Red Hat Linux Security Advisories & CVEs
5196 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2026-33007] NULL pointer dereference can cause a child process crash
NULL pointer dereference can cause a child process crash. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-476. Affected package(s): httpd, mod_authn_socache.so, httpd:2.4, jbcs-httpd24-httpd, httpd-main. Resolved in Red Hat advisory RHSA-2026:27200 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.
Medium [CVE-2026-33523] HTTP response splitting forwarding malicious status line
HTTP response splitting forwarding malicious status line. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-93. Affected package(s): httpd-main. Resolved in Red Hat advisory RHSA-2026:17080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-24072] Privilege Escalation via .htaccess file manipulation
Privilege Escalation via.htaccess file manipulation. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-73. Affected package(s): httpd-main. Resolved in Red Hat advisory RHSA-2026:13938 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-43824] Information disclosure via ServerSideDiff allows reading Kubernetes Secret data
Information disclosure via ServerSideDiff allows reading Kubernetes Secret data. Red Hat rates this important (CVSS 9.6). Weakness: CWE-312. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift GitOps.
Critical [CVE-2026-7598] integer overflow via large username or password arguments
integer overflow via large username or password arguments. Red Hat rates this important (CVSS 9.1). Weakness: CWE-190. Affected package(s): libssh2-main, rust-main. Resolved in Red Hat advisory RHSA-2026:7021 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Trusted Profile Analyzer.
High [CVE-2026-39805] HTTP Request Smuggling via Duplicate Content-Length Headers
HTTP Request Smuggling via Duplicate Content-Length Headers. Red Hat rates this important (CVSS 7.4). Weakness: CWE-444. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-39804] Denial of Service due to memory exhaustion via WebSocket permessage-deflate compression
Denial of Service due to memory exhaustion via WebSocket permessage-deflate compression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-42786] Denial of Service via uncontrolled memory growth in WebSocket connections
Denial of Service via uncontrolled memory growth in WebSocket connections. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-42788] Denial of Service via oversized HTTP/2 frames
Denial of Service via oversized HTTP/2 frames. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-43001] Unauthorized cross-project access due to improper validation in EC2 credential creation
Unauthorized cross-project access due to improper validation in EC2 credential creation. Red Hat rates this important (CVSS 8). Weakness: CWE-1288. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
High [CVE-2026-43003] OpenStack ironic-python-agent: Arbitrary code execution via malicious image
OpenStack ironic-python-agent: Arbitrary code execution via malicious image. Red Hat rates this important (CVSS 8.5). Weakness: CWE-78. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-43027] pass helper to expect cleanup
pass helper to expect cleanup. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-459. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:34094 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-43006] reject zero-length fixed buffer import
reject zero-length fixed buffer import. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-805. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:21557 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-43056] fix use-after-free in add_adev() error path
fix use-after-free in add_adev() error path. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-43020] validate LTK enc_size on load
validate LTK enc_size on load. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-120. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:21745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-43051] fix out-of-bounds read in wacom_intuos_bt_irq
fix out-of-bounds read in wacom_intuos_bt_irq. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-125. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:21745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-43023] fix race conditions in sco_sock_connect()
fix race conditions in sco_sock_connect(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-821. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:21557 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-31772] fix stack buffer overflow in hci_le_big_create_sync
fix stack buffer overflow in hci_le_big_create_sync. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-37457] denial of service via crafted FlowSpec component
denial of service via crafted FlowSpec component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): frr, frr10. Resolved in Red Hat advisory RHSA-2026:24340 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-43037] clear skb2->cb[] in ip4ip6_err()
clear skb2->cb[] in ip4ip6_err(). Red Hat rates this critical (CVSS 8.8). Weakness: CWE-843. Affected package(s): kernel, rhcos, kernel-rt, kpatch-patch. Resolved in Red Hat advisory RHSA-2026:28741 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NVIDIA for RHEL 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; and 19 more.