Red Hat Linux Security Advisories & CVEs
5483 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-64648] Information disclosure via server-side fetch cache
Information disclosure via server-side fetch cache. Red Hat rates this important (CVSS 7.5). Weakness: CWE-524.
High [CVE-2026-12383] ExternalEventStreamViewSet trusts Subject header without validation and leaks expected DN
ExternalEventStreamViewSet trusts Subject header without validation and leaks expected DN. Red Hat rates this important (CVSS 7.5). Weakness: CWE-345. Red Hat lists fixing advisory RHSA-2026:50340 with package automation-eda-controller-0:1.2.11-1.el9ap, ansible-automation-platform-27/eda-controller-rhel9:1785374869, automation-eda-controller-0:1.1.21-1.el9ap, automation-eda-controller-0:1.1.21-1.el8ap. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-66759] out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted ICNS images
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in information disclosure of heap contents, where memory contents are leaked as alpha channel pixel values, or a crash leading to a denial of service if unmapped memory is accessed. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted ICNS image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-66758] integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted FITS images
A flaw was found in the file-fits plugin in GIMP. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow when cfitsio subsequently writes a full row of pixels in the buffer, causing memory corruption, potentially leading to arbitrary code execution or a denial of service. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted FITS image with GIMP, reducing the likelihood of exploitation. However, successful exploitation may potentially lead to arbitrary code execution or a denial of service. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to this reason, this flaw has been rated with an important severity. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-64646] Denial of Service via excessive memory consumption in Server Actions
Denial of Service via excessive memory consumption in Server Actions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-64644] Denial of Service via malicious image optimization
Denial of Service via malicious image optimization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-64642] Authentication bypass leading to unauthorized access
Authentication bypass leading to unauthorized access. Red Hat rates this important (CVSS 8.2). Weakness: CWE-807.
High [CVE-2026-64641] Denial of Service via crafted requests to App Router with Server Actions
Denial of Service via crafted requests to App Router with Server Actions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-64645] Server-Side Request Forgery vulnerability
Server-Side Request Forgery vulnerability. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918.
High [CVE-2026-45623] Information disclosure and denial of service via crafted CSS input
Information disclosure and denial of service via crafted CSS input. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-22.
High [CVE-2026-54272] Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification
Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification. Red Hat rates this moderate (CVSS 7.2). Weakness: CWE-918.
High [CVE-2026-54890] Denial of Service via integer underflow in ETF decoding
Denial of Service via integer underflow in ETF decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.
High [CVE-2026-59251] Erlang/OTP public_key: Denial of Service via crafted TLS certificate chains
Erlang/OTP public_key: Denial of Service via crafted TLS certificate chains. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.
High [CVE-2026-55953] Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance
Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance. Red Hat rates this important (CVSS 7.4). Weakness: CWE-940. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.
High [CVE-2026-55737] Denial of Service via crafted external term format binary
Denial of Service via crafted external term format binary. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-42792] Erlang OTP epmd: Remote Denial of Service via connection exhaustion
Erlang OTP epmd: Remote Denial of Service via connection exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-253. Red Hat lists fixing advisory RHSA-2026:47009 with package erlang27-main-27.3.4.15-0.1.hum1.
High [CVE-2026-55971] Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow
Apache Thrift C++ bindings: Remote code execution via heap-based buffer overflow. Red Hat rates this important (CVSS 8.4). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:49716 with package thrift-0:0.24.0-1.el9ai, thrift-0:0.24.0-2.el9ai. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-55969] Denial of Service via integer overflow or wraparound
Denial of Service via integer overflow or wraparound. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:46989 with package jaeger-main-2.20.0-0.5.hum1, tempo2-10-main-2.10.7-0.2.hum1, tempo3-0-main-3.0.2-0.2.hum1.
High [CVE-2026-55968] Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation
Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-49158] Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data
Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409.