Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5616 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium4.0Vendor: LowRed Hat

Medium [CVE-2026-90463] Local OOB Read in NSS Service Request Parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`)

Local OOB Read in NSS Service Request Parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`). Red Hat rates this low (CVSS 4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-90463
Unclassified
Sep 14, 2026
Medium5.3Red Hat

Medium [CVE-2026-88932] Denial of Service via orphaned disk writes on aborted uploads

Denial of Service via orphaned disk writes on aborted uploads. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-459. Red Hat lists fixing advisory RHSA-2026:72722 with package ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Developer Hub; Self-service automation portal 2.

CVE-2026-88932
Unclassified
Sep 14, 2026
Medium5.3Red Hat

Medium [CVE-2026-90698] Denial of Service due to out-of-bounds read

Denial of Service due to out-of-bounds read. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:63224 with package memcached-main-1.6.45-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-90698
Unclassified
Sep 14, 2026
Medium4.7Red Hat

Medium [CVE-2025-64031] Denial of Service via heap-based buffer overflow in gzip writer

Denial of Service via heap-based buffer overflow in gzip writer. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:43818 with package libarchive-main-3.8.8-3.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.

CVE-2025-64031
Unclassified
Sep 14, 2026
Medium6.1Red Hat

Medium [CVE-2026-90781] Denial of Service via off-by-one stack buffer overflow

Denial of Service via off-by-one stack buffer overflow. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:40573 with package alsa-lib-main-1.2.16.1-2.hum1, alsa-lib-main-1.2.16.1-2.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: alsa-lib.

CVE-2026-90781
Red Hat Enterprise Linux
Sep 13, 2026
Medium5.9Red Hat

Medium [CVE-2026-90771] Prototype Pollution via custom messages

Prototype Pollution via custom messages. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:67610 with package grafana13-1-main-13.1.3-0.9.hum1, grafana13-2-main-13.2.1-0.4.hum1, grafana12-4-main-12.4.10-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Gatekeeper 3; Migration Toolkit for Containers; Red Hat Build of Podman Desktop; and 8 more. Affected products named by the advisory: Red Hat Data Grid 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more.

CVE-2026-90771
Red Hat Enterprise Linux
Sep 13, 2026
Medium6.7Red Hat

Medium [CVE-2022-42917] Privilege escalation via TOCTOU race condition

Privilege escalation via TOCTOU race condition. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: frr.

CVE-2022-42917
Red Hat Enterprise Linux
Sep 13, 2026
Medium5.7Red Hat

Medium [CVE-2024-53922] Denial of Service in buffer queue driver

Denial of Service in buffer queue driver. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-120. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2024-53922
Unclassified
Sep 13, 2026
Medium5.5Red Hat

Medium [CVE-2026-52296] out-of-bounds read due to missing required padding in WMA extradata allocation paths

out-of-bounds read due to missing required padding in WMA extradata allocation paths. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-52296
Unclassified
Sep 13, 2026
Medium5.5Red Hat

Medium [CVE-2026-52297] out-of-bounds read due to insufficiently padded extradata in the MOV parsing path

out-of-bounds read due to insufficiently padded extradata in the MOV parsing path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-52297
Unclassified
Sep 13, 2026
Medium6.5Red Hat

Medium [CVE-2026-90555] Denial of Service due to improper audio header validation

Denial of Service due to improper audio header validation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-90555
Unclassified
Sep 12, 2026
Medium6.2Red Hat

Medium [CVE-2026-90554] Denial of Service via video audio extraction

Denial of Service via video audio extraction. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-90554
Unclassified
Sep 12, 2026
Medium6.3Red Hat

Medium [CVE-2026-90461] Information disclosure via unexpected credential transmission

Information disclosure via unexpected credential transmission. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-201. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

CVE-2026-90461
Unclassified
Sep 11, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-89773] Skip Update HDCP Config In Transition State

Skip Update HDCP Config In Transition State. Red Hat rates this low (CVSS 5.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.

CVE-2026-89773
Linux Kernel
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89771] Fix subbuf resize race with ring buffer readers

Fix subbuf resize race with ring buffer readers. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-89771
Linux Kernel
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89770] don't free integrity payload that doesn't exist

don't free integrity payload that doesn't exist. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89770
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89769] Fix IRQ leak on cpuhp_setup_state error path

Fix IRQ leak on cpuhp_setup_state error path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89769
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89768] fix user path of nested backing files

fix user path of nested backing files. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-41. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89768
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89767] fix double end_creating on the casefold-mismatch path

fix double end_creating() on the casefold-mismatch path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341.

CVE-2026-89767
Unclassified
Sep 11, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-89765] Zero-init old itimerval before copy to userspace

Zero-init old itimerval before copy to userspace. Red Hat rates this low (CVSS 5.5). Weakness: CWE-201. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89765
Unclassified
Sep 11, 2026

← All vendors