Red Hat Linux Security Advisories & CVEs
5814 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-78892] Incorrect authorization in Chromoting
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium) An incorrect authorization flaw was found in the Chromoting component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 5.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N). Weakness: CWE-266.
Medium [CVE-2026-79276] Privilege management bypass via crafted HTML page
Privilege management bypass via crafted HTML page. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-266.
Medium [CVE-2026-79020] Out of bounds read in Skia
Out of bounds read in Skia. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: webkitgtk4; and 1 more. Affected products named by the advisory: Red Hat package: webkit2gtk3.
Medium [CVE-2026-78894] Race condition in Payments
Race condition in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 5.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-368.
Medium [CVE-2026-79137] Incorrect authorization in Extensions
Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium) An incorrect authorization flaw was found in the Extensions component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-551.
Medium [CVE-2026-79144] Information leak in Skia
Information leak in Skia. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-346. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: firefox; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Medium [CVE-2026-78898] Incorrect authorization in Downloads
Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) An incorrect authorization flaw was found in the Downloads component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-551.
Medium [CVE-2026-79237] Incorrect authorization in Navigation
Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) An incorrect authorization flaw was found in the Navigation component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N). Weakness: CWE-551.
Medium [CVE-2026-78958] Uninitialized resource in Skia
Uninitialized resource in Skia. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: firefox; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Medium [CVE-2026-61555] Denial of Service via crafted EXR image file
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable to crashing. This occurs when Imf::GetChannelsInMultiPartFile() processes a crafted EXR with an empty multiView header attribute and Imf::viewFromChannelName() indexes the empty vector for a dotless channel name. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14. When processing a specially crafted EXR image file, an attacker could trigger an application crash. This occurs because the software attempts to access an empty list of image views when a specific header attribute is empty, leading to a Denial of Service (DoS) for the application. Red Hat products ship OpenEXR versions that are affected by this vulnerability. Upstream has provided fixes only for the 3.2.x (3.2.11), 3.3.x (3.3.13), and 3.4.x (3.4.14) series. Products shipping older branches (1.x, 2.x, 3.0.x, 3.1.x) remain vulnerable as no fixes are available for these versions. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-59985] Denial of Service via heap out-of-bounds read with crafted EXR image
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to a heap out-of-bounds read. The issue occurs when a crafted RLE-compressed EXR causes the 64-bit unpacked size to truncate before allocation in OpenEXRCore decoding.c and unpack_32bit() reads beyond the resulting buffer, allowing denial of service. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14. A flaw was found in OpenEXR. This leads to a heap out-of-bounds read when unpack_32bit() attempts to read beyond the allocated buffer. Successful exploitation of this vulnerability could result in a denial of service (DoS) for the affected system. Red Hat products ship OpenEXR versions below 3.2.0 (RHEL 9 ships 3.1.1, RHEL 10 ships 3.1.10) and therefore do not contain the vulnerable code. When exploited on vulnerable 32-bit builds with affected versions, this issue can lead to denial of service. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-805.
Medium [CVE-2026-59984] Denial of service and memory corruption via crafted B44-compressed EXR
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to an out-of-bounds write. When a crafted B44-compressed scanline EXR causes the logical scratch size to truncate before allocation and uncompress_b44_impl() writes using the attacker-controlled channel width, allowing denial of service and memory corruption. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14. A flaw was found in OpenEXR. When processing a specially crafted B44-compressed EXR image, an out-of-bounds write can occur due to an integer truncation vulnerability in ILP32 builds. This vulnerability only affects 32-bit ILP32 builds; 64-bit LP64 builds are not vulnerable. Red Hat Enterprise Linux 9 and later, as well as RHIVOS, ship only 64-bit builds and are therefore not affected by this flaw. When exploited on vulnerable 32-bit builds, this issue can lead to denial of service or memory corruption. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787.
