Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-5545] Authentication bypass due to incorrect HTTP Negotiate connection reuse
Authentication bypass due to incorrect HTTP Negotiate connection reuse. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-488. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:12916 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-6429] Credential leak via reused proxy connection during HTTP redirects
Credential leak via reused proxy connection during HTTP redirects. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:12916 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-42014] Use-after-free in gnutls_pkcs11_token_set_pin
Use-after-free in gnutls_pkcs11_token_set_pin. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-825. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 11 more.
Medium [CVE-2026-42015] Memory corruption due to off-by-one error in PKCS#12 bag handling
Memory corruption due to off-by-one error in PKCS#12 bag handling. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-193. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:20613 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 11 more.
Medium [CVE-2026-6238] Application crash or uninitialized memory read via crafted DNS response
Application crash or uninitialized memory read via crafted DNS response. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1284. Affected package(s): glibc-main. Resolved in Red Hat advisory RHSA-2026:12740 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-7321] Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501. Affected package(s): firefox, thunderbird. Resolved in Red Hat advisory RHSA-2026:19370 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.
Medium [CVE-2026-5435] Out-of-bounds write via TSIG record processing
Out-of-bounds write via TSIG record processing. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-120. Affected package(s): glibc-main. Resolved in Red Hat advisory RHSA-2026:12740 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-40356] MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read
MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-191. Affected package(s): krb5-main, rhui5/haproxy-rhel9:1779798164, krb5, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791, rhui5/rhua-rhel9:1779798222. Resolved in Red Hat advisory RHSA-2026:12220 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-40355] Denial of Service via NULL pointer dereference in NegoEx mechanism
Denial of Service via NULL pointer dereference in NegoEx mechanism. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-476. Affected package(s): krb5-main, insights-proxy/insights-proxy-container-rhel9:1780420428, rhui5/haproxy-rhel9:1779798164, krb5, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:12220 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-7351] Race in MHTML
Race in MHTML. Red Hat rates this important (CVSS 5.5). Weakness: CWE-368. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-42371] Denial of Service via numeric truncation with oversized URIs
Denial of Service via numeric truncation with oversized URIs. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-190. Affected package(s): uriparser-main. Resolved in Red Hat advisory RHSA-2026:12430 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-31677] af_alg - limit RX SG extraction by receive buffer budget
af_alg - limit RX SG extraction by receive buffer budget. Red Hat rates this low (CVSS 5.5). Weakness: CWE-770. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:19074 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-41481] Information Disclosure via Server-Side Request Forgery (SSRF) Redirect Bypass
Information Disclosure via Server-Side Request Forgery (SSRF) Redirect Bypass. Red Hat rates this important (CVSS 6.5). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-31581] fix use-after-free on disconnect
fix use-after-free on disconnect. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-6019] Cross-Site Scripting (XSS) vulnerability in http.cookies module
Cross-Site Scripting (XSS) vulnerability in http.cookies module. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-79. Affected package(s): python3, python3.14. Resolved in Red Hat advisory RHSA-2026:28247 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-31467] Linux kernel: Denial of Service in erofs filesystem
Linux kernel: Denial of Service in erofs filesystem. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:25191 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-22013] Improve Kerberos credentialing (Oracle CPU 2026-04)
Improve Kerberos credentialing (Oracle CPU 2026-04). Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-319. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:11829 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-22021] Enhance certificate chain validation (Oracle CPU 2026-04)
Enhance certificate chain validation (Oracle CPU 2026-04). Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-674. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:11829 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-33813] Denial of Service via malformed WEBP image parsing
Denial of Service via malformed WEBP image parsing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, cryostat/cryostat-storage-rhel9:4.2.0, golang1, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2017-20230] Storable for Perl: Denial of service via stack overflow in retrieve_hook function
Storable for Perl: Denial of service via stack overflow in retrieve_hook function. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-190. Affected package(s): perl-storable-main. Resolved in Red Hat advisory RHSA-2026:7578 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.