Red Hat Linux Security Advisories & CVEs
2989 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-74960] Site isolation issue in the WebExtensions component
Site isolation issue in the WebExtensions component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.
Medium [CVE-2026-74959] Mitigation bypass in the Storage: Cache API component
Mitigation bypass in the Storage: Cache API component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-807. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: thunderbird.
Medium [CVE-2026-74962] Site isolation issue in the Networking: Cookies component
Site isolation issue in the Networking: Cookies component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-1100. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.
Medium [CVE-2026-74953] Privilege escalation in the Networking: Cookies component
Privilege escalation in the Networking: Cookies component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-472. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: firefox; Red Hat package: thunderbird.
Medium [CVE-2026-19608] Name-only group claims let same-name groups satisfy path-specific group policies
Name-only group claims let same-name groups satisfy path-specific group policies. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-285. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-61308] Enhance HTTP Connections (2026-08 Security Update)
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N). Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N). Affected products named by the advisory: Red Hat Build of OpenJDK 17.0.20.1; Red Hat Build of OpenJDK 21.0.12.1; Red Hat Build of OpenJDK 25.0.4.1; Red Hat Build of OpenJDK 8u504; and 18 more.
Medium [CVE-2026-70907] Enhance TLS server (2026-08 Security Update)
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Affected Red Hat products: Red Hat Build of OpenJDK 17.0.20.1; Red Hat Build of OpenJDK 21.0.12.1; Red Hat Build of OpenJDK 25.0.4.1; Red Hat Build of OpenJDK 8u504; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.6 Extended Update Support; Red Hat OpenJDK 11 els for RHEL 7; Red Hat OpenJDK 11 els for RHEL 8; Red Hat OpenJDK 11 els for RHEL 9; Red Hat Hardened Images; Exploit Intelligence; Red Hat build of OpenJDK 11 ELS; Red Hat build of OpenJDK 25; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.
Medium [CVE-2026-19999] Remote buffer overflow allows information disclosure or denial of service
Remote buffer overflow allows information disclosure or denial of service. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-120.
Medium [CVE-2026-19970] Remote heap-based buffer overflow vulnerability
Remote heap-based buffer overflow vulnerability. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.
Medium [CVE-2026-19969] Buffer overflow in 3DGS MDL7 model processing
Buffer overflow in 3DGS MDL7 model processing. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.
Medium [CVE-2026-19968] Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser
Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.
Medium [CVE-2026-19967] Heap-based buffer overflow in file decompression
Heap-based buffer overflow in file decompression. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.
Medium [CVE-2026-74579] fix mask build for partial field offload
fix mask build for partial field offload. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1335. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74796] Arbitrary file write via symlink following path traversal
Arbitrary file write via symlink following path traversal. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-59.
Medium [CVE-2024-58375] Sensitive information disclosure via static evaluation
Sensitive information disclosure via static evaluation. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-497.
Medium [CVE-2026-74578] algif_skcipher - force synchronous processing on trees without ctx->state
algif_skcipher - force synchronous processing on trees without ctx->state. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1204. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-72428] Fix stack slot index in nospec checks
Fix stack slot index in nospec checks. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-72245] Fix device reference leak in host1x_device_parse_dt error path
Fix device reference leak in host1x_device_parse_dt() error path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-72403] Fix NULL pointer dereference in interface lookup
Fix NULL pointer dereference in interface lookup. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-72190] fix mrec_lock ABBA deadlock in rename
fix mrec_lock ABBA deadlock in rename. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.