Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5615 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.8Red Hat

Medium [CVE-2026-91733] Skia in chromium-browser: Information disclosure via improper state validation

Skia in chromium-browser: Information disclosure via improper state validation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-125. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-91733
Unclassified
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91744] Race condition in PlatformIntegration

Race condition in PlatformIntegration. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-368.

CVE-2026-91744
Unclassified
Sep 15, 2026
Medium6.7Red Hat

Medium [CVE-2026-88922] Privilege escalation via crafted archive decompression

Privilege escalation via crafted archive decompression. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-278. Red Hat lists fixing advisory RHSA-2026:68259 with package opentofu1-12-main-1.12.6-0.2.hum1, opentofu1-10-main-1.10.10-0.4.hum1, syft-main-1.51.1-0.2.hum1, grype-main-0.118.0-0.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; Red Hat Trusted Artifact Signer.

CVE-2026-88922
Unclassified
Sep 15, 2026
Medium6.1Red Hat

Medium [CVE-2026-92239] Out-of-bounds read via maliciously constructed IMAP line

Out-of-bounds read via maliciously constructed IMAP line. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, thunderbird-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92239
Unclassified
Sep 15, 2026
Medium6.1Red Hat

Medium [CVE-2026-92238] Memory safety violations via maliciously crafted mail headers

Memory safety violations via maliciously crafted mail headers. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, thunderbird-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92238
Unclassified
Sep 15, 2026
Medium4.4Vendor: LowRed Hat

Medium [CVE-2026-79699] Malicious tar whiteout header allows replacement of extraction destination directory

Malicious tar whiteout header allows replacement of extraction destination directory. Red Hat rates this low (CVSS 4.4). Weakness: CWE-59. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat OpenShift Virtualization 4; Red Hat Quay 3.

CVE-2026-79699
Unclassified
Sep 15, 2026
Medium4.5Red Hat

Medium [CVE-2026-79705] Directory escape via crafted tar symlinks when used outside Buildah by non-root callers

Directory escape via crafted tar symlinks when used outside Buildah by non-root callers. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:74861 with package podman-main-6.1.3-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat OpenShift Virtualization 4; and 1 more.

CVE-2026-79705
Unclassified
Sep 15, 2026
Medium5.8Red Hat

Medium [CVE-2026-76654] Subpath symlinking on Windows nodes permits NTLM coercion

Subpath symlinking on Windows nodes permits NTLM coercion. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-59. Affected product named by the advisory: Red Hat OpenShift for Windows Containers.

CVE-2026-76654
Unclassified
Sep 15, 2026
Medium5.9Red Hat Updated

Medium [CVE-2026-2270] StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation

StatefulSet and ControllerRevision write permissions allow cross-namespace pod creation. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-1220. Affected products named by the advisory: Logical Volume Manager Storage; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Edge Manager 1; Red Hat Hardened Images; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenShift GitOps.

CVE-2026-2270
Unclassified
Sep 15, 2026
Medium5.9Red Hat

Medium [CVE-2026-91992] Credential leak via HTTP client handle reuse

Credential leak via HTTP client handle reuse. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-524. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; Migration Toolkit for Applications 8; OpenShift Lightspeed; and 11 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more.

CVE-2026-91992
Red Hat Enterprise Linux
Sep 15, 2026
Medium5.4Red Hat

Medium [CVE-2026-91991] Cookie attribute injection via capitalized keyword arguments

Cookie attribute injection via capitalized keyword arguments. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-915. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 2 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4.

CVE-2026-91991
Unclassified
Sep 15, 2026
Medium5.4Red Hat

Medium [CVE-2026-91986] Information disclosure and virtual host spoofing via control character injection

Information disclosure and virtual host spoofing via control character injection. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 2 more. Affected products named by the advisory: Red Hat package: igvm; Red Hat package: rust.

CVE-2026-91986
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.3Red Hat

Medium [CVE-2026-91962] Remote out-of-bounds access via integer overflow in audin Apple backends

Remote out-of-bounds access via integer overflow in audin Apple backends. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-91962
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91961] Denial of Service via URBDRC control-transfer request with invalid OutputBufferSize

Denial of Service via URBDRC control-transfer request with invalid OutputBufferSize. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-91961
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91960] Denial of Service via integer overflow and double free in WinPR

Denial of Service via integer overflow and double free in WinPR. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-91960
Unclassified
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91959] Denial of Service due to buffer over-read in RPC gateway

Denial of Service due to buffer over-read in RPC gateway. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-91959
Unclassified
Sep 15, 2026
Medium6.6Red Hat

Medium [CVE-2026-91958] Denial of service and potential code execution via malicious RDP file

Denial of service and potential code execution via malicious RDP file. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.

CVE-2026-91958
Red Hat Enterprise Linux
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91956] Denial of Service via out-of-bounds read in URBDRC channel

Denial of Service via out-of-bounds read in URBDRC channel. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-91956
Unclassified
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91954] Denial of Service via crafted Surface Bits command

Denial of Service via crafted Surface Bits command. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:75570 with package freerdp-2:3.10.3-12.el10_2.14. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-91954
Unclassified
Sep 15, 2026
Medium6.5Red Hat

Medium [CVE-2026-91952] Denial of Service via crafted AVC444 graphics updates

Denial of Service via crafted AVC444 graphics updates. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-91952
Red Hat Enterprise Linux
Sep 15, 2026

← All vendors