Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5475 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Critical9.9Vendor: HighLinux

Critical [CVE-2026-44210] Privilege escalation and information disclosure via command-line argument injection

Privilege escalation and information disclosure via command-line argument injection. Red Hat rates this important (CVSS 9.9). Weakness: CWE-88.

CVE-2026-44210
Unclassified
Jul 23, 2026
High8.2Linux

High [CVE-2026-16804] Sandbox escape via crafted HTML page

Sandbox escape via crafted HTML page. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787.

CVE-2026-16804
Unclassified
Jul 23, 2026
High8.8Linux

High [CVE-2026-16805] Use after free in Blink

Use after free in Blink. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-16805
Unclassified
Jul 23, 2026
High8.8Linux

High [CVE-2026-16806] Arbitrary code execution via use after free vulnerability in WebMCP

Arbitrary code execution via use after free vulnerability in WebMCP. Red Hat rates this important (CVSS 8.8).

CVE-2026-16806
Unclassified
Jul 23, 2026
High8.8Linux

High [CVE-2026-16807] Sandbox escape via crafted HTML page

Sandbox escape via crafted HTML page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-16807
Unclassified
Jul 23, 2026
High7.5Linux Updated

High [CVE-2026-14257] Denial of Service via memory exhaustion in expand function

Denial of Service via memory exhaustion in expand() function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:45381 with package nodejs26-main-26.5.0-1.4.hum1, grafana12-4-main-12.4.6-0.4.hum1, nodejs22-main-22.23.1-2.3.hum1, nodejs24-main-24.18.0-0.5.hum1.

CVE-2026-14257
Unclassified
Jul 23, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-64611] Libcupsfilters: cups-filters: libcupsfilters: cpu exhaustion via infinite loop in cfieee1284normalizemakemodel

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service. A Moderate denial-of-service vulnerability in libcupsfilters allows network attackers to exhaust CPU resources by sending malformed IEEE-1284 device IDs. Red Hat rates this as Moderate because the vulnerable component, cups-browsed, is disabled by default in RHEL. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-64611
Red Hat Enterprise Linux
Jul 23, 2026
High8.8Linux

High [CVE-2026-16745] Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without origin validation

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure. Important: This flaw allows for privilege escalation within the cluster by bypassing authentication. It is due to the odh-dashboard backend binding to 0.0.0.0:8080 and trusting the x-forwarded-access-token header without origin validation. This enables any pod in the cluster to impersonate users by supplying an arbitrary token, circumventing the intended kube-rbac-proxy authentication. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-346. Affected Red Hat products: Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-16745
Unclassified
Jul 23, 2026
Medium5.3Linux

Medium [CVE-2026-12353] Rhcs: memory leak during https connection leads to denial of service

An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary. Over time, this causes an Out of Memory condition that crashes the service. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-772. Affected Red Hat products: Red Hat Certificate System 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-12353
Red Hat Enterprise Linux
Jul 23, 2026
Medium5.5Linux

Medium [CVE-2026-65706] Arbitrary Code Execution via Crafted Video Frame

Arbitrary Code Execution via Crafted Video Frame. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.

CVE-2026-65706
Unclassified
Jul 23, 2026
Medium5.5Linux

Medium [CVE-2026-65705] Arbitrary code execution via out-of-bounds write in vf_floodfill video filter

Arbitrary code execution via out-of-bounds write in vf_floodfill video filter. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.

CVE-2026-65705
Unclassified
Jul 23, 2026
Medium5.5Linux

Medium [CVE-2026-65704] Heap corruption via crafted ffconcat file can lead to arbitrary code execution

Heap corruption via crafted ffconcat file can lead to arbitrary code execution. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.

CVE-2026-65704
Unclassified
Jul 23, 2026
Medium5.5Linux

Medium [CVE-2026-65703] Arbitrary code execution via crafted AVI file in TDSC video decoder

Arbitrary code execution via crafted AVI file in TDSC video decoder. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.

CVE-2026-65703
Unclassified
Jul 23, 2026
Medium5.3Vendor: LowLinux

Medium [CVE-2026-64785] HTTP Request Smuggling and Response Splitting via Incomplete Header Validation

HTTP Request Smuggling and Response Splitting via Incomplete Header Validation. Red Hat rates this low (CVSS 5.3). Weakness: CWE-93.

CVE-2026-64785
Unclassified
Jul 23, 2026
Medium6.6Linux

Medium [CVE-2026-65010] Arbitrary file write via symlink following

Arbitrary file write via symlink following. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-59.

CVE-2026-65010
Unclassified
Jul 23, 2026
Medium4.3Linux

Medium [CVE-2026-65920] Information disclosure via path traversal vulnerability

Information disclosure via path traversal vulnerability. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-22.

CVE-2026-65920
Unclassified
Jul 23, 2026
Medium5.3Linux

Medium [CVE-2026-16768] Gdk-pixbuf: out-of-bounds read in ico parser

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail. The only security impact of this issue is an information leak of memory contents via the generated output, such as a thumbnail. Also, the attacker does not have full control of the information obtained, further limiting its impact. Due to these reasons, this vulnerability has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-16768
Red Hat Enterprise Linux
Jul 23, 2026
Medium5.3Linux

Medium [CVE-2026-65698] Sensitive file exfiltration via AI agent path traversal vulnerability

Sensitive file exfiltration via AI agent path traversal vulnerability. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22.

CVE-2026-65698
Unclassified
Jul 23, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-54422] Credential extraction from bootc container deployment via /proc/1/root

Credential extraction from bootc container deployment via /proc/1/root. Red Hat rates this important (CVSS 6.5). Weakness: CWE-522.

CVE-2026-54422
Unclassified
Jul 23, 2026
Medium6.2Linux

Medium [CVE-2026-43823] Denial of Service due to double-free during RSA public key initialization

Denial of Service due to double-free during RSA public key initialization. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-763. Red Hat lists fixing advisory RHSA-2026:45785 with package swift-lang-main-6.3.3-0.1.1.hum1, nodejs24-main-24.18.0-0.5.hum1.

CVE-2026-43823
Unclassified
Jul 23, 2026

← All vendors