Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5297 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High8.1Linux

High [CVE-2026-11816] Arbitrary file write via path traversal in archive extraction utilities

Arbitrary file write via path traversal in archive extraction utilities. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift AI 2.25.

CVE-2026-11816
Unclassified
Jun 11, 2026
High7.5Linux

High [CVE-2026-5497] Denial of Service via unbounded video frame processing

Denial of Service via unbounded video frame processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-5497
Red Hat Enterprise Linux
Jun 11, 2026
High7.1Linux

High [CVE-2026-40987] Arbitrary file write via malicious server

Arbitrary file write via malicious server. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40987
Unclassified
Jun 11, 2026
High7.5Linux

High [CVE-2026-53461] Denial of Service via out-of-bounds heap write in ICON decoder

Denial of Service via out-of-bounds heap write in ICON decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-53461
Unclassified
Jun 10, 2026
High7.5Linux

High [CVE-2026-53460] Denial of Service via missing memory request check

Denial of Service via missing memory request check. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-53460
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-49218] Denial of Service via crafted DCM image with invalid dimensions

Denial of Service via crafted DCM image with invalid dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-49218
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-46520] Denial of Service via out-of-bounds write when processing multiple images

Denial of Service via out-of-bounds write when processing multiple images. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-46520
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-45664] Denial of Service due to excessive resource use in MNG coder

Denial of Service due to excessive resource use in MNG coder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-45664
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-46522] Denial of Service via crafted MIFF file

Denial of Service via crafted MIFF file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-46522
Red Hat Enterprise Linux
Jun 10, 2026
High7.1Linux

High [CVE-2026-45359] Information Disclosure via Invalid Connected-Components Value

Information Disclosure via Invalid Connected-Components Value. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-45359
Unclassified
Jun 10, 2026
High7.5Linux

High [CVE-2026-45031] Denial of Service due to resource policy bypass in PSD decoder

Denial of Service due to resource policy bypass in PSD decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-45031
Red Hat Enterprise Linux
Jun 10, 2026
High7.8Linux

High [CVE-2026-2049] Remote Code Execution via HDR File Parsing Heap-based Buffer Overflow

Remote Code Execution via HDR File Parsing Heap-based Buffer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-2049
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-46523] Denial of Service via crafted MSL image leading to heap-use-after-free

Denial of Service via crafted MSL image leading to heap-use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.

CVE-2026-46523
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-46625] Cookie attribute manipulation via prototype pollution

Cookie attribute manipulation via prototype pollution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift-service-mesh/kiali-rhel9:1782201466. Resolved in Red Hat advisory RHSA-2026:33183 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat OpenShift Service Mesh 3.3; OpenShift Lightspeed; Red Hat 3scale API Management Platform 2; and 4 more.

CVE-2026-46625
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-10143] Denial of Service via excessive SCRAM authentication iteration count

Denial of Service via excessive SCRAM authentication iteration count. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected package(s): quay/quay-rhel8:1782487717, quay/quay-rhel8:1781878070, quay/quay-rhel8:1781937357. Resolved in Red Hat advisory RHSA-2026:28571 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: kafka-python; Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.9; and 2 more.

CVE-2026-10143
Unclassified
Jun 10, 2026
High7.8Linux

High [CVE-2026-46529] PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen

PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen. Red Hat rates this important (CVSS 7.8). Weakness: CWE-77. Affected package(s): evince. Resolved in Red Hat advisory RHSA-2026:33416 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 8); Red Hat Enterprise Linux AppStream E4S (v.9.2); Red Hat Enterprise Linux AppStream E4S (v.9.4); Red Hat Enterprise Linux AppStream EUS (v.9.6); and 13 more.

CVE-2026-46529
Red Hat Enterprise Linux
Jun 10, 2026
High7.5Linux

High [CVE-2026-1220] Race in V8

Race in V8. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-1220
Unclassified
Jun 10, 2026
High7.5Linux

High [CVE-2026-6893] Root code execution via DHCP options command injection

Root code execution via DHCP options command injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Affected package(s): dracut, dracut-main. Resolved in Red Hat advisory RHSA-2026:26713 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more.

CVE-2026-6893
Red Hat Enterprise Linux
Jun 10, 2026
High8.2Linux

High [CVE-2026-49759] Denial of Service via crafted SCTP ERROR chunk

Denial of Service via crafted SCTP ERROR chunk. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-49759
Unclassified
Jun 10, 2026
High7.4Linux

High [CVE-2026-53437] Phishing attack via improper redirect URL validation

Phishing attack via improper redirect URL validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-601. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: OpenShift Developer Tools and Services.

CVE-2026-53437
Unclassified
Jun 10, 2026

← All vendors