Red Hat Linux Security Advisories & CVEs
5187 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-17545] Denial of Service via reserved device names on Windows
Denial of Service via reserved device names on Windows. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-66. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.
Medium [CVE-2026-6103] Archive entry injection via integer overflow in TAR parser
Archive entry injection via integer overflow in TAR parser. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.
Medium [CVE-2026-93682] Out-of-bounds read via empty HTTP redirect Location header
Out-of-bounds read via empty HTTP redirect Location header. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.
Medium [CVE-2026-67408] Denial of Service via excessive memory allocation in stream management
Denial of Service via excessive memory allocation in stream management. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-408. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-67406] Information disclosure via unredacted credentials in Shovel crash logs
Information disclosure via unredacted credentials in Shovel crash logs. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-209. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1.
Medium [CVE-2026-67412] Unauthorized cross-vhost message access via missing Federation upstream authorization
Unauthorized cross-vhost message access via missing Federation upstream authorization. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-67242] Authentication bypass via improper validation of floating-point token expiration timestamps
Authentication bypass via improper validation of floating-point token expiration timestamps. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-613. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-67241] Unauthorized message routing via missing alternate-exchange permission check
Unauthorized message routing via missing alternate-exchange permission check. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-66071] Denial of service via atom exhaustion in OAuth2 JWT scope parsing
Denial of service via atom exhaustion in OAuth2 JWT scope parsing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-67236] Information disclosure via insecure authentication cookies
Information disclosure via insecure authentication cookies. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-312. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-100230] Arbitrary code execution via path traversal in drag-and-drop file transfer
Arbitrary code execution via path traversal in drag-and-drop file transfer. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22.
Medium [CVE-2026-96448] FGAP v2 composite-blind role mapping allows privilege escalation
FGAP v2 composite-blind role mapping allows privilege escalation. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-285. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-97846] Standard Token Exchange V2 bypasses mTLS holder-of-key binding
Standard Token Exchange V2 bypasses mTLS holder-of-key binding. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-287. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-51773] Information disclosure via unvalidated external image location URI
Information disclosure via unvalidated external image location URI. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-97567] prevent race between disconnect and rtx
prevent race between disconnect() and rtx. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97560] fix one-byte OOB read in smb2_parse_native_symlink
fix one-byte OOB read in smb2_parse_native_symlink(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
Medium [CVE-2026-97578] guard VPU981 AV1 divisor and tile buffer
guard VPU981 AV1 divisor and tile buffer. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-369.
Medium [CVE-2026-97541] don't store usb_device_id
don't store usb_device_id. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-98026] properly convert mglist to rcu
properly convert mglist to rcu. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97553] lock the healthmon when inserting unmount event
lock the healthmon when inserting unmount event. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-413.