Red Hat Linux Security Advisories & CVEs
3037 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-19113] Unauthenticated denial of service via unbounded request body processing
Unauthenticated denial of service via unbounded request body processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-15972] Denial of Service via unbounded external gRPC connection acceptance
Denial of Service via unbounded external gRPC connection acceptance. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
High [CVE-2026-65819] Remote Denial of Service via crafted packet processing
Remote Denial of Service via crafted packet processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805.
High [CVE-2026-19015] Uncontrolled resource consumption leading to denial of service
Uncontrolled resource consumption leading to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-71556] Arbitrary file read/write via symbolic link resolution
Arbitrary file read/write via symbolic link resolution. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-15816] root code execution via unescaped error message written to sourced emergency hook script in die
root code execution via unescaped error message written to sourced emergency hook script in die(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:54575 with package dracut-0:057-54.git20250423.el9_4.3, dracut-0:057-25.git20250717.el9_2.2, dracut-0:057-89.git20250311.el9_6.1, dracut-0:105-4.el10_0.1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
High [CVE-2025-63235] codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets
codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772.
High [CVE-2026-70632] Arbitrary Code Execution in CFHD Decoder via Crafted AVI File
Arbitrary Code Execution in CFHD Decoder via Crafted AVI File. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-70628] Arbitrary code execution via crafted WTV file in DVB subtitle parser
Arbitrary code execution via crafted WTV file in DVB subtitle parser. Red Hat rates this important (CVSS 7.8). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-71430] Denial of Service due to excessive string length in replacements
Denial of Service due to excessive string length in replacements. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131.
High [CVE-2026-19177] Sandbox escape via crafted HTML page
Sandbox escape via crafted HTML page. Red Hat rates this important (CVSS 8). Weakness: CWE-1289.
High [CVE-2026-19175] Remote sandbox escape via use-after-free in Payments
Remote sandbox escape via use-after-free in Payments. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-19174] Arbitrary code execution via crafted HTML page
Arbitrary code execution via crafted HTML page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190.
High [CVE-2026-19171] Sandbox escape via use-after-free in Media component
Sandbox escape via use-after-free in Media component. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.
High [CVE-2026-19166] Sandbox escape due to use-after-free in Web Authentication
Sandbox escape due to use-after-free in Web Authentication. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.
High [CVE-2026-19164] Sandbox escape via crafted HTML page
Sandbox escape via crafted HTML page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1286.
High [CVE-2026-19163] Sandbox escape via use-after-free in Media component
Sandbox escape via use-after-free in Media component. Red Hat rates this important (CVSS 8). Weakness: CWE-825.
High [CVE-2026-19162] Arbitrary code execution via out-of-bounds write in V8.
Arbitrary code execution via out-of-bounds write in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-19158] Arbitrary code execution via use-after-free in Views
Arbitrary code execution via use-after-free in Views. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-19159] Arbitrary code execution via use-after-free in Views
Arbitrary code execution via use-after-free in Views. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.