Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5652 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.2Red Hat

Medium [CVE-2026-89329] Local Denial of Service via Blocking IPC Send Operations

Local Denial of Service via Blocking IPC Send Operations. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-1322. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: device-mapper-multipath.

CVE-2026-89329
Red Hat Enterprise Linux
Sep 11, 2026
Medium6.3Red Hat

Medium [CVE-2026-89258] Information disclosure via symlink confinement bypass

Information disclosure via symlink confinement bypass. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat OpenShift GitOps; Red Hat OpenStack Platform 18.0; Red Hat package: grafana.

CVE-2026-89258
Red Hat Enterprise Linux
Sep 11, 2026
Medium5.3Red Hat

Medium [CVE-2026-87859] Log Injection via unescaped double quote in log fields

Log Injection via unescaped double quote in log fields. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-117. Affected products named by the advisory: Cryostat 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 6 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Openshift Data Foundation 4; Red Hat package: linux-sgx; Red Hat package: nodejs22; and 2 more.

CVE-2026-87859
Red Hat Enterprise Linux
Sep 11, 2026
Medium6.5Red Hat

Medium [CVE-2026-89158] Out-of-bounds write via integer overflow on 32-bit platforms

Out-of-bounds write via integer overflow on 32-bit platforms. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:67534 with package pcre2-main-10.48-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 7 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: bootc; Red Hat package: mariadb10.11; and 3 more.

CVE-2026-89158
Red Hat Enterprise Linux
Sep 11, 2026
Medium5.7Red Hat

Medium [CVE-2026-89157] Out-of-bounds write via large pattern input

Out-of-bounds write via large pattern input. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:67534 with package pcre2-main-10.48-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 5 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: mariadb10.11; Red Hat package: mariadb11.8; Red Hat package: mingw-pcre2; and 1 more.

CVE-2026-89157
Red Hat Enterprise Linux
Sep 11, 2026
Medium4.2Red Hat

Medium [CVE-2026-89092] nscd stack overflow leads to degraded DNS resolution

nscd stack overflow leads to degraded DNS resolution. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-120. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.

CVE-2026-89092
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-77159] Unsafe chown in qemuTPMEmulatorPrepareHost allows arbitrary file ownership change via symlink

Unsafe chown in qemuTPMEmulatorPrepareHost() allows arbitrary file ownership change via symlink. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-61. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: libvirt.

CVE-2026-77159
Red Hat Enterprise Linux
Sep 11, 2026
Medium4.1Red Hat

Medium [CVE-2026-81005] Fix NULL pointer dereference after failed registration

Fix NULL pointer dereference after failed registration. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-476.

CVE-2026-81005
Unclassified
Sep 11, 2026
Medium5.9Red Hat

Medium [CVE-2026-49838] Denial of Service via malformed BGP UPDATE message

Denial of Service via malformed BGP UPDATE message. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-125. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-49838
Unclassified
Sep 10, 2026
Medium4.4Red Hat

Medium [CVE-2026-45767] File overwrite via malicious rule load

File overwrite via malicious rule load. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-73.

CVE-2026-45767
Unclassified
Sep 10, 2026
Medium4.9Red Hat

Medium [CVE-2026-89298] Confidential client secret disclosed to view-clients role via Client Registration GET

Confidential client secret disclosed to view-clients role via Client Registration GET. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-200. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat Single Sign-On 7.

CVE-2026-89298
Unclassified
Sep 10, 2026
Medium4.0Red Hat

Medium [CVE-2026-88059] Information Leak via HttpTransferCache Bypass

Information Leak via HttpTransferCache Bypass. Red Hat rates this moderate (CVSS 4). Weakness: CWE-524. Affected products named by the advisory: A-MQ Interconnect 1; Red Hat Ceph Storage 4; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; and 11 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat OpenStack Platform 16.2; and 7 more.

CVE-2026-88059
Red Hat Enterprise Linux
Sep 10, 2026
Medium5.4Red Hat

Medium [CVE-2026-88057] @angular/core: @angular/compiler: Angular: Arbitrary code execution via sanitization bypass in host bindings

@angular/core: @angular/compiler: Angular: Arbitrary code execution via sanitization bypass in host bindings. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat build of Apicurio Registry 3; Red Hat Ceph Storage 4; Red Hat Enterprise Linux 10; and 12 more. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 8 more.

CVE-2026-88057
Red Hat Enterprise Linux
Sep 10, 2026
Medium5.9Red Hat

Medium [CVE-2026-88032] Denial of Service via use-after-free in client-side encryption cancellation

Denial of Service via use-after-free in client-side encryption cancellation. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-825. Affected products named by the advisory: Exploit Intelligence; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Quarkus.

CVE-2026-88032
Unclassified
Sep 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-88054] Denial of Service via crafted model with empty stack dereference

Denial of Service via crafted model with empty stack dereference. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.

CVE-2026-88054
Red Hat Enterprise Linux
Sep 10, 2026
Medium4.0Red Hat

Medium [CVE-2026-89045] Denial of Service via negative length parameter

Denial of Service via negative length parameter. Red Hat rates this moderate (CVSS 4). Weakness: CWE-835. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 11 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 7 more.

CVE-2026-89045
Red Hat Enterprise Linux
Sep 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-88050] Out-of-bounds write leads to Denial of Service

Out-of-bounds write leads to Denial of Service. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.

CVE-2026-88050
Red Hat Enterprise Linux
Sep 10, 2026
Medium5.3Red Hat

Medium [CVE-2026-88046] Unauthorized data modification via path traversal in source object names

Unauthorized data modification via path traversal in source object names. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22. Affected products named by the advisory: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-88046
Unclassified
Sep 10, 2026
Medium5.3Red Hat

Medium [CVE-2026-88015] Denial of Service via crafted Range request against translated symlink

Denial of Service via crafted Range request against translated symlink. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125. Affected products named by the advisory: OpenShift Service Mesh 3; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Virtualization 4.

CVE-2026-88015
Unclassified
Sep 10, 2026
Medium5.9Red Hat

Medium [CVE-2026-88014] Arbitrary file write via Zip Slip vulnerability

Arbitrary file write via Zip Slip vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22. Affected products named by the advisory: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-88014
Unclassified
Sep 10, 2026

← All vendors