Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11060 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.0Vendor: MediumRed Hat

High [CVE-2026-97965] initialize _md in vxlan_xmit_one

initialize _md in vxlan_xmit_one(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-97965
Linux Kernel
Sep 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-98080] do not force reloc root creation during qgroup_account_snapshot

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not force reloc root creation during qgroup_account_snapshot() [BUG] When running btrfs/252 with quota enabled through MKFS_OPTIONS="-O quota", it has a high chance to trigger the following kernel warning and flips the fs RO: BTRFS info (device dm-2): relocating block group 30408704 flags metadata|dup ------------[ cut here ]------------ WARNING: fs/btrfs/extent-tree.c:879 at lookup_inline_extent_backref+0x74b/0x960 [btrfs], CPU#4: btrfs/2173 CPU: 4 UID: 0 PID: 2173 Comm: btrfs Not tainted 7.2.0-rc6-custom+ #457 PREEMPT(full) 3adc6528fb66f7a55fe1095385818e742f200aab Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022 RIP: 0010:lookup_inline_extent_backref+0x74b/0x960 [btrfs] Call Trace: insert_inline_extent_backref+0x7c/0x160 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] __btrfs_inc_extent_ref+0xa9/0x270 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] __btrfs_run_delayed_refs+0x4af/0x11c0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] btrfs_run_delayed_refs+0x9d/0xf0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] create_pending_snapshot+0x39d/0xf00 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] create_pending_snapshots+0x9b/0xc0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] btrfs_commit_transaction+0x280/0xeb0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]…

CVE-2026-98080
Linux Kernel
Sep 25, 2026
Medium5.9Red Hat

Medium [CVE-2026-92842] Information disclosure via out-of-bounds read in stream filters

Information disclosure via out-of-bounds read in stream filters. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.

CVE-2026-92842
Red Hat Enterprise Linux
Sep 25, 2026
Medium6.5Red Hat

Medium [CVE-2026-91768] Access control bypass via partial IPv6 address comparison

Access control bypass via partial IPv6 address comparison. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-940. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.

CVE-2026-91768
Red Hat Enterprise Linux
Sep 25, 2026
Medium4.3Red Hat Updated

Medium [CVE-2026-91769] Server impersonation via Common Name fallback in TLS verification

Server impersonation via Common Name fallback in TLS verification. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.

CVE-2026-91769
Red Hat Enterprise Linux
Sep 25, 2026
Medium6.5Red Hat

Medium [CVE-2026-91767] Information disclosure via crafted TLS server certificate

Information disclosure via crafted TLS server certificate. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.

CVE-2026-91767
Red Hat Enterprise Linux
Sep 25, 2026
Medium5.9Red Hat

Medium [CVE-2026-91766] Credential disclosure via cross-origin HTTP redirects

Credential disclosure via cross-origin HTTP redirects. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.

CVE-2026-91766
Red Hat Enterprise Linux
Sep 25, 2026
Medium6.5Red Hat Updated

Medium [CVE-2025-14181] Denial of Service via heap buffer overflow in SOAP client

Denial of Service via heap buffer overflow in SOAP client. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2025-14181
Unclassified
Sep 25, 2026
Medium5.9Red Hat

Medium [CVE-2026-17545] Denial of Service via reserved device names on Windows

Denial of Service via reserved device names on Windows. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-66. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.

CVE-2026-17545
Red Hat Enterprise Linux
Sep 25, 2026
Medium4.3Red Hat

Medium [CVE-2026-6103] Archive entry injection via integer overflow in TAR parser

Archive entry injection via integer overflow in TAR parser. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.

CVE-2026-6103
Red Hat Enterprise Linux
Sep 25, 2026
Medium5.8Red Hat

Medium [CVE-2026-93682] Out-of-bounds read via empty HTTP redirect Location header

Out-of-bounds read via empty HTTP redirect Location header. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.

CVE-2026-93682
Red Hat Enterprise Linux
Sep 25, 2026
Medium6.5Red Hat

Medium [CVE-2026-67408] Denial of Service via excessive memory allocation in stream management

Denial of Service via excessive memory allocation in stream management. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-408. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.

CVE-2026-67408
Unclassified
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-67406] Information disclosure via unredacted credentials in Shovel crash logs

Information disclosure via unredacted credentials in Shovel crash logs. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-209. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-67406
Unclassified
Sep 25, 2026
Medium6.5Red Hat

Medium [CVE-2026-67412] Unauthorized cross-vhost message access via missing Federation upstream authorization

Unauthorized cross-vhost message access via missing Federation upstream authorization. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.

CVE-2026-67412
Unclassified
Sep 25, 2026
Medium4.8Red Hat

Medium [CVE-2026-67242] Authentication bypass via improper validation of floating-point token expiration timestamps

Authentication bypass via improper validation of floating-point token expiration timestamps. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-613. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.

CVE-2026-67242
Unclassified
Sep 25, 2026
Medium4.3Red Hat

Medium [CVE-2026-67241] Unauthorized message routing via missing alternate-exchange permission check

Unauthorized message routing via missing alternate-exchange permission check. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.

CVE-2026-67241
Unclassified
Sep 25, 2026
Medium5.3Red Hat

Medium [CVE-2026-66071] Denial of service via atom exhaustion in OAuth2 JWT scope parsing

Denial of service via atom exhaustion in OAuth2 JWT scope parsing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.

CVE-2026-66071
Unclassified
Sep 25, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-67236] Information disclosure via insecure authentication cookies

Information disclosure via insecure authentication cookies. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-312. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-67236
Unclassified
Sep 25, 2026
Medium5.3Red Hat Updated

Medium [CVE-2026-100230] Arbitrary code execution via path traversal in drag-and-drop file transfer

Arbitrary code execution via path traversal in drag-and-drop file transfer. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22.

CVE-2026-100230
Unclassified
Sep 25, 2026
Medium6.6Red Hat

Medium [CVE-2026-96448] FGAP v2 composite-blind role mapping allows privilege escalation

FGAP v2 composite-blind role mapping allows privilege escalation. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-285. Affected product named by the advisory: Red Hat Build of Keycloak.

CVE-2026-96448
Unclassified
Sep 25, 2026

← All vendors