Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.5Red Hat

Medium [CVE-2026-64413] zero chainstack array

zero chainstack array. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824.

CVE-2026-64413
Unclassified
Jul 25, 2026
Medium5.5Red Hat

Medium [CVE-2026-64408] pin L2CAP connection during netdev registration

pin L2CAP connection during netdev registration. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.

CVE-2026-64408
Unclassified
Jul 25, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-64513] Unconditionally recompute CR8 intercept on PPR update

Unconditionally recompute CR8 intercept on PPR update. Red Hat rates this low (CVSS 5.5).

CVE-2026-64513
Unclassified
Jul 25, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-64335] fix broken rx after throttle

fix broken rx after throttle. Red Hat rates this low (CVSS 5.5).

CVE-2026-64335
Unclassified
Jul 25, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-64417] fix NULL pointer dereference in debugfs

fix NULL pointer dereference in debugfs. Red Hat rates this low (CVSS 5.5).

CVE-2026-64417
Unclassified
Jul 25, 2026
Medium5.5Red Hat

Medium [CVE-2026-64450] fix out-of-bounds read in broadcast Gap ACK blocks

fix out-of-bounds read in broadcast Gap ACK blocks. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.

CVE-2026-64450
Unclassified
Jul 25, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-64457] fix vq info pointer lookup via wrong index

fix vq info pointer lookup via wrong index. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.

CVE-2026-64457
Unclassified
Jul 25, 2026
MediumRed Hat

Medium [CVE-2026-64446] fix heap buffer overflow in rtw_cfg80211_set_wpa_ie

fix heap buffer overflow in rtw_cfg80211_set_wpa_ie(). Red Hat rates this moderate. Weakness: CWE-120.

CVE-2026-64446
Unclassified
Jul 25, 2026
MediumRed Hat

Medium [CVE-2026-64500] Initialize completion before requesting IRQ

Initialize completion before requesting IRQ. Red Hat rates this moderate.

CVE-2026-64500
Unclassified
Jul 25, 2026
Medium5.5Red Hat

Medium [CVE-2026-64353] Keep dynamic inner array lookups nullable

Keep dynamic inner array lookups nullable. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.

CVE-2026-64353
Unclassified
Jul 25, 2026
Medium5.5Red Hat

Medium [CVE-2026-64339] bound bulk IN response length to the received transfer

bound bulk IN response length to the received transfer. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.

CVE-2026-64339
Unclassified
Jul 25, 2026
Medium6.5Red Hat

Medium [CVE-2026-66337] heap buffer over-read via integer underflow in soup_filter_input_stream_read_until

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory. A malicious HTTP server can trigger this against any libsoup client using SoupMultipartInputStream by sending a crafted multipart response with a boundary string longer than the internal buffer. This issue is related to but distinct from CVE-2026-1761. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-66337
Red Hat Enterprise Linux
Jul 24, 2026
Medium5.4Vendor: LowRed Hat

Medium [CVE-2026-66338] http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests. The practical impact is limited because libsoup servers are rarely deployed in internet-facing infrastructure behind reverse proxies. This issue is distinct from CVE-2026-1801 which covers bare LF tolerance. Red Hat severity: Low — CVSS 5.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N). Weakness: CWE-444. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-66338
Red Hat Enterprise Linux
Jul 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-66339] proxy credentials leak to destination server via proxy-authorization header in connect tunnels

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure. This causes proxy credentials to be sent in cleartext to destination servers, which can capture and reuse them. This issue is distinct from CVE-2026-12547 which covers credential leak when switching between proxies. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-201. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-66339
Red Hat Enterprise Linux
Jul 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-66038] Information disclosure via malformed zlib video stream

Information disclosure via malformed zlib video stream. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-908.

CVE-2026-66038
Unclassified
Jul 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-66037] Denial of Service via uncontrolled resource consumption in IAMF demuxer

Denial of Service via uncontrolled resource consumption in IAMF demuxer. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.

CVE-2026-66037
Unclassified
Jul 24, 2026
Medium5.3Red Hat

Medium [CVE-2026-66035] Arbitrary code execution via heap buffer overflow during SSH negotiation

Arbitrary code execution via heap buffer overflow during SSH negotiation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:46955 with package libssh2-main-1.11.1-10.3.hum1.

CVE-2026-66035
Unclassified
Jul 24, 2026
Medium5.9Red Hat

Medium [CVE-2026-66034] Information disclosure and potential arbitrary code execution via heap out-of-bounds read

Information disclosure and potential arbitrary code execution via heap out-of-bounds read. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:46927 with package libssh2-main-1.11.1-10.2.hum1.

CVE-2026-66034
Unclassified
Jul 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-66033] Denial of Service via integer underflow in AES-GCM cipher negotiation

Denial of Service via integer underflow in AES-GCM cipher negotiation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:46927 with package libssh2-main-1.11.1-10.2.hum1.

CVE-2026-66033
Unclassified
Jul 24, 2026
Medium6.5Red Hat

Medium [CVE-2026-66032] Arbitrary code execution via double-free in SFTP session

Arbitrary code execution via double-free in SFTP session. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1341. Red Hat lists fixing advisory RHSA-2026:46927 with package libssh2-main-1.11.1-10.2.hum1.

CVE-2026-66032
Unclassified
Jul 24, 2026

← All vendors