Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5466 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Low2.9Linux

Low [CVE-2026-61865] Memory leak in hough lines operation can lead to denial of service

Memory leak in hough lines operation can lead to denial of service. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.

CVE-2026-61865
Unclassified
Jul 15, 2026
Low2.9Linux

Low [CVE-2026-61866] Memory leak in JNG encoder can lead to denial of service

Memory leak in JNG encoder can lead to denial of service. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.

CVE-2026-61866
Unclassified
Jul 15, 2026
Low2.9Linux

Low [CVE-2026-61864] Memory leak in color transformation to log colorspace

Memory leak in color transformation to log colorspace. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.

CVE-2026-61864
Unclassified
Jul 15, 2026
Low2.9Linux

Low [CVE-2026-61863] Memory leak in TIFF encoder

Memory leak in TIFF encoder. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.

CVE-2026-61863
Unclassified
Jul 15, 2026
Low2.9Linux

Low [CVE-2026-61862] Information disclosure via out-of-bounds read when displaying profiles with debug enabled

Information disclosure via out-of-bounds read when displaying profiles with debug enabled. Red Hat rates this low (CVSS 2.9). Weakness: CWE-125.

CVE-2026-61862
Unclassified
Jul 15, 2026
Low3.7Linux

Low [CVE-2026-61860] Denial of Service via use-after-free during freetype initialization

Denial of Service via use-after-free during freetype initialization. Red Hat rates this low (CVSS 3.7). Weakness: CWE-825.

CVE-2026-61860
Unclassified
Jul 15, 2026
LowLinux

Low [CVE-2026-61464] ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11

ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11. Red Hat rates this low.

CVE-2026-61464
Unclassified
Jul 15, 2026
Low3.3Linux

Low [CVE-2026-61859] Information disclosure via policy bypass in -script operation

Information disclosure via policy bypass in -script operation. Red Hat rates this low (CVSS 3.3). Weakness: CWE-639.

CVE-2026-61859
Unclassified
Jul 15, 2026
Low3.7Linux

Low [CVE-2026-56764] Hono - Timing Attack in basicAuth and bearerAuth Middleware

Hono - Timing Attack in basicAuth and bearerAuth Middleware. Red Hat rates this low (CVSS 3.7). Weakness: CWE-208. Red Hat lists fixing advisory RHSA-2026:47618 with package grafana13-1-main-13.1.1-0.2.hum1, grafana12-4-main-12.4.6-0.2.hum1.

CVE-2026-56764
Unclassified
Jul 15, 2026
Low3.3Linux

Low [CVE-2026-56375] Magick.NET-Q16-OpenMP-arm64: Magick.NET-Q16-OpenMP-x64: Magick.NET-Q16-OpenMP-x86: Magick.NET-Q16-arm64: Magick.NET-Q16-x64: Magick.NET-Q16-x86: Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm64: Ma…

Magick.NET-Q16-OpenMP-arm64: Magick.NET-Q16-OpenMP-x64: Magick.NET-Q16-OpenMP-x86: Magick.NET-Q16-arm64: Magick.NET-Q16-x64: Magick.NET-Q16-x86: Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm64: Magick.NET-Q8-OpenMP-x64: Magick.NET-Q8-arm64: Magick.NET-Q8-x64: Magick.NET-Q8-x86: ImageMagick: Denial of Service due to memory leak in ASHLAR coder. Red Hat rates this low (CVSS 3.3). Weakness: CWE-770.

CVE-2026-56375
Unclassified
Jul 15, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-15773] Use after free in Core

Use after free in Core. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-15773
Unclassified
Jul 14, 2026
Critical9.3Vendor: HighLinux

Critical [CVE-2026-15775] Insufficient policy enforcement in V8

Insufficient policy enforcement in V8. Red Hat rates this important (CVSS 9.3). Weakness: CWE-346.

CVE-2026-15775
Unclassified
Jul 14, 2026
Critical9.0Vendor: HighLinux

Critical [CVE-2026-15774] Use after free in Skia

Use after free in Skia. Red Hat rates this important (CVSS 9). Weakness: CWE-825.

CVE-2026-15774
Unclassified
Jul 14, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-54058] Memory disclosure or denial of service via crafted McIdas AREA image

Memory disclosure or denial of service via crafted McIdas AREA image. Red Hat rates this important (CVSS 9.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:48021 with package quay/quay-rhel8:1785261506, python-pillow-0:5.1.1-23.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-54058
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-59733] Unauthorized access to private repositories via directory traversal

Unauthorized access to private repositories via directory traversal. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-22.

CVE-2026-59733
Unclassified
Jul 14, 2026
High7.5Linux

High [CVE-2026-50651] SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM

SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50651
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux

High [CVE-2026-54572] Arbitrary file write via malicious symbolic link handling

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as.rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4. A remote attacker could exploit this by providing a malicious symlink, allowing subsequent file writes to occur outside the intended destination with content chosen by the attacker. This could lead to unauthorized modification of files on the system. Rclone's -l/--links option serializes symbolic links encountered during a sync as `.rclonelink` text objects containing the link target, and later recreates those links on the destination. Prior to 1.74.4, rclone did not validate that a stored link target stays within the intended destination tree before recreating it. A remote storage backend under an attacker's control can therefore supply a crafted `.rclonelink` object whose target escapes the destination directory (e.g. via a `../` traversal or an absolute path), causing a subsequent write during the same or a later sync to be redirected outside the intended destination with attacker-chosen content.

CVE-2026-54572
Unclassified
Jul 14, 2026
High7.4Linux

High [CVE-2026-45363] Authentication bypass due to empty key in HMAC verification

Authentication bypass due to empty key in HMAC verification. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347.

CVE-2026-45363
Unclassified
Jul 14, 2026
High7.5Linux

High [CVE-2026-49477] Denial of Service via crafted CSS selector strings

Denial of Service via crafted CSS selector strings. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:34119 with package python-rpds-py-main-2026.6.3-1.hum1, python-attrs-main-26.1.0-3.hum1.

CVE-2026-49477
Unclassified
Jul 14, 2026
High8.8Linux

High [CVE-2026-15777] Use after free in UI

Use after free in UI. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-15777
Unclassified
Jul 14, 2026

← All vendors