Red Hat Linux Security Advisories & CVEs
5814 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-80721] ensure no dangling hcon references in iso_conn
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon references in iso_conn After iso_conn_del(), ISO sockets should not dereference the hcon any more. Currently, clearing iso_conn::hcon relies on iso_conn_del() releasing the last reference to the iso_conn. A flaw was found in the Linux kernel's Bluetooth ISO (Isochronous Stream) implementation. This vulnerability occurs because the system does not properly clear references to connection handles (`hcon`) after a connection is deleted. This oversight can lead to unpredictable system behavior or instability, potentially resulting in a denial of service (DoS). Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-911. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-80685] don't read __page_2 for order-1 folios in snapshot_page
In the Linux kernel, the following vulnerability has been resolved: mm/util: don't read __page_2 for order-1 folios in snapshot_page() snapshot_page() currently reads __page_2 after checking nr_pages > 1, but it should only do so when nr_pages > 2. If an order-1 folio is allocated at the end of a vmemmap section, __page_2 will not exist and reading it will cause a fault. During DLPAR memory remove on a 22 TB ppc64le LPAR, snapshot_page() oopsed on the page isolation path while reading an order-1 folio's __page_2 from an adjacent absent section (unmapped vmemmap). Fix this to avoid reading memmap that doesn't exist (e.g., a vmemmap hole). A flaw was found in the Linux kernel's memory management subsystem. The `snapshot_page()` function attempts to read memory that may not exist when handling certain memory structures (order-1 folios) during specific memory operations, such as dynamic logical partitioning (DLPAR) memory removal. This out-of-bounds read can lead to a kernel fault (oops), resulting in a system crash and a Denial of Service (DoS). Red Hat severity: Low — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-80646] guard against possible NULL deref in __in6_dev_stats_get
In the Linux kernel, the following vulnerability has been resolved: ipv6: guard against possible NULL deref in __in6_dev_stats_get() dev_get_by_index_rcu() could return NULL if the original physical device is unregistered. Found by Sashiko. This vulnerability arises when the `dev_get_by_index_rcu()` function returns a null value if the original physical device is unregistered, leading to a NULL pointer dereference in `__in6_dev_stats_get()`. A local attacker could exploit this flaw to trigger a system crash, resulting in a Denial of Service (DoS). Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-80606] Hold notifier_lock for write on inject test path
In the Linux kernel, the following vulnerability has been resolved: drm/xe/userptr: Hold notifier_lock for write on inject test path When CONFIG_DRM_XE_USERPTR_INVAL_INJECT=y, xe_pt_svm_userptr_pre_commit() runs vma_check_userptr() with the svm notifier_lock taken for read. The test injection causes vma_check_userptr() to call xe_vma_userptr_force_invalidate(), which feeds into xe_vma_userptr_do_inval() with drm_gpusvm_ctx.in_notifier=true. That flag tells drm_gpusvm_unmap_pages() the caller already holds notifier_lock for write and only asserts the mode. Because the caller actually holds it for read, the assertion fires: WARNING: drivers/gpu/drm/drm_gpusvm.c:1669 at \ drm_gpusvm_unmap_pages+0xd4/0x130 [drm_gpusvm_helper] Call Trace: xe_vma_userptr_do_inval+0x40d/0xfd0 [xe] xe_vma_userptr_invalidate_pass1+0x3e6/0x8d0 [xe] xe_vma_userptr_force_invalidate+0xde/0x290 [xe] vma_check_userptr.constprop.0+0x1c6/0x220 [xe] xe_pt_svm_userptr_pre_commit+0x6a3/0xc60 [xe]... xe_vm_bind_ioctl+0x3a0a/0x4480 [xe] Acquire notifier_lock for write in pre-commit when the inject Kconfig is enabled, via new helpers xe_pt_svm_userptr_notifier_lock()/_unlock(). Rename xe_svm_assert_held_read() to xe_svm_assert_held_read_or_inject_write() so it asserts the correct mode under each build configuration.
Medium [CVE-2026-37236] Access control bypass via X-HTTP-Method-Override header
grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs. A remote attacker could exploit an incorrect access control vulnerability by sending a specially crafted POST request that includes the X-HTTP-Method-Override header. This vulnerability is rated as Moderate impact for Red Hat products because exploitation requires a deployment where upstream reverse proxies or perimeter filters enforce access control solely based on HTTP methods without stripping method-override headers. In typical Red Hat deployments, backend gRPC services enforce their own authentication and authorization controls, limiting an attacker's ability to execute unauthorized actions simply by tunneling rewritten request verbs. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N). Weakness: CWE-444. Affected products named by the advisory: Cryostat 4; Migration Toolkit for Applications 8; Multicluster Global Hub; OpenShift Serverless; and 9 more.
Medium [CVE-2026-80179] Denial of Service via malformed JWE tokens
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values. An attacker could provide a specially crafted malformed JWE token, causing excessive memory allocation and potentially degrading service availability. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 16.2. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: python-jwcrypto.
