Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5483 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.5Linux

High [CVE-2026-64648] Information disclosure via server-side fetch cache

Information disclosure via server-side fetch cache. Red Hat rates this important (CVSS 7.5). Weakness: CWE-524.

CVE-2026-64648
Unclassified
Jul 27, 2026
High7.5Linux

High [CVE-2026-12383] ExternalEventStreamViewSet trusts Subject header without validation and leaks expected DN

ExternalEventStreamViewSet trusts Subject header without validation and leaks expected DN. Red Hat rates this important (CVSS 7.5). Weakness: CWE-345. Red Hat lists fixing advisory RHSA-2026:50340 with package automation-eda-controller-0:1.2.11-1.el9ap, ansible-automation-platform-27/eda-controller-rhel9:1785374869, automation-eda-controller-0:1.1.21-1.el9ap, automation-eda-controller-0:1.1.21-1.el8ap. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-12383
Red Hat Enterprise Linux
Jul 27, 2026
High7.1Vendor: MediumLinux

High [CVE-2026-66759] out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted ICNS images

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted ICNS image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-66759
Red Hat Enterprise Linux
Jul 27, 2026
High7.8Linux

High [CVE-2026-66758] integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted FITS images

A flaw was found in the file-fits plugin in GIMP. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted FITS image with GIMP, reducing the likelihood of exploitation. However, successful exploitation may potentially lead to arbitrary code execution or a denial of service. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to this reason, this flaw has been rated with an important severity. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-66758
Red Hat Enterprise Linux
Jul 27, 2026
High7.5Linux

High [CVE-2026-64646] Denial of Service via excessive memory consumption in Server Actions

Denial of Service via excessive memory consumption in Server Actions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-64646
Unclassified
Jul 27, 2026
High7.5Linux

High [CVE-2026-64644] Denial of Service via malicious image optimization

Denial of Service via malicious image optimization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-64644
Unclassified
Jul 27, 2026
High8.2Linux

High [CVE-2026-64642] Authentication bypass leading to unauthorized access

Authentication bypass leading to unauthorized access. Red Hat rates this important (CVSS 8.2). Weakness: CWE-807.

CVE-2026-64642
Unclassified
Jul 27, 2026
High7.5Linux

High [CVE-2026-64641] Denial of Service via crafted requests to App Router with Server Actions

Denial of Service via crafted requests to App Router with Server Actions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-64641
Unclassified
Jul 27, 2026
High8.2Linux

High [CVE-2026-64645] Server-Side Request Forgery vulnerability

Server-Side Request Forgery vulnerability. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918.

CVE-2026-64645
Unclassified
Jul 27, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-45623] Information disclosure and denial of service via crafted CSS input

Information disclosure and denial of service via crafted CSS input. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-22.

CVE-2026-45623
Unclassified
Jul 27, 2026
High7.2Vendor: MediumLinux

High [CVE-2026-54272] Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification

Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification. Red Hat rates this moderate (CVSS 7.2). Weakness: CWE-918.

CVE-2026-54272
Unclassified
Jul 27, 2026
High7.5Linux

High [CVE-2026-54890] Denial of Service via integer underflow in ETF decoding

Denial of Service via integer underflow in ETF decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.

CVE-2026-54890
Unclassified
Jul 27, 2026
High7.5Linux

High [CVE-2026-59251] Erlang/OTP public_key: Denial of Service via crafted TLS certificate chains

Erlang/OTP public_key: Denial of Service via crafted TLS certificate chains. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.

CVE-2026-59251
Unclassified
Jul 27, 2026
High7.4Linux

High [CVE-2026-55953] Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance

Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance. Red Hat rates this important (CVSS 7.4). Weakness: CWE-940. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.

CVE-2026-55953
Unclassified
Jul 27, 2026
High7.5Linux

High [CVE-2026-55737] Denial of Service via crafted external term format binary

Denial of Service via crafted external term format binary. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-55737
Unclassified
Jul 27, 2026
High7.5Linux

High [CVE-2026-42792] Erlang OTP epmd: Remote Denial of Service via connection exhaustion

Erlang OTP epmd: Remote Denial of Service via connection exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-253. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.

CVE-2026-42792
Unclassified
Jul 27, 2026
High8.4Linux Updated

High [CVE-2026-55971] Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow

Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow. Red Hat rates this important (CVSS 8.4). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:49716 with package thrift-0:0.24.0-1.el9ai, thrift-0:0.24.0-2.el9ai. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-55971
Red Hat Enterprise Linux
Jul 27, 2026
High7.5Linux

High [CVE-2026-55969] Denial of Service via integer overflow or wraparound

Denial of Service via integer overflow or wraparound. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:46989 with package jaeger-main-2.20.0-0.5.hum1, tempo2-10-main-2.10.7-0.2.hum1, tempo3-0-main-3.0.2-0.2.hum1.

CVE-2026-55969
Unclassified
Jul 27, 2026
High7.5Linux

High [CVE-2026-55968] Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation

Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-55968
Unclassified
Jul 27, 2026
High7.5Linux

High [CVE-2026-49158] Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data

Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409.

CVE-2026-49158
Unclassified
Jul 27, 2026

← All vendors