Red Hat Linux Security Advisories & CVEs
5440 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2026-5138] Information disclosure via improper validation of nested request parameters
Information disclosure via improper validation of nested request parameters. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:34366 with package foreman-0:3.14.0.17-1.el9sat, foreman-0:3.18.0.7-1.el9sat, foreman-0:3.12.0.17-1.el9sat, foreman-0:3.12.0.17-1.el8sat. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2026-13323] Supply chain attack via cross-site scripting
Supply chain attack via cross-site scripting. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79.
Medium [CVE-2025-15666] Heap-based buffer overflow via crafted model file
Heap-based buffer overflow via crafted model file. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787.
Medium [CVE-2026-57962] Denial of Service via malicious LDAP server
A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client until it crashes due to memory exhaustion. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1. A remote attacker, by operating a malicious Lightweight Directory Access Protocol (LDAP) server, can cause a Thunderbird client to crash due to memory exhaustion. This can lead to a Denial of Service (DoS) for the affected user. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-1050. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
Medium [CVE-2026-14324] RAOP RTSP NULL Deref
RAOP RTSP NULL Deref. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476.
Medium [CVE-2026-14330] Pulse Server alloca Stack Overflow
Pulse Server alloca Stack Overflow. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770.
Medium [CVE-2026-53333] handle non-swap entries before !CONFIG_SWAP guard
handle non-swap entries before!CONFIG_SWAP guard. Red Hat rates this low (CVSS 5.5). Weakness: CWE-393.
Medium [CVE-2026-53353] Remove WARN_ONCE in hsr_addr_is_self
Remove WARN_ONCE() in hsr_addr_is_self(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-826.
Medium [CVE-2026-53349] destroy stale expectfn expectations on unregister
destroy stale expectfn expectations on unregister. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-53352] clear JOBCTL_PENDING_MASK for caller in zap_other_threads
clear JOBCTL_PENDING_MASK for caller in zap_other_threads(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-617.
Medium [CVE-2026-53348] fix NULL pointer dereference in sdca_dev_unregister_functions
fix NULL pointer dereference in sdca_dev_unregister_functions. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-53344] Initialize mcp->dev and mcp->addr before regmap init
Initialize mcp->dev and mcp->addr before regmap init. Red Hat rates this moderate. Weakness: CWE-476.
Medium [CVE-2026-53342] call pagetable dtor when freeing hot-removed page tables
call pagetable dtor when freeing hot-removed page tables. Red Hat rates this moderate. Weakness: CWE-459.
Medium [CVE-2026-53326] Don't call fill_pool in early boot hardirq context
Don't call fill_pool() in early boot hardirq context. Red Hat rates this low (CVSS 5.5). Weakness: CWE-833.
Medium [CVE-2026-53339] Fix NULL pointer dereference in cci_remove
Fix NULL pointer dereference in cci_remove(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-53331] Avoid ABBA on tx_lock/ctrl->lock
Avoid ABBA on tx_lock/ctrl->lock. Red Hat rates this moderate. Weakness: CWE-833.
Medium [CVE-2026-53327] Do not fill_pool if pi_blocked_on
Do not fill_pool() if pi_blocked_on. Red Hat rates this low (CVSS 5.5). Weakness: CWE-367.
Medium [CVE-2026-53350] Fix NULL dereference when removing firmware controls
Fix NULL dereference when removing firmware controls. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-53347] Fix driver removal with disabled KMS
Fix driver removal with disabled KMS. Red Hat rates this low (CVSS 5.5). Weakness: CWE-824.
Medium [CVE-2026-53340] fix clock and pinctrl state inconsistency in runtime PM
fix clock and pinctrl state inconsistency in runtime PM. Red Hat rates this low (CVSS 5.5). Weakness: CWE-367.