Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5245 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium6.5Linux

Medium [CVE-2026-45149] Denial of Service due to excessive memory allocation when expanding large numeric ranges

Denial of Service due to excessive memory allocation when expanding large numeric ranges. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected package(s): nodejs20-main, rust-main, llvm21-main, nodejs26-main, nodejs25-main, yarnpkg-main. Resolved in Red Hat advisory RHSA-2026:22380 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-45149
Unclassified
May 29, 2026
Critical9.8Vendor: HighLinux

Critical [CVE-2026-41565] Stack buffer overflow allows arbitrary code execution via a crafted authentication tag.

Stack buffer overflow allows arbitrary code execution via a crafted authentication tag.. Red Hat rates this important (CVSS 9.8). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41565
Unclassified
May 28, 2026
High7.5Linux

High [CVE-2026-45292] Denial of Service due to unbounded memory allocation when parsing oversized baggage

Denial of Service due to unbounded memory allocation when parsing oversized baggage. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): offline-knowledge-portal/rhokp-rhel9:1782239370. Resolved in Red Hat advisory RHSA-2026:28573 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Offline Knowledge Portal 1.2.7; Red Hat OpenShift Dev Spaces 3.29; OpenShift Serverless; Red Hat OpenShift AI (RHOAI); and 8 more.

CVE-2026-45292
Unclassified
May 28, 2026
High8.8Linux

High [CVE-2026-44477] Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE. Red Hat rates this important (CVSS 8.8). Weakness: CWE-250. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Openshift Data Foundation 4.

CVE-2026-44477
Unclassified
May 28, 2026
High7.4Linux

High [CVE-2026-48526] Authentication bypass due to forged JSON Web Tokens

Authentication bypass due to forged JSON Web Tokens. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. Affected package(s): ansible-automation-platform, quay/quay-rhel8:1782487717, python3.12-pyjwt, quay/quay-rhel8:1781878070, fence-agents, quay/quay-rhel8:1781937357. Resolved in Red Hat advisory RHSA-2026:35837 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; and 20 more.

CVE-2026-48526
Red Hat Enterprise Linux
May 28, 2026
High7.7Linux

High [CVE-2026-9804] VMExport directory symlink escape enables exporter pod file read

VMExport directory symlink escape enables exporter pod file read. Red Hat rates this important (CVSS 7.7). Weakness: CWE-59. Affected package(s): container-native-virtualization/virt-exportserver-rhel9:1781757410, container-native-virtualization/virt-exportserver-rhel9:1781590993, container-native-virtualization/virt-exportserver-rhel9:1781928221, container-native-virtualization/virt-exportserver-rhel9:1782012918, container-native-virtualization/virt-exportserver-rhel9:1781838712. Resolved in Red Hat advisory RHSA-2026:28002 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Container Native Virtualization 4.17; Red Hat Container Native Virtualization 4.18; Red Hat Container Native Virtualization 4.19; Red Hat Container Native Virtualization 4.20; and 2 more.

CVE-2026-9804
Unclassified
May 28, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-44604] Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command

Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command. Red Hat rates this moderate (CVSS 7). Weakness: CWE-78. Affected package(s): rpm-main. Resolved in Red Hat advisory RHSA-2026:28491 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-44604
Unclassified
May 28, 2026
High7.3Linux

High [CVE-2026-9795] Privilege escalation via improper scope mapping enforcement

Privilege escalation via improper scope mapping enforcement. Red Hat rates this important (CVSS 7.3). Weakness: CWE-266. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.6, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.4. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6.

CVE-2026-9795
Unclassified
May 28, 2026
High7.0Linux

High [CVE-2026-46116] defensively unhash xfrm_state lists in __xfrm_state_delete

defensively unhash xfrm_state lists in __xfrm_state_delete. Red Hat rates this important (CVSS 7). Weakness: CWE-763. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; and 7 more.

CVE-2026-46116
Red Hat Enterprise Linux
May 28, 2026
High7.0Linux

High [CVE-2026-46181] Fix mis-use of RCU in mlx4_srq_event()

Fix mis-use of RCU in mlx4_srq_event(). Red Hat rates this important (CVSS 7). Weakness: CWE-366. Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 6 more.

CVE-2026-46181
Red Hat Enterprise Linux
May 28, 2026
High7.0Linux

High [CVE-2026-46152] drop stray 'static' from fast-RX rx_result

drop stray 'static' from fast-RX rx_result. Red Hat rates this important (CVSS 7). Weakness: CWE-1058. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream E4S (v.9.4); Red Hat Enterprise Linux AppStream EUS (v.9.6); Red Hat Enterprise Linux AppStream (v. 9); and 23 more.

CVE-2026-46152
Red Hat Enterprise Linux
May 28, 2026
High7.0Linux

High [CVE-2026-46227] revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL

revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL. Red Hat rates this important (CVSS 7). Weakness: CWE-367. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:34094 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 6 more.

CVE-2026-46227
Red Hat Enterprise Linux
May 28, 2026
High7.0Linux

High [CVE-2026-46117] Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()

Remove user triggerable WARN_ON() in mana_ib_create_qp_rss(). Red Hat rates this important (CVSS 7). Weakness: CWE-1288. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:30129 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-46117
Red Hat Enterprise Linux
May 28, 2026
High7.0Linux

High [CVE-2026-46145] Validate rx_hash_key_len

Validate rx_hash_key_len. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-46145
Red Hat Enterprise Linux
May 28, 2026
High7.0Linux

High [CVE-2026-46189] Fix double free on pvrdma_alloc_ucontext() error path

Fix double free on pvrdma_alloc_ucontext() error path. Red Hat rates this important (CVSS 7). Weakness: CWE-1341. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:30848 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream E4S (v.9.2); Red Hat Enterprise Linux AppStream E4S (v.9.4); Red Hat Enterprise Linux AppStream EUS (v.9.6); and 34 more.

CVE-2026-46189
Red Hat Enterprise Linux
May 28, 2026
High7.0Linux

High [CVE-2026-46176] Fix error path fall-through in mlx5_ib_dev_res_srq_init()

Fix error path fall-through in mlx5_ib_dev_res_srq_init(). Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:34094 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.

CVE-2026-46176
Red Hat Enterprise Linux
May 28, 2026
High7.8Linux

High [CVE-2026-46215] Set old handle to NULL before prime swap in change_handle

Set old handle to NULL before prime swap in change_handle. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-46215
Unclassified
May 28, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-46173] prevent preemption of oopsing TASK_DEAD task

prevent preemption of oopsing TASK_DEAD task. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1341. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-46173
Unclassified
May 28, 2026
High7.1Vendor: MediumLinux

High [CVE-2026-46209] Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs()

Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs(). Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-190. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:34911 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-46209
Unclassified
May 28, 2026
High7.0Linux

High [CVE-2026-46166] use safe list iteration in radar detect work

use safe list iteration in radar detect work. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.

CVE-2026-46166
Red Hat Enterprise Linux
May 28, 2026

← All vendors