Red Hat Linux Security Advisories & CVEs
5198 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-25535] denial of service via malicious GIF dimensions
denial of service via malicious GIF dimensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): advanced-cluster-security/rhacs-main-rhel8:1775594119, advanced-cluster-security/rhacs-main-rhel8:1775594284. Resolved in Red Hat advisory RHSA-2026:7110 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Advanced Cluster Security for Kubernetes 4.8; Red Hat Advanced Cluster Security for Kubernetes 4.9; Red Hat Advanced Cluster Security 4.8; Red Hat Advanced Cluster Security 4.9.
Low [CVE-2026-2733] Missing Check on Disabled Client for Docker Registry Protocol
Missing Check on Disabled Client for Docker Registry Protocol. Red Hat rates this low (CVSS 3.8). Weakness: CWE-285. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-22860] Rack Directory Traversal via Rack:Directory
Rack Directory Traversal via Rack:Directory. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat 3scale API Management Platform 2.
High [CVE-2025-14009] Zip Slip Vulnerability in nltk Leading to Code Execution
Zip Slip Vulnerability in nltk Leading to Code Execution. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1775144403, rhoai/odh-ta-lmes-job-rhel9:1776271296. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; OpenShift Lightspeed; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-2648] Heap buffer overflow in PDFium
Heap buffer overflow in PDFium. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-2649] Integer overflow in V8
Integer overflow in V8. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-23216] Fix use-after-free in iscsit_dec_conn_usage_count()
Fix use-after-free in iscsit_dec_conn_usage_count(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-413. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:9870 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-27100] Information disclosure via unauthorized access to build parameters
Information disclosure via unauthorized access to build parameters. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-551. Affected package(s): ocp-tools. Resolved in Red Hat advisory RHSA-2026:10209 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-27099] Stored Cross-site Scripting (XSS) via unescaped user-provided offline cause description
Stored Cross-site Scripting (XSS) via unescaped user-provided offline cause description. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-79. Affected package(s): ocp-tools. Resolved in Red Hat advisory RHSA-2026:10209 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-24734] Certificate revocation bypass due to improper OCSP response validation
Certificate revocation bypass due to improper OCSP response validation. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected package(s): jws6-tomcat-native, tomcat, tomcat10-main, jws6-tomcat, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:5612 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat JBoss Web Server 6.2 on RHEL 10; Red Hat JBoss Web Server 6.2 on RHEL 8; and 3 more.
High [CVE-2026-24708] Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova
Arbitrary Host File Overwrite via Unconstrained qemu-img Format Handling in OpenStack Nova. Red Hat rates this important (CVSS 7.1). Weakness: CWE-73. Affected package(s): openstack-nova. Resolved in Red Hat advisory RHSA-2026:7884 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenStack Services on OpenShift 18.0; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more.
Medium [CVE-2026-24733] security constraint bypass with HTTP/0.9
security constraint bypass with HTTP/0.9. Red Hat rates this low (CVSS 5.3). Weakness: CWE-20. Affected package(s): tomcat, jws6-tomcat, tomcat10-main, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:12195 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2025-66614] Client certificate verification bypass due to virtual host mapping
Client certificate verification bypass due to virtual host mapping. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1289. Affected package(s): tomcat, jws6-tomcat, tomcat10-main, tomcat11-main. Resolved in Red Hat advisory RHSA-2026:12195 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2026-2625] Denial of Service via crafted RPM file during signature verification
Denial of Service via crafted RPM file during signature verification. Red Hat rates this moderate (CVSS 4). Weakness: CWE-347. Affected package(s): rust-rpm-sequoia-main. Resolved in Red Hat advisory RHSA-2026:12682 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-2447] Heap buffer overflow in libvpx
Heap buffer overflow in libvpx. Red Hat rates this important (CVSS 7.5). Affected package(s): libvpx, thunderbird, rhaiis/vllm-rocm-rhel9:1775680262, firefox, rhaiis/vllm-cuda-rhel9:1775680192, rhaiis/vllm-spyre-rhel9:1778244546. Resolved in Red Hat advisory RHSA-2026:3967 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 11 more.
Medium [CVE-2026-2575] Denial of Service due to excessive SAMLRequest decompression
Denial of Service due to excessive SAMLRequest decompression. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-409. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.10, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:3947 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-23171] Linux kernel: Use-after-free in bonding module can cause system crash or arbitrary code execution
Linux kernel: Use-after-free in bonding module can cause system crash or arbitrary code execution. Red Hat rates this moderate (CVSS 7). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:8342 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-23210] Linux kernel: Denial of Service in ice driver due to race condition during VSI rebuild
Linux kernel: Denial of Service in ice driver due to race condition during VSI rebuild. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:6570 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
High [CVE-2026-23209] fix error recovery in macvlan_common_newlink()
fix error recovery in macvlan_common_newlink(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel-rt, kernel. Resolved in Red Hat advisory RHSA-2026:6954 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-23136] Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state
Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-440. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:27708 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.