Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium4.7Red Hat

Medium [CVE-2025-71201] Fix early read unlock of page with EOF in middle

Fix early read unlock of page with EOF in middle. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-826. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2025:20095 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2025-71201
Unclassified
Feb 14, 2026
Medium6.7Vendor: HighRed Hat

Medium [CVE-2026-23185] cancel mlo_scan_start_wk

cancel mlo_scan_start_wk. Red Hat rates this important (CVSS 6.7). Weakness: CWE-772. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-23185
Unclassified
Feb 14, 2026
Medium5.3Red Hat

Medium [CVE-2026-23146] Linux kernel: Denial of Service in Bluetooth HCI UART driver via null pointer dereference

Linux kernel: Denial of Service in Bluetooth HCI UART driver via null pointer dereference. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-476. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2025:20095 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-23146
Unclassified
Feb 14, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-23205] fix memory leak in smb2_open_file()

fix memory leak in smb2_open_file(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2025:20095 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-23205
Unclassified
Feb 14, 2026
Medium5.6Red Hat

Medium [CVE-2025-33042] Code injection on Java generated code

Code injection on Java generated code. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-94. Affected package(s): avro. Resolved in Red Hat advisory RHSA-2026:7109 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-33042
Unclassified
Feb 13, 2026
Medium4.3Red Hat

Medium [CVE-2026-2003] PostgreSQL oidvector discloses a few bytes of memory

PostgreSQL oidvector discloses a few bytes of memory. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-1287. Affected package(s): postgresql:16, postgresql, postgresql:15, postgresql18-main, rhui5/rhua-rhel9:1773670137, postgresql16. Resolved in Red Hat advisory RHSA-2026:3896 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-2003
Unclassified
Feb 12, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-1669] Information disclosure via arbitrary file read in model loading mechanism

Information disclosure via arbitrary file read in model loading mechanism. Red Hat rates this important (CVSS 6.5). Weakness: CWE-73. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-1669
Unclassified
Feb 11, 2026
Medium6.5Red Hat

Medium [CVE-2026-0966] Denial of Service via zero-length input in ssh_get_hexa()

Denial of Service via zero-length input in ssh_get_hexa(). Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-124. Affected package(s): libssh, libssh-main. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat Enterprise Linux 8; and 1 more.

CVE-2026-0966
Unclassified
Feb 10, 2026
Medium5.0Red Hat

Medium [CVE-2026-0964] Improper sanitation of paths received from SCP servers

Improper sanitation of paths received from SCP servers. Red Hat rates this moderate (CVSS 5). Weakness: CWE-22. Affected package(s): libssh. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4.

CVE-2026-0964
Unclassified
Feb 10, 2026
Medium5.4Red Hat

Medium [CVE-2025-14778] Incorrect ownership checks in /uma-policy/

Incorrect ownership checks in /uma-policy/. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-266. Affected package(s): rhbk/keycloak-rhel9-operator, rhbk/keycloak-operator-bundle:26.2.13, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-14778
Unclassified
Feb 9, 2026
Medium5.3Red Hat

Medium [CVE-2026-24684] FreeRDP has a Heap-use-after-free in play_thread

FreeRDP has a Heap-use-after-free in play_thread. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-131. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-24684
Unclassified
Feb 9, 2026
Medium5.3Red Hat

Medium [CVE-2026-24683] FreeRDP has a heap-use-after-free in ainput_send_input_event

FreeRDP has a heap-use-after-free in ainput_send_input_event. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-24683
Unclassified
Feb 9, 2026
Medium5.3Red Hat

Medium [CVE-2026-24682] FreeRDP has a Heap-buffer-overflow in audio_formats_free

FreeRDP has a Heap-buffer-overflow in audio_formats_free. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-131. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:19033 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-24682
Unclassified
Feb 9, 2026
Medium5.3Red Hat

Medium [CVE-2026-24681] FreeRDP has a heap-use-after-free in urb_bulk_transfer_cb

FreeRDP has a heap-use-after-free in urb_bulk_transfer_cb. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:9640 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-24681
Unclassified
Feb 9, 2026
Medium5.3Red Hat

Medium [CVE-2026-24679] FreeRDP has a heap-buffer-overflow in urb_select_interface

FreeRDP has a heap-buffer-overflow in urb_select_interface. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1285. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-24679
Unclassified
Feb 9, 2026
Medium5.3Vendor: HighRed Hat

Medium [CVE-2026-24678] Denial of Service via use after free in ecam_channel_write

Denial of Service via use after free in ecam_channel_write. Red Hat rates this important (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:19033 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6.

CVE-2026-24678
Unclassified
Feb 9, 2026
Medium5.3Red Hat

Medium [CVE-2026-24676] Denial of Service via use-after-free in AUDIN format renegotiation

Denial of Service via use-after-free in AUDIN format renegotiation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-24676
Unclassified
Feb 9, 2026
Medium5.3Red Hat

Medium [CVE-2026-24675] FreeRDP has a Heap-use-after-free in urb_select_interface

FreeRDP has a Heap-use-after-free in urb_select_interface. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-24675
Unclassified
Feb 9, 2026
Medium5.3Red Hat

Medium [CVE-2026-24491] FreeRDP has a heap-use-after-free in video_timer

FreeRDP has a heap-use-after-free in video_timer. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-24491
Unclassified
Feb 9, 2026
Medium5.3Red Hat

Medium [CVE-2026-23948] FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2()

FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2(). Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-476. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-23948
Unclassified
Feb 9, 2026

← All vendors