Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5208 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Critical10.0Linux

Critical [CVE-2026-45829] Arbitrary code execution via pre-authentication code injection

Arbitrary code execution via pre-authentication code injection. Red Hat rates this critical (CVSS 10). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux; python.

CVE-2026-45829
Unclassified
May 18, 2026
High8.0Linux

High [CVE-2026-25244] Remote Code Execution via command injection in Git branch name processing

Remote Code Execution via command injection in Git branch name processing. Red Hat rates this important (CVSS 8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-25244
Unclassified
May 18, 2026
Medium6.7Vendor: HighLinux

Medium [CVE-2026-46331] extend the writable skb range per key

extend the writable skb range per key. Red Hat rates this important (CVSS 6.7). Weakness: CWE-787. Affected package(s): kernel, rhcos, kernel-rt, kpatch-patch. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NVIDIA for RHEL 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 18 more.

CVE-2026-46331
Red Hat Enterprise Linux
May 18, 2026
Critical9.8Linux

Critical [CVE-2021-47952] Arbitrary Code Execution via Malicious JSON Deserialization

Arbitrary Code Execution via Malicious JSON Deserialization. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: python jsonpickle.

CVE-2021-47952
Unclassified
May 16, 2026
High8.3Linux

High [CVE-2026-44774] Privilege escalation via Kubernetes Gateway API provider configuration bypass

Privilege escalation via Kubernetes Gateway API provider configuration bypass. Red Hat rates this important (CVSS 8.3). Weakness: CWE-15. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.29.

CVE-2026-44774
Unclassified
May 15, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-46483] command injection when decompressing .tgz archives

command injection when decompressing.tgz archives. Red Hat rates this moderate (CVSS 7). Weakness: CWE-78. Affected package(s): vim. Resolved in Red Hat advisory RHSA-2026:28049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-46483
Unclassified
May 15, 2026
High7.5Linux

High [CVE-2026-45736] Uninitialized memory disclosure via `websocket.close()` with `TypedArray`

Uninitialized memory disclosure via `websocket.close()` with `TypedArray`. Red Hat rates this important (CVSS 7.5). Weakness: CWE-824. Affected package(s): dotnet8, ansible-automation-platform, rhdh/rhdh-hub-rhel9:1782761244, dotnet10, discovery/discovery-ui-rhel9:1782166952, dotnet9. Resolved in Red Hat advisory RHSA-2026:34374 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9; Red Hat Discovery 2; and 27 more.

CVE-2026-45736
Red Hat Enterprise Linux
May 15, 2026
High7.8Linux

High [CVE-2026-46333] Read root-owned files as an unprivileged user

Read root-owned files as an unprivileged user. Red Hat rates this important (CVSS 7.8). Weakness: CWE-269. Affected package(s): kernel, rhcos, kernel-rt, openshift, kpatch-patch, cri-o. Resolved in Red Hat advisory RHSA-2026:23470 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NVIDIA for RHEL 10; Red Hat OpenShift Container Platform 4.20; Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); and 55 more.

CVE-2026-46333
Red Hat Enterprise Linux
May 15, 2026
High7.0Linux

High [CVE-2025-54518] Privilege escalation via improper CPU cache isolation

Privilege escalation via improper CPU cache isolation. Red Hat rates this important (CVSS 7). Weakness: CWE-1220. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.

CVE-2025-54518
Red Hat Enterprise Linux
May 15, 2026
High8.2Linux

High [CVE-2026-34253] vorbis-tools ogg123: Arbitrary code execution via buffer underflow in remote control functionality

vorbis-tools ogg123: Arbitrary code execution via buffer underflow in remote control functionality. Red Hat rates this important (CVSS 8.2). Weakness: CWE-124. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34253
Unclassified
May 15, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-42327] Arbitrary code execution via specially crafted certificate

Arbitrary code execution via specially crafted certificate. Red Hat rates this important (CVSS 9.1). Weakness: CWE-475. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-42327
Unclassified
May 14, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-8554] Type Confusion in ANGLE

Type Confusion in ANGLE. Red Hat rates this important (CVSS 9). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8554
Unclassified
May 14, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-8548] Out of bounds write in Media

Out of bounds write in Media. Red Hat rates this important (CVSS 9). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8548
Unclassified
May 14, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-8547] Insufficient policy enforcement in Passwords

Insufficient policy enforcement in Passwords. Red Hat rates this important (CVSS 9). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8547
Unclassified
May 14, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-8534] Integer overflow in GPU

Integer overflow in GPU. Red Hat rates this important (CVSS 9). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8534
Unclassified
May 14, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-8533] Use after free in Accessibility

Use after free in Accessibility. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8533
Unclassified
May 14, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-8531] Heap buffer overflow in WebML

Heap buffer overflow in WebML. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8531
Unclassified
May 14, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-8525] Heap buffer overflow in ANGLE

Heap buffer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8525
Unclassified
May 14, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-8526] Out of bounds write in WebRTC

Out of bounds write in WebRTC. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8526
Unclassified
May 14, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-8524] Out of bounds write in WebAudio

Out of bounds write in WebAudio. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8524
Unclassified
May 14, 2026

← All vendors