Red Hat Linux Security Advisories & CVEs
11898 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-86140] Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements
Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements. Red Hat rates this important (CVSS 7.4). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-0:2.12.5-10.el10_2.4, libxml2-0:2.9.13-14.el9_8.5, libxml2-0:2.9.7-21.el8_10.9, libxml2-main-2.15.4-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2026-18238] Information disclosure via out-of-bounds read in rpcap client
Information disclosure via out-of-bounds read in rpcap client. Red Hat rates this moderate (CVSS 5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.
Medium [CVE-2026-18313] Denial of Service via memory leak in rpcapd
Denial of Service via memory leak in rpcapd. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.
Medium [CVE-2026-6554] Denial of Service via infinite loop in BPF interpreter
Denial of Service via infinite loop in BPF interpreter. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.
Medium [CVE-2026-6244] Denial of Service via crafted BPF filter program
Denial of Service via crafted BPF filter program. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-369. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.
Medium [CVE-2026-31911] Denial of Service via crafted BPF opcode
Denial of Service via crafted BPF opcode. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.
Medium [CVE-2026-31912] Denial of service via crafted BPF filter program
Denial of service via crafted BPF filter program. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libpcap.
Medium [CVE-2026-86144] Information disclosure, SSRF, or denial of service due to improper parseFlags propagation.
Information disclosure, SSRF, or denial of service due to improper parseFlags propagation. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-669. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-0:2.12.5-10.el10_2.4, libxml2-0:2.9.13-14.el9_8.5, libxml2-0:2.9.7-21.el8_10.9, libxml2-main-2.15.4-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2026-86143] Data integrity issues due to integer overflow in write callbacks
Data integrity issues due to integer overflow in write callbacks. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-192. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-0:2.12.5-10.el10_2.4, libxml2-0:2.9.13-14.el9_8.5, libxml2-0:2.9.7-21.el8_10.9, libxml2-main-2.15.4-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2026-86142] Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturation
Heap-based buffer overflow in xmlXPtrEval due to xpointer length saturation. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-0:2.12.5-10.el10_2.4, libxml2-0:2.9.13-14.el9_8.5, libxml2-main-2.15.4-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
Medium [CVE-2026-86139] Integer overflow in xmlURIEscapeStr may lead to arbitrary code execution
Integer overflow in xmlURIEscapeStr may lead to arbitrary code execution. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-main-2.15.4-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-86138] Arbitrary code execution via heap-based buffer overflow
Arbitrary code execution via heap-based buffer overflow. Red Hat rates this moderate (CVSS 6.9). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-0:2.12.5-10.el10_2.4, libxml2-0:2.9.13-14.el9_8.5, libxml2-0:2.9.7-21.el8_10.9, libxml2-main-2.15.4-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Low [CVE-2026-86141] Denial of Service due to NULL pointer dereference in xmlRegNewParserCtxt
Denial of Service due to NULL pointer dereference in xmlRegNewParserCtxt. Red Hat rates this low (CVSS 2.9). Weakness: CWE-252. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-main-2.15.4-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Low [CVE-2026-86137] Denial of Service via out-of-bounds read in xmlFAParsePosCharGroup
Denial of Service via out-of-bounds read in xmlFAParsePosCharGroup. Red Hat rates this low (CVSS 2.9). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:64463 with package libxml2-main-2.15.4-0.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Critical [CVE-2026-85595] Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth
Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-305. Affected product named by the advisory: Red Hat OpenShift Dev Spaces.
High [CVE-2026-85781] github.com/kubernetes-sigs/aws-efs-csi-driver: Amazon EFS CSI Driver: Unauthorized directory deletion via unverified access point ownership
github.com/kubernetes-sigs/aws-efs-csi-driver: Amazon EFS CSI Driver: Unauthorized directory deletion via unverified access point ownership. Red Hat rates this important (CVSS 7.7). Weakness: CWE-639. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-19534] Denial of Service via unrequested WebSocket subprotocol
Denial of Service via unrequested WebSocket subprotocol. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:69248 with package nodejs26-main-26.8.2-0.1.hum1, grafana12-4-main-12.4.10-0.2.hum1, rhdh/rhdh-hub-rhel9:1789554285. Affected products named by the advisory: Red Hat Hardened Images; Exploit Intelligence; OpenShift Pipelines; Red Hat Build of Podman Desktop; and 14 more. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 10 more.
High [CVE-2026-84961] TLS certificate validation bypass in BalancedPool via dropped connect options
undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2. A flaw was found in undici's BalancedPool component. This vulnerability allows a remote attacker to bypass Transport Layer Security (TLS) certificate validation. The BalancedPool constructor incorrectly processes its options, silently discarding custom certificate validation functions. Consequently, a peer with an otherwise untrusted certificate may be accepted, potentially compromising the integrity of secure communication.
High [CVE-2026-85152] Authentication bypass via cross-origin cache poisoning due to missing origin isolation
undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2. A flaw was found in undici. This allows a remote attacker to perform cross-origin cache poisoning, leading to information disclosure and potentially a full authentication bypass. An attacker could exploit this by having a trusted origin accept a malicious token, without contacting the legitimate trusted origin. This flaw is present in the undici HTTP client library used by Node.js.
High [CVE-2026-85730] Denial of Service via malformed TOML documents
smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is followed by a comment with no trailing newline. In src/util.ts, skipUntil() calls indexOfNewline(), receives -1 at the end of input, and resets the cursor to the beginning of the string instead of leaving the structure scan. The parser then hangs indefinitely and can consume a service's processing capacity when an application parses attacker-controlled TOML. This issue is fixed in version 1.7.1. A remote attacker could exploit an infinite loop in the `parse()` function by providing a specially crafted TOML document. Successful exploitation leads to a Denial of Service (DoS), causing the parser to hang indefinitely and consume service processing capacity. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 10; Red Hat OpenShift AI (RHOAI). Red Hat lists Red Hat Ansible Automation Platform 2; Red Hat Developer Hub; Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cockpit-image-builder.