Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3038 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.0Vendor: MediumRed Hat

High [CVE-2026-64527] validate VMBus packet size in receive callback

validate VMBus packet size in receive callback. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805.

CVE-2026-64527
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64267] avoid 32-bit prune notification count wrap

avoid 32-bit prune notification count wrap. Red Hat rates this moderate (CVSS 7). Weakness: CWE-190.

CVE-2026-64267
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64471] fix use-after-free on registration failure

fix use-after-free on registration failure. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64471
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64473] Remove device debugfs before releasing devres

Remove device debugfs before releasing devres. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911.

CVE-2026-64473
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64319] validate reply message payload bounds against transfer length

validate reply message payload bounds against transfer length. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.

CVE-2026-64319
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64266] re-lock request before returning from fuse_ref_folio

re-lock request before returning from fuse_ref_folio(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64266
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64414] handle unreadable frags

handle unreadable frags. Red Hat rates this moderate (CVSS 7). Weakness: CWE-390.

CVE-2026-64414
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64470] fix use-after-free on marvell probe failure

fix use-after-free on marvell probe failure. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64470
Unclassified
Jul 25, 2026
High7.0Red Hat

High [CVE-2026-64304] qat - validate RSA CRT component lengths

qat - validate RSA CRT component lengths. Red Hat rates this important (CVSS 7). Weakness: CWE-787.

CVE-2026-64304
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64523] Take a long-lived file reference at submit

Take a long-lived file reference at submit. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64523
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64286] Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU

Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU. Red Hat rates this moderate (CVSS 7).

CVE-2026-64286
Unclassified
Jul 25, 2026
High7.0Red Hat

High [CVE-2026-64483] bound the sample count to the packet payload

bound the sample count to the packet payload. Red Hat rates this important (CVSS 7). Weakness: CWE-120.

CVE-2026-64483
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64438] qat - fix VF2PF work teardown race in adf_disable_sriov

qat - fix VF2PF work teardown race in adf_disable_sriov(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64438
Unclassified
Jul 25, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64371] protect ptrace_may_access with exec_update_lock (part 1)

protect ptrace_may_access() with exec_update_lock (part 1). Red Hat rates this moderate (CVSS 7).

CVE-2026-64371
Unclassified
Jul 25, 2026
High7.0Red Hat

High [CVE-2026-64386] fix query_info replay double-free

fix query_info() replay double-free. Red Hat rates this important (CVSS 7). Weakness: CWE-1341.

CVE-2026-64386
Unclassified
Jul 25, 2026
High8.8Red Hat

High [CVE-2026-66041] Arbitrary code execution via crafted PGS/SUP subtitle file

Arbitrary code execution via crafted PGS/SUP subtitle file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-66041
Unclassified
Jul 24, 2026
High8.8Red Hat

High [CVE-2026-66040] Arbitrary code execution via crafted PNG image

Arbitrary code execution via crafted PNG image. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-66040
Unclassified
Jul 24, 2026
High8.8Red Hat

High [CVE-2026-66039] Arbitrary code execution via crafted CAF file

Arbitrary code execution via crafted CAF file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-66039
Unclassified
Jul 24, 2026
High8.8Red Hat

High [CVE-2026-66036] Arbitrary code execution via crafted video in vf_hqdn3d filter

Arbitrary code execution via crafted video in vf_hqdn3d filter. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-66036
Unclassified
Jul 24, 2026
High8.5Red Hat

High [CVE-2026-17107] Impersonation header injection in service-proxy grants cluster-admin on every managed cluster

Impersonation header injection in service-proxy grants cluster-admin on every managed cluster. Red Hat rates this important (CVSS 8.5). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:48284 with package multicluster-engine/cluster-proxy-rhel9:1784342329, multicluster-engine/cluster-proxy-rhel9:1783278220, multicluster-engine/cluster-proxy-rhel9:1784925025, multicluster-engine/cluster-proxy-rhel9:1783985960.

CVE-2026-17107
Unclassified
Jul 24, 2026

← All vendors