Red Hat Linux Security Advisories & CVEs
5454 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2026-59999] OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options
OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-358. Red Hat lists fixing advisory RHSA-2026:37382 with package openssh-main-10.4p1-1.hum1.
Medium [CVE-2026-59998] Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory
Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-909. Red Hat lists fixing advisory RHSA-2026:37382 with package openssh-main-10.4p1-1.hum1.
Medium [CVE-2026-59997] SFTP security bypass due to command-line argument parsing flaw
SFTP security bypass due to command-line argument parsing flaw. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:37382 with package openssh-main-10.4p1-1.hum1.
Medium [CVE-2026-59996] `scp` file misplacement vulnerability during remote copy
`scp` file misplacement vulnerability during remote copy. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:37382 with package openssh-main-10.4p1-1.hum1.
Medium [CVE-2026-59995] sftp client allows attacker to control downloaded file location
sftp client allows attacker to control downloaded file location. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:37382 with package openssh-main-10.4p1-1.hum1.
Medium [CVE-2026-56000] GLX contextTags Use-After-Free in CommonMakeCurrent
GLX contextTags Use-After-Free in CommonMakeCurrent(). Red Hat rates this important (CVSS 6.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:38490 with package xorg-x11-server-Xwayland-0:24.1.9-4.el9_8.3, xorg-x11-server-Xwayland-0:24.1.9-4.el10_2.3. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-15044] Unauthenticated access to AI guardrails and orchestrator APIs
Unauthenticated access to AI guardrails and orchestrator APIs. Red Hat rates this moderate (CVSS 6.3).
Medium [CVE-2026-15063] Gorch port bypass when auth IS enabled
Gorch port bypass when auth IS enabled. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-306.
Low [CVE-2026-15168] Information disclosure in BLF file parser
Information disclosure in BLF file parser. Red Hat rates this low (CVSS 2.5). Weakness: CWE-237.
Low [CVE-2026-6352] Auditor-level users can modify compliance records via improper authorization in GraphQL
Auditor-level users can modify compliance records via improper authorization in GraphQL. Red Hat rates this low (CVSS 2.7). Weakness: CWE-639.
Low [CVE-2026-56362] Magick.NET-Q16-HDRI-x64: Magick.NET-Q16-HDRI-x86: Magick.NET-Q16-OpenMP-arm64: Magick.NET-Q16-OpenMP-x64: Magick.NET-Q16-OpenMP-x86: Magick.NET-Q16-arm64: Magick.NET-Q16-x64: Magick.NET-Q16-x86: Ma…
Magick.NET-Q16-HDRI-x64: Magick.NET-Q16-HDRI-x86: Magick.NET-Q16-OpenMP-arm64: Magick.NET-Q16-OpenMP-x64: Magick.NET-Q16-OpenMP-x86: Magick.NET-Q16-arm64: Magick.NET-Q16-x64: Magick.NET-Q16-x86: Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm64: Magick.NET-Q8-OpenMP-x64: Magick.NET-Q8-arm64: Magick.NET-Q8-x64: Magick.NET-Q8-x86: ImageMagick: Information disclosure via heap-buffer-overflow read. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125.
Low [CVE-2026-56374] Denial of Service and Information Disclosure via heap buffer overflow in FTXT encoder
Denial of Service and Information Disclosure via heap buffer overflow in FTXT encoder. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125.
Low [CVE-2026-15028] heap overflow OOB read while parsing a tar archive contains a PAX extended header
heap overflow OOB read while parsing a tar archive contains a PAX extended header. Red Hat rates this low (CVSS 3.9). Red Hat lists fixing advisory RHSA-2026:38279 with package libarchive-main-3.8.8-2.1.hum1.
Low [CVE-2026-15041] Non-constant-time comparison in PBKDF2-SHA256 password verification
Non-constant-time comparison in PBKDF2-SHA256 password verification. Red Hat rates this low (CVSS 3.7). Weakness: CWE-208.
High [CVE-2026-14739] Heap overflow when preparsing SQL statements with excessive placeholders
Heap overflow when preparsing SQL statements with excessive placeholders. Red Hat rates this important (CVSS 8.1). Weakness: CWE-131.
High [CVE-2026-14380] Arbitrary code execution via caller-influenced Profile attribute
Arbitrary code execution via caller-influenced Profile attribute. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94.
High [CVE-2026-11610] Heap buffer overflow in sasl_io_recv via padded SASL UNBIND
Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:36209 with package redhat-ds:11-8060020260702180044.0ca98e7e, 389-ds:1.4-8060020260626130540.824efc52, redhat-ds:12-9040020260703055735.1674d574, redhat-ds:11-8100020260702145313.37ed7c03. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.
High [CVE-2026-14474] sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation
sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1188. Red Hat lists fixing advisory RHSA-2026:42122 with package sssd-0:2.9.4-5.el8_10.5, sssd-0:2.9.8-4.el9_8.1, sssd-0:2.12.0-3.el10_2.1, sssd-0:2.10.2-3.el10_0.5. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-14476] GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass
GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass. Red Hat rates this moderate (CVSS 8). Weakness: CWE-23. Red Hat lists fixing advisory RHSA-2026:42122 with package sssd-0:2.9.4-5.el8_10.5, sssd-0:2.9.8-4.el9_8.1, sssd-0:2.12.0-3.el10_2.1, sssd-0:2.10.2-3.el10_0.5. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-58384] Gimp: gimp: integer overflow in read_rle_channel
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. Affected product named by the advisory: Red Hat Enterprise Linux 9.