Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.0Red Hat

High [CVE-2026-63993] do not reuse cached ip_hdr value after skb_tunnel_check_pmtu

do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu(). Red Hat rates this important (CVSS 7). Weakness: CWE-825.

CVE-2026-63993
Unclassified
Jul 19, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64025] bpf, skmsg: fix verdict sk_data_ready racing with ktls rx

bpf, skmsg: fix verdict sk_data_ready racing with ktls rx. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364.

CVE-2026-64025
Unclassified
Jul 19, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-63979] hand off the pinned file reference to accept_doit

hand off the pinned file reference to accept_doit. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-63979
Unclassified
Jul 19, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64015] fix missed RCU read section on lookup

fix missed RCU read section on lookup. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64015
Unclassified
Jul 19, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-63978] Drain pending requests at net namespace exit

Drain pending requests at net namespace exit. Red Hat rates this moderate (CVSS 7). Weakness: CWE-821.

CVE-2026-63978
Unclassified
Jul 19, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64034] Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer

Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367.

CVE-2026-64034
Unclassified
Jul 19, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-63984] fix hdrlen overflow in ipv6_rpl_srh_decompress

fix hdrlen overflow in ipv6_rpl_srh_decompress(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-190.

CVE-2026-63984
Unclassified
Jul 19, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64001] Fix setup list UAF on proc write error

Fix setup list UAF on proc write error. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-64001
Unclassified
Jul 19, 2026
High7.0Red Hat

High [CVE-2026-64009] Check for underflow in xfrm_state_mtu

Check for underflow in xfrm_state_mtu. Red Hat rates this important (CVSS 7). Weakness: CWE-787.

CVE-2026-64009
Unclassified
Jul 19, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-63987] cap profile updates at NET_DIM_PARAMS_NUM_PROFILES

cap profile updates at NET_DIM_PARAMS_NUM_PROFILES. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787.

CVE-2026-63987
Unclassified
Jul 19, 2026
High7.0Red Hat

High [CVE-2026-63970] bind uarg before filling zerocopy skb

bind uarg before filling zerocopy skb. Red Hat rates this important (CVSS 7). Weakness: CWE-825.

CVE-2026-63970
Unclassified
Jul 19, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-63981] Fix blockcast recursion bypass leading to stack overflow

Fix blockcast recursion bypass leading to stack overflow. Red Hat rates this moderate (CVSS 7). Weakness: CWE-770.

CVE-2026-63981
Unclassified
Jul 19, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-63996] require exact CDB reply length

require exact CDB reply length. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787.

CVE-2026-63996
Unclassified
Jul 19, 2026
High8.1Red Hat

High [CVE-2026-9323] Predictable session IDs lead to remote code execution and information disclosure

Predictable session IDs lead to remote code execution and information disclosure. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1241.

CVE-2026-9323
Unclassified
Jul 18, 2026
High7.5Red Hat

High [CVE-2026-50274] Datadog dd-trace-go: Denial of Service via malicious baggage headers

Datadog dd-trace-go: Denial of Service via malicious baggage headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-50274
Unclassified
Jul 17, 2026
High8.6Red Hat

High [CVE-2026-53727] Arbitrary local file disclosure via Server-Side Request Forgery

Arbitrary local file disclosure via Server-Side Request Forgery. Red Hat rates this important (CVSS 8.6). Weakness: CWE-918.

CVE-2026-53727
Unclassified
Jul 17, 2026
High7.5Red Hat

High [CVE-2026-44891] Denial of Service vulnerability in STOMP decoder

Denial of Service vulnerability in STOMP decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-44891
Unclassified
Jul 17, 2026
High7.5Red Hat

High [CVE-2026-54465] Denial of Service via unbounded memory consumption

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client, a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. This issue is fixed in version 0.8.1. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Red Hat lists Red Hat Hardened Images as not affected.

CVE-2026-54465
Unclassified
Jul 17, 2026
High7.5Red Hat

High [CVE-2026-54463] Denial of Service via unbounded memory consumption in WebSocket length header

websocket-driver is a WebSocket protocol handler with pluggable I/O. This can make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. This issue is fixed in version 0.8.1. A remote attacker could exploit a vulnerability in how draft versions of the WebSocket protocol handle length headers. By sending an indefinite sequence of specially crafted bytes, an attacker can cause the affected component to consume an unbounded amount of memory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Red Hat lists Red Hat Hardened Images as not affected.

CVE-2026-54463
Unclassified
Jul 17, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-16118] heap-based buffer overflow in _xdg_mime_magic_parse_magic_line in xdgmimemagic.c

heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-122.

CVE-2026-16118
Unclassified
Jul 17, 2026

← All vendors