Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5204 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium6.5Linux

Medium [CVE-2026-5265] Heap Over-Read in ICMP Error Response Generation

Heap Over-Read in ICMP Error Response Generation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-130. Affected package(s): ovn25.03, ovn25.09, ovn, ovn23.09, ovn24.03, ovn23.06. Resolved in Red Hat advisory RHSA-2026:11702 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-5265
Unclassified
Apr 6, 2026
Low3.7Linux

Low [CVE-2026-37977] Information disclosure via CORS header injection due to unvalidated JWT azp claim

Information disclosure via CORS header injection due to unvalidated JWT azp claim. Red Hat rates this low (CVSS 3.7). Weakness: CWE-346. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-37977
Unclassified
Apr 6, 2026
High8.0Linux

High [CVE-2026-34780] Context Isolation bypass via VideoFrame object transfer

Context Isolation bypass via VideoFrame object transfer. Red Hat rates this important (CVSS 8). Weakness: CWE-501. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34780
Unclassified
Apr 4, 2026
High8.1Linux

High [CVE-2026-34774] Memory corruption and crash due to use-after-free in offscreen rendering

Memory corruption and crash due to use-after-free in offscreen rendering. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34774
Unclassified
Apr 3, 2026
High7.5Linux

High [CVE-2026-34771] Memory corruption or application crash via use-after-free in permission request handling

Memory corruption or application crash via use-after-free in permission request handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-364. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34771
Unclassified
Apr 3, 2026
High7.7Linux

High [CVE-2026-34769] Arbitrary code execution and security bypass via undocumented command-line switches

Arbitrary code execution and security bypass via undocumented command-line switches. Red Hat rates this important (CVSS 7.7). Weakness: CWE-88. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-34769
Unclassified
Apr 3, 2026
High8.1Linux

High [CVE-2026-0545] Unauthenticated remote code execution via unprotected job endpoints

Unauthenticated remote code execution via unprotected job endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-306. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-0545
Unclassified
Apr 3, 2026
High7.4Linux

High [CVE-2026-35535] Privilege escalation due to failure in privilege drop calls

Privilege escalation due to failure in privilege drop calls. Red Hat rates this important (CVSS 7.4). Weakness: CWE-272. Affected package(s): rhcos, sudo, rhui5/rhua-rhel9:1779798222, rhaiis/vllm-rocm-rhel9:1782353093, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:20040 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 18 more.

CVE-2026-35535
Red Hat Enterprise Linux
Apr 3, 2026
High7.1Vendor: MediumLinux

High [CVE-2026-23455] check for zero length in DecodeQ931()

check for zero length in DecodeQ931(). Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-125. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23455
Unclassified
Apr 3, 2026
High7.8Linux

High [CVE-2026-31402] fix heap overflow in NFSv4.0 LOCK replay cache

fix heap overflow in NFSv4.0 LOCK replay cache. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION); Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION); Red Hat Enterprise Linux Server (v. 7 ELS); Red Hat Enterprise Linux for Real Time (v. 7 ELS); and 60 more.

CVE-2026-31402
Red Hat Enterprise Linux
Apr 3, 2026
Medium5.5Linux

Medium [CVE-2026-34933] Denial of Service via D-Bus method call

Denial of Service via D-Bus method call. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1288. Affected package(s): avahi-main. Resolved in Red Hat advisory RHSA-2026:11316 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34933
Unclassified
Apr 3, 2026
Medium4.7Linux

Medium [CVE-2026-27456] TOCTOU in the mount program when setting up loop devices

TOCTOU in the mount program when setting up loop devices. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-367. Affected package(s): util-linux-main. Resolved in Red Hat advisory RHSA-2026:7180 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27456
Unclassified
Apr 3, 2026
Medium6.4Linux

Medium [CVE-2026-34980] Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network

Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-78. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34980
Unclassified
Apr 3, 2026
Medium5.3Linux

Medium [CVE-2026-34979] Denial of Service via heap-based buffer overflow in job attribute processing

Denial of Service via heap-based buffer overflow in job attribute processing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-120. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34979
Unclassified
Apr 3, 2026
Medium6.5Linux

Medium [CVE-2026-34978] Denial of Service via path traversal in RSS notifier

Denial of Service via path traversal in RSS notifier. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34978
Unclassified
Apr 3, 2026
Medium5.2Linux

Medium [CVE-2026-34990] Privilege escalation via arbitrary file overwrite due to coerced authentication

Privilege escalation via arbitrary file overwrite due to coerced authentication. Red Hat rates this moderate (CVSS 5.2). Weakness: CWE-73. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34990
Unclassified
Apr 3, 2026
Medium6.4Linux

Medium [CVE-2026-27447] Authorization bypass via case-insensitive username comparison

Authorization bypass via case-insensitive username comparison. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-178. Affected package(s): cups-main. Resolved in Red Hat advisory RHSA-2026:8814 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27447
Unclassified
Apr 3, 2026
Medium5.4Linux

Medium [CVE-2026-35536] Cookie attribute injection due to improper handling of cookie arguments

Cookie attribute injection due to improper handling of cookie arguments. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-88. Affected package(s): python-tornado. Resolved in Red Hat advisory RHSA-2026:24342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-35536
Unclassified
Apr 3, 2026
High8.0Linux

High [CVE-2026-34742] Model Context Protocol (MCP) Go SDK: DNS rebinding vulnerability allows unauthorized access

Model Context Protocol (MCP) Go SDK: DNS rebinding vulnerability allows unauthorized access. Red Hat rates this important (CVSS 8). Weakness: CWE-1188. Affected package(s): devspaces/udi-rhel9:1779829736. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.28; OpenShift Serverless.

CVE-2026-34742
Unclassified
Apr 2, 2026
High7.5Linux

High [CVE-2026-34601] XML structure injection via CDATA terminator

XML structure injection via CDATA terminator. Red Hat rates this important (CVSS 7.5). Weakness: CWE-91. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34601
Unclassified
Apr 2, 2026

← All vendors