Red Hat Linux Security Advisories & CVEs
5196 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2026-31988] Denial of Service vulnerability in zip file processing
Denial of Service vulnerability in zip file processing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-193. Affected package(s): rhdh/rhdh-hub-rhel9:1780930740. Resolved in Red Hat advisory RHSA-2026:24841 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-31958] Denial of Service via large multipart bodies
Denial of Service via large multipart bodies. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected package(s): rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1780078429, rhoai/odh-llama-stack-core-rhel9:1775144403, python-tornado, rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1780078388, rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9:1780069224, pcs. Resolved in Red Hat advisory RHSA-2026:24342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9.
Medium [CVE-2026-3904] nscd client crash on x86_64 under high nscd load
nscd client crash on x86_64 under high nscd load. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-366. Affected package(s): glibc-main. Resolved in Red Hat advisory RHSA-2026:7316 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-3805] Arbitrary code execution or Denial of Service via use-after-free in SMB request handling
Arbitrary code execution or Denial of Service via use-after-free in SMB request handling. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-825. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-3784] Unauthorized access due to improper HTTP proxy connection reuse
Unauthorized access due to improper HTTP proxy connection reuse. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-305. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-3783] Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect
Information disclosure via OAuth2 bearer token leakage during HTTP(S) redirect. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-201. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-1965] Authentication bypass due to incorrect connection reuse with Negotiate authentication
Authentication bypass due to incorrect connection reuse with Negotiate authentication. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-303. Affected package(s): curl-main. Resolved in Red Hat advisory RHSA-2026:6893 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-3911] org.keycloak.services.resources.admin.UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint
org.keycloak.services.resources.admin. UserResource: Keycloak: Information disclosure of disabled user attributes via administrative endpoint. Red Hat rates this low (CVSS 2.7). Weakness: CWE-359. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-3913] Heap buffer overflow in WebML
Heap buffer overflow in WebML. Red Hat rates this critical (CVSS 9.6). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-31837] Information disclosure and authentication bypass via JWKS resolver unavailability
Information disclosure and authentication bypass via JWKS resolver unavailability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1392. Affected package(s): openshift-service-mesh/istio-proxyv2-rhel9:1774114903, rhoai/odh-kserve-agent-rhel9:1776343082, openshift-service-mesh/istio-proxyv2-rhel9:1774068855, openshift-service-mesh/istio-pilot-rhel9:1774037369, rhoai/odh-kserve-router-rhel9:1776343121, rhoai/odh-kserve-controller-rhel9:1776343105. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift Service Mesh 3.0; Red Hat OpenShift Service Mesh 3.1; Red Hat OpenShift Service Mesh 3.2; and 3 more.
High [CVE-2026-30951] Data exfiltration via SQL injection in JSON/JSONB where clause processing
Data exfiltration via SQL injection in JSON/JSONB where clause processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-89. Affected package(s): satellite/iop-remediations-rhel9:1776194798. Resolved in Red Hat advisory RHSA-2026:8498 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Satellite 6.18; Confidential Compute Attestation.
High [CVE-2026-23868] Double-free vulnerability leading to memory corruption
Double-free vulnerability leading to memory corruption. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected package(s): giflib, rhaiis/vllm-rocm-rhel9:1778244531, rhaiis/vllm-cuda-rhel9:1779223654, rhaiis/vllm-cuda-rhel9:1778274666, rhaiis/vllm-spyre-rhel9:1778244546, rhaiis/model-opt-cuda-rhel9:1780681984. Resolved in Red Hat advisory RHSA-2026:8859 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 12 more.
High [CVE-2026-28292] Remote Code Execution via bypass of prior security fixes
Remote Code Execution via bypass of prior security fixes. Red Hat rates this important (CVSS 8.8). Weakness: CWE-76. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Logging Subsystem for Red Hat OpenShift.
High [CVE-2026-26130] Denial of Service via uncontrolled resource allocation
Denial of Service via uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): dotnet8.0, dotnet9.0, dotnet10.0. Resolved in Red Hat advisory RHSA-2026:4458 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.4 Extended Update Support; Red Hat Enterprise Linux 9.6 Extended Update Support.
High [CVE-2026-26127] .net: .NET: Denial of Service via out-of-bounds read
.net:.NET: Denial of Service via out-of-bounds read. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-125. Affected package(s): dotnet9.0, dotnet10.0. Resolved in Red Hat advisory RHSA-2026:10083 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-26131] .NET: Privilege escalation via incorrect default permissions
.NET: Privilege escalation via incorrect default permissions. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-276. Affected package(s): dotnet10. Resolved in Red Hat advisory RHSA-2026:9077 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-3918] Use after free in WebMCP
Use after free in WebMCP. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-3921] Use after free in TextEncoding
Use after free in TextEncoding. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-3923] Use after free in WebMIDI
Use after free in WebMIDI. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-3914] Integer overflow in WebML
Integer overflow in WebML. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.