Red Hat Linux Security Advisories & CVEs
5233 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2025-69419] Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
Arbitrary code execution due to out-of-bounds write in PKCS#12 processing. Red Hat rates this moderate (CVSS 7.4). Weakness: CWE-131. Affected package(s): jbcs-httpd24-mod_md, rhcos, jbcs-httpd24-mod_http2, rhui5/installer-rhel9:1770646925, jbcs-httpd24-mod_proxy_cluster, openssl-main. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2025-11187] Arbitrary code execution or denial of service through crafted PKCS#12 file
Arbitrary code execution or denial of service through crafted PKCS#12 file. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-233. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-15468] Denial of Service via NULL pointer dereference in QUIC protocol handling
Denial of Service via NULL pointer dereference in QUIC protocol handling. Red Hat rates this low (CVSS 5.9). Weakness: CWE-476. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-15469] Data integrity bypass in `openssl dgst` command due to silent truncation
Data integrity bypass in `openssl dgst` command due to silent truncation. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1284. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-66199] Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression
Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression. Red Hat rates this low (CVSS 5.9). Weakness: CWE-770. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-68160] Denial of Service due to out-of-bounds write in BIO filter
Denial of Service due to out-of-bounds write in BIO filter. Red Hat rates this low (CVSS 4.7). Weakness: CWE-787. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-69418] Information disclosure and data tampering via specific low-level OCB encryption/decryption calls
Information disclosure and data tampering via specific low-level OCB encryption/decryption calls. Red Hat rates this low (CVSS 4). Weakness: CWE-325. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-69421] Denial of Service via malformed PKCS#12 file processing
Denial of Service via malformed PKCS#12 file processing. Red Hat rates this low (CVSS 6.5). Weakness: CWE-476. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-69420] Denial of Service via malformed TimeStamp Response
Denial of Service via malformed TimeStamp Response. Red Hat rates this low (CVSS 5.9). Weakness: CWE-843. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-22795] Denial of Service due to type confusion in PKCS#12 file processing
Denial of Service due to type confusion in PKCS#12 file processing. Red Hat rates this low (CVSS 5.5). Weakness: CWE-843. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-22796] Denial of Service via type confusion in PKCS#7 signature verification
Denial of Service via type confusion in PKCS#7 signature verification. Red Hat rates this low (CVSS 5.9). Weakness: CWE-1287. Affected package(s): openssl, discovery/discovery-ui-rhel9:1769111774, costmanagement/costmanagement-metrics-rhel9-operator:1770836349, insights-proxy/insights-proxy-container-rhel9:1770740405, rhui5/rhua-rhel9:1773670137, rhui5/cds-rhel9:1773670073. Resolved in Red Hat advisory RHSA-2026:3228 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2025-28164] Denial of Service via buffer overflow in png_create_read_struct() function
Denial of Service via buffer overflow in png_create_read_struct() function. Red Hat rates this moderate (CVSS 5). Weakness: CWE-120. Affected package(s): libpng-main. Resolved in Red Hat advisory RHSA-2026:6732 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2025-28162] Denial of Service via buffer overflow in pngimage utility
Denial of Service via buffer overflow in pngimage utility. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-120. Affected package(s): libpng-main. Resolved in Red Hat advisory RHSA-2026:6732 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-1504] Inappropriate implementation in Background Fetch API
Inappropriate implementation in Background Fetch API. Red Hat rates this important (CVSS 6.5). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2025-13881] Limited administrator can retrieve sensitive user attributes via Admin API
Limited administrator can retrieve sensitive user attributes via Admin API. Red Hat rates this low (CVSS 2.7). Weakness: CWE-266. Affected package(s): keycloak, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-23864] Denial of Service via specially crafted HTTP requests
Denial of Service via specially crafted HTTP requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. Affected package(s): com.github.streamshub-console. Resolved in Red Hat advisory RHSA-2026:13571 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-23001] fix possible UAF in macvlan_forward_source()
fix possible UAF in macvlan_forward_source(). Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:3966 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-23010] Linux kernel: Use-after-free in IPv6 address deletion may lead to a denial of service
Linux kernel: Use-after-free in IPv6 address deletion may lead to a denial of service. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:4723 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-23002] use __kernel_read() for sleepable context
use __kernel_read() for sleepable context. Red Hat rates this low (CVSS 4.7). Weakness: CWE-476. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:18134 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-22998] fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec
fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-476. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:2722 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.