Red Hat Linux Security Advisories & CVEs
5200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2026-43895] embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-20. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-43894] Arbitrary Code Execution or Denial of Service via Signed Integer Overflow
Arbitrary Code Execution or Denial of Service via Signed Integer Overflow. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-190. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-41256] embedded NUL truncates top-level jq programs loaded with -f
embedded NUL truncates top-level jq programs loaded with -f. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-158. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-40612] stack overflow via unbounded recursion in jv_contains
stack overflow via unbounded recursion in jv_contains. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-674. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-41257] signed-int overflow in stack_reallocate
signed-int overflow in stack_reallocate. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190. Affected package(s): jq-main. Resolved in Red Hat advisory RHSA-2026:29986 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-8177] XML::LibXML: Denial of Service via truncated UTF-8 in XML node names
XML::LibXML: Denial of Service via truncated UTF-8 in XML node names. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-45186] denial of service via crafted XML input
denial of service via crafted XML input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-407. Affected package(s): expat, rhui5/haproxy-rhel9:1781525671, rhui5/installer-rhel9:1781525693, rhui5/cds-rhel9:1781525684, libexpat, discovery/discovery-ui-rhel9:1782166952. Resolved in Red Hat advisory RHSA-2026:22715 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 9); Red Hat Enterprise Linux BaseOS (v. 10); Red Hat Enterprise Linux BaseOS (v. 8); and 9 more.
High [CVE-2026-7263] denial of service via DOMNode::C14N()
denial of service via DOMNode::C14N(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): php8.4. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-6104] global buffer over-read in mb_convert_encoding() with attacker-supplied encoding
global buffer over-read in mb_convert_encoding() with attacker-supplied encoding. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected package(s): php8.4. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-6722] PHP SOAP extension: Remote Code Execution via use-after-free vulnerability
PHP SOAP extension: Remote Code Execution via use-after-free vulnerability. Red Hat rates this important (CVSS 7.7). Weakness: CWE-825. Affected package(s): php, php:7.4. Resolved in Red Hat advisory RHSA-2026:33449 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7.
High [CVE-2026-7262] NULL pointer dereference in SOAP apache:Map decoder with missing <value>
NULL pointer dereference in SOAP apache:Map decoder with missing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Affected package(s): php, php8.4, php:8.2, php:7.4, php:8.3. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2025-14179] SQL injection in pdo_firebird via NUL bytes in quoted strings
SQL injection in pdo_firebird via NUL bytes in quoted strings. Red Hat rates this important (CVSS 8.1). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-7568] signed integer overflow in metaphone()
signed integer overflow in metaphone(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Affected package(s): php, php8.4, php:8.2, php:7.4, php:8.3. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-7258] Denial of Service via improper handling of signed characters in ctype functions
Denial of Service via improper handling of signed characters in ctype functions. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-839. Affected package(s): php, php8.4, php:8.2, php:7.4, php:8.3, php-main. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-7259] NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()
NULL pointer dereference in php_mb_check_encoding() via mb_ereg_search_init(). Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476. Affected package(s): php. Resolved in Red Hat advisory RHSA-2026:33449 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-7261] Memory corruption and information disclosure via incorrect persistence handling
Memory corruption and information disclosure via incorrect persistence handling. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-825. Affected package(s): php, php:7.4. Resolved in Red Hat advisory RHSA-2026:33449 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.
Medium [CVE-2026-6735] Cross-Site Scripting vulnerability via improper URL sanitation
Cross-Site Scripting vulnerability via improper URL sanitation. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected package(s): php, php8.4, php:8.2, php:7.4, php:8.3, php-main. Resolved in Red Hat advisory RHSA-2026:22649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-42258] Net::IMAP: IMAP Command Injection via Symbol Arguments
Net::IMAP: IMAP Command Injection via Symbol Arguments. Red Hat rates this important (CVSS 7.1). Weakness: CWE-93. Affected package(s): ruby, ruby4.0, ruby:3.3, ruby:2.5, ruby:4.0. Resolved in Red Hat advisory RHSA-2026:33514 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.
High [CVE-2026-42246] Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS
Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS. Red Hat rates this important (CVSS 7.4). Weakness: CWE-325. Affected package(s): ruby, ruby4, ruby4.0, ruby:3.3, ruby3, ruby:2.5. Resolved in Red Hat advisory RHSA-2026:33514 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 9 more.
High [CVE-2026-41163] Privilege escalation via ptrace when installed in setuid mode
Privilege escalation via ptrace when installed in setuid mode. Red Hat rates this important (CVSS 7). Weakness: CWE-269. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.