Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5567 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium4.4Vendor: LowRed Hat Updated

Medium [CVE-2026-6426] vhost inflight migration VMState integer type mismatch causes out-of-bounds access

vhost inflight migration VMState integer type mismatch causes out-of-bounds access. Red Hat rates this low (CVSS 4.4). Weakness: CWE-681.

CVE-2026-6426
Unclassified
Aug 10, 2026
Medium5.5Vendor: HighRed Hat Updated

Medium [CVE-2026-18942] feast apply CronJob runs user Python with feature-server SA — tenant code to SA token escalation

feast apply CronJob runs user Python with feature-server SA — tenant code to SA token escalation. Red Hat rates this important (CVSS 5.5).

CVE-2026-18942
Unclassified
Aug 10, 2026
Medium6.5Vendor: HighRed Hat Updated

Medium [CVE-2026-16456] Cross-namespace secret read via NIM Account CRD confused deputy

Cross-namespace secret read via NIM Account CRD confused deputy. Red Hat rates this important (CVSS 6.5). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-model-controller-rhel9:1785189333.

CVE-2026-16456
Unclassified
Aug 10, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-63623] Information disclosure via world-readable storage volume images during clone/convert

Information disclosure via world-readable storage volume images during clone/convert. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-732.

CVE-2026-63623
Unclassified
Aug 10, 2026
Medium6.3Red Hat Updated

Medium [CVE-2026-71577] Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration

Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-522.

CVE-2026-71577
Unclassified
Aug 10, 2026
Medium6.8Red Hat Updated

Medium [CVE-2026-19278] Privilege escalation via unanchored regular expressions in Auth M2M role mappings

Privilege escalation via unanchored regular expressions in Auth M2M role mappings. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-625.

CVE-2026-19278
Unclassified
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-59088] denial of service via signed integer overflow in fli file processing

A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to an incorrect calculation during memory allocation for image buffers, where the multiplication of image width and height can exceed the maximum integer value. A remote attacker could exploit this by tricking a user into opening a specially crafted FLI file, leading to the application crashing and resulting in a denial of service. This Moderate impact flaw in GIMP's FLI file processing plugin can lead to a denial of service. The vulnerability requires user interaction, as an attacker must convince a local user to open a specially crafted FLI image file, which would cause the GIMP application to crash due to an integer overflow during memory allocation. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-59088
Red Hat Enterprise Linux
Aug 10, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-55814] Information disclosure via missing authentication in download APIs

Information disclosure via missing authentication in download APIs. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-306.

CVE-2026-55814
Unclassified
Aug 10, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-19404] missing authorization allows anonymous clients to start or abort CleanAllRUV replication maintenance

missing authorization allows anonymous clients to start or abort CleanAllRUV replication maintenance. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862.

CVE-2026-19404
Unclassified
Aug 10, 2026
Medium5.0Red Hat Updated

Medium [CVE-2026-12570] Denial of Service via HDF5 Shape Bomb when loading malicious model files

Denial of Service via HDF5 Shape Bomb when loading malicious model files. Red Hat rates this moderate (CVSS 5). Weakness: CWE-770.

CVE-2026-12570
Unclassified
Aug 10, 2026
MediumRed Hat Updated

Medium [CVE-2026-68083] fix path resolution in ksmbd_vfs_kern_path_create

fix path resolution in ksmbd_vfs_kern_path_create. Red Hat rates this moderate. Weakness: CWE-22.

CVE-2026-68083
Unclassified
Aug 10, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68109] replace BUG_ON with WARN_ON

A flaw was found in the Linux kernel, specifically within the `drm/amdgpu/sdma7.1` component. This vulnerability occurs when a `BUG_ON()` macro is triggered, which can lead to an immediate kernel crash. An attacker could potentially exploit this to cause a Denial of Service (DoS) on the affected system. Red Hat severity: Low — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-617. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-68109
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68265] Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC

A flaw was found in the Linux kernel. Specifically, within the `drm/xe/vm` module, an out-of-bounds access can occur when handling the `DRM_XE_CONSULT_MEM_ADVISE_PREF_LOC` region for a Buffer Object (BO) Virtual Memory Area (VMA). This happens because a value of -1 is incorrectly used as an index into a memory type array. A local attacker could potentially exploit this to cause a denial of service (DoS) or other system instability. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-68265
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68311] guard link STA in decap offload

A flaw was found in the Linux kernel's `wifi: mt76: mt7925` driver. When handling Multi-Link Operation (MLO) stations, the `mt7925_sta_set_decap_offload()` function can attempt to dereference a null pointer if a station link is not properly associated with a Virtual Interface (VIF) link. This can lead to a system crash, resulting in a Denial of Service (DoS) for an affected system. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-68311
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68096] fix recursive locking deadlock in audit_dupe_exe

A flaw was found in the Linux kernel's audit subsystem. A local user can trigger a recursive locking deadlock by moving a file that has an existing executable audit rule. This occurs when the audit subsystem attempts to acquire a lock that is already held, leading to a system-wide deadlock. This vulnerability can result in a Denial of Service (DoS) for the affected system. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-833. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-68096
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68411] clamp virtio RX length before skb_put

A flaw was found in the Linux kernel's mac80211_hwsim component. A malicious backend device could report an oversized receive length to the `hwsim_virtio_rx_work()` function. This could cause the system to write past the end of a buffer, leading to a kernel panic and a denial of service (DoS) for the guest system. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-787. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-68411
Unclassified
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68419] Prevent rereg_mr for non-mem regions

A flaw was found in the Linux kernel's RDMA/irdma component. A local user could exploit this by attempting to re-register specific memory regions (Queue Pair, Completion Queue, or Shared Receive Queue objects) that are not intended for re-registration. This could lead to an invalid operation being performed with a zero-initialized memory key, potentially causing system instability. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-791. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-68419
Linux Kernel
Aug 10, 2026
Low3.9Red Hat Updated

Low [CVE-2026-19411] shim/dp.c library: NULL-pointer dereference in is_removable_media_path when DevicePathToStr returns NULL

shim/dp.c library: NULL-pointer dereference in is_removable_media_path() when DevicePathToStr() returns NULL. Red Hat rates this low (CVSS 3.9). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-19411
Unclassified
Aug 10, 2026
UnratedRed Hat

Unknown [CVE-2026-68199] fix OOB access from firmware ADDBA window size

A flaw was found in the Linux kernel's `ath6kl` Wi-Fi driver. This vulnerability allows a local attacker to cause an out-of-bounds memory access. The flaw occurs when the firmware provides an invalid window size during an ADDBA (Add Block Ack) request, leading to incorrect memory allocation. This can result in a denial of service or potentially lead to further system compromise. Red Hat severity: not rated. Weakness: CWE-787. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-68199
Unclassified
Aug 10, 2026
Low3.7Red Hat Updated

Low [CVE-2026-12372] Server-Side Request Forgery via improper network URL validation

Server-Side Request Forgery via improper network URL validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-12372
Unclassified
Aug 9, 2026

← All vendors