Red Hat Linux Security Advisories & CVEs
5207 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-5598] private key leakage via non-constant time comparisons
private key leakage via non-constant time comparisons. Red Hat rates this important (CVSS 7.5). Weakness: CWE-385. Affected package(s): eap8-bouncycastle, bcprov-jdk12, eap7-bouncycastle. Resolved in Red Hat advisory RHSA-2026:18054 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; and 2 more.
High [CVE-2025-14813] GOSTCTR implementation unable to process more than 255 blocks correctly
GOSTCTR implementation unable to process more than 255 blocks correctly. Red Hat rates this important (CVSS 7.5). Weakness: CWE-327. Affected package(s): bcprov-jdk15to18, eap8-bouncycastle, devspaces/openvsx-rhel9:1779528224, bcprov-ext-jdk15on, bcprov-ext-jdk18on, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:14276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat OpenShift AI 2.25; and 14 more.
High [CVE-2026-33806] Schema validation bypass via malformed Content-Type header
Schema validation bypass via malformed Content-Type header. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1289. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6358] Use after free in XR
Use after free in XR. Red Hat rates this important (CVSS 8.8). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6300] Use after free in CSS
Use after free in CSS. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6314] Out of bounds write in GPU
Out of bounds write in GPU. Red Hat rates this important (CVSS 8). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6302] Use after free in Video
Use after free in Video. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6297] Use after free in Proxy
Use after free in Proxy. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6298] Heap buffer overflow in Skia
Heap buffer overflow in Skia. Red Hat rates this important (CVSS 7.4). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6307] Type Confusion in Turbofan
Type Confusion in Turbofan. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6361] Heap buffer overflow in PDFium
Heap buffer overflow in PDFium. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-6859] Arbitrary code execution due to hardcoded `trust_remote_code=True`
Arbitrary code execution due to hardcoded `trust_remote_code=True`. Red Hat rates this important (CVSS 8.8). Weakness: CWE-829. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
Medium [CVE-2026-4630] Unauthorized resource access and data modification via Insecure Direct Object Reference
Unauthorized resource access and data modification via Insecure Direct Object Reference. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-639. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:19596 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-5135] Unauthorized modification of host configurations via broken access control
Unauthorized modification of host configurations via broken access control. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-639. Affected package(s): foreman. Resolved in Red Hat advisory RHSA-2026:34366 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2026-0636] LDAP injection vulnerability in LDAPStoreHelper.java
LDAP injection vulnerability in LDAPStoreHelper.java. Red Hat rates this important (CVSS 6.5). Weakness: CWE-90. Affected package(s): bcprov-jdk15to18, eap8-bouncycastle, devspaces/openvsx-rhel9:1779528224, bcprov-ext-jdk15on, bcprov-ext-jdk18on, devspaces/pluginregistry-rhel9:1779359423. Resolved in Red Hat advisory RHSA-2026:14276 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat OpenShift Dev Spaces 3.28; and 11 more.
Medium [CVE-2026-6313] Insufficient policy enforcement in CORS
Insufficient policy enforcement in CORS. Red Hat rates this important (CVSS 6.8). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-6312] Insufficient policy enforcement in Passwords
Insufficient policy enforcement in Passwords. Red Hat rates this important (CVSS 6.8). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-33414] Arbitrary code execution via command injection in HyperV backend
Arbitrary code execution via command injection in HyperV backend. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): podman-main. Resolved in Red Hat advisory RHSA-2026:8211 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Hardened Images.
High [CVE-2026-33023] Code execution via crafted image due to use-after-free vulnerability
Code execution via crafted image due to use-after-free vulnerability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-32178] SMTP Command Injection and Header Injection via MailAddress parsing flaw
SMTP Command Injection and Header Injection via MailAddress parsing flaw. Red Hat rates this important (CVSS 7.5). Weakness: CWE-138. Affected package(s): dotnet8.0, dotnet10.0, dotnet8, dotnet9.0, dotnet9, dotnet10. Resolved in Red Hat advisory RHSA-2026:9080 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support; and 1 more.