Red Hat Linux Security Advisories & CVEs
5204 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-33217] Access control bypass via unapplied ACLs in MQTT namespace
Access control bypass via unapplied ACLs in MQTT namespace. Red Hat rates this important (CVSS 8.1). Weakness: CWE-425. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.
High [CVE-2026-33216] Information disclosure of MQTT passwords through monitoring endpoints
Information disclosure of MQTT passwords through monitoring endpoints. Red Hat rates this important (CVSS 8.6). Weakness: CWE-213. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.
High [CVE-2026-29785] Denial of Service via leafnode compression
Denial of Service via leafnode compression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.
High [CVE-2026-27889] Denial of Service via malformed WebSockets frame
Denial of Service via malformed WebSockets frame. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.
High [CVE-2026-3104] Denial of Service via specially crafted domain query causing a memory leak
Denial of Service via specially crafted domain query causing a memory leak. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: BIND 9; Red Hat Hardened Images.
High [CVE-2026-1519] Denial of Service via maliciously crafted DNSSEC-validated zone
Denial of Service via maliciously crafted DNSSEC-validated zone. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): bind, bind9.16, bind9.18, rhcos, bind-main. Resolved in Red Hat advisory RHSA-2026:29863 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: BIND 9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; and 16 more.
High [CVE-2026-3608] Denial of Service via maliciously crafted message
Denial of Service via maliciously crafted message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Affected package(s): kea. Resolved in Red Hat advisory RHSA-2026:7342 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support.
High [CVE-2026-23375] deny THP for files on anonymous inodes
deny THP for files on anonymous inodes. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:21557 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2025-67030] org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method
org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method. Red Hat rates this important (CVSS 8.3). Weakness: CWE-22. Affected package(s): eap8-jboss-logging, eap8-guava-failureaccess, eap8-activemq-artemis, eap8-netty-transport-native-epoll, eap8-reactivex-rxjava, eap8-wildfly-javadocs. Resolved in Red Hat advisory RHSA-2026:7109 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss EAP 8.1 for RHEL 8; Red Hat JBoss EAP 8.1 for RHEL 9; Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); and 32 more.
High [CVE-2026-23392] release flowtable after rcu grace period on error
release flowtable after rcu grace period on error. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-33809] Denial of Service via maliciously crafted TIFF file
Denial of Service via maliciously crafted TIFF file. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1285. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34085] Security flaw allows arbitrary code execution or system crash
Security flaw allows arbitrary code execution or system crash. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-193. Affected package(s): fontconfig-main. Resolved in Red Hat advisory RHSA-2026:13722 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-3591] Unauthorized access due to use-after-return vulnerability in DNS query handling
Unauthorized access due to use-after-return vulnerability in DNS query handling. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-825. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-3119] Denial of Service via authenticated TKEY queries
Denial of Service via authenticated TKEY queries. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-237. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-4371] Out of bounds read in IMAP parsing
Out of bounds read in IMAP parsing. Red Hat rates this important (CVSS 8.2). Weakness: CWE-130. Affected package(s): thunderbird. Resolved in Red Hat advisory RHSA-2026:8286 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 9 more.
High [CVE-2026-33412] Arbitrary code execution via command injection in glob() function
Arbitrary code execution via command injection in glob() function. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/cds-kubernetes-tp-rhel9:1777459441, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim. Resolved in Red Hat advisory RHSA-2026:6915 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 23 more.
High [CVE-2026-32647] Denial of Service or Code Execution via specially crafted MP4 files
Denial of Service or Code Execution via specially crafted MP4 files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-125. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Open Source; NGINX Plus; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 7 more.
High [CVE-2026-4775] Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing
Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): libtiff-main, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, compat-libtiff3, libtiff, mingw-libtiff. Resolved in Red Hat advisory RHSA-2026:30349 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 13 more.
High [CVE-2026-27651] Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Open Source; NGINX Plus; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 6 more.
High [CVE-2026-27654] Denial of Service or file modification via buffer overflow in ngx_http_dav_module
Denial of Service or file modification via buffer overflow in ngx_http_dav_module. Red Hat rates this important (CVSS 8.2). Weakness: CWE-120. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Open Source; NGINX Plus; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 6 more.