Red Hat Linux Security Advisories & CVEs
3038 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-15722] pre-authentication stack buffer overflow in get_ruvelement_from_berval via unbounded replica ID parsing
pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-121. Red Hat lists fixing advisory RHSA-2026:55425 with package 389-ds-base-0:3.0.6-20.el10_0, redhat-ds:11-8080020260806114250.f969626e, 389-ds-base-0:3.2.0-9.el10_2, 389-ds:1.4-8080020260806114228.6dbb3803. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-10079] Deploy-time policy enforcement and visibility bypass via label injection
Deploy-time policy enforcement and visibility bypass via label injection. Red Hat rates this important (CVSS 8.5). Weakness: CWE-345.
High [CVE-2026-18157] Remote Code Execution via APT Argument Injection
Remote Code Execution via APT Argument Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-88.
High [CVE-2026-18140] Denial of Service via uncontrolled recursion with deeply nested JSON
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server. To remediate this issue, users should upgrade to aws-smithy-json 0.62.7 or later and rebuild. This can make the affected server unavailable to legitimate users. Red Hat products utilizing `smithy-rs` generated servers, such as components in Red Hat Enterprise Linux and Red Hat Trusted Artifact Signer, are susceptible to service disruption if exposed to untrusted networks. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-776. Affected Red Hat products: Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Trusted Artifact Signer; Red Hat Trusted Profile Analyzer. Red Hat lists Confidential Compute Attestation; Red Hat Trusted Profile Analyzer as not affected. Will not fix / out of support: Red Hat Trusted Profile Analyzer. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: goose.
High [CVE-2026-66066] Remote Code Execution via Unsafe libvips Operations
Remote Code Execution via Unsafe libvips Operations. Red Hat rates this important (CVSS 8.9). Weakness: CWE-434.
High [CVE-2026-61536] Arbitrary code execution via unsafe tool definition import
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.import_module(...) + getattr(...) to obtain the callable that handles a tool call. There is no allowlist or sanitization on import_path, so any importable Python attribute (e.g. os.system, subprocess.getoutput) can be selected. When the LLM emits a tool_calls entry whose function.name matches the attacker-supplied tool name, the resolved callable is invoked with kwargs decoded from tool_call.function.arguments, yielding arbitrary code execution in the banks-hosting process. This is distinct from GHSA-gphh-9q3h-jgpp / CVE-2026-44209. That advisory was fixed in 2.4.2 by switching src/banks/env.py from Environment to SandboxedEnvironment. The fix does not touch src/banks/extensions/completion.py, and the unsafe import + getattr chain still executes on 2.4.2. The malicious Tool JSON is plain text in the rendered template body — it requires no Jinja attribute access, so the sandbox is irrelevant. This issue has been fixed in version 2.4.3. A flaw was found in Banks, a tool for generating LLM prompts. This vulnerability allows a remote attacker to achieve arbitrary code execution by injecting a malicious tool definition into a template.
High [CVE-2026-12932] Denial of Service due to memory leak in tls-crypt-v2 client key extraction
Denial of Service due to memory leak in tls-crypt-v2 client key extraction. Red Hat rates this important (CVSS 7.5). Weakness: CWE-771.
High [CVE-2026-62663] Information Disclosure via Path Traversal in Media Filters
Information Disclosure via Path Traversal in Media Filters. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2.
High [CVE-2026-60075] Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing
Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:56971 with package perl-Date-Manip-0:6.85-3.el9_8.1, perl-Date-Manip-0:6.94-5.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-17544] Arbitrary code execution via out-of-bounds write in bccomp
Arbitrary code execution via out-of-bounds write in bccomp(). Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47200 with package php-main-8.5.9-1.hum1, php8.4-0:8.4.24-1.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-17543] SQL injection via improper backslash escaping
SQL injection via improper backslash escaping. Red Hat rates this important (CVSS 7.4). Weakness: CWE-89. Red Hat lists fixing advisory RHSA-2026:47200 with package php-main-8.5.9-1.hum1, php8.4-0:8.4.24-1.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-18353] Unauthenticated Server-Side Request Forgery via OIDC issuer allowlist bypass
Unauthenticated Server-Side Request Forgery via OIDC issuer allowlist bypass. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918.
High [CVE-2026-58043] Unauthorized filesystem access due to Permission Model enforcement flaw
Unauthorized filesystem access due to Permission Model enforcement flaw. Red Hat rates this important (CVSS 7.5). Weakness: CWE-551. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.
High [CVE-2026-16529] Denial of Service due to signed integer overflow
Denial of Service due to signed integer overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:55740 with package pcp-0:7.0.3-5.el10_2, pcp-0:5.3.7-22.el8_10.5, pcp-0:6.3.7-8.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-16527] PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules
PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules. Red Hat rates this important (CVSS 7.3). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:55740 with package pcp-0:7.0.3-5.el10_2, pcp-0:5.3.7-22.el8_10.5, pcp-0:6.3.7-8.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-16526] Privilege escalation to root via linux_sockets PMDA vulnerability
Privilege escalation to root via linux_sockets PMDA vulnerability. Red Hat rates this important (CVSS 8.8). Weakness: CWE-403. Red Hat lists fixing advisory RHSA-2026:55740 with package pcp-0:7.0.3-5.el10_2, pcp-0:5.3.7-22.el8_10.5, pcp-0:6.3.7-8.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-16524] PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection
PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:55740 with package pcp-0:7.0.3-5.el10_2, pcp-0:5.3.7-22.el8_10.5, pcp-0:6.3.7-8.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-17986] Insufficient policy enforcement in Bluetooth
Insufficient policy enforcement in Bluetooth. Red Hat rates this low (CVSS 8.7). Weakness: CWE-346.
High [CVE-2026-17985] Insufficient policy enforcement in Speech
Insufficient policy enforcement in Speech. Red Hat rates this low (CVSS 8.2). Weakness: CWE-653.
High [CVE-2026-17918] Use after free in Sync
Use after free in Sync. Red Hat rates this low (CVSS 8.8). Weakness: CWE-825.