Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3010 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.1Red Hat

High [CVE-2026-69112] Path Traversal and Denial of Service via weight_map

Path Traversal and Denial of Service via weight_map. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. Affected products named by the advisory: Lightspeed Core; OpenShift Lightspeed; Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-69112
Unclassified
Aug 10, 2026
High7.6Red Hat Updated

High [CVE-2026-18621] V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening

V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening. Red Hat rates this important (CVSS 7.6). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-ml-pipelines-api-server-v2-rhel9:1784924951, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785189934, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785187920. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18621
Unclassified
Aug 10, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-18620] User-controlled ServiceAccount for workflow pods without authorization check — confused deputy

User-controlled ServiceAccount for workflow pods without authorization check — confused deputy. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-ml-pipelines-api-server-v2-rhel9:1784924951, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785189934, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785187920. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.

CVE-2026-18620
Unclassified
Aug 10, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-18618] Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener

Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-mlmd-grpc-server-rhel9:1785260280, rhoai/odh-mlmd-grpc-server-rhel9:1785262015, rhoai/odh-mlmd-grpc-server-rhel9:1785269945. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.

CVE-2026-18618
Unclassified
Aug 10, 2026
High7.3Red Hat

High [CVE-2026-59091] multiple vulnerabilities in file format plugins via crafted image file

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further user interaction. It is triggered when a user opens a specially crafted image file, a common user action for image manipulation software. The local nature of the exploit is offset by the significant impact of potential system compromise or sensitive data exposure. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-59091
Red Hat Enterprise Linux
Aug 10, 2026
High8.8Red Hat

High [CVE-2026-18617] MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod

MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod. Red Hat rates this important (CVSS 8.8). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785189332, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1784833428, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785187936. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18617
Unclassified
Aug 10, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-18611] Cryptographically weak secret generation (math/rand) for DB and S3 credentials

Cryptographically weak secret generation (math/rand) for DB and S3 credentials. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-338. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785189332, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1784833428, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785187936. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.

CVE-2026-18611
Unclassified
Aug 10, 2026
High8.7Red Hat

High [CVE-2026-18608] Operator ClusterRole grants pods/exec:*, kubeflow.org */*, and ClusterRole/Binding CRUD cluster-wide

Operator ClusterRole grants pods/exec:*, kubeflow.org */*, and ClusterRole/Binding CRUD cluster-wide. Red Hat rates this important (CVSS 8.7). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785189332, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1784833428, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785187936. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.

CVE-2026-18608
Unclassified
Aug 10, 2026
High7.3Red Hat

High [CVE-2026-72718] Arbitrary command execution via malicious Git configuration in `goose review`

Arbitrary command execution via malicious Git configuration in `goose review`. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: goose.

CVE-2026-72718
Red Hat Enterprise Linux
Aug 10, 2026
High8.5Red Hat

High [CVE-2026-71576] Manager trusts self-asserted evt.Source for leaf-hub identity in all status handlers

Manager trusts self-asserted evt. Source() for leaf-hub identity in all status handlers. Red Hat rates this important (CVSS 8.5). Weakness: CWE-345.

CVE-2026-71576
Unclassified
Aug 10, 2026
High8.4Red Hat

High [CVE-2026-59090] arbitrary code execution in psd plugin due to unsigned underflow

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system. This is an Important severity flaw in the GIMP image manipulation program. This vulnerability primarily affects desktop environments where GIMP is installed and used to process untrusted image files. Red Hat severity: Important — CVSS 8.4 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H). Weakness: CWE-191. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-59090
Red Hat Enterprise Linux
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68415] clear mode callbacks after failed mode setup

clear mode callbacks after failed mode setup. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-68415
Unclassified
Aug 10, 2026
High7.0Red Hat

High [CVE-2026-68409] Use-after-free vulnerability in mac80211 Wi-Fi driver

Use-after-free vulnerability in mac80211 Wi-Fi driver. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.

CVE-2026-68409
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68404] use wiphy work for socket owner autodisconnect

use wiphy work for socket owner autodisconnect. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68404
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68402] Linux kernel: Wi-Fi subsystem out-of-bounds read via crafted frames

Linux kernel: Wi-Fi subsystem out-of-bounds read via crafted frames. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68402
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68401] Fix out-of-bound writes in ffa_setup_and_transmit

Fix out-of-bound writes in ffa_setup_and_transmit(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.

CVE-2026-68401
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68399] Fix UAF in sock clone early bailouts

Fix UAF in sock clone early bailouts. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel-rt.

CVE-2026-68399
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68398] Linux kernel: PPP over L2TP Use-After-Free vulnerability

Linux kernel: PPP over L2TP Use-After-Free vulnerability. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68398
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68397] take a reference on the socket found in afiucv_hs_rcv

take a reference on the socket found in afiucv_hs_rcv(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-68397
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68393] extend conn_hash lookup critical sections

extend conn_hash lookup critical sections. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-68393
Unclassified
Aug 10, 2026

← All vendors