Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4618 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.8Red Hat

High [CVE-2026-87766] symlink traversal via /oldroot allows writing files outside sandbox during setup

symlink traversal via /oldroot allows writing files outside sandbox during setup. Red Hat rates this important (CVSS 8.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-87766
Unclassified
Sep 9, 2026
High8.1Vendor: MediumRed Hat

High [CVE-2026-87874] memcached cache plugin deserializes untrusted pickle data from memcached, enabling cache-poisoning remote code execution on the Ansible controller

memcached cache plugin deserializes untrusted pickle data from memcached, enabling cache-poisoning remote code execution on the Ansible controller. Red Hat rates this moderate (CVSS 8.1). Weakness: CWE-502. Affected products named by the advisory: Red Hat Ceph Storage 5; Red Hat Ceph Storage 9; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

CVE-2026-87874
Unclassified
Sep 9, 2026
High7.0Red Hat

High [CVE-2026-88924] gvfs-admin socket ownership race permits local root

gvfs-admin socket ownership race permits local root. Red Hat rates this important (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-88924
Unclassified
Sep 9, 2026
High8.2Red Hat

High [CVE-2026-53938] Heap buffer overflow in AES Key Wrap decryption leads to denial of service

Heap buffer overflow in AES Key Wrap decryption leads to denial of service. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:73017 with package cjose-0:0.6.1-13.el9_2.1, cjose-0:0.6.1-16.el9_4.1. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-53938
Unclassified
Sep 8, 2026
High8.7Red Hat

High [CVE-2026-87049] Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events

Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events. Red Hat rates this important (CVSS 8.7). Weakness: CWE-269.

CVE-2026-87049
Unclassified
Sep 8, 2026
High8.0Red Hat

High [CVE-2026-79721] Arbitrary code execution via maliciously crafted model artifact

Arbitrary code execution via maliciously crafted model artifact. Red Hat rates this important (CVSS 8). Weakness: CWE-502. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-79721
Unclassified
Sep 8, 2026
High7.5Red Hat

High [CVE-2026-57099] Denial of Service via uncontrolled resource allocation

Denial of Service via uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-57099
Unclassified
Sep 8, 2026
High7.0Red Hat

High [CVE-2026-69806] .NET Elevation of Privilege Vulnerability

.NET Elevation of Privilege Vulnerability. Red Hat rates this important (CVSS 7). Weakness: CWE-200. Red Hat lists fixing advisory RHSA-2026:66863 with package dotnet9.0-0:9.0.121-1.el9_8, dotnet10.0-0:10.0.112-1.el9_8, dotnet9.0-0:9.0.121-1.el8_10, dotnet10.0-0:10.0.112-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-69806
Unclassified
Sep 8, 2026
High7.5Red Hat

High [CVE-2026-12611] org.eclipse.jetty.http2/jetty-http2-common: Jetty: Denial of Service via HTTP/2 race condition

org.eclipse.jetty.http2/jetty-http2-common: Jetty: Denial of Service via HTTP/2 race condition. Red Hat rates this important (CVSS 7.5). Weakness: CWE-367. Affected products named by the advisory: OpenShift Developer Tools and Services; Red Hat Offline Knowledge Portal.

CVE-2026-12611
Unclassified
Sep 8, 2026
High8.2Red Hat

High [CVE-2026-19203] HTTP request smuggling via crafted chunked requests

HTTP request smuggling via crafted chunked requests. Red Hat rates this important (CVSS 8.2). Weakness: CWE-444. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; and 11 more. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; and 7 more.

CVE-2026-19203
Red Hat Enterprise Linux
Sep 8, 2026
High7.5Red Hat

High [CVE-2026-11573] Denial of Service via uncontrolled recursion in XML serialization

Denial of Service via uncontrolled recursion in XML serialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: qt6-qtbase.

CVE-2026-11573
Red Hat Enterprise Linux
Sep 8, 2026
High8.7Red Hat

High [CVE-2026-80219] OAuthClient created with GrantMethod auto and no secret enables OAuth token theft

OAuthClient created with GrantMethod auto and no secret enables OAuth token theft. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1390. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.

CVE-2026-80219
Unclassified
Sep 8, 2026
High8.2Red Hat

High [CVE-2026-77968] Cluster-wide secrets read/write granted to operator ServiceAccount

Cluster-wide secrets read/write granted to operator ServiceAccount. Red Hat rates this important (CVSS 8.2). Weakness: CWE-269. Red Hat lists fixing advisory RHSA-2026:66120 with package rhbac-4/hawtio-operator-bundle:2.0.1-8, rhbac-4/hawtio-rhel9-operator:2.0.1-10. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.

CVE-2026-77968
Unclassified
Sep 8, 2026
High8.5Red Hat

High [CVE-2026-74860] Libxml2: double-free/uaf in libxml2 python bindings

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. Red Hat severity: Important — CVSS 8.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-763. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:64463. Affected products named by the advisory: Red Hat package: libxml2.

CVE-2026-74860
Red Hat Enterprise Linux
Sep 8, 2026
High7.2Red Hat

High [CVE-2026-76561] certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint)

certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint). Red Hat rates this important (CVSS 7.2). Weakness: CWE-78. Affected products named by the advisory: Red Hat Certificate System 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-76561
Unclassified
Sep 8, 2026
High7.5Red Hat

High [CVE-2026-6377] Information disclosure via path traversal vulnerability

Information disclosure via path traversal vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22.

CVE-2026-6377
Unclassified
Sep 7, 2026
High8.4Red Hat

High [CVE-2026-19843] Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor

Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor. Red Hat rates this important (CVSS 8.4). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:64780 with package 389-ds-base-0:3.0.6-4.el10dsrv, redhat-ds:12-9040020260903102623.1674d574, redhat-ds:12-9020020260903155914.1674d574, 389-ds-base-0:3.2.0-7.el10dsrv. Affected products named by the advisory: Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; Red Hat Directory Server 12.4 E4S for RHEL 9; and 9 more. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 12.6 EUS for RHEL 9; Red Hat Directory Server 12.8 for RHEL 9; Red Hat Directory Server 13.0 EUS for RHEL 10; and 4 more.

CVE-2026-19843
Unclassified
Sep 7, 2026
High7.5Red Hat

High [CVE-2026-18453] pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search

pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; and 13 more.

CVE-2026-18453
Unclassified
Sep 7, 2026
High7.5Red Hat

High [CVE-2026-11774 +1] heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet

heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; and 13 more.

CVE-2026-11774CVE-2026-18355
Unclassified
Sep 7, 2026
High7.5Red Hat

High [CVE-2026-76560] anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN

anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN. Red Hat rates this important (CVSS 7.5). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; and 13 more.

CVE-2026-76560
Unclassified
Sep 7, 2026

← All vendors