Red Hat Linux Security Advisories & CVEs
5200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-42296] Privilege escalation via security control bypass
Privilege escalation via security control bypass. Red Hat rates this important (CVSS 8.1). Weakness: CWE-863. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-42294] Denial of Service via large request body to Webhook Interceptor
Denial of Service via large request body to Webhook Interceptor. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-42297] Unauthorized ConfigMap manipulation due to missing authorization
Unauthorized ConfigMap manipulation due to missing authorization. Red Hat rates this important (CVSS 8.3). Weakness: CWE-425. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-4890] NSEC bitmap parsing infinite loop
NSEC bitmap parsing infinite loop. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenShift Container Platform 4.19.
High [CVE-2026-4891] RRSIG rdlen underflow leading to heap OOB read
RRSIG rdlen underflow leading to heap OOB read. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; and 2 more.
High [CVE-2026-4892] DHCPv6 CLID buffer overflow in helper process
DHCPv6 CLID buffer overflow in helper process. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat Enterprise Linux 6; and 2 more.
High [CVE-2026-5172] extract_addresses() OOB read via malformed rdlen
extract_addresses() OOB read via malformed rdlen. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:19158 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-42256] Net::IMAP: Denial of Service via large iteration count in SCRAM authentication
Net::IMAP: Denial of Service via large iteration count in SCRAM authentication. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected package(s): ruby3, ruby4. Resolved in Red Hat advisory RHSA-2026:33552 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-42245] Net::IMAP: Denial of Service via crafted IMAP responses
Net::IMAP: Denial of Service via crafted IMAP responses. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected package(s): ruby3, ruby:3.3, ruby4, ruby4.0, ruby, ruby:4.0. Resolved in Red Hat advisory RHSA-2026:33515 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-42310] Denial of Service via malicious PDF processing
Denial of Service via malicious PDF processing. Red Hat rates this moderate (CVSS 4). Weakness: CWE-835. Affected package(s): rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1778274666, rhaiis/model-opt-cuda-rhel9:1778244559. Resolved in Red Hat advisory RHSA-2026:16030 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-42309] Denial of Service via specially crafted coordinate input
Denial of Service via specially crafted coordinate input. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-131. Affected package(s): rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1778274666, rhaiis/model-opt-cuda-rhel9:1778244559. Resolved in Red Hat advisory RHSA-2026:16030 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-2291] heap buffer overflow in cache via NAME_ESCAPE expansion
heap buffer overflow in cache via NAME_ESCAPE expansion. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-131. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.
Medium [CVE-2026-4893] Broken ECS source validation bypass
Broken ECS source validation bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-20. Affected package(s): dnsmasq. Resolved in Red Hat advisory RHSA-2026:20589 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.
High [CVE-2026-42203] Arbitrary code execution via unsandboxed prompt templates
Arbitrary code execution via unsandboxed prompt templates. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.
High [CVE-2026-42271] Authenticated command execution via MCP stdio test endpoints
Authenticated command execution via MCP stdio test endpoints. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1781826406, rhoai/odh-llama-stack-core-rhel9:1782310008, rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9:1781622627. Resolved in Red Hat advisory RHSA-2026:28960 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
High [CVE-2026-42264] Prototype pollution allows information disclosure and request manipulation
Prototype pollution allows information disclosure and request manipulation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-915. Affected package(s): openshift-service-mesh/kiali-ossmc-rhel9:1782201851, advanced-cluster-security/rhacs-main-rhel8:1779371594, advanced-cluster-security/rhacs-main-rhel8:1779293013, openshift-service-mesh/kiali-rhel9:1782201812. Resolved in Red Hat advisory RHSA-2026:20889 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.11; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat OpenShift Service Mesh 3.1; and 24 more.
High [CVE-2026-43330] caam - fix overflow on long hmac keys
caam - fix overflow on long hmac keys. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-125. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-43303] clear page->private in free_pages_prepare()
clear page->private in free_pages_prepare(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-909. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:26462 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-43329] strictly check for maximum number of actions
strictly check for maximum number of actions. Red Hat rates this important (CVSS 7.8). Weakness: CWE-770. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:34094 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; and 11 more.
High [CVE-2026-43322] Fix UAF in le_read_features_complete
Fix UAF in le_read_features_complete. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:23329 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.