Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5466 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.5Linux

High [CVE-2026-50527] .NET Framework: Denial of Service via network-based buffer overflow

.NET Framework: Denial of Service via network-based buffer overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50527
Red Hat Enterprise Linux
Jul 14, 2026
High7.0Vendor: MediumLinux

High [CVE-2026-50526] .NET: Local tampering via improper link resolution

.NET: Local tampering via improper link resolution. Red Hat rates this moderate (CVSS 7). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50526
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux

High [CVE-2026-50525] .NET: Denial of Service due to uncontrolled resource allocation

.NET: Denial of Service due to uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41894 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50525
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux

High [CVE-2026-50524] .NET Framework: Denial of Service via improper input validation

.NET Framework: Denial of Service via improper input validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-50524
Red Hat Enterprise Linux
Jul 14, 2026
High8.1Linux

High [CVE-2026-47429] Arbitrary code execution and information disclosure via path traversal

Arbitrary code execution and information disclosure via path traversal. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:39058 with package prometheus3-13-main-3.13.1-0.1.hum1.

CVE-2026-47429
Unclassified
Jul 14, 2026
High8.8Linux

High [CVE-2026-47303] Privilege Elevation via Authentication Bypass

Privilege Elevation via Authentication Bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-472. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet9-0-main-9.0.119-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-47303
Red Hat Enterprise Linux
Jul 14, 2026
High8.1Linux

High [CVE-2026-47304] .NET Security Feature Bypass Vulnerability

.NET Security Feature Bypass Vulnerability. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet9-0-main-9.0.119-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-47304
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux

High [CVE-2026-47302] .NET: Denial of Service vulnerability due to uncontrolled resource allocation

.NET: Denial of Service vulnerability due to uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-47302
Red Hat Enterprise Linux
Jul 14, 2026
High8.8Linux

High [CVE-2026-47300] Privilege Escalation via Incorrect Authentication Algorithm

Privilege Escalation via Incorrect Authentication Algorithm. Red Hat rates this important (CVSS 8.8). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet9-0-main-9.0.119-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-47300
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux

High [CVE-2026-57108] .NET Core: Denial of Service via type confusion

.NET Core: Denial of Service via type confusion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-57108
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux

High [CVE-2026-45646] Denial of Service via uncontrolled resource allocation

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. This can lead to the affected system becoming unresponsive or unavailable to legitimate users. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Red Hat lists Red Hat Hardened Images as not affected.

CVE-2026-45646
Unclassified
Jul 14, 2026
High7.5Linux

High [CVE-2026-56170] Denial of Service via uncontrolled resource allocation

Denial of Service via uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet9-0-main-9.0.119-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-56170
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux

High [CVE-2026-50506] Denial of Service due to uncontrolled resource allocation

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. A flaw was found in ASP.NET Core where an unauthorized remote attacker can cause a Denial of Service (DoS) over a network. This vulnerability occurs due to the allocation of resources without proper limits or throttling mechanisms, allowing an attacker to exhaust available resources and disrupt service availability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Red Hat lists Red Hat Hardened Images as not affected.

CVE-2026-50506
Unclassified
Jul 14, 2026
High7.5Linux

High [CVE-2026-59885] Denial of Service via crafted ASN.1 OBJECT IDENTIFIER

Denial of Service via crafted ASN.1 OBJECT IDENTIFIER. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:40236 with package quay/quay-rhel8:1785261506, jaeger-main-2.19.0-1.1.hum1.

CVE-2026-59885
Unclassified
Jul 14, 2026
High7.5Linux

High [CVE-2026-59886] Denial of Service via crafted ASN.1 REAL values

Denial of Service via crafted ASN.1 REAL values. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:37094 with package quay/quay-rhel8:1785261506, mariadb11-8-main-11.8.8-3.hum1.

CVE-2026-59886
Unclassified
Jul 14, 2026
High8.2Linux

High [CVE-2026-59197] Native heap out-of-bounds write

Native heap out-of-bounds write. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:48021 with package quay/quay-rhel8:1785261506, python-pillow-0:5.1.1-23.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.

CVE-2026-59197
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux

High [CVE-2026-59200] Denial of service via crafted PDF stream

Denial of service via crafted PDF stream. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:48933 with package quay/quay-rhel8:1785261506.

CVE-2026-59200
Unclassified
Jul 14, 2026
High7.5Linux

High [CVE-2026-59205] Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API

Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:48933 with package quay/quay-rhel8:1785261506.

CVE-2026-59205
Unclassified
Jul 14, 2026
High7.5Linux

High [CVE-2026-59199] Denial of Service via out-of-bounds write in image processing

Denial of Service via out-of-bounds write in image processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:48933 with package quay/quay-rhel8:1785261506.

CVE-2026-59199
Unclassified
Jul 14, 2026
High7.5Linux

High [CVE-2026-59204] Denial of Service via crafted JPEG2000 image

Denial of Service via crafted JPEG2000 image. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:48933 with package quay/quay-rhel8:1785261506.

CVE-2026-59204
Unclassified
Jul 14, 2026

← All vendors