Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-20216] Denial of Service via crafted InstallShield file

Denial of Service via crafted InstallShield file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-20216
Unclassified
Jul 1, 2026
High7.5Red Hat

High [CVE-2026-20213] Denial of Service via crafted Portable Executable (PE) files

Denial of Service via crafted Portable Executable (PE) files. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-20213
Unclassified
Jul 1, 2026
High7.5Red Hat

High [CVE-2026-20214] Denial of Service via crafted FSG file parsing

Denial of Service via crafted FSG file parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-20214
Unclassified
Jul 1, 2026
High8.5Red Hat

High [CVE-2026-24260] Privilege escalation and code execution via race condition

Privilege escalation and code execution via race condition. Red Hat rates this important (CVSS 8.5). Weakness: CWE-367.

CVE-2026-24260
Unclassified
Jul 1, 2026
High8.8Red Hat

High [CVE-2026-5136] Privilege escalation to administrator-level access via usergroup role assignment manipulation

Privilege escalation to administrator-level access via usergroup role assignment manipulation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:34366 with package foreman-0:3.14.0.17-1.el9sat, foreman-0:3.18.0.7-1.el9sat, foreman-0:3.12.0.17-1.el9sat, foreman-0:3.12.0.17-1.el8sat. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-5136
Unclassified
Jul 1, 2026
High7.4Red Hat

High [CVE-2026-56016] Authentication bypass via predictable session IDs

Authentication bypass via predictable session IDs. Red Hat rates this important (CVSS 7.4). Weakness: CWE-331.

CVE-2026-56016
Unclassified
Jul 1, 2026
High7.5Red Hat

High [CVE-2026-57963] Chat UI manipulation by injection

An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-79. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.

CVE-2026-57963
Unclassified
Jul 1, 2026
High8.8Red Hat

High [CVE-2026-53488] Host-root command execution via unvalidated image config labels in CRI plugin

Host-root command execution via unvalidated image config labels in CRI plugin. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:37252 with package multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784060681, rhacm2/submariner-rhel9-operator:1782933193, multicluster-engine/assisted-service-8-rhel8:1783332008, multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784127491.

CVE-2026-53488
Unclassified
Jul 1, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-53341] fix UAF due to unlocked ->mnt_ns read in may_decode_fh

fix UAF due to unlocked ->mnt_ns read in may_decode_fh(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-364.

CVE-2026-53341
Unclassified
Jul 1, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-53354] Mitigate TLBI errata on various Arm CPUs

Mitigate TLBI errata on various Arm CPUs. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1037.

CVE-2026-53354
Unclassified
Jul 1, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-53355] clear i_sends on setup unwind

clear i_sends on setup unwind. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-53355
Unclassified
Jul 1, 2026
High7.5Red Hat

High [CVE-2026-54903] Heap corruption and Denial of Service via integer overflow in JSON parsing

Heap corruption and Denial of Service via integer overflow in JSON parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-54903
Unclassified
Jun 30, 2026
High7.5Red Hat

High [CVE-2026-54900] Heap corruption via crafted JSON object key

Heap corruption via crafted JSON object key. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131.

CVE-2026-54900
Unclassified
Jun 30, 2026
High7.8Red Hat

High [CVE-2026-54897] Use-After-Free in Oj::Doc Iterators via reentrant close

Use-After-Free in Oj::Doc Iterators via reentrant close. Red Hat rates this important (CVSS 7.8). Weakness: CWE-364.

CVE-2026-54897
Unclassified
Jun 30, 2026
High7.8Red Hat

High [CVE-2026-54896] Heap buffer overflow in exception serialization

Heap buffer overflow in exception serialization. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787.

CVE-2026-54896
Unclassified
Jun 30, 2026
High7.5Red Hat

High [CVE-2026-54592] Denial of Service via deeply nested JSON input

Denial of Service via deeply nested JSON input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.

CVE-2026-54592
Unclassified
Jun 30, 2026
High7.5Red Hat

High [CVE-2026-55223] Remote code execution via deserialization vulnerability

Remote code execution via deserialization vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502.

CVE-2026-55223
Unclassified
Jun 30, 2026
High7.3Red Hat

High [CVE-2026-54672] Arbitrary code execution through AppImage library loading vulnerability

Arbitrary code execution through AppImage library loading vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-427.

CVE-2026-54672
Unclassified
Jun 30, 2026
High7.3Red Hat

High [CVE-2026-58014] off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 1 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-58014
Red Hat Enterprise Linux
Jun 30, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-58374] Denial of Service via malformed Wi-Fi 7 Multi-Link Operation association request

Denial of Service via malformed Wi-Fi 7 Multi-Link Operation association request. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-787.

CVE-2026-58374
Unclassified
Jun 30, 2026

← All vendors