Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5292 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium6.2Linux

Medium [CVE-2026-45491] .NET: Local file tampering via link following vulnerability

.NET: Local file tampering via link following vulnerability. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-59. Affected package(s): dotnet8, dotnet8.0, dotnet9.0, dotnet9, dotnet10.0, dotnet10. Resolved in Red Hat advisory RHSA-2026:25110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-45491
Unclassified
Jun 9, 2026
Medium5.5Vendor: LowLinux

Medium [CVE-2026-7383] Heap buffer overflow due to signed integer overflow in Unicode output sizing

Heap buffer overflow due to signed integer overflow in Unicode output sizing. Red Hat rates this low (CVSS 5.5). Weakness: CWE-190. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-7383
Unclassified
Jun 9, 2026
Medium5.9Vendor: LowLinux

Medium [CVE-2026-9076] Denial of Service due to heap out-of-bounds read in CMS password-based decryption

Denial of Service due to heap out-of-bounds read in CMS password-based decryption. Red Hat rates this low (CVSS 5.9). Weakness: CWE-131. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-9076
Unclassified
Jun 9, 2026
Medium5.0Vendor: LowLinux

Medium [CVE-2026-34180] Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.

Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.. Red Hat rates this low (CVSS 5). Weakness: CWE-190. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-34180
Unclassified
Jun 9, 2026
Medium6.3Vendor: LowLinux

Medium [CVE-2026-34181] PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys

PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys. Red Hat rates this low (CVSS 6.3). Weakness: CWE-347. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-34181
Unclassified
Jun 9, 2026
Medium5.9Linux

Medium [CVE-2026-42764] NULL pointer dereference in QUIC server initial packet handling

NULL pointer dereference in QUIC server initial packet handling. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-476. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-42764
Unclassified
Jun 9, 2026
Medium5.3Vendor: LowLinux

Medium [CVE-2026-42766] Possible NULL Dereference in Password-Based CMS Decryption

Possible NULL Dereference in Password-Based CMS Decryption. Red Hat rates this low (CVSS 5.3). Weakness: CWE-476. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-42766
Unclassified
Jun 9, 2026
Medium5.3Vendor: LowLinux

Medium [CVE-2026-42767] NULL Pointer Dereference in CRMF EncryptedValue Decryption

NULL Pointer Dereference in CRMF EncryptedValue Decryption. Red Hat rates this low (CVSS 5.3). Weakness: CWE-476. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-42767
Unclassified
Jun 9, 2026
Medium6.3Vendor: LowLinux

Medium [CVE-2026-42768] Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()

Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt(). Red Hat rates this low (CVSS 6.3). Weakness: CWE-205. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-42768
Unclassified
Jun 9, 2026
Medium5.9Vendor: LowLinux

Medium [CVE-2026-42769] Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate

Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate. Red Hat rates this low (CVSS 5.9). Weakness: CWE-295. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-42769
Unclassified
Jun 9, 2026
Medium5.9Vendor: LowLinux

Medium [CVE-2026-42770] FFC-DH Peer Validation Uses Attacker-Supplied q

FFC-DH Peer Validation Uses Attacker-Supplied q. Red Hat rates this low (CVSS 5.9). Weakness: CWE-354. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-42770
Unclassified
Jun 9, 2026
Low3.7Linux

Low [CVE-2026-45446] Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes

Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes. Red Hat rates this low (CVSS 3.7). Weakness: CWE-347. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, rhui5/haproxy-rhel9:1781525671, openssl, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-45446
Unclassified
Jun 9, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-11697] Insufficient validation of untrusted input in UI

Insufficient validation of untrusted input in UI. Red Hat rates this important (CVSS 9.6). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11697
Unclassified
Jun 8, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-11670] Use after free in PDF

Use after free in PDF. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11670
Unclassified
Jun 8, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-11642] Use after free in Web Apps

Use after free in Web Apps. Red Hat rates this important (CVSS 9). Weakness: CWE-1341. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11642
Unclassified
Jun 8, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-11635] Use after free in Bluetooth

Use after free in Bluetooth. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11635
Unclassified
Jun 8, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-11694] Use after free in ServiceWorker

Use after free in ServiceWorker. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11694
Unclassified
Jun 8, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-11652] Use after free in Extensions

Use after free in Extensions. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11652
Unclassified
Jun 8, 2026
Critical9.8Vendor: HighLinux

Critical [CVE-2026-11643] Use after free in Proxy

Use after free in Proxy. Red Hat rates this important (CVSS 9.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11643
Unclassified
Jun 8, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-11638] Use after free in Printing

Use after free in Printing. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11638
Unclassified
Jun 8, 2026

← All vendors