Red Hat Linux Security Advisories & CVEs
4712 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-17658] Use after free in V8
Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) An use after free flaw was found in the V8 component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.
High [CVE-2026-17661] Use after free in Loader
Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) An use after free flaw was found in the Loader component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.
High [CVE-2026-17657] Use after free in Navigation
Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.
High [CVE-2026-17654] Race in Updater
Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical) A race flaw was found in the Updater component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Critical — CVSS 8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-367.
High [CVE-2026-18378] cluster pull-secret token exfiltration via user-controlled api_url (SSRF / confused deputy)
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token. Red Hat severity: Important — CVSS 7.6 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N). Weakness: CWE-918. Affected Red Hat products: Cost Management Metrics Operator. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-18381] operator service-account token exfiltration via user-controlled Prometheus service_address
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token. Red Hat severity: Important — CVSS 7.6 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N). Weakness: CWE-918. Affected Red Hat products: Cost Management Metrics Operator. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-5056] Arbitrary code execution via stack-based buffer overflow in qtdemux
GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the parsing of UncompressedFrameConfigBox structures. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29392. This occurs due to insufficient data length validation when parsing UncompressedFrameConfigBox structures. An Important security flaw in GStreamer's QuickTime parser could allow an attacker to execute malicious code if a user opens a specially crafted media file. Because the vulnerable code was introduced in GStreamer 1.26.0, Red Hat Enterprise Linux (RHEL) versions 9 and older do not contain this code and are not affected by this vulnerability. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-121. Red Hat fixing advisory: RHSA-2026:49508. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: gstreamer1-plugins-good.
High [CVE-2026-18022] Arbitrary Code Execution via Integer Wraparound
Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected. A flaw was found in pgvector. An integer wraparound vulnerability exists during the IVFFlat index build process. This flaw allows a database user on a 32-bit system to write data outside of allocated memory buffers. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-787. Red Hat lists Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 9; Red Hat Trusted Profile Analyzer as not affected.
High [CVE-2026-67201] Server-Side Request Forgery (SSRF) bypass due to URL parser differential
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers can craft a URL containing a backslash in the authority section such that net.urllib.parse() extracts the trusted host for allowlist validation while net.http.get() normalizes the backslash and connects to the internal host, enabling access to internal network services that the allowlist was intended to block. A flaw was found in V, specifically within its `net.urllib` and `net.http` components. This vulnerability allows a remote attacker to bypass host-based allowlists by exploiting a difference in how URLs are parsed. By crafting a malicious URL with a backslash, an attacker can trick the system into validating a trusted host while actually connecting to an internal network service. This enables unauthorized access to internal resources that should otherwise be protected. This flaw allows a remote attacker to circumvent host-based allowlists by exploiting a URL parser differential, enabling unauthorized access to internal network services. Applications utilizing these components for URL validation and fetching are at risk of exposing internal resources.
High [CVE-2026-18255] Global read-only superuser can view robot account tokens
A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account. Red Hat severity: Important — CVSS 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-863. Affected Red Hat products: Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.14; Red Hat Quay 3.15; Red Hat Quay 3.16; Red Hat Quay 3.17; Red Hat Quay 3.9. Red Hat fixing advisory: RHSA-2026:66084, RHSA-2026:66523, RHSA-2026:70267, RHSA-2026:63307, RHSA-2026:69255, RHSA-2026:74511, RHSA-2026:65514.
High [CVE-2026-13697] Information disclosure and Denial of Service via malformed Cache-Control directives
Information disclosure and Denial of Service via malformed Cache-Control directives. Red Hat rates this important (CVSS 7.4). Weakness: CWE-524. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs24-main-24.18.1-0.1.hum1.
High [CVE-2026-55707] Shared-network consumer can re-scope another project's subnets via subnetpool onboarding
In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3 routing and address scope behavior for victim routers. An authorization bypass was found in the OpenStack Neutron subnetpool onboarding API endpoint (PUT /v2.0/subnetpools/{id}/onboard_network_subnets). When a caller supplies a network_id, the API only verifies that the network is visible to the caller but does not verify that the caller owns the subnets on that network. When a network is RBAC-shared or globally shared, any project member with network visibility can invoke the API to onboard another project's subnets into the caller's own subnetpool, mutating the victim's subnet records (setting subnetpool_id to the attacker-controlled pool). If the attacker's subnetpool is associated with an address scope, Neutron syncs the victim's router interfaces with the attacker-controlled address scope, silently altering L3 routing, NAT, and address-scope behavior. The upstream fix adds an ownership check ensuring the caller has admin-or-owner authority over each subnet being onboarded, not merely visibility of the parent network.
