Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5207 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Critical9.6Vendor: HighLinux

Critical [CVE-2026-6308] Out of bounds read in Media

Out of bounds read in Media. Red Hat rates this important (CVSS 9.6). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6308
Unclassified
Apr 15, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-6306] Heap buffer overflow in PDFium

Heap buffer overflow in PDFium. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6306
Unclassified
Apr 15, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-6299] Use after free in Prerender

Use after free in Prerender. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6299
Unclassified
Apr 15, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-6311] Uninitialized Use in Accessibility

Uninitialized Use in Accessibility. Red Hat rates this important (CVSS 9). Weakness: CWE-824. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6311
Unclassified
Apr 15, 2026
Critical9.6Linux

Critical [CVE-2026-6296] Heap buffer overflow in ANGLE

Heap buffer overflow in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6296
Unclassified
Apr 15, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-6301] Type Confusion in Turbofan

Type Confusion in Turbofan. Red Hat rates this important (CVSS 9.6). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6301
Unclassified
Apr 15, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-6316] Use after free in Forms

Use after free in Forms. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6316
Unclassified
Apr 15, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-6310] Use after free in Dawn

Use after free in Dawn. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6310
Unclassified
Apr 15, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-6359] Use after free in Video

Use after free in Video. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6359
Unclassified
Apr 15, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-6362] Use after free in Codecs

Use after free in Codecs. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6362
Unclassified
Apr 15, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-6304] Use after free in Graphite

Use after free in Graphite. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6304
Unclassified
Apr 15, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-6315] Use after free in Permissions

Use after free in Permissions. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-6315
Unclassified
Apr 15, 2026
High7.5Linux

High [CVE-2026-40192] Denial of Service via decompression bomb in FITS image processing

Denial of Service via decompression bomb in FITS image processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected package(s): ansible-automation-platform, rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1778263054, rhelai3/bootc-rocm-rhel9:1778666124, rhaiis/vllm-rocm-rhel9:1778244531, rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1778677734, rhaiis/vllm-cuda-rhel9:1778274666. Resolved in Red Hat advisory RHSA-2026:23361 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Satellite 6.16 for RHEL 8; and 18 more.

CVE-2026-40192
Red Hat Enterprise Linux
Apr 15, 2026
High8.8Linux

High [CVE-2026-40261] command injection via malicious Perforce source reference/url

command injection via malicious Perforce source reference/url. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected package(s): composer-main. Resolved in Red Hat advisory RHSA-2026:8165 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-40261
Unclassified
Apr 15, 2026
High7.8Linux

High [CVE-2026-40176] command injection via malicious Perforce repository definition

command injection via malicious Perforce repository definition. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Affected package(s): composer-main. Resolved in Red Hat advisory RHSA-2026:8165 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-40176
Unclassified
Apr 15, 2026
High7.5Linux

High [CVE-2025-41118] sensitive COS SecretKey exposed in plaintext via configuration API due to missing type protection

sensitive COS SecretKey exposed in plaintext via configuration API due to missing type protection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273. Resolved in Red Hat advisory RHSA-2026:24503 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 6.

CVE-2025-41118
Unclassified
Apr 15, 2026
High7.3Linux

High [CVE-2026-6384] Arbitrary code execution or denial of service via buffer overflow in GIF image processing

Arbitrary code execution or denial of service via buffer overflow in GIF image processing. Red Hat rates this important (CVSS 7.3). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8.

CVE-2026-6384
Red Hat Enterprise Linux
Apr 15, 2026
High7.4Linux

High [CVE-2026-33805] @fastify/reply-from: @fastify/http-proxy: Fastify Reply From and HTTP Proxy: Security bypass via Connection header manipulation

@fastify/reply-from: @fastify/http-proxy: Fastify Reply From and HTTP Proxy: Security bypass via Connection header manipulation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-444. Affected package(s): devspaces/dashboard-rhel9:1776795511. Resolved in Red Hat advisory RHSA-2026:10175 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Red Hat OpenShift AI (RHOAI).

CVE-2026-33805
Unclassified
Apr 15, 2026
High7.5Linux

High [CVE-2026-3505] unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion

unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): eap8-bouncycastle, bcpg-jdk18on, bcpg-fips, bcpg-jdk15on. Resolved in Red Hat advisory RHSA-2026:18054 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; OpenShift Developer Tools and Services; Red Hat AMQ Clients; and 6 more.

CVE-2026-3505
Red Hat Enterprise Linux
Apr 15, 2026
High7.5Linux

High [CVE-2026-5588] PKIX draft CompositeVerifier accepts empty signature sequence as valid

PKIX draft CompositeVerifier accepts empty signature sequence as valid. Red Hat rates this important (CVSS 7.5). Weakness: CWE-347. Affected package(s): eap8-bouncycastle, devspaces/openvsx-rhel9:1779528224, eap8-guava-failureaccess, eap8-activemq-artemis, eap8-netty-transport-native-epoll, eap8-reactivex-rxjava. Resolved in Red Hat advisory RHSA-2026:14276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat OpenShift Dev Spaces 3.28; OpenShift Developer Tools and Services; and 9 more.

CVE-2026-5588
Red Hat Enterprise Linux
Apr 15, 2026

← All vendors