Red Hat Linux Security Advisories & CVEs
5506 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2026-68562] Information disclosure via Leapp report tampering
Information disclosure via Leapp report tampering. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-610.
Medium [CVE-2026-67550] Denial of Service via out-of-bounds read
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an out-of-bounds heap read and an uncatchable process crash, with limited heap information disclosure in some cases. This issue is fixed in 1.25.2. An attacker can exploit a vulnerability by manipulating the `lastIndex` parameter with a non-ASCII input. This manipulation can lead to an out-of-bounds heap read, causing the process to crash, which results in a Denial of Service (DoS). This flaw primarily impacts Availability with low Confidentiality impact and zero effect on Integrity (C:L, I:N, A:H). Practically, this leads to an uncatchable process crash (Denial of Service) via an out-of-bounds heap read, though minor heap memory exposure is theoretically possible. High Attack Complexity (AC:H) is assessed because the targeted Node.js application must explicitly maintain and expose stateful regex objects with attacker-controlled `lastIndex` properties across non-ASCII strings. Applications using stateless regex execution or not accepting external input into `lastIndex` are unaffected.
Medium [CVE-2026-12996] Denial of Service or memory leak via crafted packets
Denial of Service or memory leak via crafted packets. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-825.
Medium [CVE-2026-11771] Denial of Service via crafted NTLM proxy response
Denial of Service via crafted NTLM proxy response. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-787.
Medium [CVE-2026-13117] Denial of service or memory leakage via incomplete TLS guard
Denial of service or memory leakage via incomplete TLS guard. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-825.
Medium [CVE-2026-7260] Denial of Service via circular symbolic links in phar archives
Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9. A flaw was found in PHP. When processing a specially crafted PHP Archive (phar) file containing circular symbolic links, the PHP process can enter an uncontrolled loop. This unbounded recursion exhausts the program's memory stack, causing the PHP application to crash. This vulnerability could allow an attacker to trigger a Denial of Service (DoS) condition, making the affected PHP service unavailable. This Moderate impact flaw in PHP allows a local attacker to trigger a denial of service by providing a specially crafted phar archive containing circular symbolic links. Successful exploitation exhausts the C stack, leading to a PHP process crash, which can disrupt services utilizing PHP for archive processing. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-606. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces. Red Hat fixing advisory: RHSA-2026:47200.
Medium [CVE-2026-18369] ACME HTTP-01 validation SSRF via IP literal identifiers and unvalidated redirects
ACME HTTP-01 validation SSRF via IP literal identifiers and unvalidated redirects. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-918.
Medium [CVE-2026-56850] mTLS client identities can be reused due to HTTPS Agent connection flaw
mTLS client identities can be reused due to HTTPS Agent connection flaw. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.
Medium [CVE-2026-58040] HTTPS Agent TLS session reuse skips hostname verification
An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. A flaw was found in Node.js. An incomplete fix for a previous vulnerability allows the HTTPS Agent to reuse Transport Layer Security (TLS) sessions, bypassing hostname verification across different identity policies. This could enable an attacker to impersonate a legitimate server, leading to information disclosure or other security breaches. This issue is rated Moderate (CVSS 6.3) because successful exploitation allows session-hijacking and information disclosure without affecting system integrity or availability (C:H, I:N, A:N). The flaw occurs when an HTTPS Agent reuses an existing TLS session across requests with differing identity policies, skipping host verification. An attacker must already sit in a privileged network position (AV:N/AC:H) to perform a man-in-the-middle attack and intercept traffic intended for a distinct target on the same TLS session. Applications that explicitly configure unique HTTPS agents per target host, avoid TLS session caching, or do not make outbound HTTPS requests to varied third-party endpoints using shared client instances are not at risk.
Medium [CVE-2026-16531] Arbitrary file creation via path traversal in pmproxy logger servlet
Arbitrary file creation via path traversal in pmproxy logger servlet. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-22.
Medium [CVE-2026-16530] Remote denial of service and information leakage
Remote denial of service and information leakage. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125.
Medium [CVE-2026-18019] Side-channel information leakage in Media
Side-channel information leakage in Media. Red Hat rates this low (CVSS 4.3). Weakness: CWE-205.
Medium [CVE-2026-18015] Inappropriate implementation in Tint
Inappropriate implementation in Tint. Red Hat rates this low (CVSS 4.3). Weakness: CWE-653.
Medium [CVE-2026-18017] Use after free in Dawn
Use after free in Dawn. Red Hat rates this low (CVSS 4.3).
Medium [CVE-2026-18012] Use after free in PDFium
Use after free in PDFium. Red Hat rates this low (CVSS 4.3). Weakness: CWE-825.
Medium [CVE-2026-18008] Inappropriate implementation in Settings
Inappropriate implementation in Settings. Red Hat rates this low (CVSS 4.3). Weakness: CWE-1021.
Medium [CVE-2026-18009] Insufficient validation of untrusted input in Passwords
Insufficient validation of untrusted input in Passwords. Red Hat rates this low (CVSS 4.3). Weakness: CWE-290.
Medium [CVE-2026-18005] Inappropriate implementation in WebXR
Inappropriate implementation in WebXR. Red Hat rates this low (CVSS 4.3). Weakness: CWE-825.
Medium [CVE-2026-18002] Insufficient validation of untrusted input in Google Lens
Insufficient validation of untrusted input in Google Lens. Red Hat rates this low (CVSS 5). Weakness: CWE-1289.
Medium [CVE-2026-17999] Incorrect security UI in PictureInPicture
Incorrect security UI in PictureInPicture. Red Hat rates this low (CVSS 4.3). Weakness: CWE-368.