Red Hat Linux Security Advisories & CVEs
5208 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2026-24683] FreeRDP has a heap-use-after-free in ainput_send_input_event
FreeRDP has a heap-use-after-free in ainput_send_input_event. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2026-24682] FreeRDP has a Heap-buffer-overflow in audio_formats_free
FreeRDP has a Heap-buffer-overflow in audio_formats_free. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-131. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:19033 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-24681] FreeRDP has a heap-use-after-free in urb_bulk_transfer_cb
FreeRDP has a heap-use-after-free in urb_bulk_transfer_cb. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:9640 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Medium [CVE-2026-24679] FreeRDP has a heap-buffer-overflow in urb_select_interface
FreeRDP has a heap-buffer-overflow in urb_select_interface. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1285. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-24678] Denial of Service via use after free in ecam_channel_write
Denial of Service via use after free in ecam_channel_write. Red Hat rates this important (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:19033 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6.
Medium [CVE-2026-24676] Denial of Service via use-after-free in AUDIN format renegotiation
Denial of Service via use-after-free in AUDIN format renegotiation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-24675] FreeRDP has a Heap-use-after-free in urb_select_interface
FreeRDP has a Heap-use-after-free in urb_select_interface. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-24491] FreeRDP has a heap-use-after-free in video_timer
FreeRDP has a heap-use-after-free in video_timer. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-23948] FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2()
FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2(). Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-476. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2025-14831] Denial of Service via excessive resource consumption during certificate verification
Denial of Service via excessive resource consumption during certificate verification. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-407. Affected package(s): rhpam, rhaiis/vllm-rocm-rhel9:1778244531, gnutls-main, discovery/discovery-server-rhel9:1775668717, insights-proxy/insights-proxy-container-rhel9:1773685509, rhui5/rhua-rhel9:1773670137. Resolved in Red Hat advisory RHSA-2026:6618 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Critical [CVE-2026-1709] Authentication bypass allows unauthorized administrative operations due to missing client-side TLS authentication
Authentication bypass allows unauthorized administrative operations due to missing client-side TLS authentication. Red Hat rates this critical (CVSS 9.4). Weakness: CWE-322. Affected package(s): keylime. Resolved in Red Hat advisory RHSA-2026:2225 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.
High [CVE-2026-25793] Blocklist evasion via ECDSA Signature Malleability
Blocklist evasion via ECDSA Signature Malleability. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-25749] Arbitrary code execution via 'helpfile' option processing
Arbitrary code execution via 'helpfile' option processing. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-120. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim, rhui5/cds-rhel9:1776868774. Resolved in Red Hat advisory RHSA-2026:4715 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-25580] Information disclosure via Server-Side Request Forgery (SSRF) through malicious URLs in message history.
Information disclosure via Server-Side Request Forgery (SSRF) through malicious URLs in message history.. Red Hat rates this important (CVSS 8.6). Weakness: CWE-918. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-25731] Arbitrary Code Execution via malicious custom template file during ebook conversion
Arbitrary Code Execution via malicious custom template file during ebook conversion. Red Hat rates this important (CVSS 7.8). Weakness: CWE-917. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-25635] Remote Code Execution via path traversal in CHM reader
Remote Code Execution via path traversal in CHM reader. Red Hat rates this important (CVSS 8.6). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-25636] Arbitrary file corruption via path traversal in EPUB conversion
Arbitrary file corruption via path traversal in EPUB conversion. Red Hat rates this important (CVSS 8.2). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-25640] Arbitrary code execution and information disclosure via path traversal in web UI
Arbitrary code execution and information disclosure via path traversal in web UI. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-23740] Arbitrary code execution and file overwrite as root via insecure ast_coredumper file handling
Arbitrary code execution and file overwrite as root via insecure ast_coredumper file handling. Red Hat rates this important (CVSS 7.8). Weakness: CWE-379. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-2100] NULL dereference via C_DeriveKey with specific NULL parameters
NULL dereference via C_DeriveKey with specific NULL parameters. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-824. Affected package(s): p11-kit, insights-proxy/insights-proxy-container-rhel9:1780420428, rhui5/haproxy-rhel9:1779798164, costmanagement/costmanagement-metrics-rhel9-operator:1780946239, p11-kit-main, rhui5/rhua-rhel9:1779798222. Resolved in Red Hat advisory RHSA-2026:7065 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat Insights proxy 1.5; and 1 more.