Red Hat Linux Security Advisories & CVEs
5821 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-63381] Memory corruption due to use-after-free
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without resetting outbuf->first, outbuf->last, or outbuf->last_with_datap, and APPEND_CHAIN_MULTICAST subsequently dereferences the dangling chain pointer. A caller that can drive this buffer state can cause memory corruption or a process crash. This can lead to a dangling pointer, which an attacker could exploit to cause memory corruption or crash the application. Red Hat Enterprise Linux, OpenShift (RHCOS), RHIVOS, and community products (Fedora, Hummingbird) ship affected versions of libevent. Red Hat severity: Moderate — CVSS 6.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Cert Manager support for Red Hat OpenShift release 1.20; Red Hat Hardened Images; Red Hat Update Infrastructure 5; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Affected products named by the advisory: Red Hat package: libevent2.
Medium [CVE-2026-71492] Arbitrary file write via path traversal
Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values into a Path without canonicalization or containment validation. Relative traversal such as../victim/foo and an absolute Prompt.name can escape or discard the configured registry root, while overwrite=True permits replacement of existing target files. The poisoned name is persisted in index.json and reconstructed by _load(), allowing the out-of-root path to survive later registry loads. An application that forwards request data into these fields can therefore write Prompt.raw bytes to attacker-chosen paths writable by the application process. This issue is fixed in version 2.4.5. A flaw was found in Banks. This allows for path traversal, enabling an attacker to write arbitrary files outside the intended registry root. This vulnerability could lead to unauthorized modification of files on the system where Banks is running. The 'banks' library is vulnerable to arbitrary file write via path traversal when an application processes attacker-controlled input for prompt names or versions. This flaw allows an attacker to write arbitrary files to locations writable by the application process, potentially leading to system compromise.
Medium [CVE-2026-73199] NULL Pointer Dereference in `ipa-enrollment` Extended Operation (`JOIN_OID`) via Missing Request Value
A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the `JOIN_OID` in the `ipa-enrollment` extended operation, an attacker can trigger a server crash, potentially causing a denial of service. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-476. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: ipa.
Medium [CVE-2026-73196] Authenticated DoS in `otptoken-add` via unbounded OTP key decoding/re-encoding
A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service, degrading the availability of the IPA service. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: ipa.
Medium [CVE-2026-77014] Libsoup: libsoup: integer truncation in sort_ranges comparator causes silent omission of http range responses
A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB. A remote attacker can exploit this to cause the server to silently omit requested byte ranges from responses. Exploitation requires the server to be serving resources larger than approximately 2 GB, which limits real-world impact. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-197. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3; Red Hat package: gnome-clocks; Red Hat package: podman.
Medium [CVE-2026-76957] Memory corruption vulnerability allows arbitrary code execution or denial of service
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and CVE-2026-56412. A flaw was found in libexpat. This memory corruption flaw could allow a local attacker to cause a denial of service or potentially execute arbitrary code. Red Hat ships libexpat (packaged as "expat") across many products. All versions of expat prior to 2.8.4 are affected by this use-after-free vulnerability. Exploitation requires triggering the vulnerable code path through custom encoding callbacks, which is not a common usage pattern. Red Hat severity: Moderate — CVSS 4.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L). Weakness: CWE-825. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:60451, RHSA-2026:65568. Affected products named by the advisory: Red Hat package: expat; Red Hat package: firefox; Red Hat package: thunderbird; Red Hat package: compat-expat1; and 2 more. Affected products named by the advisory: Red Hat package: mingw-expat; Red Hat package: xmlrpc-c.
Medium [CVE-2026-76956] Denial of Service via hash flooding attack with crafted XML
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content. A flaw was found in libexpat. This vulnerability arises from the software misinterpreting a return code, leading to insufficient randomness (entropy) for hash functions. A remote attacker could exploit this by sending specially crafted XML content, triggering hash flooding attacks. This can result in a denial of service (DoS), making the affected system or application unavailable to legitimate users. Red Hat ships libexpat (packaged as "expat") across many products. Most Red Hat products ship expat versions prior to 2.8.2 and are therefore not affected. Only products shipping expat 2.8.2 or 2.8.3 are vulnerable to this hash flooding denial of service. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-331. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:60451, RHSA-2026:65568.
Medium [CVE-2026-43804] Visiting a website may lead to an app denial-of-service
This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service. A flaw was found in WebKitGTK. Visiting a malicious website can cause an application denial of service due to improper state management. To exploit this flaw, an attacker needs to trick a user into visiting a malicious website. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-664. Affected Red Hat products: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.
