Red Hat Linux Security Advisories & CVEs
5233 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-9950] Insufficient validation of untrusted input in iOS
Insufficient validation of untrusted input in iOS. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-9955] Inappropriate implementation in iOS
Inappropriate implementation in iOS. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-9956] Use after free in iOS
Use after free in iOS. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-9963] Uninitialized Use in iOS
Uninitialized Use in iOS. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-45984] Fix use-after-free in iomap inline data write path
Fix use-after-free in iomap inline data write path. Red Hat rates this important (CVSS 7.8). Weakness: CWE-826. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:33743 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream E4S (v.9.4); Red Hat Enterprise Linux AppStream EUS (v.9.6); Red Hat Enterprise Linux AppStream (v. 9); Red Hat Enterprise Linux BaseOS (v. 8); and 22 more.
High [CVE-2026-46099] fix NOREF dst use in seg6 and rpl lwtunnels
fix NOREF dst use in seg6 and rpl lwtunnels. Red Hat rates this important (CVSS 7). Weakness: CWE-911. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
High [CVE-2026-45972] fix potential UAF and double free in smb2_open_file()
fix potential UAF and double free in smb2_open_file(). Red Hat rates this important (CVSS 7). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
High [CVE-2026-46090] Fix peer runtime UAF during format-change stop
Fix peer runtime UAF during format-change stop. Red Hat rates this important (CVSS 7). Weakness: CWE-364. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27354 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-46033] authencesn - reject short ahash digests during instance creation
authencesn - reject short ahash digests during instance creation. Red Hat rates this important (CVSS 7). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-45998] Fix potential UAF after skb_unshare() failure
Fix potential UAF after skb_unshare() failure. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:34911 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
High [CVE-2026-46054] fix overlayfs mmap() and mprotect() access checks
fix overlayfs mmap() and mprotect() access checks. Red Hat rates this important (CVSS 7). Weakness: CWE-280. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:30848 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-45898] Fix workqueue list corruption by removing work_list
Fix workqueue list corruption by removing work_list. Red Hat rates this important (CVSS 7). Weakness: CWE-1341. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:30129 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.
High [CVE-2026-45852] Fix double free in rxe_srq_from_init
Fix double free in rxe_srq_from_init. Red Hat rates this important (CVSS 7). Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 5 more.
High [CVE-2026-46056] fix potential UAF in SSP passkey handlers
fix potential UAF in SSP passkey handlers. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-413. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
Medium [CVE-2026-9704] Privilege escalation due to oversized subject_token JWT
Privilege escalation due to oversized subject_token JWT. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-1284. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-2340] vfs_worm does not block directory modification
vfs_worm does not block directory modification. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-280. Affected package(s): samba, rhcos. Resolved in Red Hat advisory RHSA-2026:29863 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-9980] Insufficient validation of untrusted input in Printing
Insufficient validation of untrusted input in Printing. Red Hat rates this important (CVSS 6.7). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9917] Uninitialized Use in WebGL
Uninitialized Use in WebGL. Red Hat rates this important (CVSS 6.5). Weakness: CWE-824. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-10004] Insufficient validation of untrusted input in Passwords
Insufficient validation of untrusted input in Passwords. Red Hat rates this important (CVSS 5.4). Weakness: CWE-1173. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-9959] Race in WebRTC
Race in WebRTC. Red Hat rates this important (CVSS 6.5). Weakness: CWE-366. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.