Medium [CVE-2026-18374] Heap buffer overflow via attacker-controlled fopen mode string
Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation. This vulnerability could allow an attacker with local access to trigger a heap buffer overflow by manipulating how the `fopen` function handles certain input. This could lead to minor disruptions in system operations or limited access to sensitive information. Exploitation is highly complex as this specific usage pattern is not common in applications within typical Red Hat Enterprise Linux environments, significantly limiting its practical applicability. Red Hat severity: Moderate — CVSS 4.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L). Weakness: CWE-134. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat lists Red Hat Hardened Images as not affected. Red Hat fixing advisory: RHSA-2026:65339.
Medium [CVE-2026-81893] invalid write in JPEG ICC profile parser on error recovery
A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. Affected version >= 2.26.4 Red Hat Product Security has rated this issue as having Moderate security impact. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gdk-pixbuf2.
Medium [CVE-2026-59276] org.springframework.security/spring-security-core: Spring Security: Information disclosure via timing attack in sensitive value comparison
Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. Because String.equals() returns as soon as it finds a differing character, the time taken to reject an incorrect value is proportional to the number of leading characters that match the expected value. An attacker capable of submitting a very large number of guesses and precisely measuring response latency could, in principle, use these timing differences to recover the expected value one character at a time. Because rejection time can correlate with how many leading characters match, an attacker who can submit a very large number of requests and precisely measure response latency could, in theory, recover protected values incrementally, leading to information disclosure. Practical exploitation is difficult due to network variability and the volume of measurements required. Red Hat products that ship an affected version of Spring Security are affected. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-208. Affected Red Hat products: OpenShift Developer Tools and Services; Red Hat Fuse 7; Red Hat OpenShift Dev Spaces; Red Hat Single Sign-On 7. Will not fix / out of support: OpenShift Developer Tools and Services; Red Hat Fuse 7; Red Hat Single Sign-On 7.
Medium [CVE-2026-59272] Information disclosure due to disabled TLS hostname verification
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier When configured to ship logs to RabbitMQ over Transport Layer Security (TLS), the appender disables hostname verification by default. This misconfiguration allows a remote attacker to perform a man-in-the-middle (MITM) attack, intercepting sensitive log events. This can lead to unauthorized information disclosure. This vulnerability affects the Log4j2 AmqpAppender, a non-default, opt-in component that routes log events to a RabbitMQ broker over AMQP. No Red Hat product enables this appender by default — it requires explicit configuration by the application deployer, making exposure conditional on a deliberate architectural choice. For Red Hat Enterprise Linux, resteasy packages in RHEL 8 bundle log4j-core as a build-time dependency but do not activate or expose the AMQP Appender at runtime. PKI deployments are not affected unless a custom Log4j2 configuration independently enables the appender. Exploitation requires the attacker to already hold a man-in-the-middle position on the network path between the logging client and the RabbitMQ broker.
Medium [CVE-2026-81725] Regular Expression Denial of Service via malformed TEI blocks
NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags. Attackers can exploit lazy regex patterns in the read_block method through public APIs like words() and tagged_words() to force repeated rescans and achieve near-quadratic runtime growth. A flaw was found in NLTK, specifically within the Pl196xCorpusReader component. A remote attacker can exploit this by supplying malformed Text Encoding Initiative (TEI) blocks containing numerous unmatched opening tags. This impact flaw in NLTK's Pl196xCorpusReader can lead to a denial of service. When processing specially crafted TEI blocks containing many unmatched opening tags, the library's regular expression engine can consume excessive CPU resources. This vulnerability primarily affects applications that process untrusted TEI data using NLTK's text processing APIs, potentially impacting service availability. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1333. Affected Red Hat products: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI). Red Hat lists OpenShift Lightspeed as not affected.
Medium [CVE-2026-81723] Denial of Service via malformed XML corpus files
NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files to cause severe CPU consumption and denial of service through affected readers like BNCCorpusReader. A flaw was found in NLTK. The flaw occurs because the system repeatedly rescans accumulated XML fragments, leading to quadratic CPU exhaustion. This vulnerability in NLTK arises from a quadratic CPU exhaustion when processing specially crafted XML corpus files. While the flaw can lead to a denial of service, its impact is limited to scenarios where NLTK-based applications in Red Hat products, such as those within OpenShift AI and Lightspeed Core, are configured to process untrusted XML data. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-776. Affected Red Hat products: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI). Will not fix / out of support: Exploit Intelligence; Red Hat Ansible Automation Platform 2. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-81092] DNS Rebinding vulnerability due to missing Host header validation
mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer. ServeHTTP in server/streamable_http.go and SSEServer. ServeHTTP in server/sse.go served any request arriving over a loopback connection regardless of the host it named, and the SSE transport's cross-origin default allowed any origin. A page in a browser could therefore point a name it controlled at the loopback address and reach a server listening there, invoking tools and reading resources that the server exposed on the assumption that only local software could connect. No release before 0.56.0 validated the header on either transport; 0.56.0 adds server/http_localhost.go, which rejects a loopback-bound request carrying a host that is not a loopback name, and wires it into both transports. A flaw was found in mcp-go. A remote attacker could exploit this by using a crafted web page to perform a DNS rebinding attack. This allows the attacker to direct a controlled domain name to the loopback address, bypassing local network restrictions. Consequently, the attacker could access and interact with local services and resources, potentially leading to information disclosure or unauthorized actions. DNS rebinding requires a web browser executing JavaScript to run on the same host as the mcp-go HTTP server, with the user visiting a malicious page during that window.
