Red Hat Linux Security Advisories & CVEs
5421 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-97438] validate index entry key bounds
validate index entry key bounds. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-97472] fix temp address generation after prefix deprecation
fix temp address generation after prefix deprecation. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-359. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97441] fail probe if BAR too small for claimed ports
fail probe if BAR too small for claimed ports. Red Hat rates this low (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97434] fix handling of NAPI on the remove path
fix handling of NAPI on the remove path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-826. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
Medium [CVE-2026-97436] rework FDB management on the bridge leave path
rework FDB management on the bridge leave path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
Medium [CVE-2026-97498] pin mqd and fw object bo to avoid eviction
pin mqd and fw object bo to avoid eviction. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-97499] Retrieve path and source from event data
Retrieve path and source from event data. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-366.
Medium [CVE-2026-97500] check length before parsing PHY status IE
check length before parsing PHY status IE. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-93228] Reject Write/Reply chunks with segcount 0
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Write/Reply chunks with segcount 0 A peer can send a Write or Reply chunk whose segcount field is zero. xdr_check_write_chunk() only rejects segcount > rc_maxpages, so zero passes the range check, and xdr_inline_decode(stream, 0) returns the current (non-NULL) cursor without advancing. The function returns true and pcl_alloc_write() then links a struct svc_rdma_chunk with ch_segcount == 0 onto rc_write_pcl or rc_reply_pcl. An earlier patch in this series made pcl_for_each_segment() safe for ch_segcount == 0, so this no longer drives the memory walk it used to. Rejecting the malformed frame at the decode boundary is still worthwhile as defense in depth: it keeps degenerate zero-segment chunks off the parsed chunk lists entirely, so any future consumer that walks ch_segments directly cannot observe one, and it makes the zero-floor easy to backport to trees where the macro change is more intrusive. RFC 8166 has no meaning for a Write/Reply chunk that describes no remote buffer, so no legitimate client is affected. xdr_check_reply_chunk() funnels Reply chunks through xdr_check_write_chunk() and inherits the same rejection. pcl_alloc_write() also links each chunk onto the parsed chunk list before filling its segment array.
Medium [CVE-2026-93225] fix typec switch leak on probe error path
fix typec switch leak on probe error path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
Medium [CVE-2026-59980] Denial of Service via malformed HTTP/2 header encoding
Denial of Service via malformed HTTP/2 header encoding. Red Hat rates this low (CVSS 5.3). Weakness: CWE-770. Affected products named by the advisory: Migration Toolkit for Containers; Red Hat Ansible Automation Platform 2; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-67221] Information disclosure of AMQP 1.0 shovel URI passwords
Information disclosure of AMQP 1.0 shovel URI passwords. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-256. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-67218] Privilege escalation via super-stream HTTP creation
Privilege escalation via super-stream HTTP creation. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-66074] Denial of Service via management API regular expression filter
Denial of Service via management API regular expression filter. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-66075] Monitoring user can disrupt message flow via authorization flaw
Monitoring user can disrupt message flow via authorization flaw. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-67219] Denial of Service via unbounded consistent-hash exchange weight
Denial of Service via unbounded consistent-hash exchange weight. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-67228] Denial of Service via atom exhaustion in runtime-parameter component
Denial of Service via atom exhaustion in runtime-parameter component. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-67235] Denial of Service via AMQP 0-9-1 body size validation bypass
Denial of Service via AMQP 0-9-1 body size validation bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-66068] Information disclosure of decrypted Shovel URIs in debug logs
Information disclosure of decrypted Shovel URIs in debug logs. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-215. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-67229] Denial of Service via admin-only atom exhaustion from crafted vhost metadata
Denial of Service via admin-only atom exhaustion from crafted vhost metadata. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.