Red Hat Linux Security Advisories & CVEs
414 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Critical [CVE-2025-15467] Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing
Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing. Red Hat rates this important (CVSS 9.8). Weakness: CWE-120. Affected package(s): service-interconnect/skupper-operator-bundle:1.8.8, devspaces/dashboard-rhel9:1770764461, devspaces/pluginregistry-rhel9:1770918006, service-interconnect/skupper-controller-podman-container-rhel9:1.8.8, rhui5/rhua-rhel9:1773670137, openssl. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; and 32 more.
Critical [CVE-2026-24480] QGIS GitHub Actions workflow: Remote Code Execution and repository compromise via insecure `pull_request_target` configuration
QGIS GitHub Actions workflow: Remote Code Execution and repository compromise via insecure `pull_request_target` configuration. Red Hat rates this important (CVSS 9.9). Weakness: CWE-863. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-20912] Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure
Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-283. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-20897] Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR)
Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR). Red Hat rates this critical (CVSS 9.1). Weakness: CWE-639. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-20750] Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR)
Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR). Red Hat rates this critical (CVSS 9.1). Weakness: CWE-284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-24046] possible symlink path traversal in scaffolder actions
possible symlink path traversal in scaffolder actions. Red Hat rates this important (CVSS 9.1). Weakness: CWE-59. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9.
Critical [CVE-2026-22797] OpenStack keystonemiddleware: Privilege escalation and user impersonation via forged authentication headers
OpenStack keystonemiddleware: Privilege escalation and user impersonation via forged authentication headers. Red Hat rates this important (CVSS 9.9). Weakness: CWE-290. Affected package(s): openshift4/ose-ironic-rhel9:1772029626, openshift4/ose-ironic-rhel9:1774266098, openshift4/ose-ironic-rhel9:1773138063, openshift4/ose-ironic-rhel9:1772477045, openshift4/ose-ironic-rhel9:1772176749. Resolved in Red Hat advisory RHSA-2026:3402 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4.19; Red Hat OpenShift Container Platform 4.20; and 1 more.
Critical [CVE-2025-70968] Arbitrary code execution via Use After Free in PluginTARGA.cpp;loadRLE()
Arbitrary code execution via Use After Free in PluginTARGA.cpp;loadRLE(). Red Hat rates this important (CVSS 9.8). Weakness: CWE-416. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2025-61686] React Router has Path Traversal in File Session Storage
React Router has Path Traversal in File Session Storage. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2025-70974] Remote Code Execution via JNDI Injection due to autoType mishandling
Remote Code Execution via JNDI Injection due to autoType mishandling. Red Hat rates this critical (CVSS 10). Weakness: CWE-829. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2025-12543] Undertow HTTP Server Fails to Reject Malformed Host Headers Leading to Potential Cache Poisoning and SSRF
Undertow HTTP Server Fails to Reject Malformed Host Headers Leading to Potential Cache Poisoning and SSRF. Red Hat rates this important (CVSS 9.6). Weakness: CWE-20. Affected package(s): eap8-wildfly, eap8-undertow, eap8-apache-cxf, eap8-wildfly-clustering, eap8-bouncycastle, eap7-undertow. Resolved in Red Hat advisory RHSA-2026:3889 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; and 11 more.
Critical [CVE-2025-10230] Samba: command injection in wins server hook script
A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process. On Red Hat Enterprise Linux (RHEL) versions 6, 7, 8, 9 and 10, the Samba packages as shipped are not affected by this vulnerability. This is because Red Hat does not provide Active Directory Domain Controller (AD DC) functionality in its Samba packages, and the vulnerable wins hook execution path exists only when Samba is configured as a domain controller with WINS support enabled. As a result, the Samba deployments on RHEL cannot be exploited via this issue. This vulnerability is considered Critical rather than Important because it enables unauthenticated remote code execution (RCE) on a Samba Active Directory Domain Controller through a trivially reachable network service. This means an attacker can inject arbitrary shell metacharacters and run commands with the privileges of the Samba process—often root on a DC.
Critical [CVE-2025-49794] heap use after free (uaf) leads to denial of service (dos)
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 25 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; and 22 more.
Critical [CVE-2025-49796] type confusion leads to denial of service (dos)
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 26 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; and 23 more.