Red Hat Linux Security Advisories & CVEs
5208 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-32741] Heap buffer overflow vulnerability in image decoding
Heap buffer overflow vulnerability in image decoding. Red Hat rates this important (CVSS 7.1). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-32740] Arbitrary code execution or denial of service via crafted HEIF/AVIF file
Arbitrary code execution or denial of service via crafted HEIF/AVIF file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8975] Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151
Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-8973] Memory safety bugs fixed in Firefox 151
Memory safety bugs fixed in Firefox 151. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8948] Same-origin policy bypass in the DOM: Networking component
Same-origin policy bypass in the DOM: Networking component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8947] Use-after-free in the DOM: Bindings (WebIDL) component
Use-after-free in the DOM: Bindings (WebIDL) component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-8946] Incorrect boundary conditions in the Audio/Video: Web Codecs component
Incorrect boundary conditions in the Audio/Video: Web Codecs component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 7 more.
High [CVE-2026-8945] Sandbox escape in Firefox and Firefox Focus for Android
Sandbox escape in Firefox and Firefox Focus for Android. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-7504] Open redirect when using wildcard valid redirect URIs in Keycloak
Open redirect when using wildcard valid redirect URIs in Keycloak. Red Hat rates this important (CVSS 8.1). Weakness: CWE-601. Affected package(s): rhbk/keycloak-rhel9-operator, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-operator-bundle:26.2.16, rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9:26.2. Resolved in Red Hat advisory RHSA-2026:19594 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2.16; Red Hat build of Keycloak 26.4.12.
High [CVE-2026-7507] Session fixation in OIDC login flow that can lead to account takeover
Session fixation in OIDC login flow that can lead to account takeover. Red Hat rates this important (CVSS 7.5). Weakness: CWE-290. Affected package(s): rhbk/keycloak-rhel9-operator, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-operator-bundle:26.2.16, rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9:26.2. Resolved in Red Hat advisory RHSA-2026:19594 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2.16; Red Hat build of Keycloak 26.4.12.
High [CVE-2026-7571] Access token disclosure and implicit flow bypass via forged client data
Access token disclosure and implicit flow bypass via forged client data. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-472. Affected package(s): rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-rhel9-operator, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:19596 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-7307] Denial of Service via specially crafted SAML input
Denial of Service via specially crafted SAML input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-operator-bundle:26.2.16, rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9:26.2. Resolved in Red Hat advisory RHSA-2026:19594 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.
High [CVE-2025-51427] Arbitrary code execution via crafted configuration module
Arbitrary code execution via crafted configuration module. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-31072] Remote Code Execution via Insecure Deserialization
Remote Code Execution via Insecure Deserialization. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-9116] Insufficient policy enforcement in ServiceWorker
Insufficient policy enforcement in ServiceWorker. Red Hat rates this important (CVSS 7.4). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-9117] Type Confusion in GFX
Type Confusion in GFX. Red Hat rates this important (CVSS 8.2). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-9112] Use after free in GPU
Use after free in GPU. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-9800] Authorization bypass via incorrect URI comparison
Authorization bypass via incorrect URI comparison. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1025. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.6, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.4. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6; Red Hat JBoss Enterprise Application Platform Expansion Pack.
High [CVE-2026-46323] Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs
Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs. Red Hat rates this important (CVSS 7.8). Weakness: CWE-123. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27708 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux for NVIDIA 26; and 4 more.
Medium [CVE-2026-9799] Unauthorized access to resources via UMA permission ticket bypass
Unauthorized access to resources via UMA permission ticket bypass. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-639. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.6, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.4. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.