Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium6.5Linux

Medium [CVE-2026-6429] Credential leak via reused proxy connection during HTTP redirects

Credential leak via reused proxy connection during HTTP redirects. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:12916 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6429
Unclassified
Apr 29, 2026
Medium6.6Linux

Medium [CVE-2026-42014] Use-after-free in gnutls_pkcs11_token_set_pin

Use-after-free in gnutls_pkcs11_token_set_pin. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-825. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 11 more.

CVE-2026-42014
Red Hat Enterprise Linux
Apr 29, 2026
Medium5.3Linux

Medium [CVE-2026-42015] Memory corruption due to off-by-one error in PKCS#12 bag handling

Memory corruption due to off-by-one error in PKCS#12 bag handling. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-193. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 11 more.

CVE-2026-42015
Red Hat Enterprise Linux
Apr 29, 2026
Low3.7Linux

Low [CVE-2026-6276] Information disclosure due to cookie leak when reusing connections with custom Host headers

Information disclosure due to cookie leak when reusing connections with custom Host headers. Red Hat rates this low (CVSS 3.7). Weakness: CWE-346. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:12916 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6276
Unclassified
Apr 29, 2026
Low3.7Linux

Low [CVE-2026-5419] Information disclosure via timing side-channel in PKCS#7 padding removal

Information disclosure via timing side-channel in PKCS#7 padding removal. Red Hat rates this low (CVSS 3.7). Weakness: CWE-208. Affected package(s): rhui5/haproxy-rhel9:1781525671, gnutls, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Discovery 2; and 4 more.

CVE-2026-5419
Red Hat Enterprise Linux
Apr 29, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-41607] Out-of-bounds Read vulnerability

Out-of-bounds Read vulnerability. Red Hat rates this important (CVSS 9.1). Weakness: CWE-125. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 8 more.

CVE-2026-41607
Red Hat Enterprise Linux
Apr 28, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-7358] Use after free in Animation

Use after free in Animation. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7358
Unclassified
Apr 28, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-7352] Use after free in Media

Use after free in Media. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7352
Unclassified
Apr 28, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-7363] Use after free in Canvas

Use after free in Canvas. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7363
Unclassified
Apr 28, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-7350] Use after free in WebMIDI

Use after free in WebMIDI. Red Hat rates this important (CVSS 9). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7350
Unclassified
Apr 28, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-7342] Use after free in WebView

Use after free in WebView. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7342
Unclassified
Apr 28, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-7333] Use after free in GPU

Use after free in GPU. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7333
Unclassified
Apr 28, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-7361] Use after free in iOS

Use after free in iOS. Red Hat rates this important (CVSS 9.6). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7361
Unclassified
Apr 28, 2026
Critical9.8Linux Exploited CISA KEV

Critical [CVE-2026-42208] Unauthorized data access and modification via SQL injection

Unauthorized data access and modification via SQL injection. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-42208
Unclassified
Apr 28, 2026
High7.5Linux

High [CVE-2026-7324] Memory safety bugs fixed in Firefox 150.0.1

Memory safety bugs fixed in Firefox 150.0.1. Red Hat rates this important (CVSS 7.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7324
Unclassified
Apr 28, 2026
High7.5Linux

High [CVE-2026-7323] Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1

Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1. Red Hat rates this important (CVSS 7.5). Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-7323
Red Hat Enterprise Linux
Apr 28, 2026
High8.8Linux

High [CVE-2026-7322] Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1

Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-7322
Red Hat Enterprise Linux
Apr 28, 2026
High7.5Linux

High [CVE-2026-7320] Information disclosure due to incorrect boundary conditions in the Audio/Video component

Information disclosure due to incorrect boundary conditions in the Audio/Video component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-7320
Red Hat Enterprise Linux
Apr 28, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-41636] Node.js skip() recursion

Node.js skip() recursion. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-776. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhacm2/acm-grafana-rhel9:1780677003. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41636
Unclassified
Apr 28, 2026
High7.5Linux

High [CVE-2026-41606] Denial of Service via uncontrolled recursion

Denial of Service via uncontrolled recursion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 8 more.

CVE-2026-41606
Red Hat Enterprise Linux
Apr 28, 2026

← All vendors