Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3038 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.4Red Hat

High [CVE-2026-66140] Privilege escalation via directory traversal due to mishandled queue-name arguments

Privilege escalation via directory traversal due to mishandled queue-name arguments. Red Hat rates this important (CVSS 8.4). Weakness: CWE-22.

CVE-2026-66140
Unclassified
Jul 24, 2026
High8.8Red Hat

High [CVE-2026-66138] Arbitrary code execution via malicious configuration

Arbitrary code execution via malicious configuration. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78.

CVE-2026-66138
Unclassified
Jul 24, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64255] validate sta_mask before ffs in BA session handlers

validate sta_mask before ffs() in BA session handlers. Red Hat rates this moderate (CVSS 7). Weakness: CWE-823.

CVE-2026-64255
Unclassified
Jul 24, 2026
HighRed Hat

High [CVE-2026-64218] fix report_work leak on backbone_gw purge

fix report_work leak on backbone_gw purge. Red Hat rates this important. Weakness: CWE-825.

CVE-2026-64218
Unclassified
Jul 24, 2026
High7.0Red Hat

High [CVE-2026-64226] Linux kernel (sched_ext): Use-After-Free vulnerability in scx_root_enable_workfn

Linux kernel (sched_ext): Use-After-Free vulnerability in scx_root_enable_workfn(). Red Hat rates this important (CVSS 7). Weakness: CWE-825.

CVE-2026-64226
Unclassified
Jul 24, 2026
High7.0Red Hat

High [CVE-2026-64219] Validate payload length and link_index in dc_process_dmub_aux_transfer_async

Validate payload length and link_index in dc_process_dmub_aux_transfer_async. Red Hat rates this important (CVSS 7). Weakness: CWE-120.

CVE-2026-64219
Unclassified
Jul 24, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64247] Denial of Service due to out-of-bounds read

Denial of Service due to out-of-bounds read. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.

CVE-2026-64247
Unclassified
Jul 24, 2026
High7.0Red Hat

High [CVE-2026-64217] Linux kernel netfs: Memory corruption leading to denial of service and potential privilege escalation

Linux kernel netfs: Memory corruption leading to denial of service and potential privilege escalation. Red Hat rates this important (CVSS 7). Weakness: CWE-787.

CVE-2026-64217
Unclassified
Jul 24, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64251] Linux kernel: Use-after-free in pwrseq_debugfs_seq_next can lead to denial of service

Linux kernel: Use-after-free in pwrseq_debugfs_seq_next() can lead to denial of service. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911.

CVE-2026-64251
Unclassified
Jul 24, 2026
High7.0Red Hat

High [CVE-2026-64221] Linux kernel: spi: ti-qspi use-after-free allows privilege escalation or denial of service

Linux kernel: spi: ti-qspi use-after-free allows privilege escalation or denial of service. Red Hat rates this important (CVSS 7). Weakness: CWE-825.

CVE-2026-64221
Unclassified
Jul 24, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64208] crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks

crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120.

CVE-2026-64208
Unclassified
Jul 24, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64216] netfs Use-After-Free vulnerability allows local denial of service and memory corruption

netfs Use-After-Free vulnerability allows local denial of service and memory corruption. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64216
Unclassified
Jul 24, 2026
High8.2Red Hat

High [CVE-2026-16804] Sandbox escape via crafted HTML page

Sandbox escape via crafted HTML page. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787.

CVE-2026-16804
Unclassified
Jul 23, 2026
High8.8Red Hat

High [CVE-2026-16805] Use after free in Blink

Use after free in Blink. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-16805
Unclassified
Jul 23, 2026
High8.8Red Hat

High [CVE-2026-16806] Arbitrary code execution via use after free vulnerability in WebMCP

Arbitrary code execution via use after free vulnerability in WebMCP. Red Hat rates this important (CVSS 8.8).

CVE-2026-16806
Unclassified
Jul 23, 2026
High8.8Red Hat

High [CVE-2026-16807] Sandbox escape via crafted HTML page

Sandbox escape via crafted HTML page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-16807
Unclassified
Jul 23, 2026
High7.8Red Hat

High [CVE-2026-60122] Arbitrary OS command execution via code injection in gpsprof utility

Arbitrary OS command execution via code injection in gpsprof utility. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: gpsd-minimal.

CVE-2026-60122
Red Hat Enterprise Linux
Jul 23, 2026
High7.5Red Hat

High [CVE-2026-14257] Denial of Service via memory exhaustion in expand function

Denial of Service via memory exhaustion in expand() function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:45381 with package nodejs26-main-26.5.0-1.4.hum1, grafana12-4-main-12.4.6-0.4.hum1, nodejs22-main-22.23.1-2.3.hum1, nodejs24-main-24.18.0-0.5.hum1.

CVE-2026-14257
Unclassified
Jul 23, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-64611] cpu exhaustion via infinite loop in cfieee1284normalizemakemodel

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service. A Moderate denial-of-service vulnerability in libcupsfilters allows network attackers to exhaust CPU resources by sending malformed IEEE-1284 device IDs. Red Hat rates this as Moderate because the vulnerable component, cups-browsed, is disabled by default in RHEL. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-64611
Red Hat Enterprise Linux
Jul 23, 2026
High8.8Red Hat

High [CVE-2026-16745] backend port 8080 trusts x-forwarded-access-token without origin validation

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure. Important: This flaw allows for privilege escalation within the cluster by bypassing authentication. It is due to the odh-dashboard backend binding to 0.0.0.0:8080 and trusting the x-forwarded-access-token header without origin validation. This enables any pod in the cluster to impersonate users by supplying an arbitrary token, circumventing the intended kube-rbac-proxy authentication. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-346. Affected Red Hat products: Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-16745
Unclassified
Jul 23, 2026

← All vendors