Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5300 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium4.3Linux

Medium [CVE-2026-44169] MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check

MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-266. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-44169
Unclassified
Jun 12, 2026
Medium5.3Linux

Medium [CVE-2026-50560] Denial of Service due to HTTP/2 max header size handling

Denial of Service due to HTTP/2 max header size handling. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected package(s): netty-codec-http2. Resolved in Red Hat advisory RHSA-2026:26018 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-50560
Unclassified
Jun 12, 2026
Medium5.3Linux

Medium [CVE-2026-50020] Data manipulation via request-boundary confusion in HttpObjectDecoder

Data manipulation via request-boundary confusion in HttpObjectDecoder. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected package(s): netty-codec-http. Resolved in Red Hat advisory RHSA-2026:26018 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-50020
Unclassified
Jun 12, 2026
Medium5.3Linux

Medium [CVE-2026-47244] Denial of Service via uncontrolled HTTP/2 concurrent streams

Denial of Service via uncontrolled HTTP/2 concurrent streams. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected package(s): netty-codec-http2. Resolved in Red Hat advisory RHSA-2026:26018 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47244
Unclassified
Jun 12, 2026
Medium6.6Linux

Medium [CVE-2026-47208] Sandbox Breakout Using Promise Species

Sandbox Breakout Using Promise Species. Red Hat rates this moderate (CVSS 6.6). Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47208
Unclassified
Jun 12, 2026
Medium4.1Linux

Medium [CVE-2026-47140] Arbitrary code execution due to incomplete sandbox restrictions

Arbitrary code execution due to incomplete sandbox restrictions. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-184. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47140
Unclassified
Jun 12, 2026
Medium6.8Linux

Medium [CVE-2026-45673] Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs

Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-1241. Affected package(s): netty-resolver-dns. Resolved in Red Hat advisory RHSA-2026:26018 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-45673
Unclassified
Jun 12, 2026
Medium4.1Linux

Medium [CVE-2026-47137] Sandbox escape leading to arbitrary code execution via security bypass

Sandbox escape leading to arbitrary code execution via security bypass. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-480. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47137
Unclassified
Jun 12, 2026
Medium4.1Linux

Medium [CVE-2026-47131] Arbitrary code execution via sandbox escape vulnerability

Arbitrary code execution via sandbox escape vulnerability. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-843. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-47131
Unclassified
Jun 12, 2026
Medium6.7Linux

Medium [CVE-2026-48914] Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux for NVIDIA 26; and 1 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-48914
Red Hat Enterprise Linux
Jun 12, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-49261] Arbitrary code execution via wsrep_notify_cmd

Arbitrary code execution via wsrep_notify_cmd. Red Hat rates this important (CVSS 9). Weakness: CWE-78. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images.

CVE-2026-49261
Red Hat Enterprise Linux
Jun 11, 2026
High7.5Linux

High [CVE-2026-44890] Denial of Service via crafted Redis payloads

Denial of Service via crafted Redis payloads. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 1 more.

CVE-2026-44890
Unclassified
Jun 11, 2026
High7.5Linux

High [CVE-2026-44250] Denial of Service via crafted Redis payload with deeply nested arrays

Denial of Service via crafted Redis payload with deeply nested arrays. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 1 more.

CVE-2026-44250
Unclassified
Jun 11, 2026
High8.3Linux

High [CVE-2026-12034] Insufficient validation of untrusted input Linux Toolkit Theming

Insufficient validation of untrusted input Linux Toolkit Theming. Red Hat rates this important (CVSS 8.3). Weakness: CWE-1289. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12034
Unclassified
Jun 11, 2026
High8.8Linux

High [CVE-2026-12035] Use after free Views

Use after free Views. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12035
Unclassified
Jun 11, 2026
High8.3Linux

High [CVE-2026-12031] Inappropriate implementation Views

Inappropriate implementation Views. Red Hat rates this important (CVSS 8.3). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12031
Unclassified
Jun 11, 2026
High8.3Linux

High [CVE-2026-12030] Heap buffer overflow GPU

Heap buffer overflow GPU. Red Hat rates this important (CVSS 8.3). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12030
Unclassified
Jun 11, 2026
High8.3Linux

High [CVE-2026-12029] Use after free Video

Use after free Video. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12029
Unclassified
Jun 11, 2026
High8.3Linux

High [CVE-2026-12028] Use after free GPU

Use after free GPU. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12028
Unclassified
Jun 11, 2026
High8.3Linux

High [CVE-2026-12027] Insufficient policy enforcement Headless

Insufficient policy enforcement Headless. Red Hat rates this important (CVSS 8.3). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-12027
Unclassified
Jun 11, 2026

← All vendors