Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.8Red Hat

High [CVE-2026-14380] Arbitrary code execution via caller-influenced Profile attribute

Arbitrary code execution via caller-influenced Profile attribute. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94.

CVE-2026-14380
Unclassified
Jul 7, 2026
High8.8Red Hat

High [CVE-2026-11610] Heap buffer overflow in sasl_io_recv via padded SASL UNBIND

Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:36209 with package redhat-ds:11-8060020260702180044.0ca98e7e, 389-ds:1.4-8060020260626130540.824efc52, redhat-ds:12-9040020260703055735.1674d574, redhat-ds:11-8100020260702145313.37ed7c03. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-11610
Unclassified
Jul 7, 2026
High8.8Red Hat

High [CVE-2026-14474] sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation

sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1188. Red Hat lists fixing advisory RHSA-2026:42122 with package sssd-0:2.9.4-5.el8_10.5, sssd-0:2.9.8-4.el9_8.1, sssd-0:2.12.0-3.el10_2.1, sssd-0:2.10.2-3.el10_0.5. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-14474
Unclassified
Jul 7, 2026
High8.0Vendor: MediumRed Hat

High [CVE-2026-14476] GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass

GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass. Red Hat rates this moderate (CVSS 8). Weakness: CWE-23. Red Hat lists fixing advisory RHSA-2026:42122 with package sssd-0:2.9.4-5.el8_10.5, sssd-0:2.9.8-4.el9_8.1, sssd-0:2.12.0-3.el10_2.1, sssd-0:2.10.2-3.el10_0.5. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-14476
Unclassified
Jul 7, 2026
High7.3Red Hat

High [CVE-2026-58384] integer overflow in read_rle_channel

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-58384
Red Hat Enterprise Linux
Jul 7, 2026
High7.5Red Hat

High [CVE-2026-33630] Use-after-free / double-free in query-completion handling

Use-after-free / double-free in query-completion handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42096 with package c-ares-0:1.34.6-2.el10_2, c-ares-main-1.34.7-1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-33630
Unclassified
Jul 7, 2026
High8.5Vendor: MediumRed Hat

High [CVE-2026-54765] Unauthorized filter context application in Kubernetes Gateway API provider

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route's filter context to be applied to another route's requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6. The system may incorrectly apply the attacker's route filter context to another route's requests, potentially allowing unauthorized access or information disclosure across different namespaces. This could lead to the application of security-sensitive headers from the attacker's route to legitimate requests, bypassing intended security controls. This Moderate flaw in Traefik's Kubernetes Gateway API provider, as deployed in Red Hat OpenShift Dev Spaces, could allow an attacker to apply their route's filter context to other requests.

CVE-2026-54765
Unclassified
Jul 6, 2026
High7.5Red Hat

High [CVE-2026-55574] Denial of Service via adversarial regular expression in structured outputs API

Denial of Service via adversarial regular expression in structured outputs API. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333.

CVE-2026-55574
Unclassified
Jul 6, 2026
High7.5Red Hat

High [CVE-2026-54234] Denial of Service via malformed speculative decoding workload

Denial of Service via malformed speculative decoding workload. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125.

CVE-2026-54234
Unclassified
Jul 6, 2026
High7.5Red Hat

High [CVE-2026-55379] Denial of Service via crafted BDF font file

Denial of Service via crafted BDF font file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:39127 with package python-pillow-0:5.1.1-22.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-55379
Unclassified
Jul 6, 2026
High7.5Red Hat

High [CVE-2026-55380] Denial of Service via crafted GD 2.x image file

Denial of Service via crafted GD 2.x image file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. Red Hat lists fixing advisory RHSA-2026:39127 with package python-pillow-0:5.1.1-22.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-55380
Unclassified
Jul 6, 2026
High7.5Red Hat

High [CVE-2026-54060] Denial of Service via excessive memory allocation when processing font files

Denial of Service via excessive memory allocation when processing font files. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:39127 with package python-pillow-0:5.1.1-22.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-54060
Unclassified
Jul 6, 2026
High7.5Red Hat

High [CVE-2026-54059] Denial of Service via crafted PCF font data

Denial of Service via crafted PCF font data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:39127 with package python-pillow-0:5.1.1-22.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-54059
Unclassified
Jul 6, 2026
High7.3Vendor: MediumRed Hat

High [CVE-2026-43825] Remote code execution via untrusted Java deserialization

Remote code execution via untrusted Java deserialization. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-502.

CVE-2026-43825
Unclassified
Jul 6, 2026
High8.2Red Hat

High [CVE-2026-59195] Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config. Red Hat rates this important (CVSS 8.2).

CVE-2026-59195
Unclassified
Jul 6, 2026
High7.1Red Hat

High [CVE-2026-59194] patch-remove could delete project-selected files outside the patches directory

patch-remove could delete project-selected files outside the patches directory. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22.

CVE-2026-59194
Unclassified
Jul 6, 2026
High7.3Red Hat

High [CVE-2026-58380] stack buffer overflow in pnmscanner_gettoken

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.

CVE-2026-58380
Red Hat Enterprise Linux
Jul 6, 2026
High7.7Red Hat

High [CVE-2026-9165] Unbounded GraphQL query depth allows authenticated denial of service

Unbounded GraphQL query depth allows authenticated denial of service. Red Hat rates this important (CVSS 7.7). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:36319 with package advanced-cluster-security/rhacs-main-rhel8:1783357140, advanced-cluster-security/rhacs-main-rhel9:1783352589, advanced-cluster-security/rhacs-main-rhel8:1783357116.

CVE-2026-9165
Unclassified
Jul 6, 2026
High8.1Red Hat

High [CVE-2026-43866] Apache Camel JMS components: Arbitrary Exchange state injection

Apache Camel JMS components: Arbitrary Exchange state injection. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502.

CVE-2026-43866
Unclassified
Jul 6, 2026
High8.2Red Hat

High [CVE-2026-46726] Server-Side Request Forgery and sensitive data exposure

Server-Side Request Forgery and sensitive data exposure. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918.

CVE-2026-46726
Unclassified
Jul 6, 2026

← All vendors