Red Hat Linux Security Advisories & CVEs
5439 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-54592] Denial of Service via deeply nested JSON input
Denial of Service via deeply nested JSON input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-55223] Remote code execution via deserialization vulnerability
Remote code execution via deserialization vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502.
High [CVE-2026-54672] Arbitrary code execution through AppImage library loading vulnerability
Arbitrary code execution through AppImage library loading vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-427.
High [CVE-2026-58014] Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 1 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-58374] Denial of Service via malformed Wi-Fi 7 Multi-Link Operation association request
Denial of Service via malformed Wi-Fi 7 Multi-Link Operation association request. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-787.
High [CVE-2026-53433] Denial of Service via inefficient HTTP body processing
Denial of Service via inefficient HTTP body processing. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-1046.
High [CVE-2026-49434] Unauthorized broker instantiation via improper input validation in LDAP entries
Unauthorized broker instantiation via improper input validation in LDAP entries. Red Hat rates this important (CVSS 7.6). Weakness: CWE-90.
High [CVE-2026-49432] Denial of Service via improper input validation in STOMP connector
Denial of Service via improper input validation in STOMP connector. Red Hat rates this important (CVSS 7.5). Weakness: CWE-839.
High [CVE-2026-50734] Denial of Service via crafted WireFormatInfo frame
Denial of Service via crafted WireFormatInfo frame. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-50750] Denial of Service via repeated BrokerInfo commands
Denial of Service via repeated BrokerInfo commands. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-53916] Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec. Red Hat rates this important (CVSS 7.5). Weakness: CWE-789.
High [CVE-2026-54475] Information disclosure due to broken temporary destination isolation
Information disclosure due to broken temporary destination isolation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-1220.
High [CVE-2026-13149] Denial of Service due to exponential-time complexity
Denial of Service due to exponential-time complexity. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:35272 with package nodejs26-main-26.4.0-1.3.hum1, nodejs22-main-22.23.1-2.hum1, nodejs24-main-24.18.0-0.2.hum1, rhmtc/openshift-migration-ui-rhel8:1783690532.
High [CVE-2026-45822] Denial of Service via crafted input
Denial of Service via crafted input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:42146 with package quay/quay-rhel9:1783955846, quay/quay-rhel8:1783750447, quay/quay-rhel8:1783751865, quay/quay-rhel8:1784125838.
High [CVE-2026-12243] Information disclosure via path traversal vulnerability
Information disclosure via path traversal vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22.
Medium [CVE-2026-54902] Use-After-Free in Oj::Parser SAJ Long Key Callback
Use-After-Free in Oj::Parser SAJ Long Key Callback. Red Hat rates this moderate.
Medium [CVE-2026-54901] Use-After-Free in Oj::Parser array_class/hash_class GC Marking
Use-After-Free in Oj::Parser array_class/hash_class GC Marking. Red Hat rates this moderate.
Medium [CVE-2026-54898] Denial of Service via input string mutation during JSON parsing
Denial of Service via input string mutation during JSON parsing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-825.
Medium [CVE-2026-54502] Stack Buffer Overflow in Oj.dump via Large Indent
Stack Buffer Overflow in Oj.dump via Large Indent. Red Hat rates this moderate.
Medium [CVE-2026-54500] Information disclosure via uninitialized stack memory read
Information disclosure via uninitialized stack memory read. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125.