Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.3Red Hat

Medium [CVE-2026-12259] Installation of attacker-controlled packages due to improper checksum validation

Installation of attacker-controlled packages due to improper checksum validation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-354. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-12259
Unclassified
Aug 3, 2026
Medium5.5Red Hat

Medium [CVE-2026-6695] remote code execution via crafted paa file

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system. Red Hat Enterprise Linux systems where GIMP is installed and used to process untrusted image files are affected. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-805. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-6695
Red Hat Enterprise Linux
Aug 3, 2026
Medium5.5Red Hat

Medium [CVE-2026-6694] gimp file-png plugin: denial of service via oversized apng trns chunk

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. When processing a specially crafted APNG image, the plugin may crash due to a stack buffer overflow. As GIMP executes plugins in separate processes, the main application remains unaffected, limiting the impact to the plugin's functionality. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-6694
Red Hat Enterprise Linux
Aug 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-59652] LDAP filter injection in legacy jdk1.4 LDAPStoreHelper

LDAP filter injection in legacy jdk1.4 LDAPStoreHelper. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-90.

CVE-2026-59652
Unclassified
Aug 3, 2026
Medium6.5Red Hat

Medium [CVE-2026-18573] Client access-type policy condition bypass during client update

Client access-type policy condition bypass during client update. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862.

CVE-2026-18573
Unclassified
Aug 2, 2026
Medium6.5Red Hat

Medium [CVE-2026-18572] UMA claim token can override authorization time-policy evaluation attributes

UMA claim token can override authorization time-policy evaluation attributes. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-863.

CVE-2026-18572
Unclassified
Aug 2, 2026
Medium6.6Red Hat

Medium [CVE-2026-18571] FGAP V2 group assignment bypass during user creation

FGAP V2 group assignment bypass during user creation. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-862.

CVE-2026-18571
Unclassified
Aug 2, 2026
Medium5.4Red Hat

Medium [CVE-2026-18570] Full-scope-disabled client policy validation bypass via omitted fullScopeAllowed

Full-scope-disabled client policy validation bypass via omitted fullScopeAllowed. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-862.

CVE-2026-18570
Unclassified
Aug 2, 2026
Medium4.3Red Hat

Medium [CVE-2026-67302] Denial of service in camera redirection due to divide-by-zero

Denial of service in camera redirection due to divide-by-zero. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-369.

CVE-2026-67302
Unclassified
Aug 1, 2026
Medium5.4Red Hat

Medium [CVE-2026-67306] Out-of-bounds read vulnerability via crafted RDP messages

Out-of-bounds read vulnerability via crafted RDP messages. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-125.

CVE-2026-67306
Unclassified
Aug 1, 2026
Medium6.3Red Hat

Medium [CVE-2026-67295] Unauthorized File Access via Drive Redirection Vulnerability

Unauthorized File Access via Drive Redirection Vulnerability. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-22.

CVE-2026-67295
Unclassified
Aug 1, 2026
Medium6.5Red Hat

Medium [CVE-2026-67300] Use-After-Free vulnerability leading to denial of service

Use-After-Free vulnerability leading to denial of service. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-825.

CVE-2026-67300
Unclassified
Aug 1, 2026
Medium6.5Red Hat

Medium [CVE-2026-67292] Information Disclosure and Denial of Service via WebSocket Ping

Information Disclosure and Denial of Service via WebSocket Ping. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-805.

CVE-2026-67292
Unclassified
Aug 1, 2026
Medium6.5Red Hat

Medium [CVE-2026-67299] Denial of Service via crafted WindowIcon async message

Denial of Service via crafted WindowIcon async message. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:54487 with package freerdp-2:2.11.7-11.el8_10, freerdp-2:2.11.7-7.el9_8.5, freerdp-2:3.10.3-12.el10_2.8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-67299
Unclassified
Aug 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-67318] Denial of Service due to maxBodyLength bypass in HTTP/2 requests

Denial of Service due to maxBodyLength bypass in HTTP/2 requests. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.

CVE-2026-67318
Unclassified
Aug 1, 2026
Medium5.8Red Hat

Medium [CVE-2026-67315] NO_PROXY bypass allows exposure of local services

NO_PROXY bypass allows exposure of local services. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-115. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.

CVE-2026-67315
Unclassified
Aug 1, 2026
Medium6.5Red Hat

Medium [CVE-2026-67319] Information disclosure and data manipulation via prototype pollution

Information disclosure and data manipulation via prototype pollution. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:49387 with package grafana13-1-main-13.1.1-0.4.hum1, grafana12-4-main-12.4.6-0.3.hum1.

CVE-2026-67319
Unclassified
Aug 1, 2026
Medium6.5Red Hat

Medium [CVE-2026-67291] Denial of Service via heap out-of-bounds read

Denial of Service via heap out-of-bounds read. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125.

CVE-2026-67291
Unclassified
Aug 1, 2026
Medium4.3Red Hat

Medium [CVE-2026-67303] Denial of Service via unsupported serial device control request

Denial of Service via unsupported serial device control request. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-617.

CVE-2026-67303
Unclassified
Aug 1, 2026
Medium5.3Red Hat

Medium [CVE-2026-67288] Denial of Service via crafted smartcard cache requests

Denial of Service via crafted smartcard cache requests. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-67288
Red Hat Enterprise Linux
Aug 1, 2026

← All vendors