Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5208 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.1Linux

High [CVE-2026-32741] Heap buffer overflow vulnerability in image decoding

Heap buffer overflow vulnerability in image decoding. Red Hat rates this important (CVSS 7.1). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32741
Unclassified
May 19, 2026
High8.8Linux

High [CVE-2026-32740] Arbitrary code execution or denial of service via crafted HEIF/AVIF file

Arbitrary code execution or denial of service via crafted HEIF/AVIF file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32740
Unclassified
May 19, 2026
High7.5Linux

High [CVE-2026-8975] Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151

Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-8975
Red Hat Enterprise Linux
May 19, 2026
High7.5Linux

High [CVE-2026-8973] Memory safety bugs fixed in Firefox 151

Memory safety bugs fixed in Firefox 151. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8973
Unclassified
May 19, 2026
High7.5Linux

High [CVE-2026-8948] Same-origin policy bypass in the DOM: Networking component

Same-origin policy bypass in the DOM: Networking component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8948
Unclassified
May 19, 2026
High7.5Linux

High [CVE-2026-8947] Use-after-free in the DOM: Bindings (WebIDL) component

Use-after-free in the DOM: Bindings (WebIDL) component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-8947
Red Hat Enterprise Linux
May 19, 2026
High7.5Linux

High [CVE-2026-8946] Incorrect boundary conditions in the Audio/Video: Web Codecs component

Incorrect boundary conditions in the Audio/Video: Web Codecs component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-8946
Red Hat Enterprise Linux
May 19, 2026
High7.5Linux

High [CVE-2026-8945] Sandbox escape in Firefox and Firefox Focus for Android

Sandbox escape in Firefox and Firefox Focus for Android. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8945
Unclassified
May 19, 2026
High8.1Linux

High [CVE-2026-7504] Open redirect when using wildcard valid redirect URIs in Keycloak

Open redirect when using wildcard valid redirect URIs in Keycloak. Red Hat rates this important (CVSS 8.1). Weakness: CWE-601. Affected package(s): rhbk/keycloak-rhel9-operator, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-operator-bundle:26.2.16, rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9:26.2. Resolved in Red Hat advisory RHSA-2026:19594 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2.16; Red Hat build of Keycloak 26.4.12.

CVE-2026-7504
Unclassified
May 19, 2026
High7.5Linux

High [CVE-2026-7507] Session fixation in OIDC login flow that can lead to account takeover

Session fixation in OIDC login flow that can lead to account takeover. Red Hat rates this important (CVSS 7.5). Weakness: CWE-290. Affected package(s): rhbk/keycloak-rhel9-operator, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-operator-bundle:26.2.16, rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9:26.2. Resolved in Red Hat advisory RHSA-2026:19594 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2.16; Red Hat build of Keycloak 26.4.12.

CVE-2026-7507
Unclassified
May 19, 2026
High7.1Vendor: MediumLinux

High [CVE-2026-7571] Access token disclosure and implicit flow bypass via forged client data

Access token disclosure and implicit flow bypass via forged client data. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-472. Affected package(s): rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-rhel9-operator, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:19596 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7571
Unclassified
May 19, 2026
High7.5Linux

High [CVE-2026-7307] Denial of Service via specially crafted SAML input

Denial of Service via specially crafted SAML input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-operator-bundle:26.2.16, rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9:26.2. Resolved in Red Hat advisory RHSA-2026:19594 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.

CVE-2026-7307
Unclassified
May 19, 2026
High8.1Linux

High [CVE-2025-51427] Arbitrary code execution via crafted configuration module

Arbitrary code execution via crafted configuration module. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2025-51427
Unclassified
May 19, 2026
High8.8Linux

High [CVE-2026-31072] Remote Code Execution via Insecure Deserialization

Remote Code Execution via Insecure Deserialization. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31072
Unclassified
May 19, 2026
High7.4Linux

High [CVE-2026-9116] Insufficient policy enforcement in ServiceWorker

Insufficient policy enforcement in ServiceWorker. Red Hat rates this important (CVSS 7.4). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9116
Unclassified
May 19, 2026
High8.2Linux

High [CVE-2026-9117] Type Confusion in GFX

Type Confusion in GFX. Red Hat rates this important (CVSS 8.2). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9117
Unclassified
May 19, 2026
High8.8Linux

High [CVE-2026-9112] Use after free in GPU

Use after free in GPU. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9112
Unclassified
May 19, 2026
High8.1Linux

High [CVE-2026-9800] Authorization bypass via incorrect URI comparison

Authorization bypass via incorrect URI comparison. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1025. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.6, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.4. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6; Red Hat JBoss Enterprise Application Platform Expansion Pack.

CVE-2026-9800
Unclassified
May 19, 2026
High7.8Linux

High [CVE-2026-46323] Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs

Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs. Red Hat rates this important (CVSS 7.8). Weakness: CWE-123. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27708 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux for NVIDIA 26; and 4 more.

CVE-2026-46323
Red Hat Enterprise Linux
May 19, 2026
Medium4.6Linux

Medium [CVE-2026-9799] Unauthorized access to resources via UMA permission ticket bypass

Unauthorized access to resources via UMA permission ticket bypass. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-639. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.6, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.4. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9799
Unclassified
May 19, 2026

← All vendors