Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4426 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.0Vendor: MediumRed Hat

High [CVE-2026-97965] initialize _md in vxlan_xmit_one

initialize _md in vxlan_xmit_one(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-97965
Linux Kernel
Sep 25, 2026
High7.4Red Hat

High [CVE-2026-57178] Authentication bypass via missing signature verification in VK App backend

Authentication bypass via missing signature verification in VK App backend. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.

CVE-2026-57178
Unclassified
Sep 24, 2026
High7.1Red Hat

High [CVE-2026-67233] Privilege escalation allows monitoring users to delete shovels

Privilege escalation allows monitoring users to delete shovels. Red Hat rates this important (CVSS 7.1). Weakness: CWE-267. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-67233
Unclassified
Sep 24, 2026
High8.1Red Hat

High [CVE-2026-90959] file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and Pulp Container registry signing key theft

file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and Pulp Container registry signing key theft. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Satellite 6; Red Hat Update Infrastructure 5.

CVE-2026-90959
Unclassified
Sep 24, 2026
High7.5Red Hat

High [CVE-2026-97057] Denial of Service via invalid RESP protocol array length

Denial of Service via invalid RESP protocol array length. Red Hat rates this important (CVSS 7.5). Weakness: CWE-130. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Fuse 7; Red Hat Satellite 6; Self-service automation portal 2.

CVE-2026-97057
Unclassified
Sep 24, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-95521] shell command injection via macro expansion of source/spec file basenames when installing a source RPM

shell command injection via macro expansion of source/spec file basenames when installing a source RPM. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: rpm.

CVE-2026-95521
Red Hat Enterprise Linux
Sep 24, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-95519] Code Execution via Macro Expansion of Manifest Entries in `rpmgi` (`-q -p` / verify manifest flows)

Code Execution via Macro Expansion of Manifest Entries in `rpmgi` (`-q -p` / verify manifest flows). Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: rpm.

CVE-2026-95519
Red Hat Enterprise Linux
Sep 24, 2026
High7.8Red Hat Updated

High [CVE-2026-97185] out-of-bounds write in GIMPressionist plugin via crafted preset file

out-of-bounds write in GIMPressionist plugin via crafted preset file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:75575 with package gimp-2:3.0.4-4.el9_8.14. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-97185
Unclassified
Sep 24, 2026
High7.5Red Hat Updated

High [CVE-2026-97417] use get_unaligned_be32 in tcp_sack

use get_unaligned_be32() in tcp_sack(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:75746 with package kernel-rt-0:4.18.0-553.171.1.rt7.512.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-97417
Unclassified
Sep 24, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-93787] bound dirent name against end of SMB response in cifs_filldir

bound dirent name against end of SMB response in cifs_filldir. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-93787
Linux Kernel
Sep 24, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-93262] fix use-after-free in ppl_do_flush

fix use-after-free in ppl_do_flush(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-93262
Linux Kernel
Sep 24, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-93283] Fix device_register error path

Fix device_register() error path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-93283
Linux Kernel
Sep 24, 2026
High7.0Red Hat Updated

High [CVE-2026-93817] Fix addr_filter_ranges lifetime

Fix addr_filter_ranges lifetime. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-93817
Linux Kernel
Sep 24, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-93827] avoid double-free on failed queue setup

avoid double-free on failed queue setup. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.

CVE-2026-93827
Linux Kernel
Sep 24, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-93812] fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr

fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr. Red Hat rates this moderate (CVSS 7). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-93812
Linux Kernel
Sep 24, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-93800] fix use-after-free on reloc root after error in insert_dirty_subvol

fix use-after-free on reloc root after error in insert_dirty_subvol(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.

CVE-2026-93800
Linux Kernel
Sep 24, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-97415] validate names in ROOT_REF and ROOT_BACKREF

validate names in ROOT_REF and ROOT_BACKREF. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: kernel-rt.

CVE-2026-97415
Linux Kernel
Sep 24, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-97505] Add CAP_SYS_ADMIN check to __resource_resize_store

Add CAP_SYS_ADMIN check to __resource_resize_store(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-1220. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-97505
Linux Kernel
Sep 24, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-93813] validate INODE_REF's namelen

validate INODE_REF's namelen. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-93813
Linux Kernel
Sep 24, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-97422] fix SMI event cross-process information leak

fix SMI event cross-process information leak. Red Hat rates this moderate (CVSS 7). Weakness: CWE-201. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-97422
Linux Kernel
Sep 24, 2026

← All vendors