Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5194 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.8Linux

High [CVE-2026-33150] Arbitrary code execution via use-after-free in io_uring subsystem

Arbitrary code execution via use-after-free in io_uring subsystem. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-33150
Red Hat Enterprise Linux
Mar 20, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-32710] Remote Code Execution or Denial of Service via JSON_SCHEMA_VALID() function vulnerability

Remote Code Execution or Denial of Service via JSON_SCHEMA_VALID() function vulnerability. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-120. Affected package(s): mariadb11.8, galera, mariadb:11.8. Resolved in Red Hat advisory RHSA-2026:19182 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-32710
Unclassified
Mar 20, 2026
High7.1Linux

High [CVE-2026-4519] Command-line option injection in webbrowser.open() via crafted URLs

Command-line option injection in webbrowser.open() via crafted URLs. Red Hat rates this important (CVSS 7.1). Weakness: CWE-88. Affected package(s): python3.11, rhpam, discovery/discovery-server-rhel9:1775668717, python3.9, python3.12, rhaiis/vllm-cuda-rhel9:1778274666. Resolved in Red Hat advisory RHSA-2026:10140 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 18 more.

CVE-2026-4519
Red Hat Enterprise Linux
Mar 20, 2026
High8.3Linux

High [CVE-2026-32305] mTLS bypass allows unauthorized service access via fragmented ClientHello.

mTLS bypass allows unauthorized service access via fragmented ClientHello.. Red Hat rates this important (CVSS 8.3). Weakness: CWE-179. Affected package(s): devspaces/traefik-rhel9:1779786779, devspaces/traefik-rhel9:1776718585. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Dev Spaces 3.27; Red Hat OpenShift Dev Spaces 3.28; Red Hat OpenShift GitOps.

CVE-2026-32305
Unclassified
Mar 20, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-33036] Denial of Service via XML entity expansion bypass

Denial of Service via XML entity expansion bypass. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-776. Affected package(s): odf4/ocs-client-console-rhel9:1778050558, odf4/mcg-core-rhel9:1776403991, odf4/ocs-client-rhel9-operator:1778049818, odf4/odf-cloudnative-pg-rhel9-operator:1776406131, odf4/odf-csi-addons-sidecar-rhel9:1778050048, odf4/odf-multicluster-console-rhel9:1778078096. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33036
Unclassified
Mar 20, 2026
High7.5Linux

High [CVE-2026-32875] Denial of Service via large indent parameter in JSON serialization

Denial of Service via large indent parameter in JSON serialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32875
Unclassified
Mar 20, 2026
High7.5Linux

High [CVE-2026-32874] Denial of Service due to memory leak when parsing large integers

Denial of Service due to memory leak when parsing large integers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-32874
Unclassified
Mar 20, 2026
High7.5Linux

High [CVE-2026-23536] Unauthenticated Arbitrary File Read

Unauthenticated Arbitrary File Read. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-23536
Unclassified
Mar 20, 2026
High7.5Linux

High [CVE-2026-23538] Resource exhaustion via WebSocket endpoint

Resource exhaustion via WebSocket endpoint. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23538
Unclassified
Mar 20, 2026
Medium4.0Vendor: LowLinux

Medium [CVE-2026-4438] Invalid DNS hostname returned via gethostbyaddr functions

Invalid DNS hostname returned via gethostbyaddr functions. Red Hat rates this low (CVSS 4). Weakness: CWE-838. Affected package(s): glibc-main, rhui5/haproxy-rhel9:1781525671, insights-proxy/insights-proxy-container-rhel9:1780420428, glibc, rhui5/installer-rhel9:1781525693, costmanagement/costmanagement-metrics-rhel9-operator:1780946239. Resolved in Red Hat advisory RHSA-2026:19061 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-4438
Unclassified
Mar 20, 2026
Medium6.5Linux

Medium [CVE-2026-4437] Incorrect DNS response parsing via crafted DNS server response

