Red Hat Linux Security Advisories & CVEs
3038 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-64527] validate VMBus packet size in receive callback
validate VMBus packet size in receive callback. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805.
High [CVE-2026-64267] avoid 32-bit prune notification count wrap
avoid 32-bit prune notification count wrap. Red Hat rates this moderate (CVSS 7). Weakness: CWE-190.
High [CVE-2026-64471] fix use-after-free on registration failure
fix use-after-free on registration failure. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64473] Remove device debugfs before releasing devres
Remove device debugfs before releasing devres. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911.
High [CVE-2026-64319] validate reply message payload bounds against transfer length
validate reply message payload bounds against transfer length. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.
High [CVE-2026-64266] re-lock request before returning from fuse_ref_folio
re-lock request before returning from fuse_ref_folio(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64414] handle unreadable frags
handle unreadable frags. Red Hat rates this moderate (CVSS 7). Weakness: CWE-390.
High [CVE-2026-64470] fix use-after-free on marvell probe failure
fix use-after-free on marvell probe failure. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64304] qat - validate RSA CRT component lengths
qat - validate RSA CRT component lengths. Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-64523] Take a long-lived file reference at submit
Take a long-lived file reference at submit. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64286] Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64483] bound the sample count to the packet payload
bound the sample count to the packet payload. Red Hat rates this important (CVSS 7). Weakness: CWE-120.
High [CVE-2026-64438] qat - fix VF2PF work teardown race in adf_disable_sriov
qat - fix VF2PF work teardown race in adf_disable_sriov(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64371] protect ptrace_may_access with exec_update_lock (part 1)
protect ptrace_may_access() with exec_update_lock (part 1). Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64386] fix query_info replay double-free
fix query_info() replay double-free. Red Hat rates this important (CVSS 7). Weakness: CWE-1341.
High [CVE-2026-66041] Arbitrary code execution via crafted PGS/SUP subtitle file
Arbitrary code execution via crafted PGS/SUP subtitle file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-66040] Arbitrary code execution via crafted PNG image
Arbitrary code execution via crafted PNG image. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-66039] Arbitrary code execution via crafted CAF file
Arbitrary code execution via crafted CAF file. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-66036] Arbitrary code execution via crafted video in vf_hqdn3d filter
Arbitrary code execution via crafted video in vf_hqdn3d filter. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-17107] Impersonation header injection in service-proxy grants cluster-admin on every managed cluster
Impersonation header injection in service-proxy grants cluster-admin on every managed cluster. Red Hat rates this important (CVSS 8.5). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:48284 with package multicluster-engine/cluster-proxy-rhel9:1784342329, multicluster-engine/cluster-proxy-rhel9:1783278220, multicluster-engine/cluster-proxy-rhel9:1784925025, multicluster-engine/cluster-proxy-rhel9:1783985960.