Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.8Red Hat

High [CVE-2025-15059] heap-based buffer overflow via specially crafted PSP file

heap-based buffer overflow via specially crafted PSP file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122. Affected package(s): gimp. Resolved in Red Hat advisory RHSA-2026:2953 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2025-15059
Unclassified
Jan 23, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-22984] prevent potential out-of-bounds reads in handle_auth_done()

prevent potential out-of-bounds reads in handle_auth_done(). Red Hat rates this moderate (CVSS 7.1). Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-22984
Unclassified
Jan 23, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-22990] replace overzealous BUG_ON in osdmap_apply_incremental()

replace overzealous BUG_ON in osdmap_apply_incremental(). Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-617. Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-22990
Unclassified
Jan 23, 2026
High7.5Red Hat

High [CVE-2026-20736] Cross-Repository Unauthorized Deletion via Missing Repo Ownership Check

Cross-Repository Unauthorized Deletion via Missing Repo Ownership Check. Red Hat rates this important (CVSS 7.5). Weakness: CWE-284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-20736
Unclassified
Jan 22, 2026
High7.8Red Hat

High [CVE-2026-1260] Invalid memory access leading to potential arbitrary code execution via a crafted model file.

Invalid memory access leading to potential arbitrary code execution via a crafted model file.. Red Hat rates this important (CVSS 7.8). Weakness: CWE-119. Affected package(s): rhoai/odh-openvino-model-server-rhel9:1772093351, rhoai/odh-training-cuda124-torch25-py311-rhel9:1772093260, rhoai/odh-training-cuda121-torch24-py311-rhel9:1772093252, rhoai/odh-openvino-model-server-rhel9:1771608633, rhoai/odh-training-rocm62-torch25-py311-rhel9:1772093324, rhoai/odh-training-rocm62-torch24-py311-rhel9:1772093338. Resolved in Red Hat advisory RHSA-2026:3713 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat AI Inference Server.

CVE-2026-1260
Unclassified
Jan 22, 2026
High7.1Red Hat

High [CVE-2026-24049] Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking

Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. Affected package(s): devspaces/udi-rhel9:1774451954, rhtas/segment-reporting-rhel9:1770108732, ansible-automation-platform, rhoai/odh-training-rocm62-torch24-py311-rhel9:1772093338, quay/quay-rhel9:1770836901, rhoai/odh-training-cuda124-torch25-py311-rhel9:1772093260. Resolved in Red Hat advisory RHSA-2026:2139 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Discovery 2 for RHEL 10; Discovery 2 for RHEL 8; Discovery 2 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; and 36 more.

CVE-2026-24049
Unclassified
Jan 22, 2026
High7.5Red Hat

High [CVE-2026-24006] Denial of Service due to excessive recursion during object serialization

Denial of Service due to excessive recursion during object serialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-24006
Unclassified
Jan 22, 2026
High7.5Red Hat

High [CVE-2026-24001] denial of service vulnerability in parsePatch and applyPatch

denial of service vulnerability in parsePatch and applyPatch. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Satellite 6.

CVE-2026-24001
Unclassified
Jan 22, 2026
High7.5Red Hat

High [CVE-2026-23957] Denial of Service via large encoded array lengths

Denial of Service via large encoded array lengths. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23957
Unclassified
Jan 22, 2026
High7.5Red Hat

High [CVE-2026-23956] Denial of Service via malicious regular expressions during deserialization

Denial of Service via malicious regular expressions during deserialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23956
Unclassified
Jan 22, 2026
High7.5Red Hat

High [CVE-2026-23737] Arbitrary Code Execution via Improper JSON Deserialization

Arbitrary Code Execution via Improper JSON Deserialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23737
Unclassified
Jan 21, 2026
High7.3Red Hat

High [CVE-2026-23736] Prototype pollution via improper input validation during JSON deserialization

Prototype pollution via improper input validation during JSON deserialization. Red Hat rates this important (CVSS 7.3). Weakness: CWE-1321. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23736
Unclassified
Jan 21, 2026
High7.1Red Hat

High [CVE-2026-23960] Privilege escalation and information disclosure via stored Cross-Site Scripting (XSS)

Privilege escalation and information disclosure via stored Cross-Site Scripting (XSS). Red Hat rates this important (CVSS 7.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-23960
Unclassified
Jan 21, 2026
High8.8Red Hat

High [CVE-2026-22822] Cross-Namespace Secret Disclosure via `getSecretKey` Function

Cross-Namespace Secret Disclosure via `getSecretKey` Function. Red Hat rates this important (CVSS 8.8). Weakness: CWE-863. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: external secrets operator for Red Hat OpenShift - Tech Preview.

CVE-2026-22822
Unclassified
Jan 21, 2026
High8.8Red Hat

High [CVE-2026-22807] Arbitrary code execution via untrusted model loading

Arbitrary code execution via untrusted model loading. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-spyre-rhel9:1782352919, rhaiis/vllm-cuda-rhel9:1782352847, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhoai/odh-vllm-cpu-rhel9:1776259063, rhoai/odh-vllm-gaudi-rhel9:1770956034. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat AI Inference Server 3.2; Red Hat AI Inference Server 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; and 3 more.

CVE-2026-22807
Unclassified
Jan 21, 2026
High8.2Red Hat

High [CVE-2025-13465] prototype pollution in _.unset and _.omit functions

prototype pollution in _.unset and _.omit functions. Red Hat rates this important (CVSS 8.2). Weakness: CWE-1321. Affected package(s): network-observability/network-observability-console-plugin-rhel9:1771227650, openshift-gitops, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, openshift4/ose-console-rhel9:1770831186, multicluster-engine/console-mce-rhel9:1776223790. Resolved in Red Hat advisory RHSA-2026:3869 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Data Grid 8.6.0; Red Hat Enterprise Linux 10.0 Extended Update Support; and 77 more.

CVE-2025-13465
Unclassified
Jan 21, 2026
High7.5Red Hat

High [CVE-2025-13878] Denial of Service via corrupt or malicious record

Denial of Service via corrupt or malicious record. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: BIND 9; Red Hat Hardened Images.

CVE-2025-13878
Unclassified
Jan 21, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2025-15367] POP3 command injection in user-controlled commands

POP3 command injection in user-controlled commands. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-77. Affected package(s): discovery/discovery-server-rhel9:1775668717, python3, python3.11, python3.12, rhui5/rhua-rhel9:1773670137, rhaiis/vllm-rocm-rhel9:1775680262. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 6; and 1 more.

CVE-2025-15367
Unclassified
Jan 20, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2025-15366] IMAP command injection in user-controlled commands

IMAP command injection in user-controlled commands. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-77. Affected package(s): discovery/discovery-server-rhel9:1775668717, python3, python3.11, python3.12, rhui5/rhua-rhel9:1773670137, rhaiis/vllm-rocm-rhel9:1775680262. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 6; and 1 more.

CVE-2025-15366
Unclassified
Jan 20, 2026
High7.4Red Hat

High [CVE-2026-21932] Enhance Handling of URIs (Oracle CPU 2026-01)

Enhance Handling of URIs (Oracle CPU 2026-01). Red Hat rates this important (CVSS 7.4). Weakness: CWE-1287. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0896 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of OpenJDK 17.0.18; Red Hat Build of OpenJDK 21.0.10; Red Hat Build of OpenJDK 8u482.

CVE-2026-21932
Unclassified
Jan 20, 2026

← All vendors