Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

413 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-6301] Type Confusion in Turbofan

Type Confusion in Turbofan. Red Hat rates this important (CVSS 9.6). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6301
Unclassified
Apr 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-6316] Use after free in Forms

Use after free in Forms. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6316
Unclassified
Apr 15, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-6310] Use after free in Dawn

Use after free in Dawn. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6310
Unclassified
Apr 15, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-6359] Use after free in Video

Use after free in Video. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6359
Unclassified
Apr 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-6362] Use after free in Codecs

Use after free in Codecs. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6362
Unclassified
Apr 15, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-6304] Use after free in Graphite

Use after free in Graphite. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6304
Unclassified
Apr 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-6315] Use after free in Permissions

Use after free in Permissions. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6315
Unclassified
Apr 15, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-40175] Remote Code Execution via Prototype Pollution escalation

Remote Code Execution via Prototype Pollution escalation. Red Hat rates this important (CVSS 9). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-rhel9:1776149682, openshift-service-mesh/kiali-ossmc-rhel9:1776151134, rhtas/rhtas-console-rhel9:1776672801, devspaces/dashboard-rhel9:1776795511, openshift-service-mesh/kiali-ossmc-rhel8:1776202125, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Security for Kubernetes 4.9; and 39 more.

CVE-2026-40175
Unclassified
Apr 10, 2026
Critical10.0Red Hat

Critical [CVE-2026-5194] Reduced security of ECDSA authentication via missing digest size checks

Reduced security of ECDSA authentication via missing digest size checks. Red Hat rates this critical (CVSS 10). Weakness: CWE-295. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5194
Unclassified
Apr 9, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5874] Sandbox escape via use-after-free in PrivateAI

Sandbox escape via use-after-free in PrivateAI. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5874
Unclassified
Apr 8, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-27140] Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names

Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names. Red Hat rates this important (CVSS 9). Weakness: CWE-641. Affected package(s): openshift4/cloud-network-config-controller-rhel9:1780040126, openshift4/ose-agent-installer-utils-rhel9:1780044523, openshift4/ose-vsphere-csi-driver-rhel9-operator:1780040095, openshift4/ose-aws-cloud-controller-manager-rhel9:1780040386, openshift4/ose-aws-cluster-api-controllers-rhel9:1780040551, openshift4/ose-ironic-machine-os-downloader-rhel9:1780365576. Resolved in Red Hat advisory RHSA-2026:10704 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 12 more.

CVE-2026-27140
Unclassified
Apr 8, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-34078] Arbitrary code execution via crafted symlinks in sandbox-expose options

Arbitrary code execution via crafted symlinks in sandbox-expose options. Red Hat rates this important (CVSS 9). Weakness: CWE-59. Affected package(s): flatpak. Resolved in Red Hat advisory RHSA-2026:21757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-34078
Unclassified
Apr 7, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-34582] Client authentication bypass in TLS 1.3 implementation

Client authentication bypass in TLS 1.3 implementation. Red Hat rates this important (CVSS 9.1). Weakness: CWE-166. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-34582
Unclassified
Apr 7, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-34580] Certificate validation bypass due to incorrect certificate matching

Certificate validation bypass due to incorrect certificate matching. Red Hat rates this important (CVSS 9.1). Weakness: CWE-295. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-34580
Unclassified
Apr 7, 2026
Critical9.8Red Hat

Critical [CVE-2026-4631] Unauthenticated remote code execution due to SSH command-line argument injection

Unauthenticated remote code execution due to SSH command-line argument injection. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-78. Affected package(s): cockpit. Resolved in Red Hat advisory RHSA-2026:7383 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.

CVE-2026-4631
Unclassified
Apr 7, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5861] Use after free in V8

Use after free in V8. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5861
Unclassified
Apr 7, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5866] Use after free in Media

Use after free in Media. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5866
Unclassified
Apr 7, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5872] Use after free in Blink

Use after free in Blink. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5872
Unclassified
Apr 7, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5863] Inappropriate implementation in V8

Inappropriate implementation in V8. Red Hat rates this important (CVSS 9.6). Weakness: CWE-641. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5863
Unclassified
Apr 7, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-5870] Integer overflow in Skia

Integer overflow in Skia. Red Hat rates this important (CVSS 9.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5870
Unclassified
Apr 7, 2026

← All vendors