Red Hat Linux Security Advisories & CVEs
4432 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-15801] Insufficient validation during container checkpoint restore
Insufficient validation during container checkpoint restore. Red Hat rates this important (CVSS 8). Weakness: CWE-22. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-47321] Denial of Service via unbounded decompression amplification
Denial of Service via unbounded decompression amplification. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected products named by the advisory: OpenShift Developer Tools and Services; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Fuse 7; Red Hat package: maven-wagon.
High [CVE-2026-93990] XML Injection via Malformed UTF-16 Input
XML Injection via Malformed UTF-16 Input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-176. Red Hat lists fixing advisory RHSA-2026:74001 with package expat-main-2.8.4-0.2.hum1, expat-0:2.7.3-1.el10_2.5, expat-0:2.5.0-4.el8_10, expat-0:2.5.0-6.el9_8.5. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-96543] out-of-bounds heap write when loading non-square PVR images
out-of-bounds heap write when loading non-square PVR images. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787.
High [CVE-2026-63447] Denial of Service via crafted FTP traffic
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp.max-tx is reached while processing one large chunk of FTP command data. The oversized transaction list is repeatedly processed with quadratic complexity after the too_many_transactions event, allowing crafted FTP traffic to degrade packet processing, reduce monitoring visibility, or cause denial of service. This issue is fixed in version 8.0.6. A flaw was found in Suricata. A remote, unauthenticated attacker can exploit this issue by sending specially crafted File Transfer Protocol (FTP) traffic containing large command sequences, causing the parser to allocate transactions beyond expected limits. Processing this oversized transaction list leads to excessive CPU resource consumption, resulting in degraded packet inspection capabilities and a Denial of Service (DoS). This vulnerability is rated as Important because an unauthenticated remote attacker transmitting network traffic inspected by Suricata can trigger severe CPU exhaustion without requiring privileges, leading to packet processing starvation and denial of service.
High [CVE-2026-92708] Cross-request process memory disclosure
Cross-request process memory disclosure. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat Trusted Artifact Signer.
High [CVE-2026-93752] Denial of Service due to improper property name validation
Denial of Service due to improper property name validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-93748] Information Disclosure via max-stale directive
Information Disclosure via max-stale directive. Red Hat rates this important (CVSS 7.5). Weakness: CWE-524. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-93749] Denial of Service via malformed indexed source maps
Denial of Service via malformed indexed source maps. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. Affected products named by the advisory: Cost Management On Premise; Gatekeeper 3; Migration Toolkit for Containers; Node HealthCheck Operator; and 36 more. Affected products named by the advisory: OpenShift Lightspeed; OpenShift Pipelines; Red Hat 3scale API Management Platform 2; Red Hat AMQ Broker 7; and 32 more.
High [CVE-2026-63199] Cross-scope secret disclosure due to missing authorization in datasource proxy
Cross-scope secret disclosure due to missing authorization in datasource proxy. Red Hat rates this important (CVSS 7.7). Weakness: CWE-1220. Red Hat lists fixing advisory RHSA-2026:74609 with package cluster-observability-operator/perses-rhel9:1790854501.
High [CVE-2026-69184] CPU exhaustion denial of service via unbounded DNS name compression pointer chains
CPU exhaustion denial of service via unbounded DNS name compression pointer chains. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:40574 with package c-ares-main-1.34.8-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
High [CVE-2026-69186] Denial of Service via unvalidated DNS header record counts
Denial of Service via unvalidated DNS header record counts. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. Red Hat lists fixing advisory RHSA-2026:40574 with package c-ares-main-1.34.8-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
High [CVE-2026-61548] Denial of Service due to stack buffer overflow in mmpstrucdata plugin
Denial of Service due to stack buffer overflow in mmpstrucdata plugin. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-55556] Denial of Service via heap buffer overflow in imhttp module
Denial of Service via heap buffer overflow in imhttp module. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131.
High [CVE-2026-91149] Denial of Service via unbounded connection thread spawning
Denial of Service via unbounded connection thread spawning. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat OpenShift Dev Spaces.
High [CVE-2026-84383] Heap buffer overflow in `scale_nearest_neighbor ` via duplicate Alpha planes from nested `iden`/`auxl` items
Heap buffer overflow in `scale_nearest_neighbor()` via duplicate Alpha planes from nested `iden`/`auxl` items. Red Hat rates this critical (CVSS 7.8). Weakness: CWE-787.
High [CVE-2026-93690] Denial of Service via malformed path segments
Denial of Service via malformed path segments. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Cost Management On Premise; Multicluster Engine for Kubernetes; Node HealthCheck Operator; OpenShift Lightspeed; and 12 more. Affected products named by the advisory: OpenShift Pipelines; OpenShift Service Mesh 3; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Connectivity Link 1; and 8 more.
High [CVE-2026-93687] Denial of Service via Stack Overflow from Deeply Nested Patterns
Denial of Service via Stack Overflow from Deeply Nested Patterns. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-93568] HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-20. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; and 6 more. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat Data Grid 8; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 2 more.
High [CVE-2025-59419 +1] Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419). Red Hat rates this important (CVSS 7.5). Weakness: CWE-93. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7.