Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3177 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.5Red Hat

Medium [CVE-2026-24330] Arbitrary File Read via malicious archive deployment

Arbitrary File Read via malicious archive deployment. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-434. Affected products named by the advisory: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more. Affected products named by the advisory: Red Hat Process Automation 7; Red Hat Single Sign-On 7.

CVE-2026-24330
Unclassified
Aug 11, 2026
Medium4.9Red Hat

Medium [CVE-2026-24329] Denial of Service via malformed payload injection by an authenticated administrative user.

Denial of Service via malformed payload injection by an authenticated administrative user. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-91. Affected products named by the advisory: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more. Affected products named by the advisory: Red Hat Process Automation 7; Red Hat Single Sign-On 7.

CVE-2026-24329
Unclassified
Aug 11, 2026
Medium5.9Red Hat Updated

Medium [CVE-2026-62899] .NET:.NET Core:.NET Security Feature Bypass Vulnerability

.NET:.NET Core:.NET Security Feature Bypass Vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el10_2, dotnet8.0-0:8.0.130-1.el8_10, dotnet10.0-0:10.0.111-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-62899
Unclassified
Aug 11, 2026
Medium5.9Red Hat Updated

Medium [CVE-2026-62900] .NET:.NET Information Disclosure Vulnerability

.NET:.NET Information Disclosure Vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-212. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el10_2, dotnet8.0-0:8.0.130-1.el8_10, dotnet10.0-0:10.0.111-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-62900
Unclassified
Aug 11, 2026
Medium4.4Vendor: LowRed Hat

Medium [CVE-2026-6426] vhost inflight migration VMState integer type mismatch causes out-of-bounds access

vhost inflight migration VMState integer type mismatch causes out-of-bounds access. Red Hat rates this low (CVSS 4.4). Weakness: CWE-681. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4; Red Hat package: qemu-kvm-ma.

CVE-2026-6426
Red Hat Enterprise Linux
Aug 10, 2026
Medium5.5Vendor: HighRed Hat Updated

Medium [CVE-2026-18942] feast apply CronJob runs user Python with feature-server SA — tenant code to SA token escalation

feast apply CronJob runs user Python with feature-server SA — tenant code to SA token escalation. Red Hat rates this important (CVSS 5.5). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.

CVE-2026-18942
Unclassified
Aug 10, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-16456] Cross-namespace secret read via NIM Account CRD confused deputy

Cross-namespace secret read via NIM Account CRD confused deputy. Red Hat rates this important (CVSS 6.5). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-model-controller-rhel9:1785187158, rhoai/odh-model-controller-rhel9:1784950479, rhoai/odh-model-controller-rhel9:1785189333. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.

CVE-2026-16456
Unclassified
Aug 10, 2026
Medium5.9Red Hat

Medium [CVE-2026-6791] Denial of Service via stack exhaustion during tilde expansion

Denial of Service via stack exhaustion during tilde expansion. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:53069 with package glibc-main-2.43-8.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: glibc; and 1 more.

CVE-2026-6791
Red Hat Enterprise Linux
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-6368] Process abort due to invalid memory in wordexp

Process abort due to invalid memory in wordexp. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341. Red Hat lists fixing advisory RHSA-2026:53069 with package glibc-main-2.43-8.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: glibc; and 1 more.

CVE-2026-6368
Red Hat Enterprise Linux
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-63623] Information disclosure via world-readable storage volume images during clone/convert

Information disclosure via world-readable storage volume images during clone/convert. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-732.

CVE-2026-63623
Unclassified
Aug 10, 2026
Medium6.3Red Hat

Medium [CVE-2026-71577] Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration

Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-522.

CVE-2026-71577
Unclassified
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-18370] Heap-based buffer overflow leads to denial of service

Heap-based buffer overflow leads to denial of service. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.

CVE-2026-18370
Unclassified
Aug 10, 2026
Medium6.8Red Hat

Medium [CVE-2026-19278] Privilege escalation via unanchored regular expressions in Auth M2M role mappings

Privilege escalation via unanchored regular expressions in Auth M2M role mappings. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-625.

CVE-2026-19278
Unclassified
Aug 10, 2026
Medium6.5Red Hat

Medium [CVE-2026-19429] Arbitrary file read via symlink target validation bypass

Arbitrary file read via symlink target validation bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-59. Affected product named by the advisory: OpenShift Developer Tools and Services.

CVE-2026-19429
Unclassified
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68428] Fix use-after-free on vendor module reload

Fix use-after-free on vendor module reload. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68428
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68425] Drop unmatched RMPP responses before reassembly

Drop unmatched RMPP responses before reassembly. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-179. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68425
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68424] fix use-after-free in mtd_virt_concat_destroy_joins

fix use-after-free in mtd_virt_concat_destroy_joins(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.

CVE-2026-68424
Unclassified
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68423] fix use-after-free in mtd_virt_concat_destroy

fix use-after-free in mtd_virt_concat_destroy(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.

CVE-2026-68423
Unclassified
Aug 10, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68422] fix root leak if its reloc root is unexpected in merge_reloc_roots

fix root leak if its reloc root is unexpected in merge_reloc_roots(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68422
Linux Kernel
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-68421] Don't warn on core-sched forced idle in put_prev_task_scx

Don't warn on core-sched forced idle in put_prev_task_scx(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1288. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.

CVE-2026-68421
Linux Kernel
Aug 10, 2026

← All vendors