Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5206 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.5Linux

High [CVE-2026-32203] .NET: Denial of Service via stack overflow

.NET: Denial of Service via stack overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): dotnet8.0, dotnet10.0, dotnet8, dotnet9.0, dotnet9, dotnet10. Resolved in Red Hat advisory RHSA-2026:9080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2026-32203
Red Hat Enterprise Linux
Apr 14, 2026
High7.5Linux

High [CVE-2026-33116] .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform

.NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected package(s): dotnet8.0, dotnet10.0, dotnet8, dotnet9.0, dotnet9, dotnet10. Resolved in Red Hat advisory RHSA-2026:9080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.

CVE-2026-33116
Red Hat Enterprise Linux
Apr 14, 2026
High7.5Linux

High [CVE-2026-23666] .NET Framework: Denial of Service via Race Condition

.NET Framework: Denial of Service via Race Condition. Red Hat rates this important (CVSS 7.5). Weakness: CWE-366. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23666
Unclassified
Apr 14, 2026
High7.4Linux

High [CVE-2026-2332] HTTP request smuggling via chunked extension quoted-string parsing

HTTP request smuggling via chunked extension quoted-string parsing. Red Hat rates this important (CVSS 7.4). Weakness: CWE-444. Affected package(s): offline-knowledge-portal/rhokp-rhel9:1779996999, devspaces/pluginregistry-rhel9:1776717247, jmc, jetty-http, devspaces/openvsx-rhel9:1776716842. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Offline Knowledge Portal 1.2.7; Red Hat OpenShift Dev Spaces 3.27; OpenShift Developer Tools and Services; and 9 more.

CVE-2026-2332
Red Hat Enterprise Linux
Apr 14, 2026
Medium6.0Linux

Medium [CVE-2026-5713] Information disclosure and arbitrary code execution via remote debugging with a malicious process.

Information disclosure and arbitrary code execution via remote debugging with a malicious process.. Red Hat rates this moderate (CVSS 6). Weakness: CWE-822. Affected package(s): python3, python3.14. Resolved in Red Hat advisory RHSA-2026:19019 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-5713
Unclassified
Apr 14, 2026
High7.5Linux

High [CVE-2026-40164] Denial of Service via crafted JSON object causing hash collisions

Denial of Service via crafted JSON object causing hash collisions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-341. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, jq, rhcos, rhaiis/model-opt-cuda-rhel9:1780681984, rhaiis/vllm-rocm-rhel9:1782353093. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 19 more.

CVE-2026-40164
Red Hat Enterprise Linux
Apr 13, 2026
High8.2Linux

High [CVE-2026-39979] out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers

out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected package(s): rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, jq, rhcos, rhaiis/model-opt-cuda-rhel9:1780681984, rhaiis/vllm-rocm-rhel9:1782353093. Resolved in Red Hat advisory RHSA-2026:26542 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 21 more.

CVE-2026-39979
Red Hat Enterprise Linux
Apr 13, 2026
High7.1Linux

High [CVE-2026-4786] Arbitrary code execution via command injection in webbrowser.open() API

Arbitrary code execution via command injection in webbrowser.open() API. Red Hat rates this important (CVSS 7.1). Weakness: CWE-88. Affected package(s): python3.11, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, rhpam, python3.9, python3.12. Resolved in Red Hat advisory RHSA-2026:35838 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 16 more.

CVE-2026-4786
Red Hat Enterprise Linux
Apr 13, 2026
High7.5Linux

High [CVE-2026-33908] Denial of Service via deeply nested XML file processing

Denial of Service via deeply nested XML file processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33908
Unclassified
Apr 13, 2026
High7.5Linux

High [CVE-2026-33901] Denial of Service due to heap buffer overflow in MVG decoder

Denial of Service due to heap buffer overflow in MVG decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33901
Unclassified
Apr 13, 2026
High8.1Linux

High [CVE-2026-6100] Arbitrary code execution or information disclosure via use-after-free in decompression modules

Arbitrary code execution or information disclosure via use-after-free in decompression modules. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825. Affected package(s): python3.11, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, rhpam, python3.9, python3.12. Resolved in Red Hat advisory RHSA-2026:26187 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 16 more.

