Red Hat Linux Security Advisories & CVEs
3038 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-66140] Privilege escalation via directory traversal due to mishandled queue-name arguments
Privilege escalation via directory traversal due to mishandled queue-name arguments. Red Hat rates this important (CVSS 8.4). Weakness: CWE-22.
High [CVE-2026-66138] Arbitrary code execution via malicious configuration
Arbitrary code execution via malicious configuration. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78.
High [CVE-2026-64255] validate sta_mask before ffs in BA session handlers
validate sta_mask before ffs() in BA session handlers. Red Hat rates this moderate (CVSS 7). Weakness: CWE-823.
High [CVE-2026-64218] fix report_work leak on backbone_gw purge
fix report_work leak on backbone_gw purge. Red Hat rates this important. Weakness: CWE-825.
High [CVE-2026-64226] Linux kernel (sched_ext): Use-After-Free vulnerability in scx_root_enable_workfn
Linux kernel (sched_ext): Use-After-Free vulnerability in scx_root_enable_workfn(). Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64219] Validate payload length and link_index in dc_process_dmub_aux_transfer_async
Validate payload length and link_index in dc_process_dmub_aux_transfer_async. Red Hat rates this important (CVSS 7). Weakness: CWE-120.
High [CVE-2026-64247] Denial of Service due to out-of-bounds read
Denial of Service due to out-of-bounds read. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.
High [CVE-2026-64217] Linux kernel netfs: Memory corruption leading to denial of service and potential privilege escalation
Linux kernel netfs: Memory corruption leading to denial of service and potential privilege escalation. Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-64251] Linux kernel: Use-after-free in pwrseq_debugfs_seq_next can lead to denial of service
Linux kernel: Use-after-free in pwrseq_debugfs_seq_next() can lead to denial of service. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911.
High [CVE-2026-64221] Linux kernel: spi: ti-qspi use-after-free allows privilege escalation or denial of service
Linux kernel: spi: ti-qspi use-after-free allows privilege escalation or denial of service. Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64208] crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120.
High [CVE-2026-64216] netfs Use-After-Free vulnerability allows local denial of service and memory corruption
netfs Use-After-Free vulnerability allows local denial of service and memory corruption. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-16804] Sandbox escape via crafted HTML page
Sandbox escape via crafted HTML page. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787.
High [CVE-2026-16805] Use after free in Blink
Use after free in Blink. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-16806] Arbitrary code execution via use after free vulnerability in WebMCP
Arbitrary code execution via use after free vulnerability in WebMCP. Red Hat rates this important (CVSS 8.8).
High [CVE-2026-16807] Sandbox escape via crafted HTML page
Sandbox escape via crafted HTML page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-60122] Arbitrary OS command execution via code injection in gpsprof utility
Arbitrary OS command execution via code injection in gpsprof utility. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: gpsd-minimal.
High [CVE-2026-14257] Denial of Service via memory exhaustion in expand function
Denial of Service via memory exhaustion in expand() function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:45381 with package nodejs26-main-26.5.0-1.4.hum1, grafana12-4-main-12.4.6-0.4.hum1, nodejs22-main-22.23.1-2.3.hum1, nodejs24-main-24.18.0-0.5.hum1.
High [CVE-2026-64611] cpu exhaustion via infinite loop in cfieee1284normalizemakemodel
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service. A Moderate denial-of-service vulnerability in libcupsfilters allows network attackers to exhaust CPU resources by sending malformed IEEE-1284 device IDs. Red Hat rates this as Moderate because the vulnerable component, cups-browsed, is disabled by default in RHEL. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-16745] backend port 8080 trusts x-forwarded-access-token without origin validation
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure. Important: This flaw allows for privilege escalation within the cluster by bypassing authentication. It is due to the odh-dashboard backend binding to 0.0.0.0:8080 and trusting the x-forwarded-access-token header without origin validation. This enables any pod in the cluster to impersonate users by supplying an arbitrary token, circumventing the intended kube-rbac-proxy authentication. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-346. Affected Red Hat products: Red Hat OpenShift AI (RHOAI). Red Hat does not currently list a fixing RHSA for this CVE.