Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4432 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.2Red Hat

High [CVE-2026-95511] lpadmin can escalate to root via privileged serial backend (cups2root)

lpadmin can escalate to root via privileged serial backend (cups2root). Red Hat rates this important (CVSS 8.2). Weakness: CWE-269. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-95511
Unclassified
Sep 22, 2026
High7.5Red Hat

High [CVE-2026-94627] Denial of Service via GPU memory exhaustion

Denial of Service via GPU memory exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-94627
Unclassified
Sep 21, 2026
High7.5Red Hat

High [CVE-2026-94626] Denial of Service via unvalidated memory allocation parameter

Denial of Service via unvalidated memory allocation parameter. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-94626
Unclassified
Sep 21, 2026
High7.5Red Hat

High [CVE-2026-94625] Resource exhaustion via rejected prefill requests

Resource exhaustion via rejected prefill requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-94625
Unclassified
Sep 21, 2026
High7.5Red Hat

High [CVE-2026-94624] Denial of Service via unbounded P2P KV offloading sessions

Denial of Service via unbounded P2P KV offloading sessions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-94624
Unclassified
Sep 21, 2026
High7.5Red Hat

High [CVE-2026-94623] Denial of Service via NIXL multi-prompt assertion failure

Denial of Service via NIXL multi-prompt assertion failure. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-94623
Unclassified
Sep 21, 2026
High7.5Red Hat

High [CVE-2026-94622] Denial of Service via Incomplete NIXL KV Transfer Metadata

Denial of Service via Incomplete NIXL KV Transfer Metadata. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-94622
Unclassified
Sep 21, 2026
High8.4Red Hat

High [CVE-2026-49811] Dell Command | Monitor: Dell Command | Monitor: Elevation of Privileges via Incorrect Permission Assignment

Dell Command | Monitor: Dell Command | Monitor: Elevation of Privileges via Incorrect Permission Assignment. Red Hat rates this important (CVSS 8.4). Weakness: CWE-266.

CVE-2026-49811
Unclassified
Sep 21, 2026
High7.5Red Hat

High [CVE-2026-94449] Memory leak in @ApplyGuard leads to Denial of Service

Memory leak in @ApplyGuard leads to Denial of Service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apicurio Registry 3; Red Hat build of Quarkus.

CVE-2026-94449
Unclassified
Sep 21, 2026
High8.1Red Hat

High [CVE-2026-94184] Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure or process termination under memory hardening. Affects v5.0.8 through v6.6.6. Red Hat provided an estimated impact and CVSS vector and is subject to change. Red Hat severity: Important. Weakness: CWE-121. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: fetchmail.

CVE-2026-94184
Red Hat Enterprise Linux
Sep 21, 2026
High8.1Red Hat

High [CVE-2026-80110] Dogtag PKI v2 REST ACL filter's reverse-lexicographic tie-break lets a CA Agent invoke the admin-only raw profile creation endpoint

Dogtag PKI v2 REST ACL filter's reverse-lexicographic tie-break lets a CA Agent invoke the admin-only raw profile creation endpoint. Red Hat rates this important (CVSS 8.1). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:73765 with package dogtag-pki-0:11.9.0-5.el10_2, pki-core-0:11.7.1-2.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-80110
Unclassified
Sep 21, 2026
High7.4Red Hat

High [CVE-2026-75939] Release signature verification: OpenPGP SignatureError checked before signed body is consumed

Release signature verification: OpenPGP SignatureError checked before signed body is consumed. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-75939
Unclassified
Sep 21, 2026
High8.3Red Hat

High [CVE-2026-88807] Code injection via heap overflow in RenderQueryPictFormats

Code injection via heap overflow in RenderQueryPictFormats. Red Hat rates this important (CVSS 8.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: libxrender.

CVE-2026-88807
Red Hat Enterprise Linux
Sep 21, 2026
High7.5Red Hat

High [CVE-2026-88806] Heap-based buffer overflow via malicious X server

Heap-based buffer overflow via malicious X server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: libx11.

CVE-2026-88806
Red Hat Enterprise Linux
Sep 21, 2026
High7.1Red Hat

High [CVE-2026-94368] Presigned PUT URL escalation to CopyObject via unsigned x-amz-copy-source header

Presigned PUT URL escalation to CopyObject via unsigned x-amz-copy-source header. Red Hat rates this important (CVSS 7.1). Weakness: CWE-347. Affected product named by the advisory: Red Hat Openshift Data Foundation 4.

CVE-2026-94368
Unclassified
Sep 21, 2026
High7.5Red Hat

High [CVE-2026-91866] Denial of Service via crafted WS-Policy documents

Denial of Service via crafted WS-Policy documents. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7.

CVE-2026-91866
Unclassified
Sep 21, 2026
High7.5Red Hat

High [CVE-2026-91865] Denial of Service via crafted WS-Policy documents

Denial of Service via crafted WS-Policy documents. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7.

CVE-2026-91865
Unclassified
Sep 21, 2026
High7.5Red Hat

High [CVE-2026-91864] Denial of Service via crafted WS-Policy documents

Denial of Service via crafted WS-Policy documents. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7.

CVE-2026-91864
Unclassified
Sep 21, 2026
High7.5Red Hat

High [CVE-2026-91863] Denial of Service via uncontrolled recursion in WS-Policy document parsing

Denial of Service via uncontrolled recursion in WS-Policy document parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7.

CVE-2026-91863
Unclassified
Sep 21, 2026
High8.8Red Hat

High [CVE-2026-92574] CRI-O checkpoint restore bypasses destination security context

CRI-O checkpoint restore bypasses destination security context. Red Hat rates this important (CVSS 8.8). Weakness: CWE-250. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-92574
Unclassified
Sep 21, 2026

← All vendors