Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5207 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High8.8Linux

High [CVE-2026-41242] Arbitrary code execution via injected protobuf definition type fields

Arbitrary code execution via injected protobuf definition type fields. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): rhdh/rhdh-hub-rhel9:1779841586, rhdh/rhdh-hub-rhel9:1781187342, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, rhoai/odh-dashboard-rhel9:1780467029. Resolved in Red Hat advisory RHSA-2026:21338 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; and 5 more.

CVE-2026-41242
Unclassified
Apr 18, 2026
High8.5Linux

High [CVE-2026-40478] Server-Side Template Injection via expression execution bypass

Server-Side Template Injection via expression execution bypass. Red Hat rates this important (CVSS 8.5). Weakness: CWE-917. Affected package(s): devspaces/openvsx-rhel9:1779528224, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.28; Red Hat Fuse 7; Red Hat Single Sign-On 7.

CVE-2026-40478
Unclassified
Apr 17, 2026
High8.5Linux

High [CVE-2026-40477] Server-Side Template Injection via security bypass in expression execution

Server-Side Template Injection via security bypass in expression execution. Red Hat rates this important (CVSS 8.5). Weakness: CWE-917. Affected package(s): devspaces/openvsx-rhel9:1779528224, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.28; Red Hat Fuse 7; Red Hat Single Sign-On 7.

CVE-2026-40477
Unclassified
Apr 17, 2026
High7.7Linux

High [CVE-2026-42965] cloud metadata SSRF via FQDN-typed EndpointSlice bypasses destination validation

cloud metadata SSRF via FQDN-typed EndpointSlice bypasses destination validation. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-42965
Unclassified
Apr 17, 2026
High7.5Linux

High [CVE-2026-40293] Information disclosure of preshared API key via playground endpoint

Information disclosure of preshared API key via playground endpoint. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273, rhacm2/acm-grafana-rhel9:1780677003. Resolved in Red Hat advisory RHSA-2026:24539 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15.

CVE-2026-40293
Unclassified
Apr 17, 2026
High7.4Linux

High [CVE-2026-46579] mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend

mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend. Red Hat rates this important (CVSS 7.4). Weakness: CWE-287. Affected package(s): openshift4/ose-haproxy-router-rhel9:1781552170, openshift4/ose-haproxy-router-rhel9:1781643967, openshift4/ose-haproxy-router-rhel9:1781639027. Resolved in Red Hat advisory RHSA-2026:27063 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.20; Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.22; Red Hat OpenShift Container Platform 4.19; and 5 more.

CVE-2026-46579
Unclassified
Apr 17, 2026
High7.0Linux

High [CVE-2026-32107] Privilege Escalation via improper privilege management

Privilege Escalation via improper privilege management. Red Hat rates this important (CVSS 7). Weakness: CWE-273. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32107
Unclassified
Apr 17, 2026
High7.5Linux

High [CVE-2026-5807] Denial of Service via unauthenticated root token generation or rekey operations

Denial of Service via unauthenticated root token generation or rekey operations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Openshift Data Foundation 4.

CVE-2026-5807
Unclassified
Apr 17, 2026
High7.5Linux

High [CVE-2026-4525] Information disclosure of authentication tokens via incorrect header handling

Information disclosure of authentication tokens via incorrect header handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Openshift Data Foundation 4.

CVE-2026-4525
Unclassified
Apr 17, 2026
High8.1Linux

High [CVE-2026-3605] Denial of Service due to unauthorized secret deletion via policy bypass

Denial of Service due to unauthorized secret deletion via policy bypass. Red Hat rates this important (CVSS 8.1). Weakness: CWE-639. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Openshift Data Foundation 4.

CVE-2026-3605
Unclassified
Apr 17, 2026
High7.5Linux

High [CVE-2026-40170] Denial of service via stack buffer overflow during QUIC handshake

Denial of service via stack buffer overflow during QUIC handshake. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Affected package(s): samba, ngtcp2-main. Resolved in Red Hat advisory RHSA-2026:22963 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images.

CVE-2026-40170
Red Hat Enterprise Linux
Apr 16, 2026
High7.5Linux

High [CVE-2025-54502] APCB SMM driver: kernel: linux-firmware: AMD APCB SMM driver: Arbitrary Code Execution via incorrect boot service use

APCB SMM driver: kernel: linux-firmware: AMD APCB SMM driver: Arbitrary Code Execution via incorrect boot service use. Red Hat rates this important (CVSS 7.5). Weakness: CWE-648. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-54502
Unclassified
Apr 16, 2026
High7.1Linux

High [CVE-2026-41082] path traversal via the .install field

path traversal via the.install field. Red Hat rates this important (CVSS 7.1). Weakness: CWE-24. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-41082
Red Hat Enterprise Linux
Apr 16, 2026
High7.4Linux

High [CVE-2026-41035] Use-after-free vulnerability in extended attribute handling

Use-after-free vulnerability in extended attribute handling. Red Hat rates this important (CVSS 7.4). Weakness: CWE-805. Affected package(s): rsync, rhcos, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:25044 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 17 more.

CVE-2026-41035
Red Hat Enterprise Linux
Apr 16, 2026
High7.3Linux

High [CVE-2026-12912] Heap-based buffer overflow via crafted PixarLog-compressed TIFF image

Heap-based buffer overflow via crafted PixarLog-compressed TIFF image. Red Hat rates this important (CVSS 7.3). Weakness: CWE-122. Affected package(s): libtiff-main. Resolved in Red Hat advisory RHSA-2026:34890 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 1 more.

CVE-2026-12912
Red Hat Enterprise Linux
Apr 16, 2026
Medium6.8Linux

Medium [CVE-2026-40253] Information disclosure and Denial of Service via malformed BER-encoded cryptographic objects

Information disclosure and Denial of Service via malformed BER-encoded cryptographic objects. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-125. Affected package(s): opencryptoki. Resolved in Red Hat advisory RHSA-2026:26352 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-40253
Unclassified
Apr 16, 2026
Medium5.6Linux

Medium [CVE-2026-27820] Memory corruption via buffer overflow in Zlib::GzipReader

Memory corruption via buffer overflow in Zlib::GzipReader. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-131. Affected package(s): ruby4, ruby3. Resolved in Red Hat advisory RHSA-2026:7307 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27820
Unclassified
Apr 16, 2026
Medium6.5Linux

Medium [CVE-2026-6732] Denial of Service via crafted XSD-validated document

Denial of Service via crafted XSD-validated document. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-843. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:11503 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6732
Unclassified
Apr 16, 2026
Low3.7Linux

Low [CVE-2026-41080] Denial of Service via hash flooding with crafted XML

Denial of Service via hash flooding with crafted XML. Red Hat rates this low (CVSS 3.7). Weakness: CWE-331. Affected package(s): expat-main. Resolved in Red Hat advisory RHSA-2026:11004 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-41080
Unclassified
Apr 16, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-6388] Cross-Namespace Privilege Escalation via insufficient namespace validation

Cross-Namespace Privilege Escalation via insufficient namespace validation. Red Hat rates this important (CVSS 9.1). Weakness: CWE-1220. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift GitOps.

CVE-2026-6388
Unclassified
Apr 15, 2026

← All vendors