Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.1Red Hat

Medium [CVE-2026-22028] Arbitrary script execution via JSON serialization protection bypass

Arbitrary script execution via JSON serialization protection bypass. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-843. Affected package(s): openshift4/ose-agent-installer-ui-rhel9:1774977480. Resolved in Red Hat advisory RHSA-2026:6564 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-22028
Unclassified
Jan 8, 2026
Medium4.8Red Hat

Medium [CVE-2025-14017] Security bypass due to global TLS option changes in multi-threaded LDAPS transfers

Security bypass due to global TLS option changes in multi-threaded LDAPS transfers. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-1058. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-14017
Unclassified
Jan 8, 2026
Medium5.9Red Hat

Medium [CVE-2025-66560] Quarkus REST Worker Thread Exhaustion Vulnerability

Quarkus REST Worker Thread Exhaustion Vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-772. Affected package(s): quarkus-rest. Resolved in Red Hat advisory RHSA-2026:1899 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-66560
Unclassified
Jan 8, 2026
Medium5.9Vendor: LowRed Hat

Medium [CVE-2025-13151] Denial of Service via stack-based buffer overflow in asn1_expend_octet_string

Denial of Service via stack-based buffer overflow in asn1_expend_octet_string. Red Hat rates this low (CVSS 5.9). Weakness: CWE-120. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, libtasn1, libtasn1-main, discovery/discovery-ui-rhel9:1782756541, discovery/discovery-server-rhel9:1782763840. Resolved in Red Hat advisory RHSA-2026:28235 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2025-13151
Unclassified
Jan 7, 2026
Medium6.8Red Hat

Medium [CVE-2025-13034] Public key pinning bypass via QUIC and GnuTLS allows server impersonation

Public key pinning bypass via QUIC and GnuTLS allows server impersonation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-295. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-13034
Unclassified
Jan 7, 2026
Medium6.5Vendor: LowRed Hat

Medium [CVE-2025-14524] Information disclosure via cross-protocol redirect with OAuth2 bearer token

Information disclosure via cross-protocol redirect with OAuth2 bearer token. Red Hat rates this low (CVSS 6.5). Weakness: CWE-201. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-14524
Unclassified
Jan 7, 2026
Medium6.8Vendor: LowRed Hat

Medium [CVE-2025-14819] Improper certificate validation due to cached TLS settings reuse

Improper certificate validation due to cached TLS settings reuse. Red Hat rates this low (CVSS 6.8). Weakness: CWE-295. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-14819
Unclassified
Jan 7, 2026
Medium4.7Vendor: LowRed Hat

Medium [CVE-2025-15224] libssh key passphrase bypass without agent set

libssh key passphrase bypass without agent set. Red Hat rates this low (CVSS 4.7). Weakness: CWE-305. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-15224
Unclassified
Jan 7, 2026
Medium5.3Red Hat

Medium [CVE-2026-0707] Keycloak Authorization Header Parsing Leading to Potential Security Control Bypass

Keycloak Authorization Header Parsing Leading to Potential Security Control Bypass. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-551. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-0707
Unclassified
Jan 7, 2026
Medium6.8Red Hat

Medium [CVE-2025-69228] Denial of Service via memory exhaustion from crafted POST request

Denial of Service via memory exhaustion from crafted POST request. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-770. Affected package(s): ansible-automation-platform, rhaiis/vllm-cuda-rhel9:1774351144, rhoai/odh-caikit-nlp-rhel9:1780069094, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhaiis/model-opt-cuda-rhel9:1774547384, rhoai/odh-vllm-cpu-rhel9:1776259063. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69228
Unclassified
Jan 5, 2026
Medium6.0Red Hat

Medium [CVE-2025-14777] keycloak idor in realm client creating/deleting

A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin API endpoints for authorization resource management, specifically in ResourceSetService and PermissionTicketService. The system checks authorization against the resourceServer (client) ID provided in the API request, but the backend database lookup and modification operations (findById, delete) only use the resourceId. This mismatch allows an authenticated attacker with fine-grained admin permissions for one client (e.g., Client A) to delete or update resources belonging to another client (Client B) within the same realm by supplying a valid resource ID. Affected product named by the advisory: Red Hat build of Keycloak 26.4.

CVE-2025-14777
Unclassified
Dec 16, 2025
Medium6.5Red Hat

Medium [CVE-2025-14512] integer overflow in glib gio attribute escaping causes heap buffer overflow

A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values. This vulnerability is rated Moderate for Red Hat products because an integer overflow in GLib's GIO `escape_byte_string()` function can lead to a heap buffer overflow and denial-of-service. This occurs when processing specially crafted file or remote filesystem attribute values, requiring an attacker to provide malicious input. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 16 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; and 12 more.

CVE-2025-14512
Unclassified
Dec 11, 2025
Medium5.6Red Hat

Medium [CVE-2025-14087] buffer underflow in gvariant parser leads to heap corruption

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; and 18 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; and 13 more.

