Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5455 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

High7.3Linux

High [CVE-2026-56001] BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow

BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow. Red Hat rates this important (CVSS 7.3). Red Hat lists fixing advisory RHSA-2026:47079 with package libXfont2-0:2.0.3-2.el8_10.1, libXfont2-0:2.0.6-5.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-56001
Red Hat Enterprise Linux
Jul 8, 2026
High7.3Linux

High [CVE-2026-56002] PCF Font Parsing Heap Buffer Overflow

PCF Font Parsing Heap Buffer Overflow. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47079 with package libXfont2-0:2.0.3-2.el8_10.1, libXfont2-0:2.0.6-5.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.

CVE-2026-56002
Red Hat Enterprise Linux
Jul 8, 2026
High7.1Linux

High [CVE-2026-59691] rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer

rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer. Red Hat rates this important (CVSS 7.1). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47180 with package gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2.6. Affected product named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-59691
Red Hat Enterprise Linux
Jul 8, 2026
High7.5Linux

High [CVE-2026-59692] DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback

DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback. Red Hat rates this important (CVSS 7.5). Weakness: CWE-121. Red Hat lists fixing advisory RHSA-2026:47180 with package gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2.6. Affected product named by the advisory: Red Hat Enterprise Linux 1.

CVE-2026-59692
Red Hat Enterprise Linux
Jul 8, 2026
High7.3Linux

High [CVE-2026-56003] computeProps Property Buffer Heap Buffer Overflow

A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:47103.

CVE-2026-56003
Red Hat Enterprise Linux
Jul 8, 2026
Medium5.7Vendor: HighLinux

Medium [CVE-2026-15108] Integer overflow in Extensions API

Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (Chromium security severity: High) An integer overflow flaw was found in the Extensions API component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 5.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-125.

CVE-2026-15108
Unclassified
Jul 8, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-15109] Uninitialized Use in ANGLE

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) An uninitialized use flaw was found in the ANGLE component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-824.

CVE-2026-15109
Unclassified
Jul 8, 2026
Medium6.5Linux

Medium [CVE-2026-54528] Information disclosure via case-sensitivity bypass in excluded path enforcement

Information disclosure via case-sensitivity bypass in excluded path enforcement. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-178.

CVE-2026-54528
Unclassified
Jul 8, 2026
Medium6.5Linux

Medium [CVE-2026-59818] Authentication bypass due to improper Certificate Revocation List enforcement on gRPC listener

Authentication bypass due to improper Certificate Revocation List enforcement on gRPC listener. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-295.

CVE-2026-59818
Unclassified
Jul 8, 2026
Medium5.7Linux

Medium [CVE-2026-15166] Denial of Service via IEEE 802.11 protocol dissector crash

Denial of Service via IEEE 802.11 protocol dissector crash. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-476.

CVE-2026-15166
Unclassified
Jul 8, 2026
Medium5.5Linux

Medium [CVE-2026-15174] Denial of Service via Catapult DCT2000 protocol dissector crash

Denial of Service via Catapult DCT2000 protocol dissector crash. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.

CVE-2026-15174
Unclassified
Jul 8, 2026
Medium5.5Linux

Medium [CVE-2026-15172] Denial of service via FMP/NOTIFY protocol dissector crash

Denial of service via FMP/NOTIFY protocol dissector crash. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1286.

CVE-2026-15172
Unclassified
Jul 8, 2026
MediumLinux

Medium [CVE-2026-15173] Denial of Service via pcapng file parser crash

Denial of Service via pcapng file parser crash. Red Hat rates this moderate. Weakness: CWE-825.

CVE-2026-15173
Unclassified
Jul 8, 2026
Medium5.5Linux

Medium [CVE-2026-15171] Denial of service via SSH protocol dissector crash

Denial of service via SSH protocol dissector crash. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1286.

CVE-2026-15171
Unclassified
Jul 8, 2026
Medium5.5Linux

Medium [CVE-2026-15169] Denial of Service via UMTS FP protocol dissector crash

Denial of Service via UMTS FP protocol dissector crash. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1286.

CVE-2026-15169
Unclassified
Jul 8, 2026
Medium6.5Linux

Medium [CVE-2026-15167] Denial of Service via DBS Etherwatch file parser crash

Denial of Service via DBS Etherwatch file parser crash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1286.

CVE-2026-15167
Unclassified
Jul 8, 2026
Medium5.5Linux

Medium [CVE-2026-15170] Denial of service via Z39.50 protocol dissector crash

Denial of service via Z39.50 protocol dissector crash. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-131.

CVE-2026-15170
Unclassified
Jul 8, 2026
Medium6.5Linux

Medium [CVE-2026-15165] Denial of Service via TLS ECH decryptor crash

Denial of Service via TLS ECH decryptor crash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617.

CVE-2026-15165
Unclassified
Jul 8, 2026
Medium5.5Linux

Medium [CVE-2026-15163] Denial of Service via multiple protocol dissector infinite loops

Denial of Service via multiple protocol dissector infinite loops. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835.

CVE-2026-15163
Unclassified
Jul 8, 2026
Medium5.5Linux

Medium [CVE-2026-15164] Denial of Service vulnerability in ciscodump

Denial of Service vulnerability in ciscodump. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.

CVE-2026-15164
Unclassified
Jul 8, 2026

← All vendors