Medium [CVE-2026-79781] Path Traversal allows unauthorized file access
rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like../root-secret.txt to escape the bucket namespace and access files in the serve root directory. A flaw was found in rclone. This could lead to unauthorized access and modification of critical system files. Moderate: This path traversal flaw in `rclone` allows remote attackers to read and overwrite arbitrary files outside the intended S3 bucket when the `rclone serve s3` command is actively exposed. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-22. Affected Red Hat products: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-79779] Credential exposure via HTTPS-to-HTTP redirect downgrade.
rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext hop can capture and reuse credentials to perform WebDAV operations with the compromised account's permissions. A flaw was found in rclone. This Moderate impact flaw in rclone allows an on-path attacker to capture credentials by exploiting improper handling of HTTPS-to-HTTP redirects on the same host. Exploitation requires the attacker to be positioned on the network path between the client and the server. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-523. Affected Red Hat products: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-79780] Information disclosure via S3 redirect callbacks
rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted endpoint can capture reusable IBM IAM tokens on same-host HTTPS-to-HTTP downgrades or SSE-C keys on cross-origin redirects to access protected S3 objects. A flaw was found in rclone. When rclone interacts with S3 endpoints that issue unsafe redirects, an adjacent network attacker can capture these credentials during HTTPS-to-HTTP downgrades or cross-origin redirects. The impact is constrained by the scope of the captured token and the attacker's access to encrypted objects. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-201. Affected Red Hat products: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-79778] Denial of Service via WebDAV TUS nil-response panic
rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connections during TUS uploads to trigger a panic that terminates unrecovered goroutines and halts unrelated work in long-lived processes. A flaw was found in rclone. This leads to a complete disruption of service. When using the WebDAV backend with TUS (resumable upload) support, a nil pointer dereference panic can occur if the server returns a nil HTTP response during a TUS upload operation. A malicious or misconfigured WebDAV server can trigger this condition, causing the rclone process to crash. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-476. Affected Red Hat products: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-79775] Denial of Service via malicious SquashFS image parsing
rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and metadata values before use. An attacker who can place or modify a SquashFS image in storage exposed through an rclone:archive: remote can craft a malicious image that triggers an integer division-by-zero panic (zero block size), an out-of-bounds slice panic (out-of-range inode metadata offset), or a non-progress CPU loop (truncated metadata stream). Variants 1 and 2 terminate the rclone process and, via 'rclone serve sftp', can crash the entire SFTP server; variant 3 causes sustained CPU consumption. Parsing is lazy, so a victim or remote client must address or descend into the malicious archive object to trigger it. A flaw was found in rclone. The SquashFS image parser is vulnerable to denial of service when processing a maliciously crafted SquashFS image. A divide-by-zero error occurs during parsing, causing the application to panic and crash. An attacker who can supply a crafted SquashFS image to an application using go-diskfs for parsing can trigger the crash. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-369.
Medium [CVE-2026-79772] Signature validation bypass via unchecked return value
Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid. A flaw was found in Nokogiri. A remote attacker could exploit this by providing specially crafted XML, leading to a bypass of signature validation in Security Assertion Markup Language (SAML) libraries that rely on Nokogiri, potentially allowing malicious data to be accepted as legitimate. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-252. Affected Red Hat products: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6. Red Hat lists Red Hat Satellite 6 as not affected. Will not fix / out of support: Red Hat 3scale API Management Platform 2. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-79771] Denial of Service via XSLT transform memory leak
Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes. A flaw was found in Nokogiri. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-770. Affected Red Hat products: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6. Will not fix / out of support: Red Hat 3scale API Management Platform 2. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-79769] Process crash due to invalid memory read via programming error in internal method
Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode without a type check. If application code calls this protected method with a non-Node argument (e.g., a Namespace), it reads an xmlNs out of bounds, crashing the process. This is only triggerable by a programming error and cannot be triggered by untrusted input or normal use of the public API. Only CRuby is affected. Version 1.19.4 adds a type check and raises TypeError. A flaw was found in Nokogiri. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-843. Affected Red Hat products: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6. Will not fix / out of support: Red Hat 3scale API Management Platform 2. Red Hat does not currently list a fixing RHSA for this CVE.