Complete feed
Security advisories & CVEs
5198 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-23144] Linux kernel: Local denial of service and memory leak in DAMON sysfs via setup failure
Linux kernel: Local denial of service and memory leak in DAMON sysfs via setup failure. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-772. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:8342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-23139] update last_gc only when GC has been performed
update last_gc only when GC has been performed. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-400. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:15883 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-23193] Fix use-after-free in iscsit_dec_session_usage_count()
Fix use-after-free in iscsit_dec_session_usage_count(). Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-364. Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-23204] use skb_header_pointer_careful()
use skb_header_pointer_careful(). Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-1285. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:10756 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9.
High [CVE-2026-23191] Fix racy access at PCM trigger
Fix racy access at PCM trigger. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-367. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.
High [CVE-2026-23156] Linux kernel: Information disclosure in efivarfs via incorrect error propagation
Linux kernel: Information disclosure in efivarfs via incorrect error propagation. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-390. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:9095 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2025-71201] Fix early read unlock of page with EOF in middle
Fix early read unlock of page with EOF in middle. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-826. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2025:20095 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-23185] cancel mlo_scan_start_wk
cancel mlo_scan_start_wk. Red Hat rates this important (CVSS 6.7). Weakness: CWE-772. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
Medium [CVE-2026-23146] Linux kernel: Denial of Service in Bluetooth HCI UART driver via null pointer dereference
Linux kernel: Denial of Service in Bluetooth HCI UART driver via null pointer dereference. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-476. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2025:20095 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-23205] fix memory leak in smb2_open_file()
fix memory leak in smb2_open_file(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2025:20095 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-23111] Privilege escalation or denial of service in nf_tables via inverted element activity check
Privilege escalation or denial of service in nf_tables via inverted element activity check. Red Hat rates this important (CVSS 7.8). Weakness: CWE-672. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:9112 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream EUS (v.9.4); Red Hat Enterprise Linux AppStream EUS (v.9.6); and 24 more.
High [CVE-2026-2441] Use after free in CSS
Use after free in CSS. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-33042] Code injection on Java generated code
Code injection on Java generated code. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-94. Affected package(s): avro. Resolved in Red Hat advisory RHSA-2026:7109 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-25949] Denial of Service via stalled STARTTLS requests
Denial of Service via stalled STARTTLS requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): devspaces/traefik-rhel9:1774227265. Resolved in Red Hat advisory RHSA-2026:6192 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.27.
High [CVE-2026-2007] PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120. Affected package(s): postgresql18-main, postgresql18. Resolved in Red Hat advisory RHSA-2026:19009 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Hardened Images; Red Hat Enterprise Linux 9.
High [CVE-2026-2006] PostgreSQL missing validation of multibyte character length executes arbitrary code
PostgreSQL missing validation of multibyte character length executes arbitrary code. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1285. Affected package(s): postgresql, postgresql:16, postgresql:15, postgresql18-main, rhui5/rhua-rhel9:1773670137, postgresql:13. Resolved in Red Hat advisory RHSA-2026:4516 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 11 more.
High [CVE-2026-2005] PostgreSQL pgcrypto heap buffer overflow executes arbitrary code
PostgreSQL pgcrypto heap buffer overflow executes arbitrary code. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected package(s): postgresql, postgresql:16, postgresql:15, postgresql18-main, rhui5/rhua-rhel9:1773670137, postgresql:13. Resolved in Red Hat advisory RHSA-2026:4516 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 11 more.
High [CVE-2026-2004] PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code
PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1287. Affected package(s): postgresql, postgresql:16, postgresql:15, postgresql18-main, rhui5/rhua-rhel9:1773670137, postgresql:13. Resolved in Red Hat advisory RHSA-2026:4516 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 11 more.
High [CVE-2026-2327] Denial of Service via Regular Expression Denial of Service in linkify function
Denial of Service via Regular Expression Denial of Service in linkify function. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1333. Affected package(s): devspaces/openvsx-rhel9:1779528224. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-2003] PostgreSQL oidvector discloses a few bytes of memory
PostgreSQL oidvector discloses a few bytes of memory. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-1287. Affected package(s): postgresql:16, postgresql, postgresql:15, postgresql18-main, rhui5/rhua-rhel9:1773670137, postgresql16. Resolved in Red Hat advisory RHSA-2026:3896 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.