CVE-2026-6100
Red Hat Enterprise Linux
Apr 13, 2026
High8.1Linux

High [CVE-2026-28291] Command Execution via Option-Parsing Bypass in simple-git

Command Execution via Option-Parsing Bypass in simple-git. Red Hat rates this important (CVSS 8.1). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat Process Automation 7.

CVE-2026-28291
Unclassified
Apr 13, 2026
High7.8Linux

High [CVE-2026-1462] Arbitrary Code Execution Vulnerability Bypassing Safe Mode

Arbitrary Code Execution Vulnerability Bypassing Safe Mode. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. Affected package(s): rhoai/odh-modelmesh-runtime-adapter-rhel9:1780394782. Resolved in Red Hat advisory RHSA-2026:24977 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI).

CVE-2026-1462
Unclassified
Apr 13, 2026
High8.6Linux

High [CVE-2026-5367] Information disclosure via crafted DHCPv6 packets

Information disclosure via crafted DHCPv6 packets. Red Hat rates this important (CVSS 8.6). Weakness: CWE-130. Affected package(s): ovn25.03, ovn25.09, ovn, ovn23.09, ovn24.03, ovn23.06. Resolved in Red Hat advisory RHSA-2026:11702 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Fast Datapath for Red Hat Enterprise Linux 10; Fast Datapath for Red Hat Enterprise Linux 8; Fast Datapath for Red Hat Enterprise Linux 9; Fast Datapath for RHEL 8; and 2 more.

CVE-2026-5367
Red Hat Enterprise Linux
Apr 13, 2026
High7.5Linux

High [CVE-2026-6857] Remote Code Execution via Unsafe Deserialization

Remote Code Execution via Unsafe Deserialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. Affected package(s): camel-infinispan. Resolved in Red Hat advisory RHSA-2026:22453 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat Fuse 7.

CVE-2026-6857
Unclassified
Apr 13, 2026
High7.0Linux

High [CVE-2026-31419] Linux kernel: Use-after-free in bonding driver leads to denial of service

Linux kernel: Use-after-free in bonding driver leads to denial of service. Red Hat rates this important (CVSS 7). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 2 more.

CVE-2026-31419
Red Hat Enterprise Linux
Apr 13, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-35469] Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code. Red Hat rates this important (CVSS 6.5). Weakness: CWE-770. Affected package(s): openshift4/ose-node-feature-discovery-rhel9:1779252023, openshift4/ose-sriov-network-config-daemon:1780955979, container-native-virtualization/virt-exportserver-rhel9:1782358244, openshift4/ose-sriov-network-webhook-rhel9:1779249801, advanced-cluster-security/rhacs-roxctl-rhel8:1777986630, multicluster-engine/assisted-service. Resolved in Red Hat advisory RHSA-2026:29795 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: RHEM 1.0 for RHEL 9; Red Hat OpenShift Container Platform 4.19; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 29 more.

CVE-2026-35469
Red Hat Enterprise Linux
Apr 13, 2026
Medium6.1Linux

Medium [CVE-2026-39956] missing runtime type checks for _strindices lead to crash and limited memory disclosure

missing runtime type checks for _strindices lead to crash and limited memory disclosure. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-1287. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:8579 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-39956
Unclassified
Apr 13, 2026
Medium6.2Linux

Medium [CVE-2026-33947] unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted()

unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted(). Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-674. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:8579 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33947
Unclassified
Apr 13, 2026
Medium6.8Linux

Medium [CVE-2026-32316] Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow

Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:8579 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32316
Unclassified
Apr 13, 2026

← All vendors