Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium4.0Vendor: LowRed Hat

Medium [CVE-2025-69418] Information disclosure and data tampering via specific low-level OCB encryption/decryption calls

Information disclosure and data tampering via specific low-level OCB encryption/decryption calls. Red Hat rates this low (CVSS 4). Weakness: CWE-325. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2025-69418
Unclassified
Jan 27, 2026
Medium6.5Vendor: LowRed Hat

Medium [CVE-2025-69421] Denial of Service via malformed PKCS#12 file processing

Denial of Service via malformed PKCS#12 file processing. Red Hat rates this low (CVSS 6.5). Weakness: CWE-476. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2025-69421
Unclassified
Jan 27, 2026
Medium5.9Vendor: LowRed Hat

Medium [CVE-2025-69420] Denial of Service via malformed TimeStamp Response

Denial of Service via malformed TimeStamp Response. Red Hat rates this low (CVSS 5.9). Weakness: CWE-843. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2025-69420
Unclassified
Jan 27, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-22795] Denial of Service due to type confusion in PKCS#12 file processing

Denial of Service due to type confusion in PKCS#12 file processing. Red Hat rates this low (CVSS 5.5). Weakness: CWE-843. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-22795
Unclassified
Jan 27, 2026
Medium5.9Vendor: LowRed Hat

Medium [CVE-2026-22796] Denial of Service via type confusion in PKCS#7 signature verification

Denial of Service via type confusion in PKCS#7 signature verification. Red Hat rates this low (CVSS 5.9). Weakness: CWE-1287. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-22796
Unclassified
Jan 27, 2026
Medium5.0Red Hat

Medium [CVE-2025-28164] Denial of Service via buffer overflow in png_create_read_struct() function

Denial of Service via buffer overflow in png_create_read_struct() function. Red Hat rates this moderate (CVSS 5). Weakness: CWE-120. Affected package(s): libpng-main. Resolved in Red Hat advisory RHSA-2026:6732 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-28164
Unclassified
Jan 27, 2026
Medium6.2Red Hat

Medium [CVE-2025-28162] Denial of Service via buffer overflow in pngimage utility

Denial of Service via buffer overflow in pngimage utility. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-120. Affected package(s): libpng-main. Resolved in Red Hat advisory RHSA-2026:6732 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-28162
Unclassified
Jan 27, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-1504] Inappropriate implementation in Background Fetch API

Inappropriate implementation in Background Fetch API. Red Hat rates this important (CVSS 6.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-1504
Unclassified
Jan 27, 2026
Medium4.7Vendor: LowRed Hat

Medium [CVE-2026-23002] use __kernel_read() for sleepable context

use __kernel_read() for sleepable context. Red Hat rates this low (CVSS 4.7). Weakness: CWE-476. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:18134 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-23002
Unclassified
Jan 25, 2026
Medium6.4Red Hat

Medium [CVE-2026-22998] fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec

fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-476. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:2722 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-22998
Unclassified
Jan 25, 2026
Medium6.5Red Hat

Medium [CVE-2026-24401] Denial of Service via recursive CNAME record in mDNS response

Denial of Service via recursive CNAME record in mDNS response. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-674. Affected package(s): avahi-main. Resolved in Red Hat advisory RHSA-2026:11316 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-24401
Unclassified
Jan 24, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2025-71151] Fix memory and information leak in smb3_reconfigure()

Fix memory and information leak in smb3_reconfigure(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2025:6966 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2025-71151
Unclassified
Jan 23, 2026
Medium6.8Red Hat

Medium [CVE-2025-71176] Denial of Service or Privilege Escalation via insecure temporary directory handling

Denial of Service or Privilege Escalation via insecure temporary directory handling. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-379. Affected package(s): pytest-main. Resolved in Red Hat advisory RHSA-2026:8580 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-71176
Unclassified
Jan 22, 2026
Medium6.8Red Hat

Medium [CVE-2026-23893] Privilege Escalation or Data Exposure via Symlink Following

Privilege Escalation or Data Exposure via Symlink Following. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-59. Affected package(s): opencryptoki. Resolved in Red Hat advisory RHSA-2026:4717 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-23893
Unclassified
Jan 22, 2026
Medium6.5Red Hat

Medium [CVE-2025-14559] Keycloak keycloak-services: Business logic flaw allows unauthorized token issuance for disabled users

Keycloak keycloak-services: Business logic flaw allows unauthorized token issuance for disabled users. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-840. Affected package(s): keycloak-services, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-14559
Unclassified
Jan 21, 2026
Medium4.8Red Hat

Medium [CVE-2026-0672] Header injection in http.cookies.Morsel in Python

Header injection in http.cookies. Morsel in Python. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-93. Affected package(s): python3.12, rhui5/rhua-rhel9:1779798222, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:19064 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-0672
Unclassified
Jan 20, 2026
Medium4.8Red Hat

Medium [CVE-2025-15282] Header injection via newlines in data URL mediatype in Python

Header injection via newlines in data URL mediatype in Python. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-93. Affected package(s): python3.12, python3, rhui5/rhua-rhel9:1779798222, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:19064 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2025-15282
Unclassified
Jan 20, 2026
Medium4.5Red Hat

Medium [CVE-2026-0865] wsgiref.headers.Headers allows header newline injection in Python

wsgiref.headers. Headers allows header newline injection in Python. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-74. Affected package(s): python3.11, python3, rhui5/haproxy-rhel9:1779798164, rhui5/rhua-rhel9:1773670137, rhui5/rhua-rhel9:1779798222, python3.12. Resolved in Red Hat advisory RHSA-2026:2128 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-0865
Unclassified
Jan 20, 2026
Medium4.8Red Hat

Medium [CVE-2026-21925] Improve JMX connections (Oracle CPU 2026-01)

Improve JMX connections (Oracle CPU 2026-01). Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-322. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0895 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-21925
Unclassified
Jan 20, 2026
Medium6.1Red Hat

Medium [CVE-2026-21933] Improve HttpServer Request handling (Oracle CPU 2026-01)

Improve HttpServer Request handling (Oracle CPU 2026-01). Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-93. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0895 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-21933
Unclassified
Jan 20, 2026

← All vendors