Red Hat Linux Security Advisories & CVEs
5482 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-45112] Denial of Service due to uncontrolled resource allocation
Denial of Service due to uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-43871] Denial of Service via infinite loop
Denial of Service via infinite loop. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835.
High [CVE-2026-41608] Apache Thrift Python bindings: Denial of Service via data amplification
Apache Thrift Python bindings: Denial of Service via data amplification. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409.
High [CVE-2026-17527] cdi.kubevirt.io:view aggregated ClusterRole grants create on datavolumes/source, allowing unauthorized PVC clone
cdi.kubevirt.io:view aggregated ClusterRole grants create on datavolumes/source, allowing unauthorized PVC clone. Red Hat rates this important (CVSS 7.7). Weakness: CWE-639.
High [CVE-2026-17523] Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges
A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 8. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-15928] Cross-Site Scripting in error page component
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component. A remote attacker could exploit this by tricking a user into clicking a specially crafted link. Successful exploitation could lead to the execution of malicious scripts in the user's browser, potentially resulting in information disclosure or session hijacking. This reflected cross-site scripting (XSS) vulnerability relies entirely on client-side interaction through a web browser. If executed, the script runs within the context of the user's browser session, making sensitive session tokens or client-side data accessible to the attacker. While external CVSSv4 scoring rates this flaw to an 8.2 High, Red Hat bounds the severity to CVSS 7.4 based on explicit CIA triad mechanics. The impact is strictly confined to Confidentiality (C:H) via potential browser-side data disclosure. The flaw carries zero impact on system Integrity (I:N) or Availability (A:N), as it cannot alter server-side application logic, modify stored data, or disrupt underlying XML-RPC services. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-51300] Application crash and information leakage due to use-after-free
Application crash and information leakage due to use-after-free. Red Hat rates this a security issue. Weakness: CWE-825.
High [CVE-2026-51298] Denial of Service via use-after-free in JSON extraction
Denial of Service via use-after-free in JSON extraction. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:45779 with package sqlite-main-3.53.4-0.1.hum1.
High [CVE-2026-51302] Arbitrary code execution via malicious SQL statement
Arbitrary code execution via malicious SQL statement. Red Hat rates this a security issue. Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:45779 with package sqlite-main-3.53.4-0.1.hum1.
High [CVE-2026-51296] Use-after-free vulnerability leads to denial of service and information disclosure
Use-after-free vulnerability leads to denial of service and information disclosure. Red Hat rates this a security issue. Weakness: CWE-825.
High [CVE-2026-51297] Arbitrary code execution via use-after-free in JSON parsing
Arbitrary code execution via use-after-free in JSON parsing. Red Hat rates this a security issue. Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:45779 with package sqlite-main-3.53.4-0.1.hum1.
High [CVE-2026-51303] Arbitrary code execution via specially crafted SQL queries
Arbitrary code execution via specially crafted SQL queries. Red Hat rates this a security issue. Weakness: CWE-825.
High [CVE-2026-64534] check INIT_FAILED before nvmet_req_uninit in digest error path
check INIT_FAILED before nvmet_req_uninit in digest error path. Red Hat rates this important (CVSS 7). Weakness: CWE-911.
High [CVE-2026-64531] reject oversized nested action attrs
reject oversized nested action attrs. Red Hat rates this important (CVSS 7.8). Weakness: CWE-130. Red Hat lists fixing advisory RHSA-2026:51603 with package kernel-rt-0:5.14.0-284.186.1.rt14.471.el9_2, kernel-0:5.14.0-427.143.1.el9_4, kernel-0:5.14.0-284.186.1.el9_2. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-51235] Buffer Overflow vulnerability in image processing
Buffer Overflow vulnerability in image processing. Red Hat rates this important (CVSS 7.3). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:51105 with package LibRaw-0:0.21.1-2.el9_8.1. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-64552] fix len check in receive_big
fix len check in receive_big(). Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-64551] validate STALE_COOKIE cause length before reading staleness
validate STALE_COOKIE cause length before reading staleness. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64554] fix stale prevhdr pointer in br_ip6_fragment
fix stale prevhdr pointer in br_ip6_fragment(). Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64543] fix use-after-free of the discoverer in tipc_disc_rcv
fix use-after-free of the discoverer in tipc_disc_rcv(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64539] Fix stack OOB write when prepending the Flags AD
Fix stack OOB write when prepending the Flags AD. Red Hat rates this moderate (CVSS 7).