Red Hat Linux Security Advisories & CVEs
5445 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Low [CVE-2026-56140] Apache Camel AWS SNS Component: Defense-in-depth hardening due to improper input validation
Apache Camel AWS SNS Component: Defense-in-depth hardening due to improper input validation. Red Hat rates this low.
Low [CVE-2026-14788] Denial of Service via use-after-free in r_core_bin_load function
Denial of Service via use-after-free in r_core_bin_load function. Red Hat rates this low (CVSS 3.3). Weakness: CWE-825.
High [CVE-2026-14570] Crypt::DSA: Crypt::DSA: Private key recovery due to biased random number generation
Crypt::DSA: Crypt::DSA: Private key recovery due to biased random number generation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-338.
Medium [CVE-2026-14757] Integer overflow allows local impact
Integer overflow allows local impact. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-190.
Medium [CVE-2026-14781] OIDC email_verified claim incorrectly applied to userinfo email
OIDC email_verified claim incorrectly applied to userinfo email. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-1288.
Low [CVE-2026-14760] Denial of Service via local use-after-free vulnerability
Denial of Service via local use-after-free vulnerability. Red Hat rates this low (CVSS 3.3). Weakness: CWE-825.
Low [CVE-2026-14759] Denial of Service via heap-based buffer overflow
Denial of Service via heap-based buffer overflow. Red Hat rates this low (CVSS 3.3). Weakness: CWE-131.
Low [CVE-2026-14742] Information Disclosure via Weak Hash in Task Result Cache
Information Disclosure via Weak Hash in Task Result Cache. Red Hat rates this low (CVSS 3.1). Weakness: CWE-328.
Low [CVE-2026-14686] Data integrity impact due to incorrect comparison
Data integrity impact due to incorrect comparison. Red Hat rates this low (CVSS 3.3). Weakness: CWE-839. Red Hat lists fixing advisory RHSA-2026:26989 with package rust-main-1.96.1-1.hum1, netavark-main-2.0.0-1.hum1.
High [CVE-2026-14535] Arbitrary code execution via pickle deserialization bypass
Arbitrary code execution via pickle deserialization bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-693.
High [CVE-2026-14534] Arbitrary code execution due to incomplete denylist in deserialization
Arbitrary code execution due to incomplete denylist in deserialization. Red Hat rates this important (CVSS 8.8). Weakness: CWE-184.
High [CVE-2026-12252] Arbitrary Code Execution via Untrusted JAR File Loading
Arbitrary Code Execution via Untrusted JAR File Loading. Red Hat rates this important (CVSS 7.8). Weakness: CWE-347.
High [CVE-2026-53362] account for fraggap on the paged allocation path
In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic.
High [CVE-2026-53359] Fix shadow paging use-after-free due to unexpected role
Fix shadow paging use-after-free due to unexpected role. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:36957 with package rhcos-4.22.9.8.202607152026-0, kernel-0:5.14.0-570.127.1.el9_6, kernel-0:4.18.0-477.154.1.el8_8, kernel-0:5.14.0-427.137.1.el9_4. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-53360] Require in-GHCB scratch area if GHCB v2+ is in use
Require in-GHCB scratch area if GHCB v2+ is in use. Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-53361] Set gc_in_progress to true in unix_gc
Set gc_in_progress to true in unix_gc(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-366.
Medium [CVE-2026-14684] Denial of Service via uncontrolled memory allocation in decodeFromByteBuffer
Denial of Service via uncontrolled memory allocation in decodeFromByteBuffer. Red Hat rates this low (CVSS 5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:26989 with package rust-main-1.96.1-1.hum1, netavark-main-2.0.0-1.hum1.
Medium [CVE-2026-14647] Information disclosure via out-of-bounds read
Information disclosure via out-of-bounds read. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125.
Low [CVE-2026-14685] Local state issue via 'Count' argument manipulation
Local state issue via 'Count' argument manipulation. Red Hat rates this low (CVSS 3.3). Weakness: CWE-1284. Red Hat lists fixing advisory RHSA-2026:26989 with package rust-main-1.96.1-1.hum1, netavark-main-2.0.0-1.hum1.
Low [CVE-2026-14683] Denial of Service via uncontrolled memory allocation
Denial of Service via uncontrolled memory allocation. Red Hat rates this low (CVSS 3.3). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:26989 with package rust-main-1.96.1-1.hum1, netavark-main-2.0.0-1.hum1.