Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.5Red Hat

Medium [CVE-2026-4715] Uninitialized memory in the Graphics: Canvas2D component

Uninitialized memory in the Graphics: Canvas2D component. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-824. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4715
Unclassified
Mar 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-4714] Incorrect boundary conditions in the Audio/Video component

Incorrect boundary conditions in the Audio/Video component. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4714
Unclassified
Mar 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-4712] Information disclosure in the Widget: Cocoa component

Information disclosure in the Widget: Cocoa component. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-359. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4712
Unclassified
Mar 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-4713] Incorrect boundary conditions in the Graphics component

Incorrect boundary conditions in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4713
Unclassified
Mar 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-4711] Use-after-free in the Widget: Cocoa component

Use-after-free in the Widget: Cocoa component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4711
Unclassified
Mar 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-4709] Incorrect boundary conditions in the Audio/Video: GMP component

Incorrect boundary conditions in the Audio/Video: GMP component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4709
Unclassified
Mar 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-4710] Incorrect boundary conditions in the Audio/Video component

Incorrect boundary conditions in the Audio/Video component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4710
Unclassified
Mar 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-4706] Incorrect boundary conditions in the Graphics: Canvas2D component

Incorrect boundary conditions in the Graphics: Canvas2D component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4706
Unclassified
Mar 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-4707] Incorrect boundary conditions in the Graphics: Canvas2D component

Incorrect boundary conditions in the Graphics: Canvas2D component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-823. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4707
Unclassified
Mar 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-4705] Undefined behavior in the WebRTC: Signaling component

Undefined behavior in the WebRTC: Signaling component. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-475. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4705
Unclassified
Mar 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-4702] JIT miscompilation in the JavaScript Engine component

JIT miscompilation in the JavaScript Engine component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-733. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4702
Unclassified
Mar 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-4701] Use-after-free in the JavaScript Engine component

Use-after-free in the JavaScript Engine component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:6917 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.

CVE-2026-4701
Unclassified
Mar 24, 2026
Medium4.3Red Hat

Medium [CVE-2026-32642] Apache Artemis and Apache ActiveMQ Artemis: Unauthorized address creation due to incorrect authorization during JMS topic subscription.

Apache Artemis and Apache ActiveMQ Artemis: Unauthorized address creation due to incorrect authorization during JMS topic subscription.. Red Hat rates this moderate (CVSS 4.3). Affected package(s): artemis-server. Resolved in Red Hat advisory RHSA-2026:8509 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32642
Unclassified
Mar 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-33176] Denial of Service via large scientific notation strings

Denial of Service via large scientific notation strings. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected package(s): rubygem-activesupport. Resolved in Red Hat advisory RHSA-2026:14835 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-33176
Unclassified
Mar 23, 2026
Medium5.5Red Hat

Medium [CVE-2026-26209] Denial of Service due to uncontrolled recursion via crafted CBOR payloads

Denial of Service due to uncontrolled recursion via crafted CBOR payloads. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770. Affected package(s): rhaiis/vllm-rocm-rhel9:1779223651, rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1779223654, rhaiis/vllm-cuda-rhel9:1778274666, rhaiis/vllm-spyre-rhel9:1778244546. Resolved in Red Hat advisory RHSA-2026:19724 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-26209
Unclassified
Mar 23, 2026
Medium6.1Red Hat

Medium [CVE-2026-4647] Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library

Out-of-Bounds Read in XCOFF Relocation Processing in GNU Binutils BFD Library. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:33527 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more.

CVE-2026-4647
Unclassified
Mar 23, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-4674] Out of bounds read in CSS

Out of bounds read in CSS. Red Hat rates this important (CVSS 6.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4674
Unclassified
Mar 23, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-4675] Heap buffer overflow in WebGL

Heap buffer overflow in WebGL. Red Hat rates this important (CVSS 6.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4675
Unclassified
Mar 23, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-4677] Out of bounds read in WebAudio

Out of bounds read in WebAudio. Red Hat rates this important (CVSS 6.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4677
Unclassified
Mar 23, 2026
Medium4.0Vendor: LowRed Hat

Medium [CVE-2026-4438] Invalid DNS hostname returned via gethostbyaddr functions

Invalid DNS hostname returned via gethostbyaddr functions. Red Hat rates this low (CVSS 4). Weakness: CWE-838. Affected package(s): glibc-main, rhui5/haproxy-rhel9:1781525671, insights-proxy/insights-proxy-container-rhel9:1780420428, glibc, rhui5/installer-rhel9:1781525693, costmanagement/costmanagement-metrics-rhel9-operator:1780946239. Resolved in Red Hat advisory RHSA-2026:19061 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-4438
Unclassified
Mar 20, 2026

← All vendors