Red Hat Linux Security Advisories & CVEs
5196 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-7916] Insufficient data validation in InterestGroups
Insufficient data validation in InterestGroups. Red Hat rates this important (CVSS 8.2). Weakness: CWE-501. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-7919] Use after free in Aura
Use after free in Aura. Red Hat rates this important (CVSS 8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-7925] Use after free in Chromoting
Use after free in Chromoting. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-7912] Integer overflow in GPU
Integer overflow in GPU. Red Hat rates this important (CVSS 8). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-7927] Type Confusion in Runtime
Type Confusion in Runtime. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34002] X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling
X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-805. Affected package(s): tigervnc, xorg-x11-server-Xwayland, xorg-x11-server. Resolved in Red Hat advisory RHSA-2026:24341 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 1; and 1 more.
Medium [CVE-2026-34000] X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.
X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing.. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected package(s): tigervnc, xorg-x11-server-Xwayland, xorg-x11-server. Resolved in Red Hat advisory RHSA-2026:24341 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 6; and 1 more.
Medium [CVE-2026-7915] Insufficient data validation in DevTools
Insufficient data validation in DevTools. Red Hat rates this important (CVSS 4.3). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-7909] Inappropriate implementation in ServiceWorker
Inappropriate implementation in ServiceWorker. Red Hat rates this important (CVSS 6.8). Weakness: CWE-807. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-7904] Out of bounds read in Fonts
Out of bounds read in Fonts. Red Hat rates this important (CVSS 6.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-26332] Arbitrary code execution via SuppressedError sandbox escape
Arbitrary code execution via SuppressedError sandbox escape. Red Hat rates this important (CVSS 9.1). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-24120] Arbitrary code execution due to sandbox escape vulnerability
Arbitrary code execution due to sandbox escape vulnerability. Red Hat rates this important (CVSS 9.1). Weakness: CWE-807. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-24118] Arbitrary code execution due to sandbox breakout
Arbitrary code execution due to sandbox breakout. Red Hat rates this important (CVSS 9.1). Weakness: CWE-749. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-7482] Information disclosure via heap out-of-bounds read in GGUF model loader
Information disclosure via heap out-of-bounds read in GGUF model loader. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6321] Path traversal vulnerability allows bypass of security policies
Path traversal vulnerability allows bypass of security policies. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected package(s): odf4/odf-multicluster-rhel9-operator:1778577548, network-observability/network-observability-console-plugin-rhel9:1780556069, cluster-observability-operator/troubleshooting-panel-console-plugin-pf6-rhel9:1782839996, cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9:1782840519, odf4/odf-cli-rhel9:1781557189, satellite/iop-advisor-frontend-rhel9:1781181673. Resolved in Red Hat advisory RHSA-2026:25089 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9; Red Hat Discovery 2; and 15 more.
High [CVE-2026-42154] Denial of Service via uncontrolled memory allocation in remote read endpoint
Denial of Service via uncontrolled memory allocation in remote read endpoint. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): opentelemetry-collector, jaeger-main, rhacm2/prometheus-rhel9:1782374537, opentelemetry-collector-main, openshift-logging/logging-loki-rhel9:1782405469, opentelemetry-collector-contrib-main. Resolved in Red Hat advisory RHSA-2026:29770 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: RHEM 1.0 for RHEL 9; Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 9); Logging Subsystem for Red Hat OpenShift 6.4; and 31 more.
High [CVE-2026-42151] Information disclosure of Azure OAuth client secret via config API
Information disclosure of Azure OAuth client secret via config API. Red Hat rates this important (CVSS 7.5). Weakness: CWE-256. Affected package(s): opentelemetry-collector, opentelemetry-collector-contrib-main, jaeger-main, opentelemetry-collector-main. Resolved in Red Hat advisory RHSA-2026:25504 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: RHEM 1.0 for RHEL 9; Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream (v. 9); Red Hat Edge Manager 1.0; and 30 more.
High [CVE-2026-43964] buffer over-read via malformed enhanced status code
buffer over-read via malformed enhanced status code. Red Hat rates this important (CVSS 7.5). Weakness: CWE-193. Affected package(s): postfix. Resolved in Red Hat advisory RHSA-2026:25932 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-29004] Arbitrary Code Execution via DHCPv6 Client Heap Buffer Overflow
Arbitrary Code Execution via DHCPv6 Client Heap Buffer Overflow. Red Hat rates this important (CVSS 8.8). Weakness: CWE-131. Affected package(s): busybox-main. Resolved in Red Hat advisory RHSA-2026:30652 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-40682] XML External Entity (XXE) vulnerability via crafted dictionary parsing
XML External Entity (XXE) vulnerability via crafted dictionary parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-611. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.