Jun 15, 2026
High7.1Linux

High [CVE-2026-52722] Signed integer overflow in VMnc decoder cursor payload handling

Signed integer overflow in VMnc decoder cursor payload handling. Red Hat rates this important (CVSS 7.1). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 7 more.

CVE-2026-52722
Red Hat Enterprise Linux
Jun 15, 2026
Medium5.3Linux

Medium [CVE-2026-12087] Information Disclosure due to Out-of-Bounds Read

Information Disclosure due to Out-of-Bounds Read. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125. Affected package(s): perl-socket-main. Resolved in Red Hat advisory RHSA-2026:11342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12087
Unclassified
Jun 15, 2026
Medium6.5Linux

Medium [CVE-2026-52718] Gstreamer1-plugins-bad-free: gstreamer: denial of service via av1 tile_list_obu parser byte/bit confusion

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 10.0 Extended Update Support.

CVE-2026-52718
Red Hat Enterprise Linux
Jun 15, 2026
Medium5.3Linux

Medium [CVE-2026-44188] Session hijacking and unauthorized data access due to insufficient session expiration

Session hijacking and unauthorized data access due to insufficient session expiration. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-613. Affected package(s): ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:25928 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-44188
Unclassified
Jun 15, 2026
Medium4.8Linux

Medium [CVE-2026-54411] Plaintext password recovery via timing discrepancy in pam_userdb module

Plaintext password recovery via timing discrepancy in pam_userdb module. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-208. Affected package(s): pam-main. Resolved in Red Hat advisory RHSA-2026:35016 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-54411
Unclassified
Jun 14, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-48165] Arbitrary code execution via global system variable manipulation by a high-privileged user

Arbitrary code execution via global system variable manipulation by a high-privileged user. Red Hat rates this important (CVSS 9.1). Weakness: CWE-78. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images.

CVE-2026-48165
Red Hat Enterprise Linux
Jun 12, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-48163] Arbitrary code execution via improper parameter validation during SST

Arbitrary code execution via improper parameter validation during SST. Red Hat rates this important (CVSS 9.1). Weakness: CWE-78. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat Enterprise Linux 10.0 Extended Update Support.

CVE-2026-48163
Red Hat Enterprise Linux
Jun 12, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-44172] MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string()

MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string(). Red Hat rates this important (CVSS 9.1). Weakness: CWE-89. Affected package(s): mariadb10.11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11, mariadb-connector-c-main. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.0 Extended Update Support.

CVE-2026-44172
Red Hat Enterprise Linux
Jun 12, 2026
Critical9.9Vendor: HighLinux

Critical [CVE-2026-44170] Arbitrary shell command execution via improper sanitization in CONNECT engine

Arbitrary shell command execution via improper sanitization in CONNECT engine. Red Hat rates this important (CVSS 9.9). Weakness: CWE-78. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat Enterprise Linux 10.0 Extended Update Support.

CVE-2026-44170
Red Hat Enterprise Linux
Jun 12, 2026
High8.1Linux

High [CVE-2026-44990] `sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass

`sanitize-html`: Stored Cross-Site Scripting via HTML sanitizer bypass. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 13 more.

CVE-2026-44990
Unclassified
Jun 12, 2026
High7.5Linux

High [CVE-2026-12143] Form field override via CRLF injection

Form field override via CRLF injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-93. Affected package(s): cluster-observability-operator/troubleshooting-panel-console-plugin-rhel9:1782839494, openshift-service-mesh/kiali-ossmc-rhel9:1782201851, openshift-service-mesh/kiali-ossmc-rhel9:1782231869, cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9:1782839193, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9:1782839981. Resolved in Red Hat advisory RHSA-2026:33160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Developer Hub 1.10; Red Hat Hardened Images; and 33 more.

CVE-2026-12143
Red Hat Enterprise Linux
Jun 12, 2026
High8.1Linux

High [CVE-2026-44173] Privilege bypass allows unauthorized file write via subqueries

Privilege bypass allows unauthorized file write via subqueries. Red Hat rates this important (CVSS 8.1). Weakness: CWE-266. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images.

CVE-2026-44173
Red Hat Enterprise Linux
Jun 12, 2026
High8.0Linux

High [CVE-2026-44168] Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer

Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer. Red Hat rates this important (CVSS 8). Weakness: CWE-78. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images.

CVE-2026-44168
Red Hat Enterprise Linux
Jun 12, 2026
High7.5Linux

High [CVE-2026-45833] Arbitrary Code Execution via Code Injection

Arbitrary Code Execution via Code Injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-45833
Red Hat Enterprise Linux
Jun 12, 2026
High8.1Linux

High [CVE-2026-45832] Authorization bypass in V1 collection-level endpoints

Authorization bypass in V1 collection-level endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-551. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-45832
Red Hat Enterprise Linux
Jun 12, 2026
High7.5Linux

High [CVE-2026-50011] Denial of Service via malicious Redis array header

Denial of Service via malicious Redis array header. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 1 more.

CVE-2026-50011
Unclassified
Jun 12, 2026
High7.5Linux

High [CVE-2026-50010] Improper trust manager handling leads to hostname verification bypass

Improper trust manager handling leads to hostname verification bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-347. Affected package(s): netty-handler, offline-knowledge-portal/rhokp-rhel9:1782239370. Resolved in Red Hat advisory RHSA-2026:26586 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Offline Knowledge Portal 1.2.7; OpenShift Serverless; Red Hat AMQ Broker 7; Red Hat AMQ Clients; and 19 more.

CVE-2026-50010
Red Hat Enterprise Linux
Jun 12, 2026
High8.1Linux

High [CVE-2026-45830] Unauthorized data manipulation due to improper authorization validation

Unauthorized data manipulation due to improper authorization validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-45830
Red Hat Enterprise Linux
Jun 12, 2026
High7.5Linux

High [CVE-2026-48748] Denial of Service due to memory exhaustion in HTTP/3 codec

Denial of Service due to memory exhaustion in HTTP/3 codec. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-48748
Unclassified
Jun 12, 2026

← All vendors