Medium [CVE-2026-80213] Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames
An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its range. A label longer than 255 octets had its length stored modulo 256 but the label data was written unchanged, and thus the bytes on the wire described a different name than the one the application asked to encode. RFC 1035 section 2.3.4 limits a label to 63 octets, and the two high bits of the length octet are reserved for compression pointers. put_string packed the length with put_pack("C", d.length) and put_label used it for labels, and thus any value from 0 to 255 could end up as a label length octet, including the reserved 0x40-0xBF range and the 0xC0-0xFF pointer range. Resolv::DNS::Name.create did not check per-label or total name length either, and thus an attacker-controlled hostname reached the encoder unchanged. An application that resolves an attacker-controlled hostname sends a query whose wire bytes name a domain the attacker chose. A hostname suffix that the application validates against an allowlist becomes padding that never appears on the wire, and thus allowlist and egress checks can be bypassed. The recursive resolver caches the response under the attacker's name, and DNS logs record that name rather than the one the application asked for.
Medium [CVE-2026-81668] Cross-tenant Content View Filter rule access and modification via unauthorized parent filter lookup
A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to access and modify filter rules belonging to a Content View Filter in another organization by supplying that filter's identifier. This can result in unauthorized disclosure of filter-rule information and unauthorized changes to unpublished Content View filter configuration. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. The issue arises because the API loads the parent Content View Filter by identifier without an authorization-aware scope. Successful exploitation allows the attacker to read filter-rule metadata and to add, change, or delete rules outside their authorized organization. Those changes persist in the live filter configuration and can affect the content included in a subsequent Content View publication. Already-published Content View versions are immutable snapshots and are not modified by this flaw. Confidentiality is Low because the disclosed data is filter-rule metadata rather than repository contents or credentials. Affected product named by the advisory: Red Hat Satellite 6.
Medium [CVE-2026-81658] Cross-tenant disclosure of template revisions via unauthorized audit lookup
A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can obtain historical template contents belonging to another organization or location by supplying the corresponding audit ID. This can result in unauthorized disclosure of historical template contents, which may contain sensitive configuration information, credentials, or other secrets. The REST API revision endpoints correctly restrict this lookup. Red Hat Product Security has rated this flaw as having a Moderate impact. This vulnerability affects Foreman's template revision handling. The vulnerability permits an authenticated, low-privileged user with limited template permissions to bypass organization and location authorization boundaries and access historical template revisions outside their authorized scope. This issue requires network access to the Foreman web interface and a valid account with a template-related permission such as view_ptables. No special attack conditions and no user interaction are required. The confidentiality impact is High because a successful request returns the full historical template body, which can include credentials or other secrets. Affected product named by the advisory: Red Hat Satellite 6.
Medium [CVE-2026-80489] Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state
Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang. Some EUC_JISX0213 sequences decode to two code points. If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call. The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used. The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117. A flaw was found in glibc. Impact is limited to process hang (availability only). Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-47892] Header Predicate Bypass in WebFlux Functional Endpoints
Header Predicate Bypass in WebFlux Functional Endpoints. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-807. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat OpenShift Dev Spaces; and 1 more. Affected products named by the advisory: Red Hat package: resteasy.
Medium [CVE-2026-47887] Open redirect vulnerability in UrlFileNameViewController
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier This could allow an attacker to redirect users to arbitrary malicious websites, potentially leading to phishing attacks or other social engineering exploits. An unauthenticated remote attacker can exploit this by enticing a user to follow a specially crafted URL, leading to an external redirection to an arbitrary domain. Because redirection occurs entirely within the context of browser navigation and application-level routing, default system isolation mechanisms like SELinux or non-root container boundaries do not mitigate the flaw. Technical impact is limited to phishing and user redirection without direct impact to server integrity or confidentiality. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-601. Affected Red Hat products: Red Hat build of Apache Camel - HawtIO 4; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat OpenShift Dev Spaces. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-38350] Integer overflow leads to Denial of Service
An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. A flaw was found in FFmpeg. This can lead to the application becoming unresponsive or crashing, impacting its availability. The ffmpeg package is not shipped in base Red Hat Enterprise Linux. It is available through EPEL, Red Hat Enterprise Linux AI, and as a bundled dependency in Red Hat OpenShift AI container images. The vulnerable code resides in the bilinear interpolation routines of libswscale/output.c, which is core production code used by virtually all FFmpeg scaling operations. Despite the original CVE description referencing a function named 'target_sws_fuzzer', this is not a fuzzer-only issue — the integer overflows occur in production scaling code paths. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.