Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4618 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-85597] Authentication bypass via TLS option conflict

Authentication bypass via TLS option conflict. Red Hat rates this important (CVSS 7.5). Weakness: CWE-303. Affected product named by the advisory: Red Hat OpenShift Dev Spaces.

CVE-2026-85597
Unclassified
Sep 4, 2026
High7.5Red Hat

High [CVE-2026-85596] Authentication bypass due to TLS configuration conflict

Authentication bypass due to TLS configuration conflict. Red Hat rates this important (CVSS 7.5). Weakness: CWE-305.

CVE-2026-85596
Unclassified
Sep 4, 2026
High7.7Red Hat

High [CVE-2026-85594] Information disclosure via crossProviderNamespaces bypass in Kubernetes Ingress provider

Information disclosure via crossProviderNamespaces bypass in Kubernetes Ingress provider. Red Hat rates this important (CVSS 7.7). Weakness: CWE-1220.

CVE-2026-85594
Unclassified
Sep 4, 2026
High7.5Red Hat

High [CVE-2026-84428] Header validation bypass via incomplete schema case normalization

Header validation bypass via incomplete schema case normalization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1289. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.

CVE-2026-84428
Unclassified
Sep 4, 2026
High7.5Red Hat

High [CVE-2026-84469] Request validation bypass allows unauthorized operations

Request validation bypass allows unauthorized operations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.

CVE-2026-84469
Unclassified
Sep 4, 2026
High7.5Red Hat

High [CVE-2026-76169] Authentication bypass via malformed URLs

Authentication bypass via malformed URLs. Red Hat rates this important (CVSS 7.5). Weakness: CWE-289. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.

CVE-2026-76169
Unclassified
Sep 4, 2026
High8.1Red Hat

High [CVE-2026-84504] Unauthorized state changes and data disclosure via request body replacement

Unauthorized state changes and data disclosure via request body replacement. Red Hat rates this important (CVSS 8.1). Weakness: CWE-179. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.

CVE-2026-84504
Unclassified
Sep 4, 2026
High7.5Red Hat

High [CVE-2026-81665] heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly

heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly. Red Hat rates this important (CVSS 7.5). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:69280 with package corosync-0:3.1.9-1.el10_0.3, corosync-0:3.1.10-1.el9_8.2, corosync-0:3.1.5-2.el8_6.2, corosync-0:2.4.5-7.el7_9.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 8 more.

CVE-2026-81665
Unclassified
Sep 4, 2026
High7.7Red Hat

High [CVE-2026-71198] SSRF via location API missing host validation

SSRF via location API missing host validation. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

CVE-2026-71198
Unclassified
Sep 4, 2026
High7.7Red Hat

High [CVE-2026-71196] SSRF via web-download import due to empty default host filters

SSRF via web-download import due to empty default host filters. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

CVE-2026-71196
Unclassified
Sep 4, 2026
High7.4Red Hat

High [CVE-2026-85525] Data interception via improper OCSP response validation

Data interception via improper OCSP response validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-85525
Unclassified
Sep 4, 2026
High7.6Red Hat

High [CVE-2026-85197] Heap use-after-free in libsoup HTTP/2 client on_data_read via GOAWAY during body upload

Heap use-after-free in libsoup HTTP/2 client on_data_read() via GOAWAY during body upload. Red Hat rates this important (CVSS 7.6). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:68235 with package libsoup3-0:3.6.5-3.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-85197
Unclassified
Sep 4, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-85509] Arbitrary code execution via stack-based buffer overflow

Arbitrary code execution via stack-based buffer overflow. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freeipmi.

CVE-2026-85509
Red Hat Enterprise Linux
Sep 4, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-85508] stack-based buffer overflow in ipmi-oem Dell system info handler

stack-based buffer overflow in ipmi-oem Dell system info handler. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freeipmi.

CVE-2026-85508
Red Hat Enterprise Linux
Sep 4, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-85507] Arbitrary code execution via stack-based buffer overflow

Arbitrary code execution via stack-based buffer overflow. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freeipmi.

CVE-2026-85507
Red Hat Enterprise Linux
Sep 4, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-85506] Arbitrary code execution via stack-based buffer overflow in ipmi-oem

Arbitrary code execution via stack-based buffer overflow in ipmi-oem. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: freeipmi.

CVE-2026-85506
Red Hat Enterprise Linux
Sep 4, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-85504] Arbitrary code execution via malformed Fujitsu System Event Log responses

Arbitrary code execution via malformed Fujitsu System Event Log responses. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freeipmi.

CVE-2026-85504
Red Hat Enterprise Linux
Sep 4, 2026
High7.3Vendor: MediumRed Hat

High [CVE-2026-80863] Fix OOB in free_rd_atomic_resources

Fix OOB in free_rd_atomic_resources(). Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-80863
Linux Kernel
Sep 4, 2026
High8.3Red Hat

High [CVE-2026-80844] validate routing header segments_left

In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of addresses described by the routing header's hdrlen field. That assumption does not hold for raw IPv6 HDRINCL packets. A packet with hdrlen equal to 2 describes one address, but can carry an arbitrary segments_left value. With segments_left equal to 255, the function moves its address pointer 4,064 bytes backwards and passes a 4,064-byte length to memmove(), resulting in an out-of-bounds access. Validate the invariant locally before modifying the routing header or performing any address-pointer arithmetic, and propagate malformed-header errors to the existing AH6 input and output error paths. A flaw was found in the Linux kernel's xfrm subsystem, specifically within the AH6 (Authentication Header for IPv6) module. This oversight allows an attacker to craft a malicious packet that can cause an out-of-bounds memory access, potentially leading to memory corruption. This issue is classified as Important severity because exploitation can be achieved by a local attacker with unprivileged user access.

CVE-2026-80844
Linux Kernel
Sep 4, 2026
High8.8Red Hat

High [CVE-2026-85049] Use after free in Skia

Use after free in Skia. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:69098 with package webkit2gtk3-0:2.54.0-1.el9_8. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-85049
Unclassified
Sep 3, 2026

← All vendors