Red Hat Linux Security Advisories & CVEs
10918 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-92868] Authentication bypass via improper certificate validation
Authentication bypass via improper certificate validation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-295.
Low [CVE-2026-103012] Security policy bypass via improper credential prioritization
Security policy bypass via improper credential prioritization. Red Hat rates this low (CVSS 3.3). Weakness: CWE-280. Affected product named by the advisory: Red Hat OpenShift Dev Spaces.
Critical [CVE-2026-102331] arbitrary code execution via buffer overflow in ANGLE
arbitrary code execution via buffer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-95331] Out of bounds write in ANGLE
Out of bounds write in ANGLE. Red Hat rates this moderate (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-95274] Improper output encoding in DevTools
Improper output encoding in DevTools. Red Hat rates this important (CVSS 9.6). Weakness: CWE-116.
Critical [CVE-2026-95310] Use after free in AdFilter
Use after free in AdFilter. Red Hat rates this important (CVSS 9.6). Weakness: CWE-416.
Critical [CVE-2026-95329] Out of bounds write in WebGL
Out of bounds write in WebGL. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787.
Critical [CVE-2026-95284] Buffer overflow in ANGLE
Buffer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-95357] Out of bounds write in GPU
Out of bounds write in GPU. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787.
Critical [CVE-2026-100811] Sandbox escape via use-after-free in DOM component
Sandbox escape via use-after-free in DOM component. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: firefox.
Critical [CVE-2026-100786] Sandbox escape via use-after-free in Graphics component
Sandbox escape via use-after-free in Graphics component. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: firefox.
High [CVE-2026-102938] Arbitrary code execution via configuration injection in prompt values
Arbitrary code execution via configuration injection in prompt values. Red Hat rates this moderate (CVSS 7). Weakness: CWE-93. Affected products named by the advisory: OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 8; Red Hat OpenShift AI (RHOAI); and 4 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; Self-service automation portal 2.
High [CVE-2026-102937] Arbitrary code execution via unescaped prompt in Windows activation script
Arbitrary code execution via unescaped prompt in Windows activation script. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 8; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 3 more. Affected products named by the advisory: Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; Self-service automation portal 2.
High [CVE-2026-102930] Arbitrary code execution via unverified downloaded seed wheels
Arbitrary code execution via unverified downloaded seed wheels. Red Hat rates this important (CVSS 7.5). Weakness: CWE-494. Affected products named by the advisory: OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 8; Red Hat OpenShift AI (RHOAI); and 4 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; Self-service automation portal 2.
High [CVE-2026-102925] Arbitrary code execution via crafted paths in activation scripts
Arbitrary code execution via crafted paths in activation scripts. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94. Affected products named by the advisory: OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 8; Red Hat OpenShift AI (RHOAI); and 4 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; Self-service automation portal 2.
High [CVE-2026-102253] Denial of Service via UDP receive worker infinite loop
Denial of Service via UDP receive worker infinite loop. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: iperf3.
High [CVE-2026-102327] Incorrect authorization in WebView
Incorrect authorization in WebView. Red Hat rates this important (CVSS 8.3). Weakness: CWE-653.
High [CVE-2026-102321] Type confusion in V8
Type confusion in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843.
High [CVE-2026-102302] Buffer overflow in V8
Buffer overflow in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-102315] Uninitialized resource in Media
Uninitialized resource in Media. Red Hat rates this important (CVSS 7.4). Weakness: CWE-908.