Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5199 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High8.2Linux

High [CVE-2026-41604] Out-of-bounds Read vulnerability

Out-of-bounds Read vulnerability. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 8 more.

CVE-2026-41604
Red Hat Enterprise Linux
Apr 28, 2026
High8.2Linux

High [CVE-2026-41603] Security Bypass via Improper Certificate Hostname Validation

Security Bypass via Improper Certificate Hostname Validation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-295. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439, rhosdt/tempo-query-rhel9:1778158343. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 7 more.

CVE-2026-41603
Red Hat Enterprise Linux
Apr 28, 2026
High7.5Linux

High [CVE-2026-41602] Integer Overflow in TFramedTransport Go implementation

Integer Overflow in TFramedTransport Go implementation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273, rhosdt/opentelemetry-collector-rhel9:1778056267, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, rhosdt/tempo-rhel9:1778158374, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.9.3; Red Hat AI Inference Server; and 8 more.

CVE-2026-41602
Unclassified
Apr 28, 2026
High7.5Linux

High [CVE-2025-48431] Apache Thrift c_glib: Denial of Service via specially crafted requests

Apache Thrift c_glib: Denial of Service via specially crafted requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-763. Affected package(s): cryostat/cryostat-storage-rhel9:4.2.0, rhosdt/tempo-rhel9:1781589494, rhacm2/acm-grafana-rhel9:1780926805, rhacm2/acm-grafana-rhel9:1780677003. Resolved in Red Hat advisory RHSA-2026:24539 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Cryostat 4 on RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat OpenShift distributed tracing 3.10.1; and 5 more.

CVE-2025-48431
Red Hat Enterprise Linux
Apr 28, 2026
High8.2Linux

High [CVE-2026-7353] Heap buffer overflow in Skia

Heap buffer overflow in Skia. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7353
Unclassified
Apr 28, 2026
High8.8Linux

High [CVE-2026-7348] Use after free in Codecs

Use after free in Codecs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7348
Unclassified
Apr 28, 2026
High8.7Linux

High [CVE-2026-7360] Insufficient validation of untrusted input in Compositing

Insufficient validation of untrusted input in Compositing. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1173. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7360
Unclassified
Apr 28, 2026
High8.8Linux

High [CVE-2026-7346] Inappropriate implementation in Tint

Inappropriate implementation in Tint. Red Hat rates this important (CVSS 8.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7346
Unclassified
Apr 28, 2026
High8.0Linux

High [CVE-2026-7345] Insufficient validation of untrusted input in Feedback

Insufficient validation of untrusted input in Feedback. Red Hat rates this important (CVSS 8). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7345
Unclassified
Apr 28, 2026
Medium6.5Linux

Medium [CVE-2026-6238] Application crash or uninitialized memory read via crafted DNS response

Application crash or uninitialized memory read via crafted DNS response. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1284. Affected package(s): glibc-main. Resolved in Red Hat advisory RHSA-2026:12740 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6238
Unclassified
Apr 28, 2026
Medium6.1Linux

Medium [CVE-2026-7321] Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-7321
Unclassified
Apr 28, 2026
Medium5.9Linux

Medium [CVE-2026-5435] Out-of-bounds write via TSIG record processing

Out-of-bounds write via TSIG record processing. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-120. Affected package(s): glibc-main. Resolved in Red Hat advisory RHSA-2026:12740 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5435
Unclassified
Apr 28, 2026
Medium5.9Linux

Medium [CVE-2026-40356] MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read

MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-191. Affected package(s): krb5-main, rhui5/haproxy-rhel9:1779798164, krb5, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791, rhui5/rhua-rhel9:1779798222. Resolved in Red Hat advisory RHSA-2026:12220 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-40356
Unclassified
Apr 28, 2026
Medium5.9Linux

Medium [CVE-2026-40355] Denial of Service via NULL pointer dereference in NegoEx mechanism

Denial of Service via NULL pointer dereference in NegoEx mechanism. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-476. Affected package(s): krb5-main, insights-proxy/insights-proxy-container-rhel9:1780420428, rhui5/haproxy-rhel9:1779798164, krb5, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:12220 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-40355
Unclassified
Apr 28, 2026
Medium5.5Vendor: HighLinux

Medium [CVE-2026-7351] Race in MHTML

Race in MHTML. Red Hat rates this important (CVSS 5.5). Weakness: CWE-368. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-7351
Unclassified
Apr 28, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-40976] Security bypass due to ineffective default web security

Security bypass due to ineffective default web security. Red Hat rates this important (CVSS 9.1). Weakness: CWE-305. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Data Grid 8.

CVE-2026-40976
Unclassified
Apr 27, 2026
Critical9.4Linux

Critical [CVE-2026-33454] Altered application behavior via header injection

Altered application behavior via header injection. Red Hat rates this critical (CVSS 9.4). Weakness: CWE-1173. Affected package(s): camel-mail. Resolved in Red Hat advisory RHSA-2026:19835 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3.

CVE-2026-33454
Unclassified
Apr 27, 2026
Critical9.8Vendor: LowLinux

Critical [CVE-2026-41635] Arbitrary code execution via classname allowlist bypass

Arbitrary code execution via classname allowlist bypass. Red Hat rates this low (CVSS 9.8). Weakness: CWE-502. Affected package(s): mina-core. Resolved in Red Hat advisory RHSA-2026:17668 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41635
Unclassified
Apr 27, 2026
Critical9.9Linux

Critical [CVE-2026-40453] Remote Code Execution and Arbitrary File Write via case-variant header injection

Remote Code Execution and Arbitrary File Write via case-variant header injection. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-178. Affected package(s): camel-http-starter, camel-google-pubsub, camel-http-common, camel-jms, camel-http-base, camel-http. Resolved in Red Hat advisory RHSA-2026:19835 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 4.14 for Quarkus 3.27; Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14; Red Hat build of Apache Camel 4 for Quarkus 3.

CVE-2026-40453
Unclassified
Apr 27, 2026
High8.2Linux

High [CVE-2026-40975] Weak pseudo-random number generation can lead to information disclosure.

Weak pseudo-random number generation can lead to information disclosure.. Red Hat rates this important (CVSS 8.2). Weakness: CWE-338. Affected package(s): devspaces/openvsx-rhel9:1779528224, spring-boot, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.28; Red Hat AMQ Clients; Red Hat build of OptaPlanner 8; Red Hat Fuse 7.

CVE-2026-40975
Unclassified
Apr 27, 2026

← All vendors