Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5193 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.3Vendor: MediumLinux

High [CVE-2026-41411] Command injection allows arbitrary code execution via malicious tag files

Command injection allows arbitrary code execution via malicious tag files. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-78. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1782890503, vim, discovery/discovery-ui-rhel9:1782756541. Resolved in Red Hat advisory RHSA-2026:28049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-41411
Unclassified
Apr 24, 2026
High8.8Linux

High [CVE-2026-40897] Arbitrary code execution via expression parser

Arbitrary code execution via expression parser. Red Hat rates this important (CVSS 8.8). Weakness: CWE-917. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40897
Unclassified
Apr 24, 2026
High7.2Linux

High [CVE-2026-41044] Arbitrary code execution via improper input validation in admin console

Arbitrary code execution via improper input validation in admin console. Red Hat rates this important (CVSS 7.2). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform 7.

CVE-2026-41044
Unclassified
Apr 24, 2026
High8.8Linux

High [CVE-2026-40466] Arbitrary code execution via improper input validation in HTTP Discovery transport

Arbitrary code execution via improper input validation in HTTP Discovery transport. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform 7.

CVE-2026-40466
Unclassified
Apr 24, 2026
High7.5Linux

High [CVE-2026-21728] Denial of Service via large queries

Denial of Service via large queries. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779212259, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 9; Red Hat OpenShift distributed tracing 3; and 2 more.

CVE-2026-21728
Unclassified
Apr 24, 2026
High8.1Linux

High [CVE-2026-41316] Arbitrary code execution via deserialization bypass

Arbitrary code execution via deserialization bypass. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. Affected package(s): ruby, ruby4.0, ruby:3.3, ruby:4.0. Resolved in Red Hat advisory RHSA-2026:20614 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 3 more.

CVE-2026-41316
Red Hat Enterprise Linux
Apr 24, 2026
High7.0Linux

High [CVE-2026-31663] hold dev ref until after transport_finish NF_HOOK

hold dev ref until after transport_finish NF_HOOK. Red Hat rates this important (CVSS 7). Weakness: CWE-826. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-31663
Red Hat Enterprise Linux
Apr 24, 2026
High7.1Vendor: MediumLinux

High [CVE-2026-31636] fix RESPONSE authenticator parser OOB read

fix RESPONSE authenticator parser OOB read. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-805. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:30129 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-31636
Unclassified
Apr 24, 2026
High7.3Linux

High [CVE-2026-31641] Fix RxGK token loading to check bounds

Fix RxGK token loading to check bounds. Red Hat rates this important (CVSS 7.3). Weakness: CWE-190. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-31641
Red Hat Enterprise Linux
Apr 24, 2026
High7.0Linux

High [CVE-2026-31617] validate minimum block_len in ncm_unwrap_ntb()

validate minimum block_len in ncm_unwrap_ntb(). Red Hat rates this important (CVSS 7). Weakness: CWE-191. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-31617
Red Hat Enterprise Linux
Apr 24, 2026
High7.1Vendor: MediumLinux

High [CVE-2026-31613] fix OOB reads parsing symlink error response

fix OOB reads parsing symlink error response. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-125. Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-31613
Unclassified
Apr 24, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-31669] fix slab-use-after-free in __inet_lookup_established

fix slab-use-after-free in __inet_lookup_established. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-763. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-31669
Unclassified
Apr 24, 2026
High7.3Linux

High [CVE-2026-31607] validate number_of_packets in usbip_pack_ret_submit()

validate number_of_packets in usbip_pack_ret_submit(). Red Hat rates this important (CVSS 7.3). Weakness: CWE-805. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:19569 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 9.6 Extended Update Support.

CVE-2026-31607
Red Hat Enterprise Linux
Apr 24, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-41481] Information Disclosure via Server-Side Request Forgery (SSRF) Redirect Bypass

Information Disclosure via Server-Side Request Forgery (SSRF) Redirect Bypass. Red Hat rates this important (CVSS 6.5). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI).

CVE-2026-41481
Unclassified
Apr 24, 2026
Medium6.3Linux

Medium [CVE-2026-31581] fix use-after-free on disconnect

fix use-after-free on disconnect. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-31581
Unclassified
Apr 24, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-6921] Race in GPU

Race in GPU. Red Hat rates this important (CVSS 9.6). Weakness: CWE-368. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6921
Unclassified
Apr 23, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-6920] Out of bounds read in GPU

Out of bounds read in GPU. Red Hat rates this important (CVSS 9). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6920
Unclassified
Apr 23, 2026
Critical9.8Vendor: HighLinux

Critical [CVE-2026-41179] Unauthenticated local command execution via exposed RC endpoint

Unauthenticated local command execution via exposed RC endpoint. Red Hat rates this important (CVSS 9.8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41179
Unclassified
Apr 23, 2026
High8.1Linux

High [CVE-2026-41246] Arbitrary Code Execution and Denial of Service via Lua Code Injection

Arbitrary Code Execution and Denial of Service via Lua Code Injection. Red Hat rates this important (CVSS 8.1). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41246
Unclassified
Apr 23, 2026
High7.7Linux

High [CVE-2026-40886] Denial of Service via malformed workflow pod annotation

Denial of Service via malformed workflow pod annotation. Red Hat rates this important (CVSS 7.7). Weakness: CWE-1285. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40886
Unclassified
Apr 23, 2026

← All vendors