Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2025-69418] Information disclosure and data tampering via specific low-level OCB encryption/decryption calls
Information disclosure and data tampering via specific low-level OCB encryption/decryption calls. Red Hat rates this low (CVSS 4). Weakness: CWE-325. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-69421] Denial of Service via malformed PKCS#12 file processing
Denial of Service via malformed PKCS#12 file processing. Red Hat rates this low (CVSS 6.5). Weakness: CWE-476. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-69420] Denial of Service via malformed TimeStamp Response
Denial of Service via malformed TimeStamp Response. Red Hat rates this low (CVSS 5.9). Weakness: CWE-843. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-22795] Denial of Service due to type confusion in PKCS#12 file processing
Denial of Service due to type confusion in PKCS#12 file processing. Red Hat rates this low (CVSS 5.5). Weakness: CWE-843. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-22796] Denial of Service via type confusion in PKCS#7 signature verification
Denial of Service via type confusion in PKCS#7 signature verification. Red Hat rates this low (CVSS 5.9). Weakness: CWE-1287. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-28164] Denial of Service via buffer overflow in png_create_read_struct() function
Denial of Service via buffer overflow in png_create_read_struct() function. Red Hat rates this moderate (CVSS 5). Weakness: CWE-120. Affected package(s): libpng-main. Resolved in Red Hat advisory RHSA-2026:6732 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-28162] Denial of Service via buffer overflow in pngimage utility
Denial of Service via buffer overflow in pngimage utility. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-120. Affected package(s): libpng-main. Resolved in Red Hat advisory RHSA-2026:6732 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-1504] Inappropriate implementation in Background Fetch API
Inappropriate implementation in Background Fetch API. Red Hat rates this important (CVSS 6.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-23002] use __kernel_read() for sleepable context
use __kernel_read() for sleepable context. Red Hat rates this low (CVSS 4.7). Weakness: CWE-476. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:18134 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-22998] fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec
fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-476. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:2722 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.
Medium [CVE-2026-24401] Denial of Service via recursive CNAME record in mDNS response
Denial of Service via recursive CNAME record in mDNS response. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-674. Affected package(s): avahi-main. Resolved in Red Hat advisory RHSA-2026:11316 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-71151] Fix memory and information leak in smb3_reconfigure()
Fix memory and information leak in smb3_reconfigure(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2025:6966 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2025-71176] Denial of Service or Privilege Escalation via insecure temporary directory handling
Denial of Service or Privilege Escalation via insecure temporary directory handling. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-379. Affected package(s): pytest-main. Resolved in Red Hat advisory RHSA-2026:8580 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-23893] Privilege Escalation or Data Exposure via Symlink Following
Privilege Escalation or Data Exposure via Symlink Following. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-59. Affected package(s): opencryptoki. Resolved in Red Hat advisory RHSA-2026:4717 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2025-14559] Keycloak keycloak-services: Business logic flaw allows unauthorized token issuance for disabled users
Keycloak keycloak-services: Business logic flaw allows unauthorized token issuance for disabled users. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-840. Affected package(s): keycloak-services, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-0672] Header injection in http.cookies.Morsel in Python
Header injection in http.cookies. Morsel in Python. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-93. Affected package(s): python3.12, rhui5/rhua-rhel9:1779798222, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:19064 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.
Medium [CVE-2025-15282] Header injection via newlines in data URL mediatype in Python
Header injection via newlines in data URL mediatype in Python. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-93. Affected package(s): python3.12, python3, rhui5/rhua-rhel9:1779798222, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:19064 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.
Medium [CVE-2026-0865] wsgiref.headers.Headers allows header newline injection in Python
wsgiref.headers. Headers allows header newline injection in Python. Red Hat rates this moderate (CVSS 4.5). Weakness: CWE-74. Affected package(s): python3.11, python3, rhui5/haproxy-rhel9:1779798164, rhui5/rhua-rhel9:1773670137, rhui5/rhua-rhel9:1779798222, python3.12. Resolved in Red Hat advisory RHSA-2026:2128 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-21925] Improve JMX connections (Oracle CPU 2026-01)
Improve JMX connections (Oracle CPU 2026-01). Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-322. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0895 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-21933] Improve HttpServer Request handling (Oracle CPU 2026-01)
Improve HttpServer Request handling (Oracle CPU 2026-01). Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-93. Affected package(s): java. Resolved in Red Hat advisory RHSA-2026:0895 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.