Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5466 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High8.3Linux

High [CVE-2026-15772] Use after free in GPU

Use after free in GPU. Red Hat rates this important (CVSS 8.3). Weakness: CWE-787.

CVE-2026-15772
Unclassified
Jul 14, 2026
High8.3Linux

High [CVE-2026-15769] Insufficient validation of untrusted input in Linux Toolkit Theming

Insufficient validation of untrusted input in Linux Toolkit Theming. Red Hat rates this important (CVSS 8.3). Weakness: CWE-807.

CVE-2026-15769
Unclassified
Jul 14, 2026
High7.1Linux

High [CVE-2026-15768] Insufficient policy enforcement in HTML-in-Canvas

Insufficient policy enforcement in HTML-in-Canvas. Red Hat rates this important (CVSS 7.1). Weakness: CWE-346.

CVE-2026-15768
Unclassified
Jul 14, 2026
High7.4Linux

High [CVE-2026-15766] Uninitialized Use in Skia

Uninitialized Use in Skia. Red Hat rates this important (CVSS 7.4). Weakness: CWE-824.

CVE-2026-15766
Unclassified
Jul 14, 2026
High8.8Linux

High [CVE-2026-15767] Heap buffer overflow in libyuv

Heap buffer overflow in libyuv. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:42081 with package libyuv-main-0-0.63.20260714gitafff0cf.1.hum1.

CVE-2026-15767
Unclassified
Jul 14, 2026
High7.5Vendor: CriticalLinux

High [CVE-2026-15764] Use after free in Ozone

Use after free in Ozone. Red Hat rates this critical (CVSS 7.5). Weakness: CWE-825.

CVE-2026-15764
Unclassified
Jul 14, 2026
High8.1Linux

High [CVE-2026-53486] @xhmikosr/decompress: Decompress: Arbitrary file read/write via crafted archive extraction

@xhmikosr/decompress: Decompress: Arbitrary file read/write via crafted archive extraction. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:40415 with package dotnet8-0-main-8.0.128-1.2.hum1.

CVE-2026-53486
Unclassified
Jul 14, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-48801] Denial of Service via algorithmic complexity vulnerability

Denial of Service via algorithmic complexity vulnerability. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:49642 with package rhdh/rhdh-hub-rhel9:1785411652, rust-main-1.97.0-1.1.hum1, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki:1785332668, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1785332825.

CVE-2026-48801
Unclassified
Jul 14, 2026
High8.1Linux

High [CVE-2026-49978] Cross-site scripting vulnerability allows code execution

Cross-site scripting vulnerability allows code execution. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:46539 with package container-native-virtualization/kubevirt-console-plugin-rhel9:1784805322, rhdh/rhdh-hub-rhel9:1785411652, rhdh/red-hat-developer-hub-backstage-plugin-lightspeed:1785333413, container-native-virtualization/kubevirt-console-plugin:1784710594.

CVE-2026-49978
Unclassified
Jul 14, 2026
High7.5Linux

High [CVE-2026-47736] Denial of Service due to unbounded memory growth in PROXY protocol v1

Denial of Service due to unbounded memory growth in PROXY protocol v1. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-47736
Unclassified
Jul 14, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-15711] WebSocket remote denial of service via oversized control frame protocol violation

WebSocket remote denial of service via oversized control frame protocol violation. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770.

CVE-2026-15711
Unclassified
Jul 14, 2026
High7.5Linux

High [CVE-2026-47737] Source IP spoofing via PROXY protocol header re-parsing

Source IP spoofing via PROXY protocol header re-parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-358.

CVE-2026-47737
Unclassified
Jul 14, 2026
High7.5Vendor: MediumLinux

High [CVE-2026-15709] WebSocket permessage-deflate Unbounded Decompression Remote Denial of Service

WebSocket permessage-deflate Unbounded Decompression Remote Denial of Service. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-409.

CVE-2026-15709
Unclassified
Jul 14, 2026
High8.1Linux

High [CVE-2026-53633] @vitest/browser: vite-plus: Vitest: Remote code execution via exposed Chrome DevTools Protocol API

@vitest/browser: vite-plus: Vitest: Remote code execution via exposed Chrome DevTools Protocol API. Red Hat rates this important (CVSS 8.1). Weakness: CWE-94.

CVE-2026-53633
Unclassified
Jul 14, 2026
High8.3Linux

High [CVE-2026-47428] Arbitrary code execution via crafted browser-runner URL

Arbitrary code execution via crafted browser-runner URL. Red Hat rates this important (CVSS 8.3). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:39058 with package prometheus3-13-main-3.13.1-0.1.hum1.

CVE-2026-47428
Unclassified
Jul 14, 2026
High7.8Linux

High [CVE-2026-50650] .NET Framework: Privilege escalation via code injection

.NET Framework: Privilege escalation via code injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50650
Red Hat Enterprise Linux
Jul 14, 2026
High7.8Linux

High [CVE-2026-50649] .NET: Local code execution via deserialization of untrusted data

.NET: Local code execution via deserialization of untrusted data. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50649
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux

High [CVE-2026-50648] .NET Framework: Remote Denial of Service due to uncontrolled resource allocation

.NET Framework: Remote Denial of Service due to uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50648
Red Hat Enterprise Linux
Jul 14, 2026
High8.2Linux

High [CVE-2026-50528] .NET: Security feature bypass due to incorrect authorization

.NET: Security feature bypass due to incorrect authorization. Red Hat rates this important (CVSS 8.2). Weakness: CWE-551. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50528
Red Hat Enterprise Linux
Jul 14, 2026
High7.8Linux

High [CVE-2026-50646] .NET Framework: Local Code Execution via Protection Mechanism Failure

.NET Framework: Local Code Execution via Protection Mechanism Failure. Red Hat rates this important (CVSS 7.8). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50646
Red Hat Enterprise Linux
Jul 14, 2026

← All vendors