Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5199 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High8.8Linux

High [CVE-2006-10003] XML::Parser: Memory corruption via deeply nested XML files

XML::Parser: Memory corruption via deeply nested XML files. Red Hat rates this important (CVSS 8.8). Weakness: CWE-193. Affected package(s): perl-XML-Parser. Resolved in Red Hat advisory RHSA-2026:8608 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 11 more.

CVE-2006-10003
Red Hat Enterprise Linux
Mar 19, 2026
High7.5Linux

High [CVE-2026-4424] Information disclosure via heap out-of-bounds read in RAR archive processing

Information disclosure via heap out-of-bounds read in RAR archive processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): libarchive, rhcos, rhpam, rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1778274666, rhui5/cds-kubernetes-tp-rhel9:1777459441. Resolved in Red Hat advisory RHSA-2026:20040 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 25 more.

CVE-2026-4424
Red Hat Enterprise Linux
Mar 19, 2026
High7.8Vendor: MediumLinux

High [CVE-2025-69720] Buffer overflow vulnerability may lead to arbitrary code execution.

Buffer overflow vulnerability may lead to arbitrary code execution.. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-120. Affected package(s): ncurses, ncurses-main. Resolved in Red Hat advisory RHSA-2026:5913 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.

CVE-2025-69720
Unclassified
Mar 19, 2026
Medium6.5Linux

Medium [CVE-2006-10002] XML::Parser for Perl: Heap corruption and denial of service from crafted XML input

XML::Parser for Perl: Heap corruption and denial of service from crafted XML input. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-131. Affected package(s): perl-XML-Parser. Resolved in Red Hat advisory RHSA-2026:8608 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2006-10002
Unclassified
Mar 19, 2026
Medium6.5Linux

Medium [CVE-2026-4426] Denial of Service via malformed ISO file processing

Denial of Service via malformed ISO file processing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1335. Affected package(s): libarchive-main. Resolved in Red Hat advisory RHSA-2026:8944 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4426
Unclassified
Mar 19, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-4442] Heap buffer overflow in CSS

Heap buffer overflow in CSS. Red Hat rates this important (CVSS 9.6). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4442
Unclassified
Mar 18, 2026
Critical9.6Linux

Critical [CVE-2026-4439] Out of bounds memory access in WebGL

Out of bounds memory access in WebGL. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4439
Unclassified
Mar 18, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-4452] Integer overflow in ANGLE

Integer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4452
Unclassified
Mar 18, 2026
Critical9.6Linux

Critical [CVE-2026-4440] Out of bounds read and write in WebGL

Out of bounds read and write in WebGL. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4440
Unclassified
Mar 18, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-4458] Use after free in Extensions

Use after free in Extensions. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4458
Unclassified
Mar 18, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-4449] Use after free in Blink

Use after free in Blink. Red Hat rates this important (CVSS 9.6). Weakness: CWE-1341. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4449
Unclassified
Mar 18, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-4444] Stack buffer overflow in WebRTC

Stack buffer overflow in WebRTC. Red Hat rates this important (CVSS 9.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4444
Unclassified
Mar 18, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-4443] Heap buffer overflow in WebAudio

Heap buffer overflow in WebAudio. Red Hat rates this important (CVSS 9.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4443
Unclassified
Mar 18, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-4459] Out of bounds read and write in WebAudio

Out of bounds read and write in WebAudio. Red Hat rates this important (CVSS 9.6). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4459
Unclassified
Mar 18, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-4456] Use after free in Digital Credentials API

Use after free in Digital Credentials API. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4456
Unclassified
Mar 18, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-4463] Heap buffer overflow in WebRTC

Heap buffer overflow in WebRTC. Red Hat rates this important (CVSS 9.6). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-4463
Unclassified
Mar 18, 2026
High8.1Linux

High [CVE-2025-15031] Path Traversal Vulnerability in mlflow/mlflow

Path Traversal Vulnerability in mlflow/mlflow. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2025-15031
Unclassified
Mar 18, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-32636] Denial of Service via out-of-bounds write in NewXMLTree method

Denial of Service via out-of-bounds write in NewXMLTree method. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-787. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:17618 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7.

CVE-2026-32636
Unclassified
Mar 18, 2026
High7.3Linux

High [CVE-2026-31963] Arbitrary code execution via crafted CRAM file

Arbitrary code execution via crafted CRAM file. Red Hat rates this important (CVSS 7.3). Weakness: CWE-193. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31963
Unclassified
Mar 18, 2026
High7.3Linux

High [CVE-2026-31962] Heap buffer overflow leading to arbitrary code execution via crafted CRAM file

Heap buffer overflow leading to arbitrary code execution via crafted CRAM file. Red Hat rates this important (CVSS 7.3). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-31962
Unclassified
Mar 18, 2026

← All vendors