Red Hat Linux Security Advisories & CVEs
3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-33908] Denial of Service via deeply nested XML file processing
Denial of Service via deeply nested XML file processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-33901] Denial of Service due to heap buffer overflow in MVG decoder
Denial of Service due to heap buffer overflow in MVG decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6100] Arbitrary code execution or information disclosure via use-after-free in decompression modules
Arbitrary code execution or information disclosure via use-after-free in decompression modules. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825. Affected package(s): python3.11, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, rhpam, python3.9, python3.12. Resolved in Red Hat advisory RHSA-2026:26187 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 16 more.
High [CVE-2026-28291] Command Execution via Option-Parsing Bypass in simple-git
Command Execution via Option-Parsing Bypass in simple-git. Red Hat rates this important (CVSS 8.1). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat Process Automation 7.
High [CVE-2026-1462] Arbitrary Code Execution Vulnerability Bypassing Safe Mode
Arbitrary Code Execution Vulnerability Bypassing Safe Mode. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502. Affected package(s): rhoai/odh-modelmesh-runtime-adapter-rhel9:1780394782. Resolved in Red Hat advisory RHSA-2026:24977 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-5367] Information disclosure via crafted DHCPv6 packets
Information disclosure via crafted DHCPv6 packets. Red Hat rates this important (CVSS 8.6). Weakness: CWE-130. Affected package(s): ovn25.03, ovn25.09, ovn, ovn23.09, ovn24.03, ovn23.06. Resolved in Red Hat advisory RHSA-2026:11702 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Fast Datapath for Red Hat Enterprise Linux 10; Fast Datapath for Red Hat Enterprise Linux 8; Fast Datapath for Red Hat Enterprise Linux 9; Fast Datapath for RHEL 8; and 2 more.
High [CVE-2026-6857] Remote Code Execution via Unsafe Deserialization
Remote Code Execution via Unsafe Deserialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. Affected package(s): camel-infinispan. Resolved in Red Hat advisory RHSA-2026:22453 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform Expansion Pack.
High [CVE-2026-31419] Linux kernel: Use-after-free in bonding driver leads to denial of service
Linux kernel: Use-after-free in bonding driver leads to denial of service. Red Hat rates this important (CVSS 7). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 2 more.
High [CVE-2019-25695] Arbitrary Code Execution via Local Buffer Overflow
Arbitrary Code Execution via Local Buffer Overflow. Red Hat rates this important (CVSS 8.4). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-32146] Gleam compiler: Arbitrary file system modification and potential code execution via improper path validation in git dependency handling.
Gleam compiler: Arbitrary file system modification and potential code execution via improper path validation in git dependency handling.. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-4154] Remote Code Execution via XPM File Parsing Integer Overflow
Remote Code Execution via XPM File Parsing Integer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:17533 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.
High [CVE-2026-4153] Remote Code Execution via PSP file parsing
Remote Code Execution via PSP file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:17533 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 8 more.
High [CVE-2026-4152] Remote Code Execution via malicious JP2 file parsing
Remote Code Execution via malicious JP2 file parsing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Affected package(s): gimp. Resolved in Red Hat advisory RHSA-2026:25907 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.
High [CVE-2026-4151] Remote Code Execution via ANI File Parsing Integer Overflow
Remote Code Execution via ANI File Parsing Integer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): gimp. Resolved in Red Hat advisory RHSA-2026:16484 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-4150] Arbitrary code execution via specially crafted PSD file
Arbitrary code execution via specially crafted PSD file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): gimp, gimp:2.8. Resolved in Red Hat advisory RHSA-2026:17533 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 9 more.
High [CVE-2026-58379] Heap buffer overflow in read_channel_data()
Heap buffer overflow in read_channel_data(). Red Hat rates this important (CVSS 7.3). Weakness: CWE-122. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-5483] ODH Dashboard Kubernetes Service Account Exposure
ODH Dashboard Kubernetes Service Account Exposure. Red Hat rates this important (CVSS 8.5). Weakness: CWE-201. Affected package(s): rhoai/odh-dashboard-rhel8:1775230902, rhoai/odh-dashboard-rhel9:1775239958, rhoai/odh-dashboard-rhel9:1775234711, rhoai/odh-dashboard-rhel9:1775523049. Resolved in Red Hat advisory RHSA-2026:7404 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.16; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.2; Red Hat OpenShift AI 3.3.
High [CVE-2026-40217] Arbitrary Code Execution via bytecode rewriting
Arbitrary Code Execution via bytecode rewriting. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1782310008, ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:24866 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat OpenShift AI 3.3.
High [CVE-2026-39304] Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion
Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Fuse 7.
High [CVE-2026-40200] musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort
musl libc: Arbitrary code execution and denial of service via stack-based memory corruption in qsort. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.