High [CVE-2026-55995] Denial of Service via double-free in iSNS attribute decoder
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb. An unauthenticated man-in-the-middle (MITM) attacker can exploit a double-free vulnerability in the iSNS attribute decoder. This can lead to a denial of service (DoS) condition, making the affected system unavailable. The vulnerability is network-exploitable without requiring user interaction or authentication, posing a significant risk to the availability of iSNS services in environments where the `isns-utils` package is deployed and the iSNS service is exposed. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-763. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 7 more.
High [CVE-2026-67214] Denial of Service via negative size input in non-secure module functions
nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition. A flaw was found in nanoid (Nano ID), a JavaScript library used for generating unique identifiers. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a negative size input to the customAlphabet or nanoid functions within the library's non-secure module. When a negative size is provided, these functions enter an infinite loop, causing the application to hang indefinitely and disrupting service availability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-839. Affected products named by the advisory: multicluster engine for Kubernetes 2.17; multicluster engine for Kubernetes 2.8; multicluster engine for Kubernetes 2.9; Red Hat Advanced Cluster Management for Kubernetes 2.11; and 35 more.
High [CVE-2026-67213] Denial of Service via infinite loop in random ID generation
Denial of Service via infinite loop in random ID generation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:47619 with package jaeger-main-2.20.0-0.6.hum1, grafana13-1-main-13.1.1-0.3.hum1, grafana12-4-main-12.4.6-0.2.hum1.
High [CVE-2026-16308] io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted multipart/form-data request with an excessively large header section. This unbounded accumulation of MIME part-header bytes can exhaust the Java Virtual Machine (JVM) heap memory, leading to an OutOfMemoryError. The primary consequence is a denial of service, causing the application to crash. This is an Important flaw in Quarkus REST / RESTEasy Reactive's MultipartParser, allowing an unauthenticated remote attacker to cause a denial of service. This vulnerability does not require valid form field names or authentication. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Cryostat 4 on RHEL 9; Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.4.14; Red Hat build of Keycloak 26.6; Red Hat build of Keycloak 26.6.5; Red Hat build of Quarkus 3.27.4.SP3; Red Hat build of Quarkus 3.33.2.SP3; Streams for Apache Kafka 3.2.1; Cryostat 4; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat OpenShift Dev Spaces; streams for Apache Kafka 2.
High [CVE-2026-44944] Authentication bypass in iscsiuio control socket
An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects open-iscsi: from? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e. This enables unauthorized access to the control socket, potentially leading to system compromise or disruption of iSCSI (Internet Small Computer System Interface) operations. This could lead to unauthorized access and manipulation of iSCSI sessions, potentially compromising data confidentiality, integrity, and availability on systems where iSCSI is configured. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-1220. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat fixing advisory: RHSA-2026:53845, RHSA-2026:53844, RHSA-2026:62029, RHSA-2026:60427, RHSA-2026:60428. Affected products named by the advisory: Red Hat package: iscsi-initiator-utils.
High [CVE-2026-44943] Privilege Escalation via Path Traversal
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e. This vulnerability, known as Path Traversal, allows remote Man-in-the-Middle (MITM) attackers to manipulate file paths. By doing so, attackers can create files with root privileges outside the intended database and inject malicious content into system records. This could lead to unauthorized system modification or privilege escalation. This is an Important vulnerability in the open-iscsi `iscsi-initiator-utils` package, enabling remote Man-in-the-Middle (MITM) attackers to achieve privilege escalation. The path traversal flaw allows creating root-owned files and injecting malicious data into system records, posing a significant risk of unauthorized system modification without requiring user interaction or prior authentication. Red Hat severity: Important — CVSS 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N). Weakness: CWE-22.
High [CVE-2026-18220] Out-of-bounds write in BFD DLX ELF backend relocation processing
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access. A specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system(). Attack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code. Note: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).
High [CVE-2026-64556] Detach event groups during remove_on_exec
In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during remove_on_exec perf_event_remove_on_exec() removes events by calling perf_event_exit_event(). For top-level events, this removes the event from the context with DETACH_EXIT only. This can leave inconsistent group state when a removed event is a group leader and the group contains siblings without remove_on_exec. If the group was active, the surviving siblings can remain active and attached to the removed leader's sibling list, but are no longer represented by a valid group leader on the PMU context active lists. A later close of the removed leader uses DETACH_GROUP and can promote the still-active siblings from this stale group state. The next schedule-in can then add an already-linked active_list entry again, corrupting the PMU context active list. With DEBUG_LIST enabled, this is caught as a list_add double-add in merge_sched_in(). Fix this by detaching group relationships when remove_on_exec removes an event. This preserves the existing task-exit and revoke behavior, while ensuring surviving siblings are ungrouped before the removed event leaves the context. A flaw was found in the Linux kernel's performance monitoring unit (PMU) subsystem.