Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

2989 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.8Red Hat Updated

Medium [CVE-2026-76827] UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering)

UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering). Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-693. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-76827
Unclassified
Aug 19, 2026
Medium6.5Red Hat

Medium [CVE-2026-63117] Denial of Service via ADPCM frame size calculation

A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. An authenticated Remote Desktop Protocol (RDP) client can trigger a denial of service by sending a specially crafted DVI ADPCM frame. By advertising specific nBlockAlign and nChannels values, a division-by-zero error occurs in the rdpsnd_server_select_format function. This vulnerability leads to the termination of the server-side rdpsnd channel process, causing a denial of service. A divide-by-zero flaw was found in FreeRDP's `rdpsnd` audio channel server implementation. An authenticated remote RDP client can send malformed DVI ADPCM audio parameters (`nBlockAlign=8`, `nChannels=2`) during format selection in `rdpsnd_server_select_format`. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-369. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-63117
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.2Red Hat Updated

Medium [CVE-2026-18874] annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription

A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper escaping of annotation values when they are rendered into YAML. Successful exploitation could lead to unauthorized modification or control over OLM Subscription configurations, potentially impacting software management within the cluster. This issue primarily affects systems where the 'volsync-addon-deploy-type: olm' annotation is explicitly enabled. Red Hat severity: Moderate — CVSS 6.2 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H). Weakness: CWE-94. Affected Red Hat products: Red Hat Advanced Cluster Management for Kubernetes 2. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-18874
Unclassified
Aug 19, 2026
Medium6.7Red Hat

Medium [CVE-2026-76231] Arbitrary command execution via unsanitized dependency names

A flaw was found in Renovate. Attackers with repository write access can exploit a command injection vulnerability in the hermit manager. This occurs because user-provided dependency names are not properly sanitized when appended to install and uninstall commands. Successful exploitation allows an attacker to execute arbitrary commands on the machine running Renovate. This flaw has a MODERATE impact on Renovate. The version of Renovate shipped by Red Hat is beyond the upstream fix (40.33.0); the vulnerable hermit-manager code is not present in the shipped version, so Red Hat's product is not affected. Red Hat severity: Moderate — CVSS 6.7 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78.

CVE-2026-76231
Unclassified
Aug 19, 2026
Medium6.7Red Hat

Medium [CVE-2026-76228] Arbitrary Code Execution via malicious Gradle Wrapper properties

A flaw was found in Renovate. This command injection vulnerability occurs when Renovate processes Gradle Wrapper updates. An attacker can introduce a malicious `gradle-wrapper.properties` file into a scanned repository, where a specially crafted `distributionUrl` containing shell command substitution syntax can lead to arbitrary code execution within the Renovate runtime. This allows an attacker to execute unauthorized commands on the system running Renovate. Red Hat does not ship or use an affected version of Renovate. Red Hat severity: Moderate — CVSS 6.7 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78.

CVE-2026-76228
Unclassified
Aug 19, 2026
Medium6.7Red Hat

Medium [CVE-2026-76229] Arbitrary Command Injection via kustomize manager

A flaw was found in Renovate. This arbitrary command injection vulnerability exists within the kustomize manager, where user-provided chart names are not properly sanitized before being used in helm pull commands. An attacker with write access to a repository can exploit this by crafting malicious kustomization.yaml files with specially designed chart names. This allows them to execute arbitrary commands on the Renovate host machine, leading to arbitrary code execution. Red Hat does not ship or use an affected version of Renovate. Red Hat severity: Moderate — CVSS 6.7 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78.

CVE-2026-76229
Unclassified
Aug 19, 2026
Medium4.3Red Hat Updated

Medium [CVE-2026-76166] mod_cluster Advertise Listener: unauthenticated DoS via crafted multicast datagram

mod_cluster Advertise Listener: unauthenticated DoS via crafted multicast datagram. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-476. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 5; and 3 more. Affected products named by the advisory: Red Hat JBoss Web Server 6; Red Hat JBoss Web Server 7; Red Hat Single Sign-On 7.

CVE-2026-76166
Unclassified
Aug 19, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-75900] Out-of-bounds read in SWTPM_NVRAM_CheckHeader due to sizeof(pointer) vs sizeof(struct) mismatch

Out-of-bounds read in SWTPM_NVRAM_CheckHeader due to sizeof(pointer) vs sizeof(struct) mismatch. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: swtpm.

CVE-2026-75900
Red Hat Enterprise Linux
Aug 19, 2026
Medium6.8Red Hat Updated

Medium [CVE-2026-76042] Information disclosure via uninitialized resource in GPU

Information disclosure via uninitialized resource in GPU. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-824.

CVE-2026-76042
Unclassified
Aug 18, 2026
Medium6.5Vendor: HighRed Hat Updated

Medium [CVE-2026-66781] IPsec PSK stored cleartext in Submariner CR spec

IPsec PSK stored cleartext in Submariner CR spec. Red Hat rates this important (CVSS 6.5). Weakness: CWE-312. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66781
Unclassified
Aug 18, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-75485] cluster Proxy object dumped raw, bypassing inspect redaction of proxy basic-auth credentials

cluster Proxy object dumped raw, bypassing inspect redaction of proxy basic-auth credentials. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-532. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-75485
Unclassified
Aug 18, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-73834] embedded Secret data in ACM wrapper CRs collected without redaction

embedded Secret data in ACM wrapper CRs collected without redaction. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-312. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-73834
Unclassified
Aug 18, 2026
Medium6.3Red Hat Updated

Medium [CVE-2026-75032] Out-of-bounds read in AVRCP parse_media_element and parse_media_folder

Out-of-bounds read in AVRCP parse_media_element and parse_media_folder. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-75032
Unclassified
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74974] Same-origin policy bypass in the Graphics: ImageLib component

Same-origin policy bypass in the Graphics: ImageLib component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-346. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-74974
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74973] Race condition, use-after-free in the Graphics component

Race condition, use-after-free in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-74973
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74969] Use-after-free in the Layout: Text and Fonts component

Use-after-free in the Layout: Text and Fonts component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-74969
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74965] Privilege escalation in the Shell Integration component

Privilege escalation in the Shell Integration component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-74965
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74967] Same-origin policy bypass in the Audio/Video: Playback component

Same-origin policy bypass in the Audio/Video: Playback component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-940. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-74967
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74963] Same-origin policy bypass in the Networking: Cookies component

Same-origin policy bypass in the Networking: Cookies component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-346. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-74963
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-74964] Integer overflow in the Graphics component

Integer overflow in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.

CVE-2026-74964
Red Hat Enterprise Linux
Aug 18, 2026

← All vendors