Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5197 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.5Linux

High [CVE-2026-8401] Sandbox escape in the Profile Backup component

Sandbox escape in the Profile Backup component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-8401
Red Hat Enterprise Linux
May 12, 2026
High7.5Linux

High [CVE-2026-42006] Denial of Service via excessive IMAP bracing

Denial of Service via excessive IMAP bracing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; and 7 more.

CVE-2026-42006
Red Hat Enterprise Linux
May 12, 2026
High7.4Linux

High [CVE-2026-27851] SQL/LDAP injection via incorrect safe filter interpretation with variable expansion

SQL/LDAP injection via incorrect safe filter interpretation with variable expansion. Red Hat rates this important (CVSS 7.4). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27851
Unclassified
May 12, 2026
High7.5Linux

High [CVE-2026-8391] Other issue in the JavaScript Engine component

Other issue in the JavaScript Engine component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-475. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-8391
Red Hat Enterprise Linux
May 12, 2026
High7.5Linux

High [CVE-2026-8390] Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8390
Unclassified
May 12, 2026
High7.5Linux

High [CVE-2026-8388] Incorrect boundary conditions in the JavaScript Engine: JIT component

Incorrect boundary conditions in the JavaScript Engine: JIT component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.

CVE-2026-8388
Red Hat Enterprise Linux
May 12, 2026
High8.8Linux

High [CVE-2026-31228] Adversarial Robustness Toolbox (ART) Kubeflow: Remote code execution via unsanitized user input

Adversarial Robustness Toolbox (ART) Kubeflow: Remote code execution via unsanitized user input. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-31228
Unclassified
May 12, 2026
High8.8Linux

High [CVE-2026-31230] Arbitrary Code Execution via Command-Line Argument Injection

Arbitrary Code Execution via Command-Line Argument Injection. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-31230
Unclassified
May 12, 2026
High7.3Linux

High [CVE-2026-31236] llm CLI tool: Arbitrary code execution via code injection in --functions argument

llm CLI tool: Arbitrary code execution via code injection in --functions argument. Red Hat rates this important (CVSS 7.3). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31236
Unclassified
May 12, 2026
Medium5.4Linux

Medium [CVE-2026-43515] Improper Authorization allows security bypass

Improper Authorization allows security bypass. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-551. Affected package(s): tomcat11-main. Resolved in Red Hat advisory RHSA-2026:13745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-43515
Unclassified
May 12, 2026
Medium6.5Linux

Medium [CVE-2026-43512] Authentication bypass via digest authentication

Authentication bypass via digest authentication. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-303. Affected package(s): tomcat10-main, tomcat11-main, devspaces/server-rhel9:1780694994. Resolved in Red Hat advisory RHSA-2026:25123 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-43512
Unclassified
May 12, 2026
Medium6.5Linux

Medium [CVE-2026-42498] Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.

Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201. Affected package(s): tomcat10-main, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:13745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-42498
Unclassified
May 12, 2026
Low3.7Linux

Low [CVE-2026-43514] Information disclosure via AJP secret timing discrepancy

Information disclosure via AJP secret timing discrepancy. Red Hat rates this low (CVSS 3.7). Weakness: CWE-208. Affected package(s): tomcat10-main, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:13745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-43514
Unclassified
May 12, 2026
High7.5Linux

High [CVE-2026-2614] Arbitrary file read via bypassed source path validation

Arbitrary file read via bypassed source path validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected package(s): rhoai/odh-th06-cuda130-torch210-py312-rhel9:1782136276, rhoai/odh-th06-cpu-torch210-py312-rhel9:1782135464, rhoai/odh-training-cuda128-torch29-py312-rhel9:1782132240, rhoai/odh-th06-rocm64-torch291-py312-rhel9:1782135346. Resolved in Red Hat advisory RHSA-2026:34456 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4; Red Hat OpenShift AI (RHOAI).

CVE-2026-2614
Unclassified
May 11, 2026
High8.0Linux

High [CVE-2026-4802] Arbitrary command execution via crafted links in system logs UI

Arbitrary command execution via crafted links in system logs UI. Red Hat rates this important (CVSS 8). Weakness: CWE-78. Affected package(s): cockpit. Resolved in Red Hat advisory RHSA-2026:21390 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; and 6 more.

CVE-2026-4802
Red Hat Enterprise Linux
May 11, 2026
High7.8Linux

High [CVE-2026-43500] "Dirty Frag" RxRPC variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel

"Dirty Frag" RxRPC variant is a new universal Local Privilege Escalation (LPE) vulnerability in the Linux kernel. Red Hat rates this important (CVSS 7.8). Weakness: CWE-123. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-43500
Unclassified
May 11, 2026
Medium5.5Linux

Medium [CVE-2026-43896] stack overflow in recursive object merge

stack overflow in recursive object merge. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-674. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-43896
Unclassified
May 11, 2026
Medium4.4Linux

Medium [CVE-2026-43895] embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts

embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-20. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-43895
Unclassified
May 11, 2026
Medium6.2Linux

Medium [CVE-2026-43894] Arbitrary Code Execution or Denial of Service via Signed Integer Overflow

Arbitrary Code Execution or Denial of Service via Signed Integer Overflow. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-190. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-43894
Unclassified
May 11, 2026
Medium5.5Linux

Medium [CVE-2026-41256] embedded NUL truncates top-level jq programs loaded with -f

embedded NUL truncates top-level jq programs loaded with -f. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-158. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41256
Unclassified
May 11, 2026

← All vendors