Red Hat Linux Security Advisories & CVEs
432 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Critical [CVE-2026-20750] Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR)
Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR). Red Hat rates this critical (CVSS 9.1). Weakness: CWE-284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-24046] possible symlink path traversal in scaffolder actions
possible symlink path traversal in scaffolder actions. Red Hat rates this important (CVSS 9.1). Weakness: CWE-59. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6174 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Developer Hub 1.8; Red Hat Developer Hub 1.9.
Critical [CVE-2026-22797] OpenStack keystonemiddleware: Privilege escalation and user impersonation via forged authentication headers
OpenStack keystonemiddleware: Privilege escalation and user impersonation via forged authentication headers. Red Hat rates this important (CVSS 9.9). Weakness: CWE-290. Affected package(s): openshift4/ose-ironic-rhel9:1772029626, openshift4/ose-ironic-rhel9:1774266098, openshift4/ose-ironic-rhel9:1773138063, openshift4/ose-ironic-rhel9:1772477045, openshift4/ose-ironic-rhel9:1772176749. Resolved in Red Hat advisory RHSA-2026:3402 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4.19; Red Hat OpenShift Container Platform 4.20; and 1 more.
Critical [CVE-2025-70968] Arbitrary code execution via Use After Free in PluginTARGA.cpp;loadRLE()
Arbitrary code execution via Use After Free in PluginTARGA.cpp;loadRLE(). Red Hat rates this important (CVSS 9.8). Weakness: CWE-416. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2025-61686] React Router has Path Traversal in File Session Storage
React Router has Path Traversal in File Session Storage. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2025-70974] Remote Code Execution via JNDI Injection due to autoType mishandling
Remote Code Execution via JNDI Injection due to autoType mishandling. Red Hat rates this critical (CVSS 10). Weakness: CWE-829. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2025-12543] Undertow HTTP Server Fails to Reject Malformed Host Headers Leading to Potential Cache Poisoning and SSRF
Undertow HTTP Server Fails to Reject Malformed Host Headers Leading to Potential Cache Poisoning and SSRF. Red Hat rates this important (CVSS 9.6). Weakness: CWE-20. Affected package(s): eap8-wildfly, eap8-undertow, eap8-apache-cxf, eap8-wildfly-clustering, eap8-bouncycastle, eap7-undertow. Resolved in Red Hat advisory RHSA-2026:3889 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; and 11 more.
Critical [CVE-2025-10230] Samba: command injection in wins server hook script
A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process. On Red Hat Enterprise Linux (RHEL) versions 6, 7, 8, 9 and 10, the Samba packages as shipped are not affected by this vulnerability. This is because Red Hat does not provide Active Directory Domain Controller (AD DC) functionality in its Samba packages, and the vulnerable wins hook execution path exists only when Samba is configured as a domain controller with WINS support enabled. As a result, the Samba deployments on RHEL cannot be exploited via this issue. This vulnerability is considered Critical rather than Important because it enables unauthenticated remote code execution (RCE) on a Samba Active Directory Domain Controller through a trivially reachable network service. This means an attacker can inject arbitrary shell metacharacters and run commands with the privileges of the Samba process—often root on a DC.
Critical [CVE-2025-49794] heap use after free (uaf) leads to denial of service (dos)
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors. This issue was rated with a severity impact of Important by Red Hat Product Security, as libxml can be used to parse XML coming from the network depending on how the program consumes it and uses the library. Additionally, although the initial report shows a crash due to invalid memory access (A:H), other undefined issues that can present data integrity due to the application overwriting sensitive data are not discarded (I:H). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 26 more. Affected products named by the advisory: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; and 22 more.
Critical [CVE-2025-49796] type confusion leads to denial of service (dos)
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory. The Red Hat Product Security team has evaluated this vulnerability as having an Important security impact, as libxml can be used to parse XML from the network depending on how the program consumes it using the library. Additionally, although the initial report shows a crash due to invalid memory access (A:H), other undefined issues that can present data integrity due to the application overwriting sensitive data are not discarded (I:H). Red Hat severity: Important — CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 27 more.
Critical [CVE-2024-45496] Openshift-controller-manager: elevated build pods can lead to node compromise in openshift
A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, allowing unrestricted access to the node. An attacker with developer-level access can provide a crafted.gitconfig file containing commands executed during the cloning process, leading to arbitrary command execution on the worker node. An attacker running code in a privileged container could escalate their permissions on the node running the container. In all versions of OpenShift, the "Custom" build strategy gives developers permission to run arbitrary commands in a privileged container. This is disabled by default, and documentation explicitly warns that this should only be enabled for highly trusted users (eg: cluster admins). We therefore do not consider this vulnerability a privilege escalation path for "Custom" strategy builds. Microshift is not affected by this vulnerability. Red Hat severity: Important — CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L). Weakness: CWE-269. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; and 3 more.
Critical [CVE-2024-7387] Openshift/builder: path traversal allows command injection in privileged buildcontainer using docker build strategy
A flaw was found in openshift/builder. When using the “Docker” strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container. In all versions of OpenShift, the "Custom" build strategy gives developers permission to run arbitrary commands in a privileged container. This is disabled by default, and documentation explicitly warns that this should only be enabled for highly trusted users (eg: cluster admins). We therefore do not consider this vulnerability a privilege escalation path for "Custom" strategy builds. Microshift is not affected by this vulnerability. Red Hat severity: Important — CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-250. Affected Red Hat products: Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18. Red Hat fixing advisory: RHSA-2024:6705, RHSA-2024:6691, RHSA-2024:6689, RHSA-2024:6685, RHSA-2024:6687, RHSA-2024:3718, RHSA-2024:6122.