Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5244 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium6.5Linux

Medium [CVE-2026-23732] Denial of Service via FastGlyph parsing buffer overflow

Denial of Service via FastGlyph parsing buffer overflow. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-122. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-23732
Unclassified
Jan 19, 2026
Medium6.3Vendor: HighLinux

Medium [CVE-2026-1145] quickjs-ng quickjs: Heap-based buffer overflow leading to information disclosure or denial of service

quickjs-ng quickjs: Heap-based buffer overflow leading to information disclosure or denial of service. Red Hat rates this important (CVSS 6.3). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-1145
Unclassified
Jan 19, 2026
Medium6.3Vendor: HighLinux

Medium [CVE-2026-1144] Use-after-free vulnerability in Atomics Ops Handler

Use-after-free vulnerability in Atomics Ops Handler. Red Hat rates this important (CVSS 6.3). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-1144
Unclassified
Jan 19, 2026
Medium5.8Linux

Medium [CVE-2026-1180] Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri

Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-918. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-1180
Unclassified
Jan 19, 2026
Low3.1Linux

Low [CVE-2026-1190] Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData

Keycloak SAML brokering: Response delay due to unchecked NotOnOrAfter in SubjectConfirmationData. Red Hat rates this low (CVSS 3.1). Weakness: CWE-112. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-1190
Unclassified
Jan 19, 2026
High8.2Linux

High [CVE-2026-23745] Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives

Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives. Red Hat rates this important (CVSS 8.2). Weakness: CWE-22. Affected package(s): network-observability/network-observability-console-plugin-rhel9:1771227650, devspaces/udi-rhel9:1774451954, rhtas/rekor-search-ui-rhel9:1770107452, rhtas/rekor-search-ui-rhel9:1770739056, rhoai/odh-dashboard-rhel9:1779189627, linux-sgx. Resolved in Red Hat advisory RHSA-2026:19712 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; and 19 more.

CVE-2026-23745
Red Hat Enterprise Linux
Jan 16, 2026
HighLinux

High [CVE-2021-47839] Remote Code Execution via persistent cross-site scripting

Remote Code Execution via persistent cross-site scripting. Red Hat rates this important. Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2021-47839
Unclassified
Jan 16, 2026
High7.5Linux

High [CVE-2026-23490] Denial of Service due to memory exhaustion from malformed RELATIVE-OID

Denial of Service due to memory exhaustion from malformed RELATIVE-OID. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): python-pyasn1, ansible-automation-platform, fence-agents, rhelai3/bootc-azure-rocm-rhel9:1778677745, resource-agents, automation-controller. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Enterprise Linux 10.0 Extended Update Support; and 34 more.

CVE-2026-23490
Red Hat Enterprise Linux
Jan 16, 2026
High8.1Linux

High [CVE-2025-62291] Arbitrary Code Execution and Denial of Service via crafted EAP-MSCHAPv2 message

Arbitrary Code Execution and Denial of Service via crafted EAP-MSCHAPv2 message. Red Hat rates this important (CVSS 8.1). Weakness: CWE-191. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2025-62291
Unclassified
Jan 16, 2026
High8.9Linux

High [CVE-2026-23527] HTTP Request Smuggling due to improper case-sensitive parsing of Transfer-Encoding header

HTTP Request Smuggling due to improper case-sensitive parsing of Transfer-Encoding header. Red Hat rates this important (CVSS 8.9). Weakness: CWE-444. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-23527
Unclassified
Jan 15, 2026
High7.5Linux

High [CVE-2026-22775] Denial of Service due to improper input validation

Denial of Service due to improper input validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-405. Affected package(s): rhtas/rekor-search-ui-rhel9:1770107452, rhtas/rekor-search-ui-rhel9:1770739056. Resolved in Red Hat advisory RHSA-2026:2926 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Trusted Artifact Signer 1.2; Red Hat Trusted Artifact Signer 1.3; Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-22775
Unclassified
Jan 15, 2026
High7.5Linux

High [CVE-2026-22774] Denial of Service due to excessive resource consumption from untrusted input

Denial of Service due to excessive resource consumption from untrusted input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-405. Affected package(s): rhtas/rekor-search-ui-rhel9:1770107452, rhtas/rekor-search-ui-rhel9:1770739056. Resolved in Red Hat advisory RHSA-2026:2926 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Trusted Artifact Signer 1.2; Red Hat Trusted Artifact Signer 1.3; Red Hat Build of Podman Desktop - Tech Preview.

