Red Hat Linux Security Advisories & CVEs
5201 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-43051] fix out-of-bounds read in wacom_intuos_bt_irq
fix out-of-bounds read in wacom_intuos_bt_irq. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-125. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:21745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-43023] fix race conditions in sco_sock_connect()
fix race conditions in sco_sock_connect(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-821. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:21557 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-31772] fix stack buffer overflow in hci_le_big_create_sync
fix stack buffer overflow in hci_le_big_create_sync. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27288 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-37457] denial of service via crafted FlowSpec component
denial of service via crafted FlowSpec component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Affected package(s): frr, frr10. Resolved in Red Hat advisory RHSA-2026:24340 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-43037] clear skb2->cb[] in ip4ip6_err()
clear skb2->cb[] in ip4ip6_err(). Red Hat rates this critical (CVSS 8.8). Weakness: CWE-843. Affected package(s): kernel, rhcos, kernel-rt, kpatch-patch. Resolved in Red Hat advisory RHSA-2026:28741 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NVIDIA for RHEL 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; and 19 more.
High [CVE-2026-31703] Fix use after free in inode_switch_wbs_work_fn()
Fix use after free in inode_switch_wbs_work_fn(). Red Hat rates this important (CVSS 7). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-43038] clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
clear skb2->cb[] in ip6_err_gen_icmpv6_unreach(). Red Hat rates this important (CVSS 7.3). Weakness: CWE-843. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); Red Hat Enterprise Linux AppStream E4S (v.9.2); Red Hat Enterprise Linux AppStream E4S (v.9.4); and 44 more.
High [CVE-2026-31709] validate the whole DACL before rewriting it in cifsacl
validate the whole DACL before rewriting it in cifsacl. Red Hat rates this important (CVSS 7.8). Weakness: CWE-1288. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:21745 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; and 1 more.
Medium [CVE-2026-42404] Information disclosure and network access bypass via PolicyReference API
Information disclosure and network access bypass via PolicyReference API. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-918. Affected package(s): neethi. Resolved in Red Hat advisory RHSA-2026:19835 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-42402] Denial of Service via algorithmic complexity in policy normalization
Denial of Service via algorithmic complexity in policy normalization. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected package(s): neethi. Resolved in Red Hat advisory RHSA-2026:19835 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-42403] Denial of Service via circular policy references
Denial of Service via circular policy references. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Affected package(s): neethi. Resolved in Red Hat advisory RHSA-2026:19835 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-5403] Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-5656] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark. Red Hat rates this important (CVSS 7.8). Weakness: CWE-22. Affected package(s): wireshark. Resolved in Red Hat advisory RHSA-2026:20600 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support.
High [CVE-2026-5405] Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122. Affected package(s): wireshark. Resolved in Red Hat advisory RHSA-2026:20600 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support.
High [CVE-2026-40912] Authentication bypass via crafted URL dot-segments in StripPrefixRegex middleware
Authentication bypass via crafted URL dot-segments in StripPrefixRegex middleware. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. Affected package(s): devspaces/traefik-rhel9:1779786779. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.28.
High [CVE-2026-39858] Authentication bypass via unsanitized alias headers
Authentication bypass via unsanitized alias headers. Red Hat rates this important (CVSS 8.2). Weakness: CWE-289. Affected package(s): devspaces/traefik-rhel9:1779786779. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.28.
High [CVE-2026-35051] Authentication bypass in ForwardAuth middleware
Authentication bypass in ForwardAuth middleware. Red Hat rates this important (CVSS 8.2). Weakness: CWE-501. Affected package(s): devspaces/traefik-rhel9:1779786779. Resolved in Red Hat advisory RHSA-2026:21772 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat OpenShift Dev Spaces 3.28.
High [CVE-2026-33845] Denial of Service via DTLS zero-length fragment
Denial of Service via DTLS zero-length fragment. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Affected package(s): rhui5/installer-rhel9:1781525693, libtasn1, gnutls, rhui5/cds-rhel9:1781525684, discovery/discovery-ui-rhel9:1782166952, discovery/discovery-server-rhel9:1782159791. Resolved in Red Hat advisory RHSA-2026:29197 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 37 more.
High [CVE-2026-7246] Arbitrary command execution via command injection in click.edit()
Arbitrary command execution via command injection in click.edit(). Red Hat rates this important (CVSS 7.2). Weakness: CWE-78. Affected package(s): python3.12-click, python-click. Resolved in Red Hat advisory RHSA-2026:24761 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 10; Red Hat Ansible Automation Platform 2.6 for RHEL 9.
High [CVE-2025-14576] Arbitrary QML/JavaScript code injection via malicious SVG file
Arbitrary QML/JavaScript code injection via malicious SVG file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94. Affected package(s): qt6-main, qt6-qtdeclarative, qt5-main. Resolved in Red Hat advisory RHSA-2026:20567 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Hardened Images.