Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.3Red Hat

Medium [CVE-2026-16768] out-of-bounds read in ico parser

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail. The only security impact of this issue is an information leak of memory contents via the generated output, such as a thumbnail. Also, the attacker does not have full control of the information obtained, further limiting its impact. Due to these reasons, this vulnerability has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-16768
Red Hat Enterprise Linux
Jul 23, 2026
Medium5.3Red Hat

Medium [CVE-2026-65698] Sensitive file exfiltration via AI agent path traversal vulnerability

Sensitive file exfiltration via AI agent path traversal vulnerability. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22.

CVE-2026-65698
Unclassified
Jul 23, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-54422] Credential extraction from bootc container deployment via /proc/1/root

Credential extraction from bootc container deployment via /proc/1/root. Red Hat rates this important (CVSS 6.5). Weakness: CWE-522.

CVE-2026-54422
Unclassified
Jul 23, 2026
Medium6.2Red Hat

Medium [CVE-2026-43823] Denial of Service due to double-free during RSA public key initialization

Denial of Service due to double-free during RSA public key initialization. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-763. Red Hat lists fixing advisory RHSA-2026:45785 with package swift-lang-main-6.3.3-0.1.1.hum1, nodejs24-main-24.18.0-0.5.hum1.

CVE-2026-43823
Unclassified
Jul 23, 2026
Medium5.3Red Hat

Medium [CVE-2026-16733] bahmutov find-cypress-specs: OS Command Injection via Branch Argument Manipulation

bahmutov find-cypress-specs: OS Command Injection via Branch Argument Manipulation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-78.

CVE-2026-16733
Unclassified
Jul 23, 2026
Medium6.1Red Hat

Medium [CVE-2026-65903] Security bypass allows injection of malicious content

Security bypass allows injection of malicious content. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-79.

CVE-2026-65903
Unclassified
Jul 23, 2026
Medium5.3Red Hat

Medium [CVE-2026-15037] XML injection via improper output neutralization in QDom serialization.

XML injection via improper output neutralization in QDom serialization. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-91.

CVE-2026-15037
Unclassified
Jul 23, 2026
Medium5.5Red Hat

Medium [CVE-2026-59677] Denial of Service via missing authorization in seunshares

Denial of Service via missing authorization in seunshares. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:44343 with package policycoreutils-main-3.11-2.1.hum1.

CVE-2026-59677
Unclassified
Jul 23, 2026
Medium5.3Red Hat

Medium [CVE-2026-59676] Arbitrary file deletion via TOCTOU race condition in seunshare

Arbitrary file deletion via TOCTOU race condition in seunshare. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367. Red Hat lists fixing advisory RHSA-2026:44343 with package policycoreutils-main-3.11-2.1.hum1.

CVE-2026-59676
Unclassified
Jul 23, 2026
Medium6.8Red Hat

Medium [CVE-2026-6390] GNU nano: Arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling.

GNU nano: Arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-134. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more.

CVE-2026-6390
Unclassified
Jul 23, 2026
Medium5.3Red Hat

Medium [CVE-2026-21723] Denial of Service via uncontrolled memory usage in alertmanager templates

Denial of Service via uncontrolled memory usage in alertmanager templates. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.

CVE-2026-21723
Unclassified
Jul 23, 2026
Medium5.3Red Hat

Medium [CVE-2026-16631] Arbitrary Command Execution via OS Command Injection

Arbitrary Command Execution via OS Command Injection. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-78.

CVE-2026-16631
Unclassified
Jul 22, 2026
Medium6.1Red Hat

Medium [CVE-2026-14899] Off-by-one out of bounds read in MIME header parser for forwarding

Off-by-one out of bounds read in MIME header parser for forwarding. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:53455 with package thunderbird-0:140.13.0-1.el10_0, thunderbird-0:140.13.0-1.el9_6, thunderbird-0:140.13.0-1.el8_6, thunderbird-0:140.13.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-14899
Unclassified
Jul 22, 2026
Medium6.8Vendor: HighRed Hat

Medium [CVE-2026-16615] weak random number generation in pkce implementation

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow. This allows the attacker to hold a valid access token and impersonate the user, access their protected data and perform actions on their behalf. Due to these reasons, this vulnerability has been rated with an important severity. Red Hat severity: Important — CVSS 6.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N). Weakness: CWE-338. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:47085.

CVE-2026-16615
Red Hat Enterprise Linux
Jul 22, 2026
Medium6.3Red Hat

Medium [CVE-2026-16552] systemd-tmpfiles symlink-redirected arbitrary file overwrite via a CHASE_SAFE root-to-unprivileged ownership transition bypass

systemd-tmpfiles symlink-redirected arbitrary file overwrite via a CHASE_SAFE root-to-unprivileged ownership transition bypass. Red Hat rates this a security issue. Weakness: CWE-59.

CVE-2026-16552
Unclassified
Jul 22, 2026
Medium5.3Vendor: LowRed Hat

Medium [CVE-2026-53910] heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations

heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Red Hat rates this low (CVSS 5.3). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:45327 with package diffutils-main-3.12-6.1.hum1.

CVE-2026-53910
Unclassified
Jul 22, 2026
Medium4.8Red Hat

Medium [CVE-2026-56416] Heap buffer overflow via malformed DNSSEC record

Heap buffer overflow via malformed DNSSEC record. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.

CVE-2026-56416
Unclassified
Jul 22, 2026
Medium5.9Red Hat

Medium [CVE-2026-55991] Denial of Service via crafted DNS-over-QUIC connection

Denial of Service via crafted DNS-over-QUIC connection. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.

CVE-2026-55991
Unclassified
Jul 22, 2026
Medium5.9Red Hat

Medium [CVE-2026-55990] Denial of Service via faulty DNSCrypt configuration

Denial of Service via faulty DNSCrypt configuration. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.

CVE-2026-55990
Unclassified
Jul 22, 2026
Medium5.9Red Hat

Medium [CVE-2026-52863] Denial of service due to memory corruption under specific configurations.

Denial of service due to memory corruption under specific configurations. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-1098. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.

CVE-2026-52863
Unclassified
Jul 22, 2026

← All vendors