Red Hat Linux Security Advisories & CVEs
3066 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-26200] Denial of Service due to heap buffer overflow when parsing a crafted h5 file
Denial of Service due to heap buffer overflow when parsing a crafted h5 file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-25535] denial of service via malicious GIF dimensions
denial of service via malicious GIF dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.
High [CVE-2026-22860] Rack Directory Traversal via Rack:Directory
Rack Directory Traversal via Rack:Directory. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat 3scale API Management Platform 2.
High [CVE-2025-14009] Zip Slip Vulnerability in nltk Leading to Code Execution
Zip Slip Vulnerability in nltk Leading to Code Execution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1775144403, rhoai/odh-ta-lmes-job-rhel9:1776271296. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; OpenShift Lightspeed; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-2648] Heap buffer overflow in PDFium
Heap buffer overflow in PDFium. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-2649] Integer overflow in V8
Integer overflow in V8. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-23216] Fix use-after-free in iscsit_dec_conn_usage_count()
Fix use-after-free in iscsit_dec_conn_usage_count(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-413. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:9870 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-24734] Certificate revocation bypass due to improper OCSP response validation
Certificate revocation bypass due to improper OCSP response validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected package(s): jws6-tomcat-native, tomcat, tomcat10-main, jws6-tomcat, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:5612 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 6.2 on RHEL 10; Red Hat JBoss Web Server 6.2 on RHEL 8; and 3 more.
High [CVE-2026-24708] Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova
Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova. Red Hat rates this important (CVSS 7.1). Weakness: CWE-73. Affected package(s): openstack-nova. Resolved in Red Hat advisory RHSA-2026:7884 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenStack Services on OpenShift 18.0; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more.
High [CVE-2026-2447] Heap buffer overflow in libvpx
Heap buffer overflow in libvpx. Red Hat rates this important (CVSS 7.5). Affected package(s): libvpx, thunderbird, rhaiis/vllm-rocm-rhel9:1775680262, firefox, rhaiis/vllm-cuda-rhel9:1775680192, rhaiis/vllm-spyre-rhel9:1778244546. Resolved in Red Hat advisory RHSA-2026:3967 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 11 more.
High [CVE-2026-23171] Linux kernel: Use-after-free in bonding module can cause system crash or arbitrary code execution
Linux kernel: Use-after-free in bonding module can cause system crash or arbitrary code execution. Red Hat rates this moderate (CVSS 7). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:8342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-23210] Linux kernel: Denial of Service in ice driver due to race condition during VSI rebuild
Linux kernel: Denial of Service in ice driver due to race condition during VSI rebuild. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:6570 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-23209] fix error recovery in macvlan_common_newlink()
fix error recovery in macvlan_common_newlink(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:6954 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-23136] Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state
Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-440. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27708 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-23144] Linux kernel: Local denial of service and memory leak in DAMON sysfs via setup failure
Linux kernel: Local denial of service and memory leak in DAMON sysfs via setup failure. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-772. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:8342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-23139] update last_gc only when GC has been performed
update last_gc only when GC has been performed. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-400. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:15883 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-23193] Fix use-after-free in iscsit_dec_session_usage_count()
Fix use-after-free in iscsit_dec_session_usage_count(). Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-364. Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-23204] use skb_header_pointer_careful()
use skb_header_pointer_careful(). Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-1285. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:10756 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9.
High [CVE-2026-23191] Fix racy access at PCM trigger
Fix racy access at PCM trigger. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-367. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.
High [CVE-2026-23156] Linux kernel: Information disclosure in efivarfs via incorrect error propagation
Linux kernel: Information disclosure in efivarfs via incorrect error propagation. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-390. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:9095 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.