Medium [CVE-2026-64713] Websites may know if the user has visited a given link
This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link. A flaw was found in WebKitGTK. To exploit this flaw, an attacker needs to trick a user into visiting a malicious website. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N). Weakness: CWE-200. Affected Red Hat products: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.
Medium [CVE-2026-64728] Maliciously crafted web content may violate iframe sandboxing policy
A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Maliciously crafted web content may violate iframe sandboxing policy. A flaw was found in WebKitGTK. To exploit this flaw, an attacker needs to trick a user into processing or loading malicious web content. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N). Weakness: CWE-693. Affected Red Hat products: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.
Medium [CVE-2026-64730] Visiting a website that frames malicious content may lead to UI spoofing
The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website that frames malicious content may lead to UI spoofing. A flaw was found in WebKitGTK. To exploit this flaw, an attacker needs to trick a user into visiting a malicious website. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N). Weakness: CWE-451. Affected Red Hat products: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:69098. Affected products named by the advisory: Red Hat package: webkit2gtk3; Red Hat package: webkitgtk4.
Medium [CVE-2026-76928] Denial of Service via X.509IF protocol dissector crash
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service By providing a specially crafted capture file or network stream, an attacker can crash the application, making it unavailable. The impact is limited strictly to Wireshark's availability and does not affect the host system. RHEL 9 and older versions are not affected. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: wireshark.
Medium [CVE-2026-76924] Denial of Service via Out-of-bounds Read in Kerberos Dissector
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. An out-of-bounds read vulnerability exists within the Kerberos protocol dissector. This flaw can be triggered by processing a specially crafted Kerberos packet, leading to a crash of the Wireshark application. This results in a denial of service (DoS) for the user. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76923] Denial of Service due to out-of-bounds read in Bluetooth HFP dissector
Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. An out-of-bounds read vulnerability exists within the Bluetooth HFP (Hands-Free Profile) protocol dissector. A remote attacker could exploit this by tricking a user into opening a specially crafted capture file. Successful exploitation leads to a crash of the Wireshark application, resulting in a denial of service. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-125. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76918] Denial of Service via SSH protocol dissector crash
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. A local attacker could exploit a vulnerability in the SSH (Secure Shell) protocol dissector, which is responsible for analyzing SSH network traffic. This flaw, triggered by user interaction, could lead to a crash of the Wireshark application, resulting in a denial of service (DoS). Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-248. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76917] Denial of Service via Heap-based Buffer Overflow in Bluetooth AVRCP Dissector
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. A heap-based buffer overflow vulnerability exists within the Bluetooth Audio/Video Remote Control Profile (AVRCP) protocol dissector. This flaw can be triggered by a local user processing a specially crafted Bluetooth AVRCP packet, which requires user interaction. Successful exploitation leads to a crash of the Wireshark application, resulting in a denial of service. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76880] Denial of Service via RRC protocol dissector out-of-bounds write
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending a specially crafted Universal Mobile Telecommunications System (UMTS) RRC protocol packet. The flaw resides in the UMTS RRC protocol dissector, which can lead to a crash of the Wireshark application. This can disrupt network analysis operations. While exploitable by a remote attacker, successful exploitation requires a user to either open a malicious capture file or actively capture network traffic containing the crafted packet. This limits the attack surface to scenarios where Wireshark is actively used for network analysis. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: wireshark.
Medium [CVE-2026-76879] Denial of Service via C12.22 protocol dissector crash
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service By sending a specially crafted network packet or capture file, an attacker can crash the application, disrupting network analysis capabilities. RHEL 9 and older versions are not affected. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-617. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: wireshark.
Medium [CVE-2026-76889] Denial of Service via UMTS FP protocol dissector crash
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. A local attacker could exploit a crash in the UMTS FP protocol dissector. This vulnerability, which requires user interaction, leads to a denial of service, making the application unavailable. Red Hat Enterprise Linux 6, 7, 8, and 9 ship Wireshark versions prior to the affected range and are not vulnerable. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-617. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76886] Denial of Service via C12.22 protocol dissector crash
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. An unauthenticated remote attacker could exploit a vulnerability in the C12.22 protocol dissector by sending specially crafted network traffic. This could lead to a crash of the application, resulting in a Denial of Service (DoS). Exploitation requires user interaction, such as opening a malicious file, limiting its impact in typical Red Hat deployments where Wireshark is used for network analysis rather than as a continuously exposed service. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-617. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: wireshark.