Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.3Red Hat

Medium [CVE-2026-15392] DBD::File: Arbitrary file read/write via symlink vulnerability

DBD::File: Arbitrary file read/write via symlink vulnerability. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-59.

CVE-2026-15392
Unclassified
Jul 14, 2026
Medium6.3Red Hat

Medium [CVE-2026-15697] Remote object prototype pollution

Remote object prototype pollution. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-915.

CVE-2026-15697
Unclassified
Jul 14, 2026
Medium4.3Red Hat

Medium [CVE-2026-15043] DBI::SQL::Nano: DBI::SQL::Nano: Incorrect SQL operator evaluation can lead to incorrect data filtering.

DBI::SQL::Nano: DBI::SQL::Nano: Incorrect SQL operator evaluation can lead to incorrect data filtering. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-480.

CVE-2026-15043
Unclassified
Jul 14, 2026
Medium4.8Red Hat

Medium [CVE-2026-0716 +1] incomplete fix for CVE-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)

The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup-based client when max_incoming_payload_size is set to 0. This vulnerability is rated Moderate for Red Hat because it requires a non-default configuration where max_incoming_payload_size is explicitly set to 0 or unset in libsoup's WebSocket frame processing. In typical Red Hat deployments, this configuration is not enabled by default, limiting the exposure to memory disclosure or application instability. Red Hat severity: Moderate — CVSS 4.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-0716CVE-2026-12478
Red Hat Enterprise Linux
Jul 14, 2026
Medium4.2Red Hat

Medium [CVE-2026-12482] Arbitrary File Operations via Malicious Tar Archive Processing

Arbitrary File Operations via Malicious Tar Archive Processing. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-22.

CVE-2026-12482
Unclassified
Jul 14, 2026
Medium6.1Red Hat

Medium [CVE-2026-60103] Denial of Service and information disclosure via crafted.blend file

Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or read adjacent heap memory by supplying a crafted.blend file with a malicious signed short member_index value in the SDNA block. The member_index field is used as an array index into the sdna->members[] array in sdna_expand_names() without bounds validation, allowing any value outside the allocated range to produce an invalid pointer subsequently passed to strlen(), resulting in a SIGSEGV crash or unintended heap memory disclosure. A flaw was found in Blender. A remote attacker could exploit an out-of-bounds read vulnerability by providing a specially crafted.blend file. This vulnerability occurs when the application processes a malicious member_index value without proper validation, leading to an attempt to access memory outside of its allocated boundaries. Successful exploitation can result in a denial of service, causing the application to crash, or potentially lead to the disclosure of sensitive information from the system's memory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125.

CVE-2026-60103
Unclassified
Jul 13, 2026
Medium4.4Red Hat

Medium [CVE-2026-40468] Memory corruption via integer overflow

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below. A flaw was found in gawk. An integer overflow vulnerability could allow a local attacker to cause memory exhaustion, leading to a denial of service. This flaw may also enable an attacker to corrupt gawk's internal memory, potentially leading to system instability. This could lead to system instability or a denial of service on affected Red Hat products, requiring local access to execute a malicious gawk script. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L). Weakness: CWE-190. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:40041, RHSA-2026:49661.

CVE-2026-40468
Unclassified
Jul 13, 2026
Medium4.0Red Hat

Medium [CVE-2026-40467] Denial of Service due to Use After Free vulnerability in io.c

Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below. A flaw was found in gawk. This vulnerability can be triggered by an attacker, potentially leading to a system crash and causing a Denial of Service (DoS). This flaw, affecting gawk in Red Hat Hardened Images, requires a local attacker with low privileges to trick a user into interacting with specially crafted input, limiting its immediate impact. Red Hat severity: Moderate — CVSS 4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-825. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:40041, RHSA-2026:49661.

CVE-2026-40467
Unclassified
Jul 13, 2026
Medium6.5Red Hat

Medium [CVE-2026-62147] Query RBAC bypass

Query RBAC bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-863.

CVE-2026-62147
Unclassified
Jul 13, 2026
Medium6.3Red Hat

Medium [CVE-2026-15538] Remote attacker can modify object prototype attributes

Remote attacker can modify object prototype attributes. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-915.

CVE-2026-15538
Unclassified
Jul 13, 2026
Medium5.5Red Hat

Medium [CVE-2026-53365] fix zerocopy completion for multi-skb sends

fix zerocopy completion for multi-skb sends. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-911.

CVE-2026-53365
Unclassified
Jul 13, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-53364] Fix memory leak in hci_le_big_terminate

Fix memory leak in hci_le_big_terminate(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772.

CVE-2026-53364
Unclassified
Jul 13, 2026
Medium5.9Red Hat

Medium [CVE-2026-61861] Use-after-free vulnerability leading to denial of service or code execution

Use-after-free vulnerability leading to denial of service or code execution. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-825.

CVE-2026-61861
Unclassified
Jul 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-61465] Denial of Service via crafted image due to missing memory allocation check

Denial of Service via crafted image due to missing memory allocation check. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770.

CVE-2026-61465
Unclassified
Jul 11, 2026
Medium6.5Red Hat

Medium [CVE-2026-61857] Application crashes via malicious XMP profiles

Application crashes via malicious XMP profiles. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476.

CVE-2026-61857
Unclassified
Jul 11, 2026
Medium6.1Red Hat

Medium [CVE-2026-56372] Information Disclosure and Denial of Service

Information Disclosure and Denial of Service. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125.

CVE-2026-56372
Unclassified
Jul 11, 2026
Medium5.8Red Hat

Medium [CVE-2026-52747] Security rule bypass due to incorrect handling of line breaks in form data

Security rule bypass due to incorrect handling of line breaks in form data. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-179.

CVE-2026-52747
Unclassified
Jul 10, 2026
Medium5.8Red Hat

Medium [CVE-2026-52761] Web Application Firewall rules bypass due to incorrect UTF-8 to Unicode transformation

Web Application Firewall rules bypass due to incorrect UTF-8 to Unicode transformation. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-131.

CVE-2026-52761
Unclassified
Jul 10, 2026
Medium5.9Red Hat

Medium [CVE-2026-49844] Malformed JSON output due to improper encoding of floating-point values

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values. This can corrupt log records or disrupt downstream log ingestion and parsing, potentially leading to a Denial of Service (DoS) or information integrity issues.

CVE-2026-49844
Unclassified
Jul 10, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-57217] Authorization bypass allows unauthorized topic writes and binds during metadata-store failures

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6. This vulnerability could enable an attacker to bypass intended topic restrictions, potentially leading to unauthorized message manipulation or access. Red Hat severity: Important — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-280. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.

CVE-2026-57217
Unclassified
Jul 10, 2026

← All vendors