Red Hat Linux Security Advisories & CVEs
10918 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-95393] Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-95392] Buffer Over-read in Wireshark
Buffer Over-read in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-126. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-95388] Denial of Service via heap-based buffer overflow in sharkd
Denial of Service via heap-based buffer overflow in sharkd. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96422] Reachable Assertion in Wireshark
Reachable Assertion in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96421] Denial of Service via USB HID dissector infinite loop
Denial of Service via USB HID dissector infinite loop. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96417] Denial of Service via malformed RF4CE packet
Denial of Service via malformed RF4CE packet. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96418] Denial of Service via infinite loop in TIFF protocol dissector
Denial of Service via infinite loop in TIFF protocol dissector. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96419] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-22. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96420] Buffer Over-read in Wireshark
Buffer Over-read in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96423] Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96416] Denial of Service via malformed IEEE 802.11 packet processing
Denial of Service via malformed IEEE 802.11 packet processing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1286. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-96415] Stack-based Buffer Overflow in Wireshark
Stack-based Buffer Overflow in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-97029] Sandboxed app can signal unsandboxed processes in the same process group
Sandboxed app can signal unsandboxed processes in the same process group. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-653. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.
Medium [CVE-2026-102474] Heap out-of-bounds write in conv_escape via undersized Unicode escape reservation
Heap out-of-bounds write in conv_escape via undersized Unicode escape reservation. Red Hat rates this moderate (CVSS 4). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: dash.
Medium [CVE-2026-102473] Super-polynomial backtracking in pmatch when libc fnmatch is disabled
Super-polynomial backtracking in pmatch when libc fnmatch is disabled. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: dash.
Medium [CVE-2026-98164] Check write tracking in all address spaces
Check write tracking in all address spaces. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Low [CVE-2026-102621] Denial of Service via integer overflow in SplashClip
Denial of Service via integer overflow in SplashClip. Red Hat rates this low (CVSS 3.3). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:74469 with package poppler-main-26.08.0-1.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: poppler; Red Hat package: compat-poppler022.
Low [CVE-2026-102620] Data corruption via integer overflow in FoFiTrueType::cvtSfnts
Data corruption via integer overflow in FoFiTrueType::cvtSfnts. Red Hat rates this moderate (CVSS 3.3). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:74469 with package poppler-main-26.08.0-1.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: poppler; Red Hat package: compat-poppler022.
Low [CVE-2026-102330] Incorrect authorization in SiteIsolation
Incorrect authorization in SiteIsolation. Red Hat rates this low (CVSS 3.1). Weakness: CWE-346.
Low [CVE-2026-102825] Authentication attempt limit bypass via unenforced maximum authentication attempts
Authentication attempt limit bypass via unenforced maximum authentication attempts. Red Hat rates this low (CVSS 3.7). Weakness: CWE-307. Red Hat lists fixing advisory RHSA-2026:74586 with package openshell-main-0.1.2-0.2.hum1. Affected product named by the advisory: Red Hat Hardened Images.