Red Hat Linux Security Advisories & CVEs
4426 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-102996] Denial of Service via excessive memory consumption during font parsing
Denial of Service via excessive memory consumption during font parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Ansible Automation Orchestrator 2026; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat Quay 3.
High [CVE-2026-102994] Denial of Service via crafted indirect object tokens in PDF files
Denial of Service via crafted indirect object tokens in PDF files. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Affected products named by the advisory: Ansible Automation Orchestrator 2026; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat Quay 3.
High [CVE-2026-102990] Denial of Service via crafted Unix directory listings
Denial of Service via crafted Unix directory listings. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift GitOps; Self-service automation portal 2; and 2 more.
High [CVE-2026-103500] Heap buffer overflow via opening large emails
Heap buffer overflow via opening large emails. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: thunderbird.
High [CVE-2026-19553] Certificate verification bypass via missing server_hostname validation in SSLContext.wrap_bio
Certificate verification bypass via missing server_hostname validation in SSLContext.wrap_bio(). Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:74594 with package python3-12-main-3.12.14-1.4.hum1, python3-13-main-3.13.15-1.4.hum1, python3-11-main-3.11.16-1.5.hum1, python3-14-main-3.14.7-1.3.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift Virtualization 4; and 4 more.
High [CVE-2026-47496] Privilege escalation via crafted RPC in Virtual GPU Manager
Privilege escalation via crafted RPC in Virtual GPU Manager. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47574] Arbitrary code execution via incorrect resource transfer between spheres
Arbitrary code execution via incorrect resource transfer between spheres. Red Hat rates this important. Weakness: CWE-664.
High [CVE-2026-47519] Arbitrary code execution via kernel-mode out-of-bounds read
Arbitrary code execution via kernel-mode out-of-bounds read. Red Hat rates this important. Weakness: CWE-125.
High [CVE-2026-47598] Arbitrary code execution via use-after-free in event delivery path
Arbitrary code execution via use-after-free in event delivery path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47596] Privilege escalation via unpreserved memory permissions
Privilege escalation via unpreserved memory permissions. Red Hat rates this important (CVSS 7.8). Weakness: CWE-281. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47582] Code execution via out-of-bounds write in kernel module
Code execution via out-of-bounds write in kernel module. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47602] Denial of Service via untrusted pointer dereference
Denial of Service via untrusted pointer dereference. Red Hat rates this important (CVSS 7.1). Weakness: CWE-822. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47554] Data tampering via signature verification bypass under memory pressure
Data tampering via signature verification bypass under memory pressure. Red Hat rates this important (CVSS 7.1). Weakness: CWE-347. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47601] Privilege escalation via improper memory access permissions in DMA-BUF import
Privilege escalation via improper memory access permissions in DMA-BUF import. Red Hat rates this important (CVSS 7.8). Weakness: CWE-281. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47600] Arbitrary code execution via improperly initialized resource
Arbitrary code execution via improperly initialized resource. Red Hat rates this important (CVSS 7.8). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47599] Privilege escalation via improper memory permissions during DMA mapping
Privilege escalation via improper memory permissions during DMA mapping. Red Hat rates this important (CVSS 7.8). Weakness: CWE-281.
High [CVE-2026-47597] Arbitrary code execution via use-after-free in Resource Server
Arbitrary code execution via use-after-free in Resource Server. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47595] Arbitrary code execution via write to read-only memory
Arbitrary code execution via write to read-only memory. Red Hat rates this important (CVSS 7.8). Weakness: CWE-281. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47594] Arbitrary code execution via use-after-free driver commands
Arbitrary code execution via use-after-free driver commands. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.
High [CVE-2026-47592] Arbitrary code execution via out-of-bounds read in kernel mode layer
Arbitrary code execution via out-of-bounds read in kernel mode layer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: nvidia-driver.