CVE-2025-14087
Red Hat Enterprise Linux
Dec 10, 2025
Medium4.9Red Hat

Medium [CVE-2025-54770] Grub2: use-after-free in net_set_vlan

A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the net_set_vlan command is not properly unregistered when the network module is unloaded from memory. An attacker who can execute this command can force the system to access memory locations that are no longer valid. Successful exploitation leads directly to system instability, which can result in a complete crash and halt system availability This vulnerability has been rated as have the impact of Moderate by the Red Hat Product Security team. This decision was made based in the fact an attacker needs local or physical access to the machine, to execute the the net_set_vlan command after it was unloaded. Additionally the most likely outcome from an successful attack is a Denial of Service by leading the grub2 to crash. Red Hat severity: Moderate — CVSS 4.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: grub2.

CVE-2025-54770
Red Hat Enterprise Linux
Nov 18, 2025
Medium4.9Red Hat

Medium [CVE-2025-61664] Grub2: missing unregister call for normal_exit command may lead to use-after-free

A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacker can exploit this condition by invoking the command after the module has been removed, causing the system to improperly access a previously freed memory location. This leads to a system crash or possible impacts in data confidentiality and integrity. This vulnerability has been rated as have the impact of Moderate by the Red Hat Product Security team. This decision was made based in the fact an attacker needs local or physical access to the machine, to execute the normal_exit command after it was unloaded. Additionally the most likely outcome from an successful attack is a Denial of Crash by leading the grub2 to crash. Red Hat severity: Moderate — CVSS 4.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: grub2.

CVE-2025-61664
Red Hat Enterprise Linux
Nov 18, 2025
Medium4.9Red Hat

Medium [CVE-2025-61663] Grub2: missing unregister call for normal commands may lead to use-after-free

A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the normal command is not properly unregistered when the module is unloaded. An attacker who can execute this command can force the system to access memory locations that are no longer valid. Successful exploitation leads directly to system instability, which can result in a complete crash and halt system availability. Impact on the data integrity and confidentiality is also not discarded. This vulnerability has been rated as have the impact of Moderate by the Red Hat Product Security team. This decision was made based in the fact an attacker needs local or physical access to the machine, to execute the normal command after it was unloaded. Additionally the most likely outcome from an successful attack is a Denial of Crash by leading the grub2 to crash. Red Hat severity: Moderate — CVSS 4.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: grub2.

CVE-2025-61663
Red Hat Enterprise Linux
Nov 18, 2025
Medium4.8Red Hat

Medium [CVE-2025-61661] Grub2: grub2: out-of-bounds write via malicious usb device

A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootloader mishandles string conversion when reading information from a USB device, allowing an attacker to exploit inconsistent length values. A local attacker can connect a maliciously configured USB device during the boot sequence to trigger this issue. A successful exploitation may lead GRUB to crash, leading to a Denial of Service. Data corruption may be also possible, although given the complexity of the exploit the impact is most likely limited. This vulnerability was rated as having the impact of Moderate by the Red Hat Product Security Engineering team. To exploit this flaw the attacker needs to have physical access to the machine and connect a maliciously crafted USB device which will leverage the lack of string size validation to cause a out-of-bounds write when reading strings from it. Red Hat severity: Moderate — CVSS 4.8 (CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H). Weakness: CWE-131. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: grub2.

CVE-2025-61661
Red Hat Enterprise Linux
Nov 18, 2025
Medium4.9Red Hat

Medium [CVE-2025-54771] Grub2: use-after-free in grub_file_close

A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. An attacker could exploit this vulnerability to cause grub to crash, leading to a Denial of Service. Possible data integrity or confidentiality compromise is not discarded. This vulnerability has been rated as having a Moderate severity by the Red Hat Product Security Team. This classification is due to the needs of an attacker to have local access to the machine. Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: grub2.

CVE-2025-54771
Red Hat Enterprise Linux
Nov 18, 2025
Medium6.2Red Hat

Medium [CVE-2025-12464] Qemu-kvm: stack buffer overflow in e1000 device via short frames in loopback mode

A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to process a short frame in loopback mode. This could lead to a buffer overrun in the e1000_receive_iov() function via the loopback code path. A malicious guest user could use this vulnerability to crash the QEMU process on the host, resulting in a denial of service. This CVE is rated as Moderate because the vulnerability is confined to the loopback interface. Furthermore, even though e1000 is common for legacy Operating Systems, the device is generally discouraged in modern virtualization deployments (where virtio-net is recommended). Red Hat severity: Moderate — CVSS 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-121. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: qemu-kvm.

CVE-2025-12464
Red Hat Enterprise Linux
Oct 31, 2025
Medium5.0Red Hat

Medium [CVE-2025-12103] trusty ai grants all authenticated users to list pods in any namespace

A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a cluster permissions to get, list, watch any pod in any namespace on the cluster. TrustyAI is creating a role `trustyai-service-operator-lmeval-user-role` and a CRB `trustyai-service-operator-default-lmeval-user-rolebinding` which is being applied to `system:authenticated` making it so that every single user or service account can get a list of pods running in any namespace on the cluster Additionally users can access all `persistentvolumeclaims` and `lmevaljobs` Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.0; Red Hat OpenShift AI (RHOAI).

CVE-2025-12103
Unclassified
Oct 28, 2025

← All vendors