Red Hat Linux Security Advisories & CVEs
5441 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-14363] SQL Injection vulnerability
SQL Injection vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-89.
High [CVE-2026-53492] Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.
Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. Red Hat rates this important (CVSS 8.2). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:42852 with package multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784061472, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784060681, rhacm2/submariner-rhel9-operator:1782933193, multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784127491.
High [CVE-2026-46680] Privilege escalation via incorrect user ID handling
Privilege escalation via incorrect user ID handling. Red Hat rates this important (CVSS 7.8). Weakness: CWE-681. Red Hat lists fixing advisory RHSA-2026:35111 with package trivy-main-0.72.0-0.1.hum1.
High [CVE-2026-54428] org.apache.httpcomponents.core5/httpcore5: org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks
org.apache.httpcomponents.core5/httpcore5: org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-54399] org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers
org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-20243] Denial of Service via crafted ALZ file
Denial of Service via crafted ALZ file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-20244] Denial of Service via crafted DMG file
Denial of Service via crafted DMG file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190.
High [CVE-2026-20215] Denial of Service via crafted 7z file
Denial of Service via crafted 7z file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-20217] Denial of Service via crafted PESpin file
Denial of Service via crafted PESpin file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-20216] Denial of Service via crafted InstallShield file
Denial of Service via crafted InstallShield file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-20213] Denial of Service via crafted Portable Executable (PE) files
Denial of Service via crafted Portable Executable (PE) files. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-20214] Denial of Service via crafted FSG file parsing
Denial of Service via crafted FSG file parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-24260] Privilege escalation and code execution via race condition
Privilege escalation and code execution via race condition. Red Hat rates this important (CVSS 8.5). Weakness: CWE-367.
High [CVE-2026-5136] Privilege escalation to administrator-level access via usergroup role assignment manipulation
Privilege escalation to administrator-level access via usergroup role assignment manipulation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:34366 with package foreman-0:3.14.0.17-1.el9sat, foreman-0:3.18.0.7-1.el9sat, foreman-0:3.12.0.17-1.el9sat, foreman-0:3.12.0.17-1.el8sat. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-56016] Authentication bypass via predictable session IDs
Authentication bypass via predictable session IDs. Red Hat rates this important (CVSS 7.4). Weakness: CWE-331.
High [CVE-2026-57963] Chat UI manipulation by injection
An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-79. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
High [CVE-2026-53488] Host-root command execution via unvalidated image config labels in CRI plugin
Host-root command execution via unvalidated image config labels in CRI plugin. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:37252 with package multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784060681, rhacm2/submariner-rhel9-operator:1782933193, multicluster-engine/assisted-service-8-rhel8:1783332008, multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784127491.
High [CVE-2026-53341] fix UAF due to unlocked ->mnt_ns read in may_decode_fh
fix UAF due to unlocked ->mnt_ns read in may_decode_fh(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-364.
High [CVE-2026-53354] Mitigate TLBI errata on various Arm CPUs
Mitigate TLBI errata on various Arm CPUs. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1037.
High [CVE-2026-53355] clear i_sends on setup unwind
clear i_sends on setup unwind. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.