Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5196 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.5Linux

High [CVE-2026-42027] Arbitrary Class Loading via Model Manifest

Arbitrary Class Loading via Model Manifest. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI).

CVE-2026-42027
Unclassified
May 4, 2026
High7.5Linux

High [CVE-2026-42440] Denial of Service via unbounded array allocation in crafted model files

Denial of Service via unbounded array allocation in crafted model files. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform Expansion Pack.

CVE-2026-42440
Unclassified
May 4, 2026
High8.1Linux

High [CVE-2026-24781] Arbitrary code execution via sandbox breakout through inspect function

Arbitrary code execution via sandbox breakout through inspect function. Red Hat rates this important (CVSS 8.1). Weakness: CWE-653. Affected package(s): rhdh/rhdh-hub-rhel9:1781187342. Resolved in Red Hat advisory RHSA-2026:26234 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9.

CVE-2026-24781
Unclassified
May 4, 2026
High7.5Vendor: LowLinux

High [CVE-2026-29169] NULL pointer dereference via specially crafted request

NULL pointer dereference via specially crafted request. Red Hat rates this low (CVSS 7.5). Weakness: CWE-476. Affected package(s): jbcs-httpd24-httpd, httpd, httpd-main, mod_dav_lock.so. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-29169
Unclassified
May 4, 2026
High8.8Linux

High [CVE-2026-23918] Remote Code Execution via Double Free in HTTP/2 Protocol

Remote Code Execution via Double Free in HTTP/2 Protocol. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1341. Affected package(s): httpd-main. Resolved in Red Hat advisory RHSA-2026:13938 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-23918
Unclassified
May 4, 2026
High8.3Linux

High [CVE-2026-6266] Account hijacking and unauthorized access via unverified email linking

Account hijacking and unauthorized access via unverified email linking. Red Hat rates this important (CVSS 8.3). Weakness: CWE-305. Affected package(s): automation-gateway, automation-controller, python3.12-django-ansible-base, ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:13508 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9.

CVE-2026-6266
Red Hat Enterprise Linux
May 4, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-33857] off-by-one out-of-bounds reads in AJP getter functions

off-by-one out-of-bounds reads in AJP getter functions. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-125. Affected package(s): httpd, httpd:2.4, jbcs-httpd24-httpd, httpd-main, mod_proxy_ajp.so. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-33857
Unclassified
May 4, 2026
High8.2Vendor: MediumLinux

High [CVE-2026-34032] heap-based buffer over-read due to missing null-termination check

heap-based buffer over-read due to missing null-termination check. Red Hat rates this moderate (CVSS 8.2). Weakness: CWE-170. Affected package(s): httpd, httpd:2.4, jbcs-httpd24-httpd, httpd-main, mod_proxy_ajp.so. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-34032
Unclassified
May 4, 2026
High8.2Vendor: MediumLinux

High [CVE-2026-34059] heap-based buffer over-read and memory disclosure in ajp_parse_data()

heap-based buffer over-read and memory disclosure in ajp_parse_data(). Red Hat rates this moderate (CVSS 8.2). Weakness: CWE-126. Affected package(s): httpd, httpd:2.4, jbcs-httpd24-httpd, httpd-main, mod_proxy_ajp.so. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-34059
Unclassified
May 4, 2026
High7.5Linux

High [CVE-2026-33846] Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly

Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly. Red Hat rates this important (CVSS 7.5). Weakness: CWE-130. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 37 more.

CVE-2026-33846
Red Hat Enterprise Linux
May 4, 2026
High7.5Linux

High [CVE-2026-7737] osrg GoBGP: Denial of service via out-of-bounds read in BMP Parser

osrg GoBGP: Denial of service via out-of-bounds read in BMP Parser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7737
Unclassified
May 4, 2026
High7.5Linux

High [CVE-2026-7736] osrg GoBGP: Integer underflow via manipulation in parseRibEntry function

osrg GoBGP: Integer underflow via manipulation in parseRibEntry function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7736
Unclassified
May 4, 2026
High8.2Linux

High [CVE-2026-39852] io.quarkus:quarkus-vertx-http: io.quarkus:quarkus-vertx-http: Authorization bypass via semicolons in HTTP requests

io.quarkus:quarkus-vertx-http: io.quarkus:quarkus-vertx-http: Authorization bypass via semicolons in HTTP requests. Red Hat rates this important (CVSS 8.2). Weakness: CWE-551. Affected package(s): cryostat/jfr-datasource-rhel9:4.2.0, quarkus-vertx-http, cryostat/cryostat-reports-rhel9:4.2.0, cryostat/cryostat-rhel9:4.2.0. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Build of Apache Camel 4.14 for Quarkus 3.27; Red Hat build of Quarkus 3.20.6.SP1; OpenShift Serverless; and 7 more.

CVE-2026-39852
Red Hat Enterprise Linux
May 4, 2026
High7.5Linux

High [CVE-2025-70069] Denial of Service via FBXConverter.cpp and ConvertMeshMultiMaterial() method

Denial of Service via FBXConverter.cpp and ConvertMeshMultiMaterial() method. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2025-70069
Unclassified
May 4, 2026
High7.5Linux

High [CVE-2025-70071] Denial of Service via FBXParser.cpp ParseVectorDataArray() function

Denial of Service via FBXParser.cpp ParseVectorDataArray() function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2025-70071
Unclassified
May 4, 2026
High7.5Linux

High [CVE-2026-37459] denial of service via crafted BGP UPDATE message

denial of service via crafted BGP UPDATE message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Affected package(s): frr10, frr. Resolved in Red Hat advisory RHSA-2026:24370 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-37459
Red Hat Enterprise Linux
May 4, 2026
High7.8Linux

High [CVE-2026-54228] TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories

TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories. Red Hat rates this important (CVSS 7.8). Weakness: CWE-367. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 3 more.

CVE-2026-54228
Red Hat Enterprise Linux
May 4, 2026
High7.0Linux

High [CVE-2026-54229] ChownProblemDir succeeds during active post-create event processing due to inadequate locking

ChownProblemDir succeeds during active post-create event processing due to inadequate locking. Red Hat rates this important (CVSS 7). Weakness: CWE-362. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 3 more.

CVE-2026-54229
Red Hat Enterprise Linux
May 4, 2026
High7.0Linux

High [CVE-2026-54230] event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites

event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites. Red Hat rates this important (CVSS 7). Weakness: CWE-59. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.

CVE-2026-54230
Red Hat Enterprise Linux
May 4, 2026
Medium4.8Linux

Medium [CVE-2026-33006] timing attack allows a bypass of digest authentication

timing attack allows a bypass of digest authentication. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-208. Affected package(s): httpd-main. Resolved in Red Hat advisory RHSA-2026:17080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33006
Unclassified
May 4, 2026

← All vendors