Red Hat Linux Security Advisories & CVEs
5297 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-11816] Arbitrary file write via path traversal in archive extraction utilities
Arbitrary file write via path traversal in archive extraction utilities. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift AI 2.25.
High [CVE-2026-5497] Denial of Service via unbounded video frame processing
Denial of Service via unbounded video frame processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-40987] Arbitrary file write via malicious server
Arbitrary file write via malicious server. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-53461] Denial of Service via out-of-bounds heap write in ICON decoder
Denial of Service via out-of-bounds heap write in ICON decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-53460] Denial of Service via missing memory request check
Denial of Service via missing memory request check. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-49218] Denial of Service via crafted DCM image with invalid dimensions
Denial of Service via crafted DCM image with invalid dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-46520] Denial of Service via out-of-bounds write when processing multiple images
Denial of Service via out-of-bounds write when processing multiple images. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-45664] Denial of Service due to excessive resource use in MNG coder
Denial of Service due to excessive resource use in MNG coder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-46522] Denial of Service via crafted MIFF file
Denial of Service via crafted MIFF file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-45359] Information Disclosure via Invalid Connected-Components Value
Information Disclosure via Invalid Connected-Components Value. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-45031] Denial of Service due to resource policy bypass in PSD decoder
Denial of Service due to resource policy bypass in PSD decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-2049] Remote Code Execution via HDR File Parsing Heap-based Buffer Overflow
Remote Code Execution via HDR File Parsing Heap-based Buffer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-46523] Denial of Service via crafted MSL image leading to heap-use-after-free
Denial of Service via crafted MSL image leading to heap-use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): ImageMagick. Resolved in Red Hat advisory RHSA-2026:32961 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support.
High [CVE-2026-46625] Cookie attribute manipulation via prototype pollution
Cookie attribute manipulation via prototype pollution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782231869, openshift-service-mesh/kiali-rhel9:1782201466. Resolved in Red Hat advisory RHSA-2026:33183 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat OpenShift Service Mesh 3.3; OpenShift Lightspeed; Red Hat 3scale API Management Platform 2; and 4 more.
High [CVE-2026-10143] Denial of Service via excessive SCRAM authentication iteration count
Denial of Service via excessive SCRAM authentication iteration count. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected package(s): quay/quay-rhel8:1782487717, quay/quay-rhel8:1781878070, quay/quay-rhel8:1781937357. Resolved in Red Hat advisory RHSA-2026:28571 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: kafka-python; Red Hat Quay 3.10; Red Hat Quay 3.12; Red Hat Quay 3.9; and 2 more.
High [CVE-2026-46529] PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen. Red Hat rates this important (CVSS 7.8). Weakness: CWE-77. Affected package(s): evince. Resolved in Red Hat advisory RHSA-2026:33416 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 8); Red Hat Enterprise Linux AppStream E4S (v.9.2); Red Hat Enterprise Linux AppStream E4S (v.9.4); Red Hat Enterprise Linux AppStream EUS (v.9.6); and 13 more.
High [CVE-2026-1220] Race in V8
Race in V8. Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6893] Root code execution via DHCP options command injection
Root code execution via DHCP options command injection. Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Affected package(s): dracut, dracut-main. Resolved in Red Hat advisory RHSA-2026:26713 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more.
High [CVE-2026-49759] Denial of Service via crafted SCTP ERROR chunk
Denial of Service via crafted SCTP ERROR chunk. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-53437] Phishing attack via improper redirect URL validation
Phishing attack via improper redirect URL validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-601. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: OpenShift Developer Tools and Services.