Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3177 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.5Red Hat

Medium [CVE-2026-68445] Prevent shader BO mappings from becoming writable

Prevent shader BO mappings from becoming writable. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-179. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68445
Linux Kernel
Aug 12, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68434] Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms

Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68434
Linux Kernel
Aug 12, 2026
Medium5.5Red Hat

Medium [CVE-2026-68441] Handle TC_ACT_REDIRECT from qdisc filter chains

Handle TC_ACT_REDIRECT from qdisc filter chains. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68441
Linux Kernel
Aug 12, 2026
Medium5.5Red Hat

Medium [CVE-2026-68435] Fix address space mismatch in kexec command line lookup

Fix address space mismatch in kexec command line lookup. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-822. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.

CVE-2026-68435
Linux Kernel
Aug 12, 2026
Medium5.5Red Hat

Medium [CVE-2026-68444] Fix NULL dereference in ffa_partition_info_get

Fix NULL dereference in ffa_partition_info_get(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68444
Linux Kernel
Aug 12, 2026
Medium5.5Red Hat

Medium [CVE-2026-68437] Fit paired fragment job in the correct CCCB

Fit paired fragment job in the correct CCCB. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.

CVE-2026-68437
Linux Kernel
Aug 12, 2026
Medium5.5Red Hat

Medium [CVE-2026-68443] (gigabyte_waterforce) Stop device IO before calling hid_hw_stop

(gigabyte_waterforce) Stop device IO before calling hid_hw_stop. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.

CVE-2026-68443
Linux Kernel
Aug 12, 2026
Medium5.5Red Hat

Medium [CVE-2026-68449] fix infinite loop in NCQ tag completion bit-scanning

fix infinite loop in NCQ tag completion bit-scanning. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-68449
Linux Kernel
Aug 12, 2026
Medium5.5Red Hat

Medium [CVE-2026-68447] clamp v9 CRIU control stack checkpoint copy to BO size

clamp v9 CRIU control stack checkpoint copy to BO size. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68447
Linux Kernel
Aug 12, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-18710] Credential disclosure via cleartext logging during client initialization

Credential disclosure via cleartext logging during client initialization. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-312. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Debezium 3; Red Hat build of Quarkus.

CVE-2026-18710
Unclassified
Aug 11, 2026
Medium6.4Red Hat

Medium [CVE-2026-73242] Out-of-bounds memory access in Kerberos decryption

Out-of-bounds memory access in Kerberos decryption. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.

CVE-2026-73242
Red Hat Enterprise Linux
Aug 11, 2026
Medium6.3Red Hat

Medium [CVE-2026-71474] Pull-secret bearer token written to logs on non-200 CCX response

Pull-secret bearer token written to logs on non-200 CCX response. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-532. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-71474
Unclassified
Aug 11, 2026
Medium5.3Red Hat

Medium [CVE-2026-71468] Cross-user bearer-token reuse via global federation-config cache

Cross-user bearer-token reuse via global federation-config cache. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-266. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-71468
Unclassified
Aug 11, 2026
Medium5.0Red Hat

Medium [CVE-2026-71475] Spoke-controlled ClusterID injected unencoded into Insights API URL path

Spoke-controlled ClusterID injected unencoded into Insights API URL path. Red Hat rates this moderate (CVSS 5). Weakness: CWE-22. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-71475
Unclassified
Aug 11, 2026
Medium6.3Red Hat

Medium [CVE-2026-71845] CCX_TOKEN bearer credential logged in clear text at startup via setDefault

CCX_TOKEN bearer credential logged in clear text at startup via setDefault(). Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-532. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-71845
Unclassified
Aug 11, 2026
Medium5.4Red Hat

Medium [CVE-2026-73283] Tunnel forwarding restriction bypass

Tunnel forwarding restriction bypass. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-305. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: openssh.

CVE-2026-73283
Red Hat Enterprise Linux
Aug 11, 2026
Medium5.6Red Hat

Medium [CVE-2026-73282] Information disclosure and data corruption via use-after-free in ssh client

Information disclosure and data corruption via use-after-free in ssh client. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: openssh.

CVE-2026-73282
Red Hat Enterprise Linux
Aug 11, 2026
Medium4.3Red Hat

Medium [CVE-2026-73229] Django REST framework: Information disclosure via improper permission checks in AdminRenderer

Django REST framework: Information disclosure via improper permission checks in AdminRenderer. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-425. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; and 1 more. Affected products named by the advisory: Red Hat Update Infrastructure 5.

CVE-2026-73229
Unclassified
Aug 11, 2026
Medium5.3Red Hat

Medium [CVE-2026-73228] Django REST framework: Denial of Service via oversized request bodies

Django REST framework: Denial of Service via oversized request bodies. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; and 1 more. Affected products named by the advisory: Red Hat Update Infrastructure 5.

CVE-2026-73228
Unclassified
Aug 11, 2026
Medium6.5Red Hat

Medium [CVE-2026-73216] Authenticated client can exhaust relay capacity via quota bypass

Authenticated client can exhaust relay capacity via quota bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-911.

CVE-2026-73216
Unclassified
Aug 11, 2026

← All vendors