CVE-2026-22774
Unclassified
Jan 15, 2026
High7.6Linux

High [CVE-2026-0897] Denial of Service via crafted HDF5 weight loading file

Denial of Service via crafted HDF5 weight loading file. Red Hat rates this important (CVSS 7.6). Weakness: CWE-770. Affected package(s): rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1772093304, rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1772093283, rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1772093300, rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1771502844, rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1771502884, rhoai/odh-modelmesh-runtime-adapter-rhel9:1772094445. Resolved in Red Hat advisory RHSA-2026:4271 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat Trusted Artifact Signer 1.3; Red Hat OpenShift AI (RHOAI).

CVE-2026-0897
Unclassified
Jan 15, 2026
Medium5.9Linux

Medium [CVE-2026-22045] Denial of Service via ACME TLS-ALPN fast path resource exhaustion

Denial of Service via ACME TLS-ALPN fast path resource exhaustion. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-770. Affected package(s): devspaces/traefik-rhel9:1774227265. Resolved in Red Hat advisory RHSA-2026:6192 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-22045
Unclassified
Jan 15, 2026
Medium5.3Linux

Medium [CVE-2026-0915] Information disclosure via zero-valued network query

Information disclosure via zero-valued network query. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-908. Affected package(s): insights-proxy/insights-proxy-container-rhel9:1773685509, rhui5/rhua-rhel9:1773670137, glibc, discovery/discovery-server-rhel9:1773273243, discovery/discovery-ui-rhel9:1773273070, glibc-main. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-0915
Unclassified
Jan 15, 2026
Medium5.3Linux

Medium [CVE-2026-1002] static handler component cache can be manipulated to deny the access to static files

static handler component cache can be manipulated to deny the access to static files. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected package(s): rhoai/odh-trustyai-service-rhel9:1776748859, eap7-wildfly, vertx-core, cryostat/jfr-datasource-rhel9:4.2.0, vertx-core-logging, devspaces/server-rhel9:1774228740. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7.

CVE-2026-1002
Unclassified
Jan 15, 2026
Medium5.9Linux

Medium [CVE-2026-0990] Denial of Service via uncontrolled recursion in XML catalog processing

Denial of Service via uncontrolled recursion in XML catalog processing. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-674. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:7519 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-0990
Unclassified
Jan 15, 2026
Low3.7Linux

Low [CVE-2026-0988] Denial of Service via Integer Overflow in g_buffered_input_stream_peek()

Denial of Service via Integer Overflow in g_buffered_input_stream_peek(). Red Hat rates this low (CVSS 3.7). Weakness: CWE-190. Affected package(s): glib2-main. Resolved in Red Hat advisory RHSA-2026:7461 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-0988
Unclassified
Jan 15, 2026
Low3.7Linux

Low [CVE-2026-0989] Unbounded RelaxNG Include Recursion Leading to Stack Overflow

Unbounded RelaxNG Include Recursion Leading to Stack Overflow. Red Hat rates this low (CVSS 3.7). Weakness: CWE-674. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:7519 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-0989
Unclassified
Jan 15, 2026
Low2.9Linux

Low [CVE-2026-0992] Denial of Service via crafted XML catalogs

Denial of Service via crafted XML catalogs. Red Hat rates this low (CVSS 2.9). Weakness: CWE-400. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:7519 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-0992
Unclassified
Jan 15, 2026

← All vendors