Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5204 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High8.1Linux

High [CVE-2026-33217] Access control bypass via unapplied ACLs in MQTT namespace

Access control bypass via unapplied ACLs in MQTT namespace. Red Hat rates this important (CVSS 8.1). Weakness: CWE-425. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.

CVE-2026-33217
Unclassified
Mar 25, 2026
High8.6Linux

High [CVE-2026-33216] Information disclosure of MQTT passwords through monitoring endpoints

Information disclosure of MQTT passwords through monitoring endpoints. Red Hat rates this important (CVSS 8.6). Weakness: CWE-213. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.

CVE-2026-33216
Unclassified
Mar 25, 2026
High7.5Linux

High [CVE-2026-29785] Denial of Service via leafnode compression

Denial of Service via leafnode compression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.

CVE-2026-29785
Unclassified
Mar 25, 2026
High7.5Linux

High [CVE-2026-27889] Denial of Service via malformed WebSockets frame

Denial of Service via malformed WebSockets frame. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.

CVE-2026-27889
Unclassified
Mar 25, 2026
High7.5Linux

High [CVE-2026-3104] Denial of Service via specially crafted domain query causing a memory leak

Denial of Service via specially crafted domain query causing a memory leak. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: BIND 9; Red Hat Hardened Images.

CVE-2026-3104
Unclassified
Mar 25, 2026
High7.5Linux

High [CVE-2026-1519] Denial of Service via maliciously crafted DNSSEC-validated zone

Denial of Service via maliciously crafted DNSSEC-validated zone. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): bind, bind9.16, bind9.18, rhcos, bind-main. Resolved in Red Hat advisory RHSA-2026:29863 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: BIND 9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; and 16 more.

CVE-2026-1519
Red Hat Enterprise Linux
Mar 25, 2026
High7.5Linux

High [CVE-2026-3608] Denial of Service via maliciously crafted message

Denial of Service via maliciously crafted message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Affected package(s): kea. Resolved in Red Hat advisory RHSA-2026:7342 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support.

CVE-2026-3608
Red Hat Enterprise Linux
Mar 25, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-23375] deny THP for files on anonymous inodes

deny THP for files on anonymous inodes. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:21557 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-23375
Unclassified
Mar 25, 2026
High8.3Linux

High [CVE-2025-67030] org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method

org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method. Red Hat rates this important (CVSS 8.3). Weakness: CWE-22. Affected package(s): eap8-jboss-logging, eap8-guava-failureaccess, eap8-activemq-artemis, eap8-netty-transport-native-epoll, eap8-reactivex-rxjava, eap8-wildfly-javadocs. Resolved in Red Hat advisory RHSA-2026:7109 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss EAP 8.1 for RHEL 8; Red Hat JBoss EAP 8.1 for RHEL 9; Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); and 32 more.

CVE-2025-67030
Red Hat Enterprise Linux
Mar 25, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-23392] release flowtable after rcu grace period on error

release flowtable after rcu grace period on error. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23392
Unclassified
Mar 25, 2026
Medium6.5Linux

Medium [CVE-2026-33809] Denial of Service via maliciously crafted TIFF file

Denial of Service via maliciously crafted TIFF file. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1285. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33809
Unclassified
Mar 25, 2026
Medium6.6Linux

Medium [CVE-2026-34085] Security flaw allows arbitrary code execution or system crash

Security flaw allows arbitrary code execution or system crash. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-193. Affected package(s): fontconfig-main. Resolved in Red Hat advisory RHSA-2026:13722 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-34085
Unclassified
Mar 25, 2026
Medium5.4Linux

Medium [CVE-2026-3591] Unauthorized access due to use-after-return vulnerability in DNS query handling

Unauthorized access due to use-after-return vulnerability in DNS query handling. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-825. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3591
Unclassified
Mar 25, 2026
Medium6.5Linux

Medium [CVE-2026-3119] Denial of Service via authenticated TKEY queries

Denial of Service via authenticated TKEY queries. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-237. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-3119
Unclassified
Mar 25, 2026
High8.2Linux

High [CVE-2026-4371] Out of bounds read in IMAP parsing

Out of bounds read in IMAP parsing. Red Hat rates this important (CVSS 8.2). Weakness: CWE-130. Affected package(s): thunderbird. Resolved in Red Hat advisory RHSA-2026:8286 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 9 more.

CVE-2026-4371
Red Hat Enterprise Linux
Mar 24, 2026
High7.3Linux

High [CVE-2026-33412] Arbitrary code execution via command injection in glob() function

Arbitrary code execution via command injection in glob() function. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/cds-kubernetes-tp-rhel9:1777459441, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim. Resolved in Red Hat advisory RHSA-2026:6915 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 23 more.

CVE-2026-33412
Red Hat Enterprise Linux
Mar 24, 2026
High7.8Linux

High [CVE-2026-32647] Denial of Service or Code Execution via specially crafted MP4 files

Denial of Service or Code Execution via specially crafted MP4 files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-125. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Open Source; NGINX Plus; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 7 more.

CVE-2026-32647
Red Hat Enterprise Linux
Mar 24, 2026
High7.8Linux

High [CVE-2026-4775] Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing

Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): libtiff-main, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, compat-libtiff3, libtiff, mingw-libtiff. Resolved in Red Hat advisory RHSA-2026:30349 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 13 more.

CVE-2026-4775
Red Hat Enterprise Linux
Mar 24, 2026
High7.5Linux

High [CVE-2026-27651] Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled

Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Open Source; NGINX Plus; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 6 more.

CVE-2026-27651
Red Hat Enterprise Linux
Mar 24, 2026
High8.2Linux

High [CVE-2026-27654] Denial of Service or file modification via buffer overflow in ngx_http_dav_module

Denial of Service or file modification via buffer overflow in ngx_http_dav_module. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Open Source; NGINX Plus; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 6 more.

CVE-2026-27654
Red Hat Enterprise Linux
Mar 24, 2026

← All vendors