Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5485 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.8Vendor: MediumLinux

High [CVE-2026-18107] container escape via rseq critical section hijack during checkpoint/restore

container escape via rseq critical section hijack during checkpoint/restore. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-269.

CVE-2026-18107
Unclassified
Jul 28, 2026
High7.6Linux

High [CVE-2026-16313] Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected. sg3_utils versions 1.34 through 1.48 contain a command injection flaw in the export_dev_ids() function of sg_inq. A crafted SCSI/USB device can embed a newline in this field, splitting sg_inq's udev KEY=VALUE output into two lines and injecting an arbitrary udev property, including REMOVE_CMD. On systems whose default udev rules invoke sg_inq --export for SCSI device identification and act on REMOVE_CMD when a device is removed, this allows a local attacker with physical access to a USB/SCSI port to achieve arbitrary command execution as root simply by disconnecting the crafted device. Exploitation requires physical access to attach the malicious device, consistent with Red Hat's Physical (AV:P) attack vector scoring. The upstream fix (udev-conforming character escaping for this field) has not yet been included in any tagged sg3_utils release; all Red Hat-shipped versions of sg3_utils in the 1.34-1.48 range are affected.

CVE-2026-16313
Red Hat Enterprise Linux
Jul 28, 2026
High7.5Vendor: MediumLinux Updated

High [CVE-2026-71190] Unauthenticated denial of service via catastrophic backtracking in Accept header parser

Unauthenticated denial of service via catastrophic backtracking in Accept header parser. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1333.

CVE-2026-71190
Unclassified
Jul 28, 2026
High8.2Linux Updated

High [CVE-2026-71191] S3API presigned URL unsigned header authorization bypass

S3API presigned URL unsigned header authorization bypass. Red Hat rates this important (CVSS 8.2). Weakness: CWE-863.

CVE-2026-71191
Unclassified
Jul 28, 2026
High8.1Linux Updated

High [CVE-2026-66713] Remote code execution via deserialization of untrusted data in Tribes clustering

Remote code execution via deserialization of untrusted data in Tribes clustering. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502.

CVE-2026-66713
Unclassified
Jul 28, 2026
High8.5Linux

High [CVE-2026-49332] underscore header smuggling enables identity impersonation on WSGI/PHP upstreams

underscore header smuggling enables identity impersonation on WSGI/PHP upstreams. Red Hat rates this important (CVSS 8.5). Weakness: CWE-436.

CVE-2026-49332
Unclassified
Jul 28, 2026
High7.5Linux

High [CVE-2026-65624] Denial of Service via HTTP/1.1 duplicate header names

Denial of Service via HTTP/1.1 duplicate header names. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:47231 with package rabbitmq-server4-3-main-4.3.4-0.2.hum1, rabbitmq-server4-2-main-4.2.9-0.2.hum1.

CVE-2026-65624
Unclassified
Jul 28, 2026
High7.5Linux

High [CVE-2026-6949] TSIG packet with crafted name compression can crash DNS server

TSIG packet with crafted name compression can crash DNS server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-6949
Unclassified
Jul 28, 2026
High8.8Linux

High [CVE-2026-58222] Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes

Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes. Red Hat rates this important (CVSS 8.8). Weakness: CWE-90.

CVE-2026-58222
Unclassified
Jul 28, 2026
High8.8Linux

High [CVE-2026-58221] authenticated LDAP access to internal LDB special DNs permits domain takeover

authenticated LDAP access to internal LDB special DNs permits domain takeover. Red Hat rates this important (CVSS 8.8). Weakness: CWE-284.

CVE-2026-58221
Unclassified
Jul 28, 2026
High7.5Linux

High [CVE-2026-59248] Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding

Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:47231 with package rabbitmq-server4-3-main-4.3.4-0.2.hum1, rabbitmq-server4-2-main-4.2.9-0.2.hum1.

CVE-2026-59248
Unclassified
Jul 28, 2026
Medium4.5Linux

Medium [CVE-2026-54620] Use-After-Free vulnerability in SQLite aggregate function callbacks

Use-After-Free vulnerability in SQLite aggregate function callbacks. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-825.

CVE-2026-54620
Unclassified
Jul 28, 2026
Medium4.5Linux Updated

Medium [CVE-2026-54619] Use-after-free when redefining SQLite functions with different arity

Use-after-free when redefining SQLite functions with different arity. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-825.

CVE-2026-54619
Unclassified
Jul 28, 2026
Medium6.5Linux Updated

Medium [CVE-2026-71192] S3API cross-tenant object read via Swift-native header injection

S3API cross-tenant object read via Swift-native header injection. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-863.

CVE-2026-71192
Unclassified
Jul 28, 2026
Medium5.3Linux Updated

Medium [CVE-2026-66299] Denial of Service via WebSocket chat example

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. This can lead to the affected system becoming unresponsive or crashing. The impact is limited as the vulnerable component is part of an example application, which is generally not deployed in production environments. Exploitation requires the example application to be present and accessible. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images. Under investigation: Red Hat JBoss Web Server 5. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7 as not affected. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-66299
Red Hat Enterprise Linux
Jul 28, 2026
Medium6.5Linux

Medium [CVE-2026-18047] ACME admin enable/disable endpoint authentication bypass via trailing slash

ACME admin enable/disable endpoint authentication bypass via trailing slash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-288.

CVE-2026-18047
Unclassified
Jul 28, 2026
Medium5.3Linux

Medium [CVE-2026-58216] kpasswd service: kpasswd packet that contains malformed ASN.1 might cause the server to access 6 bytes of unallocated memory leading server to crash

kpasswd service: kpasswd packet that contains malformed ASN.1 might cause the server to access 6 bytes of unallocated memory leading server to crash. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125.

CVE-2026-58216
Unclassified
Jul 28, 2026
Medium5.3Linux

Medium [CVE-2026-58218] DNS signing DoS via TKEY name cache exhaustion

DNS signing DoS via TKEY name cache exhaustion. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-410.

CVE-2026-58218
Unclassified
Jul 28, 2026
Low2.2Linux Updated

Low [CVE-2026-6879] Performance degradation in XML processing due to quadratic time complexity

Performance degradation in XML processing due to quadratic time complexity. Red Hat rates this low (CVSS 2.2). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:48278 with package python3-12-main-3.12.13-3.8.hum1, python3-10-main-3.10.20-3.2.hum1, python3-14-main-3.14.6-2.2.hum1, python3-13-main-3.13.14-1.7.hum1.

CVE-2026-6879
Unclassified
Jul 28, 2026
Low3.5Vendor: MediumLinux

Low [CVE-2026-58341] CSRF risk in group messaging state toggle

CSRF risk in group messaging state toggle. Red Hat rates this moderate (CVSS 3.5). Weakness: CWE-22.

CVE-2026-58341
Unclassified
Jul 28, 2026

← All vendors