Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5204 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium5.3Linux

Medium [CVE-2026-34480] Invalid XML output causes denial of service in logging

Invalid XML output causes denial of service in logging. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-168. Affected package(s): log4j-core-test, offline-knowledge-portal/rhokp-rhel9:1779996999, log4j-core. Resolved in Red Hat advisory RHSA-2026:22619 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34480
Unclassified
Apr 10, 2026
Medium5.3Linux

Medium [CVE-2026-34479] Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping

Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-91. Affected package(s): offline-knowledge-portal/rhokp-rhel9:1779996999. Resolved in Red Hat advisory RHSA-2026:21773 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34479
Unclassified
Apr 10, 2026
Medium5.8Linux

Medium [CVE-2026-34478] Log injection via CRLF sequences due to configuration attribute renames

Log injection via CRLF sequences due to configuration attribute renames. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-93. Affected package(s): log4j-core-test, offline-knowledge-portal/rhokp-rhel9:1779996999, log4j-core. Resolved in Red Hat advisory RHSA-2026:22619 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34478
Unclassified
Apr 10, 2026
Medium6.8Linux

Medium [CVE-2026-34477] Man-in-the-middle attack due to incomplete hostname verification

Man-in-the-middle attack due to incomplete hostname verification. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-295. Affected package(s): offline-knowledge-portal/rhokp-rhel9:1779996999. Resolved in Red Hat advisory RHSA-2026:21773 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34477
Unclassified
Apr 10, 2026
Medium5.5Linux

Medium [CVE-2026-40227] Denial of Service via malicious IPC API call with null element

Denial of Service via malicious IPC API call with null element. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40227
Unclassified
Apr 10, 2026
Medium6.4Linux

Medium [CVE-2026-40226] systemd nspawn: Escape-to-host action via crafted config file

systemd nspawn: Escape-to-host action via crafted config file. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-348. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40226
Unclassified
Apr 10, 2026
Medium6.4Linux

Medium [CVE-2026-40225] udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output

udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-250. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40225
Unclassified
Apr 10, 2026
Medium6.7Linux

Medium [CVE-2026-40224] Local privilege escalation via varlink

Local privilege escalation via varlink. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-266. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40224
Unclassified
Apr 10, 2026
Medium4.7Linux

Medium [CVE-2026-40223] Local unprivileged user can cause Denial of Service

Local unprivileged user can cause Denial of Service. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-617. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40223
Unclassified
Apr 10, 2026
Low2.9Linux

Low [CVE-2026-40228] Unintended output to user terminals via logger command

Unintended output to user terminals via logger command. Red Hat rates this low (CVSS 2.9). Weakness: CWE-117. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-40228
Unclassified
Apr 10, 2026
Critical10.0Linux

Critical [CVE-2026-5194] Reduced security of ECDSA authentication via missing digest size checks

Reduced security of ECDSA authentication via missing digest size checks. Red Hat rates this critical (CVSS 10). Weakness: CWE-295. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5194
Unclassified
Apr 9, 2026
High7.5Linux

High [CVE-2026-34486] Missing Encryption of Sensitive Data due to EncryptInterceptor bypass

Missing Encryption of Sensitive Data due to EncryptInterceptor bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-807. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; and 8 more.

CVE-2026-34486
Red Hat Enterprise Linux
Apr 9, 2026
High7.3Vendor: MediumLinux

High [CVE-2026-32990] Improper Input Validation vulnerability due to incomplete fix

Improper Input Validation vulnerability due to incomplete fix. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-184. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:12195 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-32990
Unclassified
Apr 9, 2026
High7.5Linux

High [CVE-2026-29146] Information disclosure via Padding Oracle vulnerability in EncryptInterceptor

Information disclosure via Padding Oracle vulnerability in EncryptInterceptor. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1240. Affected package(s): jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; and 10 more.

CVE-2026-29146
Red Hat Enterprise Linux
Apr 9, 2026
High7.8Linux

High [CVE-2026-34734] HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file

HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-34734
Red Hat Enterprise Linux
Apr 9, 2026
High8.5Linux

High [CVE-2026-34971] Sandbox escape due to miscompiled heap access on aarch64

Sandbox escape due to miscompiled heap access on aarch64. Red Hat rates this important (CVSS 8.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Connectivity Link 1.

CVE-2026-34971
Unclassified
Apr 9, 2026
High8.6Linux

High [CVE-2026-39983] Command injection via CRLF sequences in file path parameters

Command injection via CRLF sequences in file path parameters. Red Hat rates this important (CVSS 8.6). Weakness: CWE-93. Affected package(s): rhdh/rhdh-hub-rhel9:1777903262, rhdh/rhdh-hub-rhel9:1776784286. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; Red Hat OpenShift Container Platform 4.

CVE-2026-39983
Unclassified
Apr 9, 2026
High8.0Linux

High [CVE-2026-35205] Arbitrary code execution due to insufficient plugin provenance verification

Arbitrary code execution due to insufficient plugin provenance verification. Red Hat rates this important (CVSS 8). Weakness: CWE-347. Affected package(s): helm-cli. Resolved in Red Hat advisory RHSA-2026:26441 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-35205
Unclassified
Apr 9, 2026
High8.2Linux

High [CVE-2026-35204] Arbitrary file write via specially crafted plugin

Arbitrary file write via specially crafted plugin. Red Hat rates this important (CVSS 8.2). Weakness: CWE-22. Affected package(s): helm-cli. Resolved in Red Hat advisory RHSA-2026:26441 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-35204
Unclassified
Apr 9, 2026
High7.0Linux

High [CVE-2025-62718] Server-Side Request Forgery and proxy bypass due to improper hostname normalization

Server-Side Request Forgery and proxy bypass due to improper hostname normalization. Red Hat rates this important (CVSS 7). Weakness: CWE-1289. Affected package(s): openshift-service-mesh/kiali-rhel9:1776149682, openshift-service-mesh/kiali-ossmc-rhel9:1776151134, rhoai/odh-mod-arch-model-registry-rhel9:1780467147, devspaces/dashboard-rhel9:1776795511, openshift-service-mesh/kiali-ossmc-rhel8:1776202125, rhoai/odh-mod-arch-gen-ai-rhel9:1778473763. Resolved in Red Hat advisory RHSA-2026:13826 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; and 35 more.

CVE-2025-62718
Red Hat Enterprise Linux
Apr 9, 2026

← All vendors