Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-33947] unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted()
unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted(). Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-674. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:8579 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-32316] Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow
Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-190. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:8579 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-33555] Request smuggling via HTTP/3 parser desynchronization
Request smuggling via HTTP/3 parser desynchronization. Red Hat rates this moderate (CVSS 4). Weakness: CWE-130. Affected package(s): haproxy-main. Resolved in Red Hat advisory RHSA-2026:8749 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-6845] Denial of Service via crafted ELF file
Denial of Service via crafted ELF file. Red Hat rates this moderate (CVSS 5). Weakness: CWE-476. Affected package(s): binutils-main. Resolved in Red Hat advisory RHSA-2026:34924 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more.
Medium [CVE-2026-40386] Denial of Service and information disclosure via integer underflow in MakerNote decoding
Denial of Service and information disclosure via integer underflow in MakerNote decoding. Red Hat rates this moderate (CVSS 4). Weakness: CWE-191. Affected package(s): libexif. Resolved in Red Hat advisory RHSA-2026:26276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.
Medium [CVE-2026-40385] Information disclosure and crashes via integer overflow in Nikon MakerNote handling
Information disclosure and crashes via integer overflow in Nikon MakerNote handling. Red Hat rates this moderate (CVSS 4). Weakness: CWE-190. Affected package(s): libexif. Resolved in Red Hat advisory RHSA-2026:26276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7.
Medium [CVE-2026-3446] Python base64: Incomplete data decoding due to premature stop at padding
Python base64: Incomplete data decoding due to premature stop at padding. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1286. Affected package(s): python3. Resolved in Red Hat advisory RHSA-2026:10118 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-1502] HTTP header injection via CR/LF in proxy tunnel headers
HTTP header injection via CR/LF in proxy tunnel headers. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-93. Affected package(s): python3, python3.12, python3.14, rhui5/rhua-rhel9:1779798222, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:19019 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.
Medium [CVE-2026-34481] Denial of Service via invalid JSON output
Denial of Service via invalid JSON output. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-241. Affected package(s): log4j-layout-template-json, offline-knowledge-portal/rhokp-rhel9:1779996999. Resolved in Red Hat advisory RHSA-2026:22619 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34480] Invalid XML output causes denial of service in logging
Invalid XML output causes denial of service in logging. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-168. Affected package(s): log4j-core-test, offline-knowledge-portal/rhokp-rhel9:1779996999, log4j-core. Resolved in Red Hat advisory RHSA-2026:22619 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34479] Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping
Apache Log4j 1-to-Log4j 2 bridge: Log processing denial of service due to improper XML escaping. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-91. Affected package(s): offline-knowledge-portal/rhokp-rhel9:1779996999. Resolved in Red Hat advisory RHSA-2026:21773 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34478] Log injection via CRLF sequences due to configuration attribute renames
Log injection via CRLF sequences due to configuration attribute renames. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-93. Affected package(s): log4j-core-test, offline-knowledge-portal/rhokp-rhel9:1779996999, log4j-core. Resolved in Red Hat advisory RHSA-2026:22619 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34477] Man-in-the-middle attack due to incomplete hostname verification
Man-in-the-middle attack due to incomplete hostname verification. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-295. Affected package(s): offline-knowledge-portal/rhokp-rhel9:1779996999. Resolved in Red Hat advisory RHSA-2026:21773 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-40227] Denial of Service via malicious IPC API call with null element
Denial of Service via malicious IPC API call with null element. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-40226] systemd nspawn: Escape-to-host action via crafted config file
systemd nspawn: Escape-to-host action via crafted config file. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-348. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-40225] udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output
udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-250. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-40224] Local privilege escalation via varlink
Local privilege escalation via varlink. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-266. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-40223] Local unprivileged user can cause Denial of Service
Local unprivileged user can cause Denial of Service. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-617. Affected package(s): systemd-main. Resolved in Red Hat advisory RHSA-2026:7299 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-35206] Files written to unexpected directory via specially crafted Chart
Files written to unexpected directory via specially crafted Chart. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-22. Affected package(s): helm-cli, rhacm2/multicloud-integrations-rhel9:1782256081, multicluster-engine/backplane-rhel9-operator:1782476869. Resolved in Red Hat advisory RHSA-2026:26441 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34500] Authentication bypass via client certificate misconfiguration
Authentication bypass via client certificate misconfiguration. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-303. Affected package(s): tomcat, jws6-tomcat. Resolved in Red Hat advisory RHSA-2026:20405 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.