Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-9117] Type Confusion in GFX
Type Confusion in GFX. Red Hat rates this important (CVSS 8.2). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-9112] Use after free in GPU
Use after free in GPU. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-9800] Authorization bypass via incorrect URI comparison
Authorization bypass via incorrect URI comparison. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1025. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.6, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.4. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6; Red Hat JBoss Enterprise Application Platform Expansion Pack.
High [CVE-2026-46323] Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs
Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs. Red Hat rates this important (CVSS 7.8). Weakness: CWE-123. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27708 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux for NVIDIA 26; and 5 more.
High [CVE-2026-25244] Remote Code Execution via command injection in Git branch name processing
Remote Code Execution via command injection in Git branch name processing. Red Hat rates this important (CVSS 8). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-44774] Privilege escalation via Kubernetes Gateway API provider configuration bypass
Privilege escalation via Kubernetes Gateway API provider configuration bypass. Red Hat rates this important (CVSS 8.3). Weakness: CWE-15. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.29.
High [CVE-2026-46483] command injection when decompressing .tgz archives
command injection when decompressing.tgz archives. Red Hat rates this moderate (CVSS 7). Weakness: CWE-78. Affected package(s): vim. Resolved in Red Hat advisory RHSA-2026:28049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-45736] Uninitialized memory disclosure via `websocket.close()` with `TypedArray`
Uninitialized memory disclosure via `websocket.close()` with `TypedArray`. Red Hat rates this important (CVSS 7.5). Weakness: CWE-824. Affected package(s): dotnet8, ansible-automation-platform, rhdh/rhdh-hub-rhel9:1782761244, dotnet10, discovery/discovery-ui-rhel9:1782166952, dotnet9. Resolved in Red Hat advisory RHSA-2026:34374 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9; Red Hat Discovery 2; and 30 more.
High [CVE-2026-46333] Read root-owned files as an unprivileged user
Read root-owned files as an unprivileged user. Red Hat rates this important (CVSS 7.8). Weakness: CWE-269. Affected package(s): kernel, rhcos, kernel-rt, openshift, kpatch-patch, cri-o. Resolved in Red Hat advisory RHSA-2026:23470 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NVIDIA for RHEL 10; Red Hat OpenShift Container Platform 4.20; Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); and 55 more.
High [CVE-2025-54518] Privilege escalation via improper CPU cache isolation
Privilege escalation via improper CPU cache isolation. Red Hat rates this important (CVSS 7). Weakness: CWE-1220. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; and 5 more.
High [CVE-2026-34253] vorbis-tools ogg123: Arbitrary code execution via buffer underflow in remote control functionality
vorbis-tools ogg123: Arbitrary code execution via buffer underflow in remote control functionality. Red Hat rates this important (CVSS 8.2). Weakness: CWE-124. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-44673] Denial of Service or arbitrary code execution via maliciously crafted LYB binary blob
Denial of Service or arbitrary code execution via maliciously crafted LYB binary blob. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): libyang. Resolved in Red Hat advisory RHSA-2026:24758 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 2 more.
High [CVE-2026-8559] Integer overflow in Internationalization
Integer overflow in Internationalization. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8555] Use after free in GTK
Use after free in GTK. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8551] Use after free in Downloads
Use after free in Downloads. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8552] Heap buffer overflow in GPU
Heap buffer overflow in GPU. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8542] Use after free in Core
Use after free in Core. Red Hat rates this important (CVSS 8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8539] Script injection in SanitizerAPI
Script injection in SanitizerAPI. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8536] Insufficient validation of untrusted input in ReadingMode
Insufficient validation of untrusted input in ReadingMode. Red Hat rates this important (CVSS 8.7). Weakness: CWE-1289. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8537] Insufficient policy enforcement in ViewTransitions
Insufficient policy enforcement in ViewTransitions. Red Hat rates this important (CVSS 7.4). Weakness: CWE-368. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.