Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5196 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High8.2Linux

High [CVE-2026-7916] Insufficient data validation in InterestGroups

Insufficient data validation in InterestGroups. Red Hat rates this important (CVSS 8.2). Weakness: CWE-501. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7916
Unclassified
May 5, 2026
High8.0Linux

High [CVE-2026-7919] Use after free in Aura

Use after free in Aura. Red Hat rates this important (CVSS 8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7919
Unclassified
May 5, 2026
High8.2Linux

High [CVE-2026-7925] Use after free in Chromoting

Use after free in Chromoting. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7925
Unclassified
May 5, 2026
High8.0Linux

High [CVE-2026-7912] Integer overflow in GPU

Integer overflow in GPU. Red Hat rates this important (CVSS 8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7912
Unclassified
May 5, 2026
High8.8Linux

High [CVE-2026-7927] Type Confusion in Runtime

Type Confusion in Runtime. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7927
Unclassified
May 5, 2026
Medium6.1Linux

Medium [CVE-2026-34002] X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling

X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-805. Affected package(s): tigervnc, xorg-x11-server-Xwayland, xorg-x11-server. Resolved in Red Hat advisory RHSA-2026:24341 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 1; and 1 more.

CVE-2026-34002
Unclassified
May 5, 2026
Medium6.1Linux

Medium [CVE-2026-34000] X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.

X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected package(s): tigervnc, xorg-x11-server-Xwayland, xorg-x11-server. Resolved in Red Hat advisory RHSA-2026:24341 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 6; and 1 more.

CVE-2026-34000
Unclassified
May 5, 2026
Medium4.3Vendor: HighLinux

Medium [CVE-2026-7915] Insufficient data validation in DevTools

Insufficient data validation in DevTools. Red Hat rates this important (CVSS 4.3). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7915
Unclassified
May 5, 2026
Medium6.8Vendor: HighLinux

Medium [CVE-2026-7909] Inappropriate implementation in ServiceWorker

Inappropriate implementation in ServiceWorker. Red Hat rates this important (CVSS 6.8). Weakness: CWE-807. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7909
Unclassified
May 5, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-7904] Out of bounds read in Fonts

Out of bounds read in Fonts. Red Hat rates this important (CVSS 6.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7904
Unclassified
May 5, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-26332] Arbitrary code execution via SuppressedError sandbox escape

Arbitrary code execution via SuppressedError sandbox escape. Red Hat rates this important (CVSS 9.1). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-26332
Unclassified
May 4, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-24120] Arbitrary code execution due to sandbox escape vulnerability

Arbitrary code execution due to sandbox escape vulnerability. Red Hat rates this important (CVSS 9.1). Weakness: CWE-807. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-24120
Unclassified
May 4, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-24118] Arbitrary code execution due to sandbox breakout

Arbitrary code execution due to sandbox breakout. Red Hat rates this important (CVSS 9.1). Weakness: CWE-749. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-24118
Unclassified
May 4, 2026
Critical9.1Linux

Critical [CVE-2026-7482] Information disclosure via heap out-of-bounds read in GGUF model loader

Information disclosure via heap out-of-bounds read in GGUF model loader. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7482
Unclassified
May 4, 2026
High7.5Linux

High [CVE-2026-6321] Path traversal vulnerability allows bypass of security policies

Path traversal vulnerability allows bypass of security policies. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected package(s): odf4/odf-multicluster-rhel9-operator:1778577548, network-observability/network-observability-console-plugin-rhel9:1780556069, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9:1782840519, odf4/odf-cli-rhel9:1781557189, satellite/iop-advisor-frontend-rhel9:1781181673. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; Red Hat Discovery 2; and 15 more.

CVE-2026-6321
Red Hat Enterprise Linux
May 4, 2026
High7.5Linux

High [CVE-2026-42154] Denial of Service via uncontrolled memory allocation in remote read endpoint

Denial of Service via uncontrolled memory allocation in remote read endpoint. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): opentelemetry-collector, jaeger-main, rhacm2/prometheus-rhel9:1782374537, opentelemetry-collector-main, openshift-logging/logging-loki-rhel9:1782405469, opentelemetry-collector-contrib-main. Resolved in Red Hat advisory RHSA-2026:29770 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: RHEM 1.0 for RHEL 9; Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 9); Logging Subsystem for Red Hat OpenShift 6.4; and 31 more.

CVE-2026-42154
Red Hat Enterprise Linux
May 4, 2026
High7.5Linux

High [CVE-2026-42151] Information disclosure of Azure OAuth client secret via config API

Information disclosure of Azure OAuth client secret via config API. Red Hat rates this important (CVSS 7.5). Weakness: CWE-256. Affected package(s): opentelemetry-collector, opentelemetry-collector-contrib-main, jaeger-main, opentelemetry-collector-main. Resolved in Red Hat advisory RHSA-2026:25504 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: RHEM 1.0 for RHEL 9; Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 9); Red Hat Edge Manager 1.0; and 30 more.

CVE-2026-42151
Red Hat Enterprise Linux
May 4, 2026
High7.5Linux

High [CVE-2026-43964] buffer over-read via malformed enhanced status code

buffer over-read via malformed enhanced status code. Red Hat rates this important (CVSS 7.5). Weakness: CWE-193. Affected package(s): postfix. Resolved in Red Hat advisory RHSA-2026:25932 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-43964
Red Hat Enterprise Linux
May 4, 2026
High8.8Linux

High [CVE-2026-29004] Arbitrary Code Execution via DHCPv6 Client Heap Buffer Overflow

Arbitrary Code Execution via DHCPv6 Client Heap Buffer Overflow. Red Hat rates this important (CVSS 8.8). Weakness: CWE-131. Affected package(s): busybox-main. Resolved in Red Hat advisory RHSA-2026:30652 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-29004
Unclassified
May 4, 2026
High7.5Linux

High [CVE-2026-40682] XML External Entity (XXE) vulnerability via crafted dictionary parsing

XML External Entity (XXE) vulnerability via crafted dictionary parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-611. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40682
Unclassified
May 4, 2026

← All vendors