Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.5Red Hat

Medium [CVE-2026-17059] Information disclosure via role-users endpoint bypasses per-user view filter

Information disclosure via role-users endpoint bypasses per-user view filter. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-639.

CVE-2026-17059
Unclassified
Jul 24, 2026
Medium5.5Red Hat

Medium [CVE-2026-17048] Vault-resolved rotated client secrets leaked via Admin REST API

Vault-resolved rotated client secrets leaked via Admin REST API. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-200. Affected product named by the advisory: Red Hat build of Keycloak 26.6.

CVE-2026-17048
Unclassified
Jul 24, 2026
Medium5.5Red Hat

Medium [CVE-2026-16743] arbitrary file read via SetIconFile for systemd-homed users

arbitrary file read via SetIconFile for systemd-homed users. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-269.

CVE-2026-16743
Unclassified
Jul 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-66010] Cross-Site Scripting (XSS) via custom element attribute bypass

Cross-Site Scripting (XSS) via custom element attribute bypass. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-79.

CVE-2026-66010
Unclassified
Jul 24, 2026
Medium5.5Red Hat

Medium [CVE-2026-16730] session bus denial of service via EMFILE during peer setup

session bus denial of service via EMFILE during peer setup. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-755. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.

CVE-2026-16730
Unclassified
Jul 24, 2026
Medium5.8Red Hat

Medium [CVE-2026-63317] Arbitrary class instantiation via crafted XML or untrusted format names

Arbitrary class instantiation via crafted XML or untrusted format names. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-502. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform Expansion Pack.

CVE-2026-63317
Unclassified
Jul 24, 2026
Medium4.4Red Hat

Medium [CVE-2026-56392] GNU coreutils unexpand: Denial of Service via crafted tab stop values

GNU coreutils unexpand: Denial of Service via crafted tab stop values. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-787. Red Hat lists fixing advisory RHBA-2026:47115 with package coreutils-0:8.30-20.el8_10, coreutils-main-9.11-5.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-56392
Unclassified
Jul 24, 2026
Medium6.1Red Hat

Medium [CVE-2026-56391] GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte input

GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte input. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:46515 with package coreutils-main-9.11-5.1.hum1.

CVE-2026-56391
Unclassified
Jul 24, 2026
Medium5.5Red Hat

Medium [CVE-2026-16910] SSRF in Red Hat Quay notification webhooks (Slack/generic)

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should not be reachable from the application. The Quay worker issues requests to attacker-specified URLs when notifications fire, but response data is not returned to the attacker, limiting exploitable impact to network probing and unauthenticated side-effects on internal services. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N). Weakness: CWE-918. Affected Red Hat products: Red Hat OpenShift Update Service; Red Hat Quay 3. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-16910
Unclassified
Jul 24, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-64227] Check ACPI_COMPANION against NULL during probe

Check ACPI_COMPANION() against NULL during probe. Red Hat rates this low (CVSS 5.5).

CVE-2026-64227
Unclassified
Jul 24, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-64254] Avoid pci_iounmap with offset when PEER_SPAD and CONFIG share BAR

Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR. Red Hat rates this low (CVSS 5.5).

CVE-2026-64254
Unclassified
Jul 24, 2026
Medium5.5Red Hat

Medium [CVE-2026-64212] don't dereference a pointer before NULL checking it

don't dereference a pointer before NULL checking it. Red Hat rates this moderate (CVSS 5.5).

CVE-2026-64212
Unclassified
Jul 24, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-64228] avoid NULL deref when PHY driver is unbound

avoid NULL deref when PHY driver is unbound. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.

CVE-2026-64228
Unclassified
Jul 24, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-64232] Linux kernel: Denial of Service in block subsystem due to incorrect integrity segment recomputation.

Linux kernel: Denial of Service in block subsystem due to incorrect integrity segment recomputation. Red Hat rates this low (CVSS 5.5). Weakness: CWE-617.

CVE-2026-64232
Unclassified
Jul 24, 2026
Medium5.5Red Hat

Medium [CVE-2026-64235] Local denial of service via incorrect relocation of ftrace trampoline references

Local denial of service via incorrect relocation of ftrace trampoline references. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.

CVE-2026-64235
Unclassified
Jul 24, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-64237] elan_i2c - validate firmware size before use

elan_i2c - validate firmware size before use. Red Hat rates this low (CVSS 5.5). Weakness: CWE-125.

CVE-2026-64237
Unclassified
Jul 24, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-64229] Disable broadcast TLB flush when PCID is disabled

Disable broadcast TLB flush when PCID is disabled. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.

CVE-2026-64229
Unclassified
Jul 24, 2026
Medium5.5Red Hat

Medium [CVE-2026-64224] fix double free in rvu_rep_rsrc_init

fix double free in rvu_rep_rsrc_init(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-763.

CVE-2026-64224
Unclassified
Jul 24, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-64213] (lm90) Add lock protection to lm90_alert

(lm90) Add lock protection to lm90_alert. Red Hat rates this low (CVSS 5.5). Weakness: CWE-820.

CVE-2026-64213
Unclassified
Jul 24, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-64214] Remove redundant preempt_disable|enable calls from arch_irq_work_raise

Remove redundant preempt_disable|enable() calls from arch_irq_work_raise(). Red Hat rates this low (CVSS 5.5).

CVE-2026-64214
Unclassified
Jul 24, 2026

← All vendors