Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

2989 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.1Red Hat Updated

Medium [CVE-2026-74960] Site isolation issue in the WebExtensions component

Site isolation issue in the WebExtensions component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-74960
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74959] Mitigation bypass in the Storage: Cache API component

Mitigation bypass in the Storage: Cache API component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-807. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: thunderbird.

CVE-2026-74959
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74962] Site isolation issue in the Networking: Cookies component

Site isolation issue in the Networking: Cookies component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-1100. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-74962
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74953] Privilege escalation in the Networking: Cookies component

Privilege escalation in the Networking: Cookies component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-472. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-74953
Red Hat Enterprise Linux
Aug 18, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-19608] Name-only group claims let same-name groups satisfy path-specific group policies

Name-only group claims let same-name groups satisfy path-specific group policies. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-285. Affected product named by the advisory: Red Hat Build of Keycloak.

CVE-2026-19608
Unclassified
Aug 18, 2026
Medium6.8Red Hat

Medium [CVE-2026-61308] Enhance HTTP Connections (2026-08 Security Update)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N). Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N). Affected products named by the advisory: Red Hat Build of OpenJDK 17.0.20.1; Red Hat Build of OpenJDK 21.0.12.1; Red Hat Build of OpenJDK 25.0.4.1; Red Hat Build of OpenJDK 8u504; and 18 more.

CVE-2026-61308
Red Hat Enterprise Linux
Aug 18, 2026
Medium5.3Red Hat

Medium [CVE-2026-70907] Enhance TLS server (2026-08 Security Update)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Affected Red Hat products: Red Hat Build of OpenJDK 17.0.20.1; Red Hat Build of OpenJDK 21.0.12.1; Red Hat Build of OpenJDK 25.0.4.1; Red Hat Build of OpenJDK 8u504; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenJDK 11 els for RHEL 7; Red Hat OpenJDK 11 els for RHEL 8; Red Hat OpenJDK 11 els for RHEL 9; Red Hat Hardened Images; Exploit Intelligence; Red Hat build of OpenJDK 11 ELS; Red Hat build of OpenJDK 25; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-70907
Red Hat Enterprise Linux
Aug 18, 2026
Medium5.6Red Hat Updated

Medium [CVE-2026-19999] Remote buffer overflow allows information disclosure or denial of service

Remote buffer overflow allows information disclosure or denial of service. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-120.

CVE-2026-19999
Unclassified
Aug 17, 2026
Medium6.3Red Hat Updated

Medium [CVE-2026-19970] Remote heap-based buffer overflow vulnerability

Remote heap-based buffer overflow vulnerability. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.

CVE-2026-19970
Red Hat Enterprise Linux
Aug 17, 2026
Medium5.4Red Hat Updated

Medium [CVE-2026-19969] Buffer overflow in 3DGS MDL7 model processing

Buffer overflow in 3DGS MDL7 model processing. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.

CVE-2026-19969
Red Hat Enterprise Linux
Aug 17, 2026
Medium4.3Red Hat Updated

Medium [CVE-2026-19968] Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser

Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.

CVE-2026-19968
Red Hat Enterprise Linux
Aug 17, 2026
Medium6.3Red Hat Updated

Medium [CVE-2026-19967] Heap-based buffer overflow in file decompression

Heap-based buffer overflow in file decompression. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.

CVE-2026-19967
Red Hat Enterprise Linux
Aug 17, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-74579] fix mask build for partial field offload

fix mask build for partial field offload. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1335. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74579
Linux Kernel
Aug 17, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74796] Arbitrary file write via symlink following path traversal

Arbitrary file write via symlink following path traversal. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-59.

CVE-2026-74796
Unclassified
Aug 16, 2026
Medium5.9Red Hat Updated

Medium [CVE-2024-58375] Sensitive information disclosure via static evaluation

Sensitive information disclosure via static evaluation. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-497.

CVE-2024-58375
Unclassified
Aug 16, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74578] algif_skcipher - force synchronous processing on trees without ctx->state

algif_skcipher - force synchronous processing on trees without ctx->state. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1204. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74578
Linux Kernel
Aug 16, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-72428] Fix stack slot index in nospec checks

Fix stack slot index in nospec checks. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72428
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-72245] Fix device reference leak in host1x_device_parse_dt error path

Fix device reference leak in host1x_device_parse_dt() error path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72245
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-72403] Fix NULL pointer dereference in interface lookup

Fix NULL pointer dereference in interface lookup. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72403
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-72190] fix mrec_lock ABBA deadlock in rename

fix mrec_lock ABBA deadlock in rename. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.

CVE-2026-72190
Unclassified
Aug 15, 2026

← All vendors