Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2025-14831] Denial of Service via excessive resource consumption during certificate verification
Denial of Service via excessive resource consumption during certificate verification. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-407. Affected package(s): rhpam, rhaiis/vllm-rocm-rhel9:1778244531, gnutls-main, discovery/discovery-server-rhel9:1775668717, insights-proxy/insights-proxy-container-rhel9:1773685509, rhui5/rhua-rhel9:1773670137. Resolved in Red Hat advisory RHSA-2026:6618 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 17 more.
Medium [CVE-2026-2100] NULL dereference via C_DeriveKey with specific NULL parameters
NULL dereference via C_DeriveKey with specific NULL parameters. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-824. Affected package(s): p11-kit, insights-proxy/insights-proxy-container-rhel9:1780420428, rhui5/haproxy-rhel9:1779798164, costmanagement/costmanagement-metrics-rhel9-operator:1780946239, p11-kit-main, rhui5/rhua-rhel9:1779798222. Resolved in Red Hat advisory RHSA-2026:7065 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat Insights proxy 1.5; and 1 more.
Medium [CVE-2026-0598] Broken Object Level Authorization Leading to Cross-User AI Conversation Context Injection in Ansible Lightspeed API
Broken Object Level Authorization Leading to Cross-User AI Conversation Context Injection in Ansible Lightspeed API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-283. Affected package(s): ansible-automation-platform. Resolved in Red Hat advisory RHSA-2026:13545 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-47911] Quadratic parsing complexity in golang.org/x/net/html
Quadratic parsing complexity in golang.org/x/net/html. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-400. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1782844225, golang1, cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1782839658, cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9:1782840519, cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-58190] Infinite parsing loop in golang.org/x/net
Infinite parsing loop in golang.org/x/net. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-835. Affected package(s): cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279, cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1782844225, golang1, cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1782839658, multicluster-engine/hive-rhel9:1770693331, cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9:1782840519. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-22873] Information disclosure via path traversal using specially crafted filenames
Information disclosure via path traversal using specially crafted filenames. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-25547] Denial of Service via unbounded brace range expansion
Denial of Service via unbounded brace range expansion. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-409. Affected package(s): nodejs:22, nodejs22, nodejs24, nodejs:24. Resolved in Red Hat advisory RHSA-2026:7350 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-1642] Data injection via man-in-the-middle attack on TLS proxied connections
Data injection via man-in-the-middle attack on TLS proxied connections. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-349. Affected package(s): nginx-main, nginx, nginx:1.24, discovery/discovery-ui-rhel9:1773273070, nginx:1.26, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6408 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-23060] Linux kernel: Denial of Service in authencesn due to too-short AAD
Linux kernel: Denial of Service in authencesn due to too-short AAD. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1284. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:19074 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-61645] Cross-site scripting vulnerability allows information disclosure via improper input neutralization
Cross-site scripting vulnerability allows information disclosure via improper input neutralization. Red Hat rates this important (CVSS 4.6). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-1757] Memory Leak Leading to Local Denial of Service in xmllint Interactive Shell
Memory Leak Leading to Local Denial of Service in xmllint Interactive Shell. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-401. Affected package(s): libxml2-main. Resolved in Red Hat advisory RHSA-2026:7519 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more.
Medium [CVE-2026-25128] fast-xml-parser has RangeError DoS Numeric Entities Bug
fast-xml-parser has RangeError DoS Numeric Entities Bug. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-248. Affected package(s): odf4/ocs-metrics-exporter-rhel9:1781557202, odf4/mcg-core-rhel9:1781555645, odf4/odf-rhel9-operator:1781556958, advanced-cluster-security/rhacs-main-rhel8:1775594119, odf4/cephcsi-rhel9-operator:1781554936, odf4/ocs-client-console-rhel9:1781558423. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-25068] alsa-lib Topology Decoder Heap-based Buffer Overflow
alsa-lib Topology Decoder Heap-based Buffer Overflow. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-787. Affected package(s): alsa-lib-main. Resolved in Red Hat advisory RHSA-2026:7401 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-61730] Handshake messages may be processed at the incorrect encryption level in crypto/tls
Handshake messages may be processed at the incorrect encryption level in crypto/tls. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-325. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-68119] Local code execution and arbitrary file write via malicious module version strings
Local code execution and arbitrary file write via malicious module version strings. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-11187] Arbitrary code execution or denial of service through crafted PKCS#12 file
Arbitrary code execution or denial of service through crafted PKCS#12 file. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-233. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-15468] Denial of Service via NULL pointer dereference in QUIC protocol handling
Denial of Service via NULL pointer dereference in QUIC protocol handling. Red Hat rates this low (CVSS 5.9). Weakness: CWE-476. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-15469] Data integrity bypass in `openssl dgst` command due to silent truncation
Data integrity bypass in `openssl dgst` command due to silent truncation. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1284. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-66199] Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression
Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression. Red Hat rates this low (CVSS 5.9). Weakness: CWE-770. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-68160] Denial of Service due to out-of-bounds write in BIO filter
Denial of Service due to out-of-bounds write in BIO filter. Red Hat rates this low (CVSS 4.7). Weakness: CWE-787. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.