Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-12314] Memory safety bug fixed in Thunderbird ESR 140.12
Memory safety bug fixed in Thunderbird ESR 140.12. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-12313] Information disclosure, sandbox escape in the Security: Process Sandboxing component
Information disclosure, sandbox escape in the Security: Process Sandboxing component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-403. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-12311] Information disclosure, sandbox escape in the Security: Process Sandboxing component
Information disclosure, sandbox escape in the Security: Process Sandboxing component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-243. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-12310] Memory safety bug fixed in Thunderbird ESR 140.12
Memory safety bug fixed in Thunderbird ESR 140.12. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-12308] Memory safety bug fixed in Thunderbird ESR 140.12
Memory safety bug fixed in Thunderbird ESR 140.12. Red Hat rates this moderate (CVSS 6.1). Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-12304] Same-origin policy bypass in the Networking: Cookies component
Same-origin policy bypass in the Networking: Cookies component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-346. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-12302] Mitigation bypass in the DOM: Security component
Mitigation bypass in the DOM: Security component. Red Hat rates this moderate (CVSS 6.1). Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:29940 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-12087] Information Disclosure due to Out-of-Bounds Read
Information Disclosure due to Out-of-Bounds Read. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125. Affected package(s): perl-socket-main. Resolved in Red Hat advisory RHSA-2026:11342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-52718] denial of service via av1 tile_list_obu parser byte/bit confusion
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchronization. A remote attacker could trick a user into opening a specially crafted AV1 media file, triggering an assertion abort and causing the application to crash. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 10.0 Extended Update Support.
Medium [CVE-2026-44188] Session hijacking and unauthorized data access due to insufficient session expiration
Session hijacking and unauthorized data access due to insufficient session expiration. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-613. Affected package(s): ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:25928 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6; Red Hat Ansible Automation Platform 2.7.
Medium [CVE-2026-54411] Plaintext password recovery via timing discrepancy in pam_userdb module
Plaintext password recovery via timing discrepancy in pam_userdb module. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-208. Affected package(s): pam-main. Resolved in Red Hat advisory RHSA-2026:35016 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-44171] Unauthorized file creation via path traversal
Unauthorized file creation via path traversal. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-22. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-44169] MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check
MariaDB server: Information disclosure of stored routine definitions due to insufficient privilege check. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-266. Affected package(s): mariadb10.11, mariadb11, galera, mariadb:11.8, mariadb11.8, mariadb:10.11. Resolved in Red Hat advisory RHSA-2026:33093 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-50560] Denial of Service due to HTTP/2 max header size handling
Denial of Service due to HTTP/2 max header size handling. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected package(s): netty-codec-http2. Resolved in Red Hat advisory RHSA-2026:26018 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-50020] Data manipulation via request-boundary confusion in HttpObjectDecoder
Data manipulation via request-boundary confusion in HttpObjectDecoder. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected package(s): netty-codec-http. Resolved in Red Hat advisory RHSA-2026:26018 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-47244] Denial of Service via uncontrolled HTTP/2 concurrent streams
Denial of Service via uncontrolled HTTP/2 concurrent streams. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected package(s): netty-codec-http2. Resolved in Red Hat advisory RHSA-2026:26018 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-47208] Sandbox Breakout Using Promise Species
Sandbox Breakout Using Promise Species. Red Hat rates this moderate (CVSS 6.6). Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-47140] Arbitrary code execution due to incomplete sandbox restrictions
Arbitrary code execution due to incomplete sandbox restrictions. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-184. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-45673] Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs
Netty DNS resolver: DNS Cache Poisoning via predictable transaction IDs. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-1241. Affected package(s): netty-resolver-dns. Resolved in Red Hat advisory RHSA-2026:26018 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-47137] Sandbox escape leading to arbitrary code execution via security bypass
Sandbox escape leading to arbitrary code execution via security bypass. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-480. Affected package(s): rhdh/rhdh-hub-rhel9:1782761244. Resolved in Red Hat advisory RHSA-2026:33574 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.