Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

413 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-7902] Out of bounds memory access in V8

Out of bounds memory access in V8. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7902
Unclassified
May 5, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-7908] Use after free in Fullscreen

Use after free in Fullscreen. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7908
Unclassified
May 5, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-7914] Type Confusion in Accessibility

Type Confusion in Accessibility. Red Hat rates this important (CVSS 9). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7914
Unclassified
May 5, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-7923] Out of bounds write in Skia

Out of bounds write in Skia. Red Hat rates this important (CVSS 9). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7923
Unclassified
May 5, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-7905] Insufficient validation of untrusted input in Media

Insufficient validation of untrusted input in Media. Red Hat rates this important (CVSS 9). Weakness: CWE-1289. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7905
Unclassified
May 5, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-7906] Use after free in SVG

Use after free in SVG. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7906
Unclassified
May 5, 2026
Critical9.8Red Hat

Critical [CVE-2026-7898] Use after free in Chromoting

Use after free in Chromoting. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7898
Unclassified
May 5, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-7922] Use after free in ServiceWorker

Use after free in ServiceWorker. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7922
Unclassified
May 5, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-7897] Use after free in Mobile

Use after free in Mobile. Red Hat rates this important (CVSS 9.6). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7897
Unclassified
May 5, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-26332] Arbitrary code execution via SuppressedError sandbox escape

Arbitrary code execution via SuppressedError sandbox escape. Red Hat rates this important (CVSS 9.1). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-26332
Unclassified
May 4, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-24120] Arbitrary code execution due to sandbox escape vulnerability

Arbitrary code execution due to sandbox escape vulnerability. Red Hat rates this important (CVSS 9.1). Weakness: CWE-807. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-24120
Unclassified
May 4, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-24118] Arbitrary code execution due to sandbox breakout

Arbitrary code execution due to sandbox breakout. Red Hat rates this important (CVSS 9.1). Weakness: CWE-749. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-24118
Unclassified
May 4, 2026
Critical9.1Red Hat

Critical [CVE-2026-7482] Information disclosure via heap out-of-bounds read in GGUF model loader

Information disclosure via heap out-of-bounds read in GGUF model loader. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7482
Unclassified
May 4, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-43824] Information disclosure via ServerSideDiff allows reading Kubernetes Secret data

Information disclosure via ServerSideDiff allows reading Kubernetes Secret data. Red Hat rates this important (CVSS 9.6). Weakness: CWE-312. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift GitOps.

CVE-2026-43824
Unclassified
May 2, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-7598] integer overflow via large username or password arguments

integer overflow via large username or password arguments. Red Hat rates this important (CVSS 9.1). Weakness: CWE-190. Affected package(s): libssh2-main, rust-main. Resolved in Red Hat advisory RHSA-2026:7021 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Trusted Profile Analyzer.

CVE-2026-7598
Unclassified
May 1, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-41607] Out-of-bounds Read vulnerability

Out-of-bounds Read vulnerability. Red Hat rates this important (CVSS 9.1). Weakness: CWE-125. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 13 more.

CVE-2026-41607
Unclassified
Apr 28, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-7358] Use after free in Animation

Use after free in Animation. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7358
Unclassified
Apr 28, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-7352] Use after free in Media

Use after free in Media. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7352
Unclassified
Apr 28, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-7363] Use after free in Canvas

Use after free in Canvas. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7363
Unclassified
Apr 28, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-7350] Use after free in WebMIDI

Use after free in WebMIDI. Red Hat rates this important (CVSS 9). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7350
Unclassified
Apr 28, 2026

← All vendors