Red Hat Linux Security Advisories & CVEs
3038 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-55969] Denial of Service via integer overflow or wraparound
Denial of Service via integer overflow or wraparound. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:54577 with package multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1785863006, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1785442872, jaeger-main-2.20.0-0.5.hum1, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1785443657.
High [CVE-2026-55968] Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation
Apache Thrift Node.js bindings: Denial of Service due to inefficient algorithmic complexity and resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-49158] Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data
Apache Thrift Ruby bindings: Denial of Service via improper handling of highly compressed data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409.
High [CVE-2026-48586] Denial of Service via improper handling of highly compressed data
Denial of Service via improper handling of highly compressed data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:43799 with package opentelemetry-collector-main-0.157.0-0.1.hum1, jaeger-main-2.20.0-0.5.hum1, libthrift, loki3-7-main-3.7.4-0.1.hum1.
High [CVE-2026-45112] Denial of Service due to uncontrolled resource allocation
Denial of Service due to uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:54776 with package libthrift.
High [CVE-2026-43871] Denial of Service via infinite loop
Denial of Service via infinite loop. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835.
High [CVE-2026-41608] Apache Thrift Python bindings: Denial of Service via data amplification
Apache Thrift Python bindings: Denial of Service via data amplification. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:49837 with package thrift-main-0.24.0-0.1.hum1.
High [CVE-2026-17527] cdi.kubevirt.io:view aggregated ClusterRole grants create on datavolumes/source, allowing unauthorized PVC clone
cdi.kubevirt.io:view aggregated ClusterRole grants create on datavolumes/source, allowing unauthorized PVC clone. Red Hat rates this important (CVSS 7.7). Weakness: CWE-639.
High [CVE-2026-17523] can:bcm: arbitrary kernel code execution leading to escalate privileges
A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 8. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-15928] Cross-Site Scripting in error page component
Cross-Site Scripting in error page component. Red Hat rates this important (CVSS 7.4). Weakness: CWE-79.
High [CVE-2026-51300] Application crash and information leakage due to use-after-free
Application crash and information leakage due to use-after-free. Red Hat rates this a security issue. Weakness: CWE-825.
High [CVE-2026-51298] Denial of Service via use-after-free in JSON extraction
Denial of Service via use-after-free in JSON extraction. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:45779 with package sqlite-main-3.53.4-0.1.hum1.
High [CVE-2026-51302] Arbitrary code execution via malicious SQL statement
Arbitrary code execution via malicious SQL statement. Red Hat rates this a security issue. Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:45779 with package sqlite-main-3.53.4-0.1.hum1.
High [CVE-2026-51296] Use-after-free vulnerability leads to denial of service and information disclosure
Use-after-free vulnerability leads to denial of service and information disclosure. Red Hat rates this a security issue. Weakness: CWE-825.
High [CVE-2026-51297] Arbitrary code execution via use-after-free in JSON parsing
Arbitrary code execution via use-after-free in JSON parsing. Red Hat rates this a security issue. Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:45779 with package sqlite-main-3.53.4-0.1.hum1.
High [CVE-2026-51303] Arbitrary code execution via specially crafted SQL queries
Arbitrary code execution via specially crafted SQL queries. Red Hat rates this a security issue. Weakness: CWE-825.
High [CVE-2026-64534] check INIT_FAILED before nvmet_req_uninit in digest error path
check INIT_FAILED before nvmet_req_uninit in digest error path. Red Hat rates this important (CVSS 7). Weakness: CWE-911.
High [CVE-2026-64531] reject oversized nested action attrs
reject oversized nested action attrs. Red Hat rates this important (CVSS 7.8). Weakness: CWE-130. Red Hat lists fixing advisory RHSA-2026:53330 with package kernel-0:6.12.0-211.46.1.el10_2, kernel-rt-0:5.14.0-284.186.1.rt14.471.el9_2, kernel-0:5.14.0-427.143.1.el9_4, kernel-0:5.14.0-284.186.1.el9_2. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
High [CVE-2026-51235] Buffer Overflow vulnerability in image processing
Buffer Overflow vulnerability in image processing. Red Hat rates this important (CVSS 7.3). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:51105 with package LibRaw-0:0.21.1-2.el9_8.1. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-64552] fix len check in receive_big
fix len check in receive_big(). Red Hat rates this important (CVSS 7). Weakness: CWE-787.