Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5265 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.2Linux

High [CVE-2025-66648] Cross-Site Scripting via untrusted user input

Cross-Site Scripting via untrusted user input. Red Hat rates this important (CVSS 7.2). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2025-66648
Unclassified
Jan 5, 2026
High8.1Linux

High [CVE-2025-65110] Arbitrary code execution through malicious visualization definitions

Arbitrary code execution through malicious visualization definitions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2025-65110
Unclassified
Jan 5, 2026
Medium6.8Linux

Medium [CVE-2025-69228] Denial of Service via memory exhaustion from crafted POST request

Denial of Service via memory exhaustion from crafted POST request. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-770. Affected package(s): ansible-automation-platform, rhaiis/vllm-cuda-rhel9:1774351144, rhoai/odh-caikit-nlp-rhel9:1780069094, rhoai/odh-vllm-gaudi-rhel9:1772093278, rhaiis/model-opt-cuda-rhel9:1774547384, rhoai/odh-vllm-cpu-rhel9:1776259063. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2025-69228
Unclassified
Jan 5, 2026
High7.5Linux

High [CVE-2025-67269] Denial of Service due to malformed NAVCOM packet parsing

Denial of Service due to malformed NAVCOM packet parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Affected package(s): gpsd-minimal, gpsd. Resolved in Red Hat advisory RHSA-2026:0770 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2025-67269
Red Hat Enterprise Linux
Jan 2, 2026
High7.5Linux

High [CVE-2025-67268] Arbitrary code execution via heap-based out-of-bounds write in NMEA2000 packet handling

Arbitrary code execution via heap-based out-of-bounds write in NMEA2000 packet handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. Affected package(s): gpsd-minimal, gpsd. Resolved in Red Hat advisory RHSA-2026:1621 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.

CVE-2025-67268
Red Hat Enterprise Linux
Jan 2, 2026
High8.7Linux

High [CVE-2026-21428] Server-Side Request Forgery via header injection

Server-Side Request Forgery via header injection. Red Hat rates this important (CVSS 8.7). Weakness: CWE-93. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-21428
Unclassified
Jan 1, 2026
High7.8Linux

High [CVE-2025-11157] Remote Code Execution via insecure YAML deserialization

Remote Code Execution via insecure YAML deserialization. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. Affected package(s): rhoai/odh-feature-server-rhel9:1776338381. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI (RHOAI).

CVE-2025-11157
Unclassified
Jan 1, 2026
High8.7Linux

High [CVE-2025-11393] Insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: improper proxy configuration allows unauthorized administrative commands

A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user within the cluster to send unauthorized commands to the management platform, effectively acting with the full permissions of the cluster administrator. This could lead to unauthorized changes to the cluster's configuration or status on the Red Hat platform. Affected products named by the advisory: Red Hat Lightspeed (formerly Insights) for Runtimes 1.0; Red Hat Runtimes Inventory Operator.

CVE-2025-11393
Unclassified
Dec 15, 2025
Medium6.5Linux

Medium [CVE-2025-14512] integer overflow in glib gio attribute escaping causes heap buffer overflow

A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values. This vulnerability is rated Moderate for Red Hat products because an integer overflow in GLib's GIO `escape_byte_string()` function can lead to a heap buffer overflow and denial-of-service. This occurs when processing specially crafted file or remote filesystem attribute values, requiring an attacker to provide malicious input. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 16 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; and 12 more.

CVE-2025-14512
Red Hat Enterprise Linux
Dec 11, 2025
Medium5.6Linux

Medium [CVE-2025-14087] Glib: glib: buffer underflow in gvariant parser leads to heap corruption

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; and 18 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; and 13 more.

CVE-2025-14087
Red Hat Enterprise Linux
Dec 10, 2025
High7.5Linux

High [CVE-2024-3884] Undertow: outofmemory when parsing form data encoding with application/x-www-form-urlencoded

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform; Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; and 7 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9; and 2 more.

CVE-2024-3884
Red Hat Enterprise Linux
Dec 3, 2025
Medium5.0Linux

Medium [CVE-2025-12103] Openshift-ai: trusty ai grants all authenticated users to list pods in any namespace

A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a cluster permissions to get, list, watch any pod in any namespace on the cluster. TrustyAI is creating a role `trustyai-service-operator-lmeval-user-role` and a CRB `trustyai-service-operator-default-lmeval-user-rolebinding` which is being applied to `system:authenticated` making it so that every single user or service account can get a list of pods running in any namespace on the cluster Additionally users can access all `persistentvolumeclaims` and `lmevaljobs` Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.0; Red Hat OpenShift AI (RHOAI).

CVE-2025-12103
Unclassified
Oct 28, 2025
Medium6.0Linux

Medium [CVE-2025-12390] Org.keycloak.protocol.oidc.endpoints.logoutendpoint: offline session takeover due to reused authentication session id

A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up properly during logout when browser cookies are missing. As a result, one user may receive tokens that belong to another user. Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.

CVE-2025-12390
Unclassified
Oct 28, 2025
Medium5.5Linux

Medium [CVE-2025-10911] Libxslt: use-after-free with key data stored cross-rvt

A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 15 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 10 more.

CVE-2025-10911
Red Hat Enterprise Linux
Sep 25, 2025
High7.5Linux

High [CVE-2025-9784] Undertow: undertow madeyoureset http/2 ddos vulnerability

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform; Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; and 12 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9; and 7 more.

CVE-2025-9784
Red Hat Enterprise Linux
Sep 2, 2025
Medium6.4Linux

Medium [CVE-2025-7195] Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure user_setup script is still being used to build new container images. In affected images, the /etc/passwd file is created during build time with group-writable permissions and a group ownership of root (gid=0). An attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container. Affected products named by the advisory: RHEL-9-CNV-4.17; RHEL-9-CNV-4.18; RHEL-9-CNV-4.20; Compliance Operator 1; and 12 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.12; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; and 8 more.

CVE-2025-7195
Red Hat Enterprise Linux
Aug 7, 2025
High7.8Linux

High [CVE-2025-7425] Libxslt: libxml2: heap use-after-free in libxslt caused by atype corruption in xmlattrptr

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 29 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; and 27 more.

CVE-2025-7425
Red Hat Enterprise Linux
Jul 10, 2025
Medium6.5Linux

Medium [CVE-2025-6395] Gnutls: null pointer dereference in _gnutls_figure_common_ciphersuite

A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite(). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Ceph Storage 7; Red Hat Discovery 2; Red Hat Insights proxy 1.5; and 1 more.

CVE-2025-6395
Red Hat Enterprise Linux
Jul 10, 2025
Medium5.3Linux

Medium [CVE-2025-32989] Gnutls: vulnerability in gnutls sct extension parsing

A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This issue leads to the exposure of confidential information when GnuTLS verifies certificates from certain websites when the certificate (SCT) is not checked correctly. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Extended Update Support; and 5 more. Affected products named by the advisory: Red Hat Ceph Storage 7; Red Hat Discovery 2; Red Hat Hardened Images; Red Hat Insights proxy 1.5; and 1 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2025-32989
Red Hat Enterprise Linux
Jul 10, 2025
Medium6.5Linux

Medium [CVE-2025-32988] Gnutls: vulnerability in gnutls othername san export

A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure. This vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 6 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Ceph Storage 7; Red Hat Discovery 2; Red Hat Hardened Images; and 2 more.

CVE-2025-32988
Red Hat Enterprise Linux
Jul 10, 2025

← All vendors