Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-7261] Memory corruption and information disclosure via incorrect persistence handling
Memory corruption and information disclosure via incorrect persistence handling. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-825. Affected package(s): php, php:7.4. Resolved in Red Hat advisory RHSA-2026:33449 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.
Medium [CVE-2026-6735] Cross-Site Scripting vulnerability via improper URL sanitation
Cross-Site Scripting vulnerability via improper URL sanitation. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected package(s): php, php8.4, php:8.2, php:7.4, php:8.3, php-main. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-42256] Net::IMAP: Denial of Service via large iteration count in SCRAM authentication
Net::IMAP: Denial of Service via large iteration count in SCRAM authentication. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected package(s): ruby3, ruby4. Resolved in Red Hat advisory RHSA-2026:33552 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-42245] Net::IMAP: Denial of Service via crafted IMAP responses
Net::IMAP: Denial of Service via crafted IMAP responses. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected package(s): ruby3, ruby:3.3, ruby4, ruby4.0, ruby, ruby:4.0. Resolved in Red Hat advisory RHSA-2026:33515 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-42310] Denial of Service via malicious PDF processing
Denial of Service via malicious PDF processing. Red Hat rates this moderate (CVSS 4). Weakness: CWE-835. Affected package(s): rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1778274666, rhaiis/model-opt-cuda-rhel9:1778244559. Resolved in Red Hat advisory RHSA-2026:16030 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-42309] Denial of Service via specially crafted coordinate input
Denial of Service via specially crafted coordinate input. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-131. Affected package(s): rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1778274666, rhaiis/model-opt-cuda-rhel9:1778244559. Resolved in Red Hat advisory RHSA-2026:16030 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-2291] heap buffer overflow in cache via NAME_ESCAPE expansion
heap buffer overflow in cache via NAME_ESCAPE expansion. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-131. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.
Medium [CVE-2026-4893] Broken ECS source validation bypass
Broken ECS source validation bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-20. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.
Medium [CVE-2026-41889] SQL injection via specific SQL query conditions
SQL injection via specific SQL query conditions. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-89. Affected package(s): caddy-main, cosign-main, go-fdo-server-main. Resolved in Red Hat advisory RHSA-2026:16133 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-41506] Information disclosure of HTTP authentication credentials via redirects
Information disclosure of HTTP authentication credentials via redirects. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-601. Affected package(s): syft-main. Resolved in Red Hat advisory RHSA-2026:17669 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-44928] Incorrect URI comparison leading to integrity issues
Incorrect URI comparison leading to integrity issues. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1025. Affected package(s): uriparser-main. Resolved in Red Hat advisory RHSA-2026:16341 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-39823] Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content
Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:23262 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-39826] Cross-site scripting due to incorrect script tag escaping
Cross-site scripting due to incorrect script tag escaping. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-1289. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:23262 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-39825] ReverseProxy forwards hidden query parameters, potentially bypassing security controls
ReverseProxy forwards hidden query parameters, potentially bypassing security controls. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-472. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:23262 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-13595] heap use-after-free in libblkid nested partition probing
heap use-after-free in libblkid nested partition probing. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-416. Affected package(s): util-linux-main. Resolved in Red Hat advisory RHSA-2026:26573 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more.
Medium [CVE-2026-6420] Security bypass due to hardcoded TPM quote nonce
Security bypass due to hardcoded TPM quote nonce. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-1241. Affected package(s): keylime. Resolved in Red Hat advisory RHSA-2026:28582 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-6860] Denial of Service via TLS handshake with wildcard server name
Denial of Service via TLS handshake with wildcard server name. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator, rhbk/keycloak-rhel9:26.6, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-43163] fix GPF in write_page caused by resize race
fix GPF in write_page caused by resize race. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:21745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.
Medium [CVE-2026-43205] Linux kernel dpaa2-switch: Kernel memory corruption via out-of-bounds write
Linux kernel dpaa2-switch: Kernel memory corruption via out-of-bounds write. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-787. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:21557 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-43279] Add sanity check for OOB writes at silencing
Add sanity check for OOB writes at silencing. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-787. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.