Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5506 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium6.2Linux

Medium [CVE-2026-68562] Information disclosure via Leapp report tampering

Information disclosure via Leapp report tampering. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-610.

CVE-2026-68562
Unclassified
Jul 30, 2026
Medium5.7Linux Updated

Medium [CVE-2026-67550] Denial of Service via out-of-bounds read

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an out-of-bounds heap read and an uncatchable process crash, with limited heap information disclosure in some cases. This issue is fixed in 1.25.2. An attacker can exploit a vulnerability by manipulating the `lastIndex` parameter with a non-ASCII input. This manipulation can lead to an out-of-bounds heap read, causing the process to crash, which results in a Denial of Service (DoS). This flaw primarily impacts Availability with low Confidentiality impact and zero effect on Integrity (C:L, I:N, A:H). Practically, this leads to an uncatchable process crash (Denial of Service) via an out-of-bounds heap read, though minor heap memory exposure is theoretically possible. High Attack Complexity (AC:H) is assessed because the targeted Node.js application must explicitly maintain and expose stateful regex objects with attacker-controlled `lastIndex` properties across non-ASCII strings. Applications using stateless regex execution or not accepting external input into `lastIndex` are unaffected.

CVE-2026-67550
Red Hat Enterprise Linux
Jul 30, 2026
Medium5.9Linux

Medium [CVE-2026-12996] Denial of Service or memory leak via crafted packets

Denial of Service or memory leak via crafted packets. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-825.

CVE-2026-12996
Unclassified
Jul 30, 2026
Medium5.3Linux

Medium [CVE-2026-11771] Denial of Service via crafted NTLM proxy response

Denial of Service via crafted NTLM proxy response. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-787.

CVE-2026-11771
Unclassified
Jul 30, 2026
Medium5.9Linux

Medium [CVE-2026-13117] Denial of service or memory leakage via incomplete TLS guard

Denial of service or memory leakage via incomplete TLS guard. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-825.

CVE-2026-13117
Unclassified
Jul 30, 2026
Medium5.5Linux Updated

Medium [CVE-2026-7260] Denial of Service via circular symbolic links in phar archives

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9. A flaw was found in PHP. When processing a specially crafted PHP Archive (phar) file containing circular symbolic links, the PHP process can enter an uncontrolled loop. This unbounded recursion exhausts the program's memory stack, causing the PHP application to crash. This vulnerability could allow an attacker to trigger a Denial of Service (DoS) condition, making the affected PHP service unavailable. This Moderate impact flaw in PHP allows a local attacker to trigger a denial of service by providing a specially crafted phar archive containing circular symbolic links. Successful exploitation exhausts the C stack, leading to a PHP process crash, which can disrupt services utilizing PHP for archive processing. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-606. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces. Red Hat fixing advisory: RHSA-2026:47200.

CVE-2026-7260
Red Hat Enterprise Linux
Jul 30, 2026
Medium5.8Linux

Medium [CVE-2026-18369] ACME HTTP-01 validation SSRF via IP literal identifiers and unvalidated redirects

ACME HTTP-01 validation SSRF via IP literal identifiers and unvalidated redirects. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-918.

CVE-2026-18369
Unclassified
Jul 30, 2026
Medium4.1Linux

Medium [CVE-2026-56850] mTLS client identities can be reused due to HTTPS Agent connection flaw

mTLS client identities can be reused due to HTTPS Agent connection flaw. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-56850
Unclassified
Jul 30, 2026
Medium6.3Linux Updated

Medium [CVE-2026-58040] HTTPS Agent TLS session reuse skips hostname verification

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. A flaw was found in Node.js. An incomplete fix for a previous vulnerability allows the HTTPS Agent to reuse Transport Layer Security (TLS) sessions, bypassing hostname verification across different identity policies. This could enable an attacker to impersonate a legitimate server, leading to information disclosure or other security breaches. This issue is rated Moderate (CVSS 6.3) because successful exploitation allows session-hijacking and information disclosure without affecting system integrity or availability (C:H, I:N, A:N). The flaw occurs when an HTTPS Agent reuses an existing TLS session across requests with differing identity policies, skipping host verification. An attacker must already sit in a privileged network position (AV:N/AC:H) to perform a man-in-the-middle attack and intercept traffic intended for a distinct target on the same TLS session. Applications that explicitly configure unique HTTPS agents per target host, avoid TLS session caching, or do not make outbound HTTPS requests to varied third-party endpoints using shared client instances are not at risk.

CVE-2026-58040
Red Hat Enterprise Linux
Jul 30, 2026
Medium5.3Linux

Medium [CVE-2026-16531] Arbitrary file creation via path traversal in pmproxy logger servlet

Arbitrary file creation via path traversal in pmproxy logger servlet. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22.

CVE-2026-16531
Unclassified
Jul 30, 2026
Medium6.5Linux

Medium [CVE-2026-16530] Remote denial of service and information leakage

Remote denial of service and information leakage. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125.

CVE-2026-16530
Unclassified
Jul 30, 2026
Medium4.3Vendor: LowLinux

Medium [CVE-2026-18019] Side-channel information leakage in Media

Side-channel information leakage in Media. Red Hat rates this low (CVSS 4.3). Weakness: CWE-205.

CVE-2026-18019
Unclassified
Jul 30, 2026
Medium4.3Vendor: LowLinux

Medium [CVE-2026-18015] Inappropriate implementation in Tint

Inappropriate implementation in Tint. Red Hat rates this low (CVSS 4.3). Weakness: CWE-653.

CVE-2026-18015
Unclassified
Jul 30, 2026
Medium4.3Vendor: LowLinux

Medium [CVE-2026-18017] Use after free in Dawn

Use after free in Dawn. Red Hat rates this low (CVSS 4.3).

CVE-2026-18017
Unclassified
Jul 30, 2026
Medium4.3Vendor: LowLinux

Medium [CVE-2026-18012] Use after free in PDFium

Use after free in PDFium. Red Hat rates this low (CVSS 4.3). Weakness: CWE-825.

CVE-2026-18012
Unclassified
Jul 30, 2026
Medium4.3Vendor: LowLinux

Medium [CVE-2026-18008] Inappropriate implementation in Settings

Inappropriate implementation in Settings. Red Hat rates this low (CVSS 4.3). Weakness: CWE-1021.

CVE-2026-18008
Unclassified
Jul 30, 2026
Medium4.3Vendor: LowLinux

Medium [CVE-2026-18009] Insufficient validation of untrusted input in Passwords

Insufficient validation of untrusted input in Passwords. Red Hat rates this low (CVSS 4.3). Weakness: CWE-290.

CVE-2026-18009
Unclassified
Jul 30, 2026
Medium4.3Vendor: LowLinux

Medium [CVE-2026-18005] Inappropriate implementation in WebXR

Inappropriate implementation in WebXR. Red Hat rates this low (CVSS 4.3). Weakness: CWE-825.

CVE-2026-18005
Unclassified
Jul 30, 2026
Medium5.0Vendor: LowLinux

Medium [CVE-2026-18002] Insufficient validation of untrusted input in Google Lens

Insufficient validation of untrusted input in Google Lens. Red Hat rates this low (CVSS 5). Weakness: CWE-1289.

CVE-2026-18002
Unclassified
Jul 30, 2026
Medium4.3Vendor: LowLinux

Medium [CVE-2026-17999] Incorrect security UI in PictureInPicture

Incorrect security UI in PictureInPicture. Red Hat rates this low (CVSS 4.3). Weakness: CWE-368.

CVE-2026-17999
Unclassified
Jul 30, 2026

← All vendors