Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5243 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.5Linux

High [CVE-2026-46195] validate dacloffset before building DACL pointers

validate dacloffset before building DACL pointers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:21745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-46195
Red Hat Enterprise Linux
May 28, 2026
High7.1Vendor: MediumLinux

High [CVE-2026-46135] fix race between ICReq handling and queue teardown

fix race between ICReq handling and queue teardown. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-1341. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-46135
Unclassified
May 28, 2026
Medium5.0Linux

Medium [CVE-2026-42250] Denial of Service in bzip2recover via a specially crafted file

Denial of Service in bzip2recover via a specially crafted file. Red Hat rates this moderate (CVSS 5). Weakness: CWE-193. Affected package(s): bzip2-main. Resolved in Red Hat advisory RHSA-2026:30268 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-42250
Unclassified
May 28, 2026
Medium6.1Linux

Medium [CVE-2026-9673] CSV Injection vulnerability allows arbitrary code execution via `preventCsvInjection` bypass.

CSV Injection vulnerability allows arbitrary code execution via `preventCsvInjection` bypass.. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-1236. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9673
Unclassified
May 28, 2026
Medium4.9Linux

Medium [CVE-2026-9801] Denial of Service via malformed LDAP password policy response

Denial of Service via malformed LDAP password policy response. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-1284. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9801
Unclassified
May 28, 2026
Medium6.8Linux

Medium [CVE-2026-9802] Unauthorized account access via replayed refresh tokens after cluster restart

Unauthorized account access via replayed refresh tokens after cluster restart. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-613. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9802
Unclassified
May 28, 2026
Medium5.3Linux

Medium [CVE-2026-9803] Denial of Service via malformed Authorization header

Denial of Service via malformed Authorization header. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9803
Unclassified
May 28, 2026
Medium5.3Linux

Medium [CVE-2026-9794] Information disclosure via SAML ECP endpoint

Information disclosure via SAML ECP endpoint. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-209. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9794
Unclassified
May 28, 2026
Medium6.5Linux

Medium [CVE-2026-9792] Security restriction bypass allows unauthorized ROPC token acquisition

Security restriction bypass allows unauthorized ROPC token acquisition. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-280. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9792
Unclassified
May 28, 2026
Medium4.3Linux

Medium [CVE-2026-9791] Organization Data Leak After Feature Disabled in Keycloak

Organization Data Leak After Feature Disabled in Keycloak. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9791
Unclassified
May 28, 2026
Medium5.5Vendor: LowLinux

Medium [CVE-2026-44605] heap buffer overflow in NDB slot table parsing

heap buffer overflow in NDB slot table parsing. Red Hat rates this low (CVSS 5.5). Weakness: CWE-190. Affected package(s): rpm-main. Resolved in Red Hat advisory RHSA-2026:33507 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-44605
Unclassified
May 28, 2026
Medium6.8Vendor: HighLinux

Medium [CVE-2026-46125] remove station if connection prep fails

remove station if connection prep fails. Red Hat rates this important (CVSS 6.8). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 2 more.

CVE-2026-46125
Red Hat Enterprise Linux
May 28, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-9915] Heap buffer overflow in ANGLE

Heap buffer overflow in ANGLE. Red Hat rates this important (CVSS 9). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9915
Unclassified
May 27, 2026
Critical9.8Linux

Critical [CVE-2026-9887] Use after free in Proxy

Use after free in Proxy. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9887
Unclassified
May 27, 2026
Critical9.0Linux

Critical [CVE-2026-9885] Insufficient validation of untrusted input in UI

Insufficient validation of untrusted input in UI. Red Hat rates this critical (CVSS 9). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9885
Unclassified
May 27, 2026
Critical9.6Linux

Critical [CVE-2026-9875] Out of bounds read in WebGL

Out of bounds read in WebGL. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9875
Unclassified
May 27, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-9928] Out of bounds read in ANGLE

Out of bounds read in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9928
Unclassified
May 27, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-9970] Use after free in WebGL

Use after free in WebGL. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9970
Unclassified
May 27, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-9932] Use after free in ANGLE

Use after free in ANGLE. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9932
Unclassified
May 27, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-9904] Use after free in ANGLE

Use after free in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9904
Unclassified
May 27, 2026

← All vendors