Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5197 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.3Linux

High [CVE-2026-2045] Remote Code Execution via out-of-bounds write in XWD file parsing

Remote Code Execution via out-of-bounds write in XWD file parsing. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:5391 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-2045
Red Hat Enterprise Linux
Feb 20, 2026
High8.8Linux

High [CVE-2026-2044] Remote Code Execution via uninitialized memory in PGM file parsing

Remote Code Execution via uninitialized memory in PGM file parsing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-908. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:5391 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-2044
Red Hat Enterprise Linux
Feb 20, 2026
High7.8Linux

High [CVE-2026-2492] Local privilege escalation via uncontrolled search path for plugins

Local privilege escalation via uncontrolled search path for plugins. Red Hat rates this important (CVSS 7.8). Weakness: CWE-427. Affected package(s): rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1776243249, rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1776319453. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift AI 2.25.

CVE-2026-2492
Unclassified
Feb 20, 2026
High7.3Linux

High [CVE-2026-2033] MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2033
Unclassified
Feb 20, 2026
High8.8Linux

High [CVE-2026-0797] Remote Code Execution via ICO File Parsing Vulnerability

Remote Code Execution via ICO File Parsing Vulnerability. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:5391 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.

CVE-2026-0797
Red Hat Enterprise Linux
Feb 20, 2026
High7.1Linux

High [CVE-2026-25896] Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling

Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling. Red Hat rates this important (CVSS 7.1). Weakness: CWE-79. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; and 8 more.

CVE-2026-25896
Unclassified
Feb 20, 2026
High8.1Linux

High [CVE-2026-2472] Arbitrary code execution via Stored Cross-Site Scripting (XSS)

Arbitrary code execution via Stored Cross-Site Scripting (XSS). Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1775144403. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Vertex AI SDK for Python; Red Hat OpenShift AI 2.25.

CVE-2026-2472
Unclassified
Feb 20, 2026
High7.1Linux

High [CVE-2026-2818] org.springframework.data/spring-data-geode: Spring Data Geode: Path traversal vulnerability allows arbitrary file write via import snapshot functionality.

org.springframework.data/spring-data-geode: Spring Data Geode: Path traversal vulnerability allows arbitrary file write via import snapshot functionality.. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2818
Unclassified
Feb 20, 2026
High7.1Vendor: MediumLinux

High [CVE-2026-26960] Arbitrary file read/write via malicious archive hardlink creation

Arbitrary file read/write via malicious archive hardlink creation. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-22. Affected package(s): rhtas/rekor-search-ui-rhel9:1773308315, network-observability/network-observability-console-plugin-rhel9:1774431617, devspaces/dashboard-rhel9:1774476526, devspaces/code-rhel9:1774448966. Resolved in Red Hat advisory RHSA-2026:5447 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-26960
Unclassified
Feb 20, 2026
High8.4Linux

High [CVE-2026-26967] Arbitrary code execution via H.264 unpacketizer heap-based buffer overflow

Arbitrary code execution via H.264 unpacketizer heap-based buffer overflow. Red Hat rates this important (CVSS 8.4). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-26967
Unclassified
Feb 20, 2026
High7.4Linux

High [CVE-2024-7730 +1] heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for CVE-2024-7730)

heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for CVE-2024-7730). Red Hat rates this important (CVSS 7.4). Weakness: CWE-122. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2024-7730CVE-2026-3195
Unclassified
Feb 20, 2026
Medium6.5Linux

Medium [CVE-2026-26996] Denial of Service via specially crafted glob patterns

Denial of Service via specially crafted glob patterns. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1333. Affected package(s): openshift4/ose-console-rhel9:1780365421, quay/quay-rhel9:1775069491, nodejs:20, nodejs:22, rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1776336652, devspaces/openvsx-rhel9:1779528224. Resolved in Red Hat advisory RHSA-2026:13508 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-26996
Unclassified
Feb 20, 2026
Critical9.3Vendor: HighLinux

Critical [CVE-2026-24834] Arbitrary code execution in guest virtual machine via file system modification

Arbitrary code execution in guest virtual machine via file system modification. Red Hat rates this important (CVSS 9.3). Weakness: CWE-281. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-24834
Unclassified
Feb 19, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-25940] PDF injection in AcroForm module allows arbitrary JavaScript execution (RadioButton children)

PDF injection in AcroForm module allows arbitrary JavaScript execution (RadioButton children). Red Hat rates this important (CVSS 9.6). Weakness: CWE-116. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.

CVE-2026-25940
Unclassified
Feb 19, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-25755] PDF object injection via unsanitized input in addJS method

PDF object injection via unsanitized input in addJS method. Red Hat rates this important (CVSS 9.6). Weakness: CWE-94. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.

CVE-2026-25755
Unclassified
Feb 19, 2026
High8.8Linux

High [CVE-2026-26318] Arbitrary code execution via unsanitized `locate` output

Arbitrary code execution via unsanitized `locate` output. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Developer Hub.

CVE-2026-26318
Unclassified
Feb 19, 2026
High8.4Linux

High [CVE-2026-26280] Arbitrary command execution via unsanitized network interface parameter

Arbitrary command execution via unsanitized network interface parameter. Red Hat rates this important (CVSS 8.4). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Developer Hub.

CVE-2026-26280
Unclassified
Feb 19, 2026
High7.5Linux

High [CVE-2026-26278] Denial of Service via unlimited XML entity expansion

Denial of Service via unlimited XML entity expansion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; and 8 more.

CVE-2026-26278
Unclassified
Feb 19, 2026
High7.8Linux

High [CVE-2026-26200] Denial of Service due to heap buffer overflow when parsing a crafted h5 file

Denial of Service due to heap buffer overflow when parsing a crafted h5 file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-26200
Red Hat Enterprise Linux
Feb 19, 2026
High7.5Linux

High [CVE-2026-25535] denial of service via malicious GIF dimensions

denial of service via malicious GIF dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.

CVE-2026-25535
Unclassified
Feb 19, 2026

← All vendors