Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5201 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High8.8Linux

High [CVE-2026-5731] Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2

Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:11805 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.

CVE-2026-5731
Red Hat Enterprise Linux
Apr 7, 2026
High7.4Linux

High [CVE-2026-28808] Erlang OTP inets modules: Unauthenticated access to protected CGI scripts via incorrect authorization

Erlang OTP inets modules: Unauthenticated access to protected CGI scripts via incorrect authorization. Red Hat rates this important (CVSS 7.4). Weakness: CWE-551. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1.

CVE-2026-28808
Unclassified
Apr 7, 2026
High7.4Linux

High [CVE-2026-32144] Erlang OTP public_key: OCSP authorization bypass and information disclosure due to missing signature verification

Erlang OTP public_key: OCSP authorization bypass and information disclosure due to missing signature verification. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

CVE-2026-32144
Unclassified
Apr 7, 2026
High8.8Linux Exploited CISA KEV

High [CVE-2026-34197] RCE via crafted discovery URI in Jolokia JMX-HTTP bridge

RCE via crafted discovery URI in Jolokia JMX-HTTP bridge. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34197
Unclassified
Apr 7, 2026
High8.8Linux

High [CVE-2026-5868] Heap buffer overflow in ANGLE

Heap buffer overflow in ANGLE. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5868
Unclassified
Apr 7, 2026
High8.8Linux

High [CVE-2026-5862] Inappropriate implementation in V8

Inappropriate implementation in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-130. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5862
Unclassified
Apr 7, 2026
Medium6.7Linux

Medium [CVE-2026-34079] Arbitrary file deletion on host via improper cache file path validation

Arbitrary file deletion on host via improper cache file path validation. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-22. Affected package(s): flatpak. Resolved in Red Hat advisory RHSA-2026:21757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9.

CVE-2026-34079
Unclassified
Apr 7, 2026
Medium4.0Linux

Medium [CVE-2026-39316] Denial of Service and potential arbitrary code execution via use-after-free vulnerability when deleting temporary printers.

Denial of Service and potential arbitrary code execution via use-after-free vulnerability when deleting temporary printers.. Red Hat rates this moderate (CVSS 4). Weakness: CWE-825. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-39316
Unclassified
Apr 7, 2026
Medium4.0Linux

Medium [CVE-2026-39314] Denial of Service via integer underflow in IPP attribute handling

Denial of Service via integer underflow in IPP attribute handling. Red Hat rates this moderate (CVSS 4). Weakness: CWE-191. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-39314
Unclassified
Apr 7, 2026
Medium6.8Linux

Medium [CVE-2026-35554] Information disclosure and data corruption due to race condition in producer buffer management

Information disclosure and data corruption due to race condition in producer buffer management. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-367. Affected package(s): kafka-clients. Resolved in Red Hat advisory RHSA-2026:11721 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-35554
Unclassified
Apr 7, 2026
Medium5.9Linux

Medium [CVE-2026-31790] Information Disclosure from Uninitialized Memory via Invalid RSA Public Key

Information Disclosure from Uninitialized Memory via Invalid RSA Public Key. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-824. Affected package(s): openssl, openssl-fips-provider, rhui5/haproxy-rhel9:1779798164, openssl-main, rhui5/rhua-rhel9:1779798222, openssl-fips-provider-main. Resolved in Red Hat advisory RHSA-2026:28211 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-31790
Unclassified
Apr 7, 2026
Medium5.8Vendor: LowLinux

Medium [CVE-2026-31789] Heap buffer overflow on 32-bit systems from large X.509 certificate processing

Heap buffer overflow on 32-bit systems from large X.509 certificate processing. Red Hat rates this low (CVSS 5.8). Weakness: CWE-190. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31789
Unclassified
Apr 7, 2026
Medium5.9Vendor: LowLinux

Medium [CVE-2026-28389] Denial of Service vulnerability in CMS processing

Denial of Service vulnerability in CMS processing. Red Hat rates this low (CVSS 5.9). Weakness: CWE-166. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-28389
Unclassified
Apr 7, 2026
Medium5.9Vendor: LowLinux

Medium [CVE-2026-28388] Denial of Service due to NULL pointer dereference in delta CRL processing

Denial of Service due to NULL pointer dereference in delta CRL processing. Red Hat rates this low (CVSS 5.9). Weakness: CWE-476. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-28388
Unclassified
Apr 7, 2026
Medium5.9Linux

Medium [CVE-2026-28386] Denial of Service due to out-of-bounds read in AES-CFB128

Denial of Service due to out-of-bounds read in AES-CFB128. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-805. Affected package(s): openssl-main. Resolved in Red Hat advisory RHSA-2026:7261 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-28386
Unclassified
Apr 7, 2026
Medium5.5Linux

Medium [CVE-2026-5745] A NULL pointer dereference vulnerability exists in the ACL parser of libarchive

A NULL pointer dereference vulnerability exists in the ACL parser of libarchive. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected package(s): libarchive-main. Resolved in Red Hat advisory RHSA-2026:8944 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5745
Unclassified
Apr 7, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-5864] Heap buffer overflow in WebAudio

Heap buffer overflow in WebAudio. Red Hat rates this important (CVSS 6.5). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5864
Unclassified
Apr 7, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-5867] Heap buffer overflow in WebML

Heap buffer overflow in WebML. Red Hat rates this important (CVSS 6.5). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5867
Unclassified
Apr 7, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-5869] Heap buffer overflow in WebML

Heap buffer overflow in WebML. Red Hat rates this important (CVSS 6.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-5869
Unclassified
Apr 7, 2026
Low3.5Linux

Low [CVE-2026-33551] Privilege escalation through EC2 credential creation

Privilege escalation through EC2 credential creation. Red Hat rates this low (CVSS 3.5). Weakness: CWE-266. Affected package(s): openstack-keystone. Resolved in Red Hat advisory RHSA-2026:28044 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-33551
Unclassified
Apr 7, 2026

← All vendors