Red Hat Linux Security Advisories & CVEs
5485 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Low [CVE-2026-17910] Insufficient policy enforcement in NFC
Insufficient policy enforcement in NFC. Red Hat rates this low (CVSS 3.1). Weakness: CWE-346.
Low [CVE-2026-17909] Insufficient validation of untrusted input in Isolated Web Apps
Insufficient validation of untrusted input in Isolated Web Apps. Red Hat rates this low (CVSS 3.1). Weakness: CWE-346.
Low [CVE-2026-17908] Insufficient validation of untrusted input in Printing
Insufficient validation of untrusted input in Printing. Red Hat rates this low. Weakness: CWE-1286.
Low [CVE-2026-17906] Insufficient validation of untrusted input in Bluetooth
Insufficient validation of untrusted input in Bluetooth. Red Hat rates this low. Weakness: CWE-1286.
Low [CVE-2026-17903] Insufficient policy enforcement in Chromecast
Insufficient policy enforcement in Chromecast. Red Hat rates this low. Weakness: CWE-79.
Low [CVE-2026-17899] Insufficient policy enforcement in DevTools
Insufficient policy enforcement in DevTools. Red Hat rates this low (CVSS 2.8). Weakness: CWE-266.
Low [CVE-2026-17821] Insufficient policy enforcement in Extensions
Insufficient policy enforcement in Extensions. Red Hat rates this moderate (CVSS 3.9). Weakness: CWE-807.
Low [CVE-2026-17786] Insufficient validation of untrusted input in DevTools
Insufficient validation of untrusted input in DevTools. Red Hat rates this moderate (CVSS 3.9). Weakness: CWE-807.
Critical [CVE-2026-51992] Arbitrary code execution via SQL Injection in create dictionaries function
SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function. A flaw was found in ClickHouse Server. This could lead to a complete compromise of the affected system. Red Hat severity: Critical — CVSS 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-89.
High [CVE-2026-5056] Arbitrary code execution via stack-based buffer overflow in qtdemux
Arbitrary code execution via stack-based buffer overflow in qtdemux. Red Hat rates this important (CVSS 7.8). Weakness: CWE-121. Red Hat lists fixing advisory RHSA-2026:49508 with package gstreamer1-plugins-good-0:1.26.7-2.el10_2.2. Affected product named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-18022] Arbitrary Code Execution via Integer Wraparound
Arbitrary Code Execution via Integer Wraparound. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-18255] Global read-only superuser can view robot account tokens
Global read-only superuser can view robot account tokens. Red Hat rates this important (CVSS 7.2). Weakness: CWE-863.
High [CVE-2026-13697] Information disclosure and Denial of Service via malformed Cache-Control directives
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the same cache key, disclosing private response bodies and headers including Set-Cookie. Separately, a Cache-Control header that combines an unqualified private directive with a qualified one triggers an uncaught TypeError in the cache-control parser, which rejects the request and, depending on the consumer's error handling, can terminate the process. Both issues affect applications using the cache interceptor in shared mode, including the default configuration. The issues are fixed in undici 7.29.0 and 8.9.0. A flaw was found in undici. Additionally, a specially crafted Cache-Control header can trigger an unhandled error in the cache parser, leading to a process termination and a Denial of Service (DoS). Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H). Weakness: CWE-524. Affected Red Hat products: Red Hat Hardened Images. Will not fix / out of support: Red Hat Hardened Images. Red Hat fixing advisory: RHSA-2026:48273, RHSA-2026:48537.
High [CVE-2026-55707] Shared-network consumer can re-scope another project's subnets via subnetpool onboarding
Shared-network consumer can re-scope another project's subnets via subnetpool onboarding. Red Hat rates this important (CVSS 7.1). Weakness: CWE-863.
High [CVE-2026-55995] Denial of Service via double-free in iSNS attribute decoder
Denial of Service via double-free in iSNS attribute decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-763.
High [CVE-2026-16308] io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service
io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:47172 with package rhbk/keycloak-rhel9:26.6-11, rhbk/keycloak-operator-bundle:26.4.14-1, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, rhbk-openshift-rhel9/rhbk-openshift-rhel9.
High [CVE-2026-44944] Authentication bypass in iscsiuio control socket
Authentication bypass in iscsiuio control socket. Red Hat rates this important (CVSS 7.8). Weakness: CWE-1220.
High [CVE-2026-44943] Privilege Escalation via Path Traversal
Privilege Escalation via Path Traversal. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22.
High [CVE-2026-18220] Out-of-bounds write in BFD DLX ELF backend relocation processing
Out-of-bounds write in BFD DLX ELF backend relocation processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787.
High [CVE-2026-64556] Detach event groups during remove_on_exec
Detach event groups during remove_on_exec. Red Hat rates this important (CVSS 7). Weakness: CWE-663.