Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5245 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium6.8Vendor: HighLinux

Medium [CVE-2026-10977] Uninitialized Use in Skia

Uninitialized Use in Skia. Red Hat rates this important (CVSS 6.8). Weakness: CWE-824. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-10977
Unclassified
Jun 2, 2026
Medium6.8Vendor: HighLinux

Medium [CVE-2026-10938] Insufficient validation of untrusted input in Input

Insufficient validation of untrusted input in Input. Red Hat rates this important (CVSS 6.8). Weakness: CWE-501. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-10938
Unclassified
Jun 2, 2026
Medium5.5Linux

Medium [CVE-2026-50262] out-of-bounds read/write in GLX ChangeDrawableAttributes

out-of-bounds read/write in GLX ChangeDrawableAttributes. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected package(s): xorg-x11-server, xorg-x11-server-Xwayland, tigervnc. Resolved in Red Hat advisory RHSA-2026:26562 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-50262
Red Hat Enterprise Linux
Jun 2, 2026
Medium5.5Linux

Medium [CVE-2026-50263] use-after-free information disclosure in CreateSaverWindow()

use-after-free information disclosure in CreateSaverWindow(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-416. Affected package(s): xorg-x11-server, xorg-x11-server-Xwayland, tigervnc. Resolved in Red Hat advisory RHSA-2026:26562 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-50263
Red Hat Enterprise Linux
Jun 2, 2026
High8.3Linux

High [CVE-2024-52011] Arbitrary command execution via insufficient file argument sanitization

Arbitrary command execution via insufficient file argument sanitization. Red Hat rates this important (CVSS 8.3). Weakness: CWE-88. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539. Resolved in Red Hat advisory RHSA-2026:34342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2024-52011
Unclassified
Jun 1, 2026
High8.1Linux

High [CVE-2026-49121] AI Tensor Engine for ROCm (AITER): Remote Code Execution via Unauthenticated Pickle Deserialization

AI Tensor Engine for ROCm (AITER): Remote Code Execution via Unauthenticated Pickle Deserialization. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-49121
Red Hat Enterprise Linux
Jun 1, 2026
High7.8Vendor: MediumLinux

High [CVE-2026-43958] Stack buffer overflow allows local code execution or denial of service

Stack buffer overflow allows local code execution or denial of service. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-121. Affected package(s): rrdtool. Resolved in Red Hat advisory RHSA-2026:34155 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-43958
Unclassified
Jun 1, 2026
High7.5Linux

High [CVE-2026-44740] Denial of Service via crafted input due to insufficient validation

Denial of Service via crafted input due to insufficient validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-44740
Unclassified
Jun 1, 2026
High7.8Linux

High [CVE-2026-10118] Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication

Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, poppler, rhaiis/vllm-rocm-rhel9:1782353093, rhaiis/vllm-cuda-rhel9:1782352847, poppler-main. Resolved in Red Hat advisory RHSA-2026:29952 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 9 more.

CVE-2026-10118
Red Hat Enterprise Linux
Jun 1, 2026
High8.8Linux

High [CVE-2026-45505] Arbitrary Code Execution via crafted discovery URI bypass

Arbitrary Code Execution via crafted discovery URI bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-45505
Unclassified
Jun 1, 2026
High8.1Linux

High [CVE-2026-49157] Unauthorized Broker Management via Incorrect Default Permissions

Unauthorized Broker Management via Incorrect Default Permissions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-276. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-49157
Unclassified
Jun 1, 2026
High7.5Linux

High [CVE-2026-49270] Information disclosure via unauthenticated BrokerInfo command

Information disclosure via unauthenticated BrokerInfo command. Red Hat rates this important (CVSS 7.5). Weakness: CWE-306. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-49270
Unclassified
Jun 1, 2026
UnratedLinux Exploited CISA KEV

Unknown [CVE-2025-37849 +2] Kernel Live Patch Security Notice

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCPU data initialised. In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg->length/offset values, leading to _copy_to_iter() GPF/KASAN. It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container.)(CVE-2026-31431) Affected Ubuntu releases: 24.04, 22.04, 20.04, 18.04. Affected products named by the advisory: Ubuntu 24.04; Ubuntu 22.04; Ubuntu 20.04; Ubuntu 18.04.

CVE-2025-37849CVE-2026-23112CVE-2026-31431
Unclassified
Jun 1, 2026
High7.5Linux

High [CVE-2026-46385] CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration

CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): rhacm2/acm-grafana-rhel9:1782383730. Resolved in Red Hat advisory RHSA-2026:30651 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Hardened Images; Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat multicluster global hub 1.4.3; and 4 more.

CVE-2026-46385
Red Hat Enterprise Linux
May 29, 2026
High7.5Linux

High [CVE-2026-46384] Integer Overflow in Avro Decoder

Integer Overflow in Avro Decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): rhacm2/acm-grafana-rhel9:1782383730. Resolved in Red Hat advisory RHSA-2026:30651 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Hardened Images; Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat multicluster global hub 1.4.3; and 4 more.

CVE-2026-46384
Red Hat Enterprise Linux
May 29, 2026
High8.8Linux

High [CVE-2026-45700] Out-of-bounds write in planar bitmap decoder allows arbitrary code execution

Out-of-bounds write in planar bitmap decoder allows arbitrary code execution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 7 more.

CVE-2026-45700
Red Hat Enterprise Linux
May 29, 2026
High8.8Linux

High [CVE-2026-44420] Arbitrary code execution and denial of service via heap-buffer-overflow

Arbitrary code execution and denial of service via heap-buffer-overflow. Red Hat rates this important (CVSS 8.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-44420
Red Hat Enterprise Linux
May 29, 2026
High7.5Linux

High [CVE-2026-44422] Arbitrary code execution or denial of service via heap use-after-free in RDPEAR NDR parser

Arbitrary code execution or denial of service via heap use-after-free in RDPEAR NDR parser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2026-44422
Red Hat Enterprise Linux
May 29, 2026
High8.8Linux

High [CVE-2026-44421] Arbitrary code execution via crafted RDPGFX PDUs

Arbitrary code execution via crafted RDPGFX PDUs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-44421
Red Hat Enterprise Linux
May 29, 2026
High8.1Linux

High [CVE-2026-11800] org.keycloak:keycloak-services: Keycloak: Authentication bypass via JWT algorithm confusion

org.keycloak:keycloak-services: Keycloak: Authentication bypass via JWT algorithm confusion. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. Affected package(s): rhbk/keycloak-rhel9:26.6, rhbk/keycloak-operator-bundle:26.6.4, rhbk/keycloak-rhel9-operator:26.6. Resolved in Red Hat advisory RHSA-2026:30083 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat build of Keycloak 26.6.

CVE-2026-11800
Unclassified
May 29, 2026

← All vendors