Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5455 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Low2.8Vendor: MediumLinux

Low [CVE-2026-60081] DBI::ProfileData: Denial of Service due to unbounded path index

DBI::ProfileData: Denial of Service due to unbounded path index. Red Hat rates this moderate (CVSS 2.8). Weakness: CWE-770.

CVE-2026-60081
Unclassified
Jul 14, 2026
Low3.8Linux

Low [CVE-2026-59084] Insufficient documentation for EncryptInterceptor may lead to insecure configurations

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue. Insufficient technical documentation regarding the secure configuration of the EncryptInterceptor component may lead to deployments with insecure settings. This vulnerability could allow an attacker to exploit misconfigurations that arise from unclear guidance, potentially compromising the confidentiality or integrity of data processed by the affected system. Without clear guidance on secure configuration, administrators might inadvertently deploy the interceptor in a way that weakens security, rather than a direct code flaw. This issue affects Red Hat products utilizing Apache Tomcat, including Red Hat Enterprise Linux and Red Hat JBoss Web Server. Red Hat severity: Low — CVSS 3.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-1188. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-59084
Red Hat Enterprise Linux
Jul 14, 2026
Low3.7Linux

Low [CVE-2026-59083] Security constraint bypass via improper URL encoding in rewrite valve

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue. A remote attacker could exploit this to bypass security constraints in certain configurations, potentially gaining unauthorized access or performing actions that should be restricted. Exploitation requires specific configurations and has high attack complexity, limiting its overall risk to Red Hat products. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-807. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 5. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2026:36872, RHSA-2026:37767.

CVE-2026-59083
Red Hat Enterprise Linux
Jul 14, 2026
High7.5Linux

High [CVE-2026-15685] Denial of Service via improper array index validation in downloadBlob function

Denial of Service via improper array index validation in download Blob function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-15685
Unclassified
Jul 13, 2026
High7.5Linux

High [CVE-2026-15584] Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot debug pods created in shared default namespace enable privilege escalation to node root

A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged debug pods with host filesystem access in the shared default namespace, where any user with the standard edit role can exec into them and obtain root access on cluster nodes. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-250. Affected Red Hat products: Pen Drive Powered by Red Hat Lightspeed. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-15584
Unclassified
Jul 13, 2026
High8.2Linux

High [CVE-2026-51537] Out-of-bounds read via malformed ForwardOpen requests

Out-of-bounds read via malformed ForwardOpen requests. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125.

CVE-2026-51537
Unclassified
Jul 13, 2026
Medium6.1Linux

Medium [CVE-2026-60103] Denial of Service and information disclosure via crafted.blend file

Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or read adjacent heap memory by supplying a crafted.blend file with a malicious signed short member_index value in the SDNA block. The member_index field is used as an array index into the sdna->members[] array in sdna_expand_names() without bounds validation, allowing any value outside the allocated range to produce an invalid pointer subsequently passed to strlen(), resulting in a SIGSEGV crash or unintended heap memory disclosure. A flaw was found in Blender. A remote attacker could exploit an out-of-bounds read vulnerability by providing a specially crafted.blend file. This vulnerability occurs when the application processes a malicious member_index value without proper validation, leading to an attempt to access memory outside of its allocated boundaries. Successful exploitation can result in a denial of service, causing the application to crash, or potentially lead to the disclosure of sensitive information from the system's memory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125.

CVE-2026-60103
Unclassified
Jul 13, 2026
Medium4.4Linux

Medium [CVE-2026-40468] Memory corruption via integer overflow

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below. A flaw was found in gawk. An integer overflow vulnerability could allow a local attacker to cause memory exhaustion, leading to a denial of service. This flaw may also enable an attacker to corrupt gawk's internal memory, potentially leading to system instability. This could lead to system instability or a denial of service on affected Red Hat products, requiring local access to execute a malicious gawk script. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L). Weakness: CWE-190. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:40041, RHSA-2026:49661.

CVE-2026-40468
Red Hat Enterprise Linux
Jul 13, 2026
Medium4.0Linux

Medium [CVE-2026-40467] Denial of Service due to Use After Free vulnerability in io.c

Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below. A flaw was found in gawk. This vulnerability can be triggered by an attacker, potentially leading to a system crash and causing a Denial of Service (DoS). This flaw, affecting gawk in Red Hat Hardened Images, requires a local attacker with low privileges to trick a user into interacting with specially crafted input, limiting its immediate impact. Red Hat severity: Moderate — CVSS 4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-825. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:40041, RHSA-2026:49661.

CVE-2026-40467
Red Hat Enterprise Linux
Jul 13, 2026
Medium6.5Linux

Medium [CVE-2026-62147] Query RBAC bypass

Query RBAC bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-863.

CVE-2026-62147
Unclassified
Jul 13, 2026
Medium6.3Linux

Medium [CVE-2026-15538] Remote attacker can modify object prototype attributes

Remote attacker can modify object prototype attributes. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-915.

CVE-2026-15538
Unclassified
Jul 13, 2026
Medium5.5Linux

Medium [CVE-2026-53365] fix zerocopy completion for multi-skb sends

fix zerocopy completion for multi-skb sends. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-911.

CVE-2026-53365
Unclassified
Jul 13, 2026
Medium5.5Vendor: LowLinux

Medium [CVE-2026-53364] Fix memory leak in hci_le_big_terminate

Fix memory leak in hci_le_big_terminate(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772.

CVE-2026-53364
Unclassified
Jul 13, 2026
Low3.1Linux

Low [CVE-2026-15605] Information disclosure due to weak hash in artifact integrity validation

Information disclosure due to weak hash in artifact integrity validation. Red Hat rates this low (CVSS 3.1). Weakness: CWE-328.

CVE-2026-15605
Unclassified
Jul 13, 2026
Low2.8Vendor: MediumLinux

Low [CVE-2026-40469] Denial of Service due to integer overflow

Denial of Service due to integer overflow. Red Hat rates this moderate (CVSS 2.8). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:40041 with package gawk-main-5.4.0-3.1.hum1.

CVE-2026-40469
Unclassified
Jul 13, 2026
Medium5.9Linux

Medium [CVE-2026-61861] Use-after-free vulnerability leading to denial of service or code execution

Use-after-free vulnerability leading to denial of service or code execution. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-825.

CVE-2026-61861
Unclassified
Jul 11, 2026
Medium5.5Linux

Medium [CVE-2026-61465] Denial of Service via crafted image due to missing memory allocation check

Denial of Service via crafted image due to missing memory allocation check. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770.

CVE-2026-61465
Unclassified
Jul 11, 2026
Medium6.5Linux

Medium [CVE-2026-61857] Application crashes via malicious XMP profiles

Application crashes via malicious XMP profiles. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476.

CVE-2026-61857
Unclassified
Jul 11, 2026
Medium6.1Linux

Medium [CVE-2026-56372] Information Disclosure and Denial of Service

Information Disclosure and Denial of Service. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125.

CVE-2026-56372
Unclassified
Jul 11, 2026
Low2.9Linux

Low [CVE-2026-61870] Denial of Service via specially crafted VIFF images

Denial of Service via specially crafted VIFF images. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.

CVE-2026-61870
Unclassified
Jul 11, 2026

← All vendors