Incorrect DNS response parsing via crafted DNS server response. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1286. Affected package(s): glibc-main, rhui5/haproxy-rhel9:1781525671, insights-proxy/insights-proxy-container-rhel9:1780420428, glibc, rhui5/installer-rhel9:1781525693, costmanagement/costmanagement-metrics-rhel9-operator:1780946239. Resolved in Red Hat advisory RHSA-2026:19061 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-4437
Unclassified
Mar 20, 2026
Medium6.5Linux

Medium [CVE-2026-33022] Denial of Service via long resolver names

Denial of Service via long resolver names. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-130. Affected package(s): openshift-pipelines/pipelines-controller-rhel9:1775707731, openshift-pipelines/pipelines-operator-bundle:1776925111, openshift-pipelines/pipelines-operator-bundle:1774871390, openshift-pipelines/pipelines-controller-rhel9:1774556221. Resolved in Red Hat advisory RHSA-2026:6170 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-33022
Unclassified
Mar 20, 2026
Critical10.0Linux

Critical [CVE-2026-30836] Unauthenticated certificate issuance via SCEP Update Request

Unauthenticated certificate issuance via SCEP Update Request. Red Hat rates this critical (CVSS 10). Weakness: CWE-306. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-30836
Unclassified
Mar 19, 2026
High8.2Vendor: MediumLinux

High [CVE-2026-22731] Authentication bypass via misconfigured Health Group additional path

Authentication bypass via misconfigured Health Group additional path. Red Hat rates this moderate (CVSS 8.2). Weakness: CWE-305. Affected package(s): devspaces/pluginregistry-rhel9:1776717247, spring-boot, devspaces/openvsx-rhel9:1776716842. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-22731
Unclassified
Mar 19, 2026
High8.2Linux

High [CVE-2026-3029] Arbitrary file write via path traversal vulnerability

Arbitrary file write via path traversal vulnerability. Red Hat rates this important (CVSS 8.2). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-3029
Red Hat Enterprise Linux
Mar 19, 2026
High8.8Linux

High [CVE-2006-10003] XML::Parser: Memory corruption via deeply nested XML files

XML::Parser: Memory corruption via deeply nested XML files. Red Hat rates this important (CVSS 8.8). Weakness: CWE-193. Affected package(s): perl-XML-Parser. Resolved in Red Hat advisory RHSA-2026:8608 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 11 more.

CVE-2006-10003
Red Hat Enterprise Linux
Mar 19, 2026
High7.5Linux

High [CVE-2026-4424] Information disclosure via heap out-of-bounds read in RAR archive processing

Information disclosure via heap out-of-bounds read in RAR archive processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): libarchive, rhcos, rhpam, rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1778274666, rhui5/cds-kubernetes-tp-rhel9:1777459441. Resolved in Red Hat advisory RHSA-2026:20040 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 25 more.

CVE-2026-4424
Red Hat Enterprise Linux
Mar 19, 2026
High7.8Vendor: MediumLinux

High [CVE-2025-69720] Buffer overflow vulnerability may lead to arbitrary code execution.

Buffer overflow vulnerability may lead to arbitrary code execution.. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-120. Affected package(s): ncurses, ncurses-main. Resolved in Red Hat advisory RHSA-2026:5913 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2025-69720
Unclassified
Mar 19, 2026
Medium6.5Linux

Medium [CVE-2006-10002] XML::Parser for Perl: Heap corruption and denial of service from crafted XML input

XML::Parser for Perl: Heap corruption and denial of service from crafted XML input. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-131. Affected package(s): perl-XML-Parser. Resolved in Red Hat advisory RHSA-2026:8608 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2006-10002
Unclassified
Mar 19, 2026
Medium6.5Linux

Medium [CVE-2026-4426] Denial of Service via malformed ISO file processing

Denial of Service via malformed ISO file processing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1335. Affected package(s): libarchive-main. Resolved in Red Hat advisory RHSA-2026:8944 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4426
Unclassified
Mar 19, 2026

← All vendors