Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5197 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.9Linux

High [CVE-2026-43133] Always use vmcb01 in VMLOAD/VMSAVE emulation

Always use vmcb01 in VMLOAD/VMSAVE emulation. Red Hat rates this important (CVSS 7.9). Weakness: CWE-628. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-43133
Red Hat Enterprise Linux
May 6, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-43128] Fix double dma_buf_unpin in failure path

Fix double dma_buf_unpin in failure path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:19569 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-43128
Unclassified
May 6, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-43158] fix freemap adjustments when adding xattrs to leaf blocks

fix freemap adjustments when adding xattrs to leaf blocks. Red Hat rates this moderate (CVSS 7). Weakness: CWE-617. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-43158
Unclassified
May 6, 2026
High7.0Linux

High [CVE-2026-43125] validate length in dlm_search_rsb_tree

validate length in dlm_search_rsb_tree. Red Hat rates this important (CVSS 7). Weakness: CWE-130. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 4 more.

CVE-2026-43125
Red Hat Enterprise Linux
May 6, 2026
Medium6.3Linux

Medium [CVE-2026-6420] Security bypass due to hardcoded TPM quote nonce

Security bypass due to hardcoded TPM quote nonce. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-1241. Affected package(s): keylime. Resolved in Red Hat advisory RHSA-2026:28582 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-6420
Unclassified
May 6, 2026
Medium5.3Linux

Medium [CVE-2026-6860] Denial of Service via TLS handshake with wildcard server name

Denial of Service via TLS handshake with wildcard server name. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator, rhbk/keycloak-rhel9:26.6, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6860
Unclassified
May 6, 2026
Medium4.7Linux

Medium [CVE-2026-43163] fix GPF in write_page caused by resize race

fix GPF in write_page caused by resize race. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:21745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-43163
Unclassified
May 6, 2026
Medium6.7Linux

Medium [CVE-2026-43205] Linux kernel dpaa2-switch: Kernel memory corruption via out-of-bounds write

Linux kernel dpaa2-switch: Kernel memory corruption via out-of-bounds write. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-787. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:21557 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-43205
Unclassified
May 6, 2026
Medium5.8Linux

Medium [CVE-2026-43279] Add sanity check for OOB writes at silencing

Add sanity check for OOB writes at silencing. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-787. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-43279
Unclassified
May 6, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-7902] Out of bounds memory access in V8

Out of bounds memory access in V8. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7902
Unclassified
May 5, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-7908] Use after free in Fullscreen

Use after free in Fullscreen. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7908
Unclassified
May 5, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-7914] Type Confusion in Accessibility

Type Confusion in Accessibility. Red Hat rates this important (CVSS 9). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7914
Unclassified
May 5, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-7923] Out of bounds write in Skia

Out of bounds write in Skia. Red Hat rates this important (CVSS 9). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7923
Unclassified
May 5, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-7905] Insufficient validation of untrusted input in Media

Insufficient validation of untrusted input in Media. Red Hat rates this important (CVSS 9). Weakness: CWE-1289. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7905
Unclassified
May 5, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-7906] Use after free in SVG

Use after free in SVG. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7906
Unclassified
May 5, 2026
Critical9.8Linux

Critical [CVE-2026-7898] Use after free in Chromoting

Use after free in Chromoting. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7898
Unclassified
May 5, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-7922] Use after free in ServiceWorker

Use after free in ServiceWorker. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7922
Unclassified
May 5, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-7897] Use after free in Mobile

Use after free in Mobile. Red Hat rates this important (CVSS 9.6). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7897
Unclassified
May 5, 2026
High8.1Linux

High [CVE-2026-28780] Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow

Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Affected package(s): httpd, httpd:2.4, jbcs-httpd24-httpd. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: JBoss Core Services for RHEL 8; JBoss Core Services on RHEL 7; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-28780
Red Hat Enterprise Linux
May 5, 2026
High7.1Linux

High [CVE-2026-40110] Cross-Origin Resource Sharing (CORS) bypass via improper Origin header validation

Cross-Origin Resource Sharing (CORS) bypass via improper Origin header validation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-625. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat Migration Toolkit for Applications 8.2.

CVE-2026-40110
Unclassified
May 5, 2026

← All vendors