Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5198 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.5Linux

High [CVE-2026-25535] denial of service via malicious GIF dimensions

denial of service via malicious GIF dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.

CVE-2026-25535
Unclassified
Feb 19, 2026
Low3.8Linux

Low [CVE-2026-2733] Missing Check on Disabled Client for Docker Registry Protocol

Missing Check on Disabled Client for Docker Registry Protocol. Red Hat rates this low (CVSS 3.8). Weakness: CWE-285. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2733
Unclassified
Feb 19, 2026
High7.5Linux

High [CVE-2026-22860] Rack Directory Traversal via Rack:Directory

Rack Directory Traversal via Rack:Directory. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat 3scale API Management Platform 2.

CVE-2026-22860
Unclassified
Feb 18, 2026
High8.8Linux

High [CVE-2025-14009] Zip Slip Vulnerability in nltk Leading to Code Execution

Zip Slip Vulnerability in nltk Leading to Code Execution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1775144403, rhoai/odh-ta-lmes-job-rhel9:1776271296. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; OpenShift Lightspeed; Red Hat OpenShift AI (RHOAI).

CVE-2025-14009
Unclassified
Feb 18, 2026
High8.8Linux

High [CVE-2026-2648] Heap buffer overflow in PDFium

Heap buffer overflow in PDFium. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2648
Unclassified
Feb 18, 2026
High8.8Linux

High [CVE-2026-2649] Integer overflow in V8

Integer overflow in V8. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2649
Unclassified
Feb 18, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-23216] Fix use-after-free in iscsit_dec_conn_usage_count()

Fix use-after-free in iscsit_dec_conn_usage_count(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-413. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:9870 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23216
Unclassified
Feb 18, 2026
Medium4.3Linux

Medium [CVE-2026-27100] Information disclosure via unauthorized access to build parameters

Information disclosure via unauthorized access to build parameters. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-551. Affected package(s): ocp-tools. Resolved in Red Hat advisory RHSA-2026:10209 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27100
Unclassified
Feb 18, 2026
Medium4.6Linux

Medium [CVE-2026-27099] Stored Cross-site Scripting (XSS) via unescaped user-provided offline cause description

Stored Cross-site Scripting (XSS) via unescaped user-provided offline cause description. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-79. Affected package(s): ocp-tools. Resolved in Red Hat advisory RHSA-2026:10209 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-27099
Unclassified
Feb 18, 2026
High7.4Linux

High [CVE-2026-24734] Certificate revocation bypass due to improper OCSP response validation

Certificate revocation bypass due to improper OCSP response validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected package(s): jws6-tomcat-native, tomcat, tomcat10-main, jws6-tomcat, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:5612 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 6.2 on RHEL 10; Red Hat JBoss Web Server 6.2 on RHEL 8; and 3 more.

CVE-2026-24734
Red Hat Enterprise Linux
Feb 17, 2026
High7.1Linux

High [CVE-2026-24708] Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova

Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova. Red Hat rates this important (CVSS 7.1). Weakness: CWE-73. Affected package(s): openstack-nova. Resolved in Red Hat advisory RHSA-2026:7884 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenStack Services on OpenShift 18.0; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more.

CVE-2026-24708
Unclassified
Feb 17, 2026
Medium5.3Vendor: LowLinux

Medium [CVE-2026-24733] security constraint bypass with HTTP/0.9

security constraint bypass with HTTP/0.9. Red Hat rates this low (CVSS 5.3). Weakness: CWE-20. Affected package(s): tomcat, jws6-tomcat, tomcat10-main, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:12195 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-24733
Unclassified
Feb 17, 2026
Medium5.3Linux

Medium [CVE-2025-66614] Client certificate verification bypass due to virtual host mapping

Client certificate verification bypass due to virtual host mapping. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1289. Affected package(s): tomcat, jws6-tomcat, tomcat10-main, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:12195 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2025-66614
Unclassified
Feb 17, 2026
Medium4.0Linux

Medium [CVE-2026-2625] Denial of Service via crafted RPM file during signature verification

Denial of Service via crafted RPM file during signature verification. Red Hat rates this moderate (CVSS 4). Weakness: CWE-347. Affected package(s): rust-rpm-sequoia-main. Resolved in Red Hat advisory RHSA-2026:12682 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2625
Unclassified
Feb 17, 2026
High7.5Linux

High [CVE-2026-2447] Heap buffer overflow in libvpx

Heap buffer overflow in libvpx. Red Hat rates this important (CVSS 7.5). Affected package(s): libvpx, thunderbird, rhaiis/vllm-rocm-rhel9:1775680262, firefox, rhaiis/vllm-cuda-rhel9:1775680192, rhaiis/vllm-spyre-rhel9:1778244546. Resolved in Red Hat advisory RHSA-2026:3967 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 11 more.

CVE-2026-2447
Red Hat Enterprise Linux
Feb 16, 2026
Medium5.3Linux

Medium [CVE-2026-2575] Denial of Service due to excessive SAMLRequest decompression

Denial of Service due to excessive SAMLRequest decompression. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-409. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-2575
Unclassified
Feb 16, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-23171] Linux kernel: Use-after-free in bonding module can cause system crash or arbitrary code execution

Linux kernel: Use-after-free in bonding module can cause system crash or arbitrary code execution. Red Hat rates this moderate (CVSS 7). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:8342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23171
Unclassified
Feb 14, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-23210] Linux kernel: Denial of Service in ice driver due to race condition during VSI rebuild

Linux kernel: Denial of Service in ice driver due to race condition during VSI rebuild. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:6570 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.

CVE-2026-23210
Unclassified
Feb 14, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-23209] fix error recovery in macvlan_common_newlink()

fix error recovery in macvlan_common_newlink(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:6954 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-23209
Unclassified
Feb 14, 2026
High7.6Vendor: MediumLinux

High [CVE-2026-23136] Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state

Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-440. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27708 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-23136
Unclassified
Feb 14, 2026

← All vendors