Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5475 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

UnratedLinux

Unknown [CVE-2026-64504] clamp the device-reported FIFO frame count

clamp the device-reported FIFO frame count. Red Hat rates this a security issue. Weakness: CWE-787.

CVE-2026-64504
Unclassified
Jul 25, 2026
UnratedLinux

Unknown [CVE-2026-64389] validate NTLMv2 response before updating session key

validate NTLMv2 response before updating session key. Red Hat rates this a security issue. Weakness: CWE-179.

CVE-2026-64389
Unclassified
Jul 25, 2026
UnratedLinux

Unknown [CVE-2026-64390] track the connection owning a byte-range lock

track the connection owning a byte-range lock. Red Hat rates this a security issue.

CVE-2026-64390
Unclassified
Jul 25, 2026
UnratedLinux

Unknown [CVE-2026-64501] fix CS held asserted and state leaks

fix CS held asserted and state leaks. Red Hat rates this a security issue. Weakness: CWE-772.

CVE-2026-64501
Unclassified
Jul 25, 2026
UnratedLinux

Unknown [CVE-2026-64444] fix OOB read in OnAssocRsp IE loop

fix OOB read in OnAssocRsp() IE loop. Red Hat rates this a security issue. Weakness: CWE-125.

CVE-2026-64444
Unclassified
Jul 25, 2026
UnratedLinux

Unknown [CVE-2026-64498] free scan_mask on buffer release

free scan_mask on buffer release. Red Hat rates this a security issue. Weakness: CWE-772.

CVE-2026-64498
Unclassified
Jul 25, 2026
UnratedLinux Updated

Unknown [CVE-2026-64462] Fix resource leaks on probe failure

In the Linux kernel, the following vulnerability has been resolved: PCI: altera: Fix resource leaks on probe failure The chained IRQ handler is set during probe, but is only removed during the driver remove(). If pci_host_probe() fails, the handler and INTx IRQ domain remain set even though the devm-managed host bridge storage containing struct altera_pcie will be released, leaving the handler with a stale data pointer. Interrupts are also enabled before pci_host_probe() is called. If probe fails after that point, the controller interrupt source should be disabled before the chained handler and INTx domain are removed. Disable controller interrupts during IRQ teardown, and tear the IRQ setup down if pci_host_probe() fails. [mani: commit log] When the driver fails to initialize properly, it can leave interrupt handlers and related resources active with outdated information. This resource leak and stale data pointer can lead to system instability or a denial of service, where the system becomes unresponsive or crashes. Red Hat severity: not rated. Weakness: CWE-825. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-64462
Unclassified
Jul 25, 2026
High8.8Linux

High [CVE-2026-66041] Arbitrary code execution via crafted PGS/SUP subtitle file

Arbitrary code execution via crafted PGS/SUP subtitle file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-66041
Unclassified
Jul 24, 2026
High8.8Linux

High [CVE-2026-66040] Arbitrary code execution via crafted PNG image

Arbitrary code execution via crafted PNG image. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-66040
Unclassified
Jul 24, 2026
High8.8Linux

High [CVE-2026-66039] Arbitrary code execution via crafted CAF file

Arbitrary code execution via crafted CAF file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-66039
Unclassified
Jul 24, 2026
High8.8Linux

High [CVE-2026-66036] Arbitrary code execution via crafted video in vf_hqdn3d filter

Arbitrary code execution via crafted video in vf_hqdn3d filter. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-66036
Unclassified
Jul 24, 2026
High8.5Linux

High [CVE-2026-17107] Impersonation header injection in service-proxy grants cluster-admin on every managed cluster

Impersonation header injection in service-proxy grants cluster-admin on every managed cluster. Red Hat rates this important (CVSS 8.5). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:48284 with package multicluster-engine/cluster-proxy-rhel9:1784342329, multicluster-engine/cluster-proxy-rhel9:1783278220, multicluster-engine/cluster-proxy-rhel9:1784925025, multicluster-engine/cluster-proxy-rhel9:1783985960.

CVE-2026-17107
Unclassified
Jul 24, 2026
High8.4Linux

High [CVE-2026-66140] Privilege escalation via directory traversal due to mishandled queue-name arguments

Privilege escalation via directory traversal due to mishandled queue-name arguments. Red Hat rates this important (CVSS 8.4). Weakness: CWE-22.

CVE-2026-66140
Unclassified
Jul 24, 2026
High8.8Linux

High [CVE-2026-66138] Arbitrary code execution via malicious configuration

Arbitrary code execution via malicious configuration. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78.

CVE-2026-66138
Unclassified
Jul 24, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-64255] validate sta_mask before ffs in BA session handlers

validate sta_mask before ffs() in BA session handlers. Red Hat rates this moderate (CVSS 7). Weakness: CWE-823.

CVE-2026-64255
Unclassified
Jul 24, 2026
High7.0Linux

High [CVE-2026-64219] Validate payload length and link_index in dc_process_dmub_aux_transfer_async

Validate payload length and link_index in dc_process_dmub_aux_transfer_async. Red Hat rates this important (CVSS 7). Weakness: CWE-120.

CVE-2026-64219
Unclassified
Jul 24, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-64247] Bound the bank index when querying sparse banks

Bound the bank index when querying sparse banks. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.

CVE-2026-64247
Unclassified
Jul 24, 2026
High7.0Linux

High [CVE-2026-64217] Fix overrun check in netfs_extract_user_iter

Fix overrun check in netfs_extract_user_iter(). Red Hat rates this important (CVSS 7).

CVE-2026-64217
Unclassified
Jul 24, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-64251] fix use-after-free in pwrseq_debugfs_seq_next

fix use-after-free in pwrseq_debugfs_seq_next(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-911.

CVE-2026-64251
Unclassified
Jul 24, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-64208] crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks

crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120.

CVE-2026-64208
Unclassified
Jul 24, 2026

← All vendors