Red Hat Linux Security Advisories & CVEs
3038 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-19496] SQL injection (CWE-89) in query parameter filtering — unsanitised user input interpolated into WHERE clause
SQL injection (CWE-89) in query parameter filtering — unsanitised user input interpolated into WHERE clause. Red Hat rates this important (CVSS 8.8). Weakness: CWE-89.
High [CVE-2026-64835] Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files
Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files. Red Hat rates this important (CVSS 8.8). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:51180 with package ffmpeg-0:6.1.6-3.el9ai. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-64834] Denial of Service via crafted RTP/ASF stream
Denial of Service via crafted RTP/ASF stream. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835.
High [CVE-2026-64831] Arbitrary code execution via crafted HEVC/H.265 bitstream
Arbitrary code execution via crafted HEVC/H.265 bitstream. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120.
High [CVE-2026-44191] Visual Studio Code Ansible Lightspeed extension: Remote Code Execution via command injection in configuration settings
Visual Studio Code Ansible Lightspeed extension: Remote Code Execution via command injection in configuration settings. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.
High [CVE-2026-44190] Ansible Lightspeed Visual Studio Code extension: Arbitrary code execution via command injection in activation script setting
Ansible Lightspeed Visual Studio Code extension: Arbitrary code execution via command injection in activation script setting. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.
High [CVE-2026-44189] Visual Studio Code Ansible Lightspeed Extension: Arbitrary Code Execution via Malicious Playbook Filename
Visual Studio Code Ansible Lightspeed Extension: Arbitrary Code Execution via Malicious Playbook Filename. Red Hat rates this important (CVSS 7.8). Weakness: CWE-88.
High [CVE-2026-40691] Denial of Service via crafted DNSCrypt query
Denial of Service via crafted DNSCrypt query. Red Hat rates this important (CVSS 7.5). Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
High [CVE-2026-11331] Potential wildcard CNAME RPZ policy bypass
Potential wildcard CNAME RPZ policy bypass. Red Hat rates this important (CVSS 7.5). Red Hat lists fixing advisory RHSA-2026:54071 with package bind-main-9.20.26-0.1.hum1.
High [CVE-2026-13321] DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field. Red Hat rates this important (CVSS 8.6). Red Hat lists fixing advisory RHSA-2026:54071 with package bind-main-9.20.26-0.1.hum1.
High [CVE-2026-11605] Unnecessary validation of DNSSEC signed records
Unnecessary validation of DNSSEC signed records. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:42853 with package bind-main-9.18.50-22.hum1.
High [CVE-2026-11622] Potential memory usage beyond configured limits
Potential memory usage beyond configured limits. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:54071 with package bind-main-9.20.26-0.1.hum1.
High [CVE-2026-11721] Cache poisoning via label count discrepancy, RRSIG, wildcards
Cache poisoning via label count discrepancy, RRSIG, wildcards. Red Hat rates this important (CVSS 7.5). Weakness: CWE-345. Red Hat lists fixing advisory RHSA-2026:54071 with package bind-main-9.20.26-0.1.hum1.
High [CVE-2026-12617] Record ordering based unexpected exit with CNAME or DNAME
Record ordering based unexpected exit with CNAME or DNAME. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Red Hat lists fixing advisory RHSA-2026:54071 with package bind-main-9.20.26-0.1.hum1.
High [CVE-2026-13204] Unexpected exit with NSEC and NSEC3 both present
Unexpected exit with NSEC and NSEC3 both present. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Red Hat lists fixing advisory RHSA-2026:54071 with package bind-main-9.20.26-0.1.hum1.
High [CVE-2026-32665] Denial of Service via improper validation of DNS-over-QUIC client length
Denial of Service via improper validation of DNS-over-QUIC client length. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
High [CVE-2026-44690] Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes
Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes. Red Hat rates this important (CVSS 8.6). Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
High [CVE-2026-55973] Denial of Service via malformed EDNS Report-Channel option
Denial of Service via malformed EDNS Report-Channel option. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
High [CVE-2025-50327] Privilege escalation and arbitrary code execution via Mark-of-the-Web bypass
Privilege escalation and arbitrary code execution via Mark-of-the-Web bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1289.
High [CVE-2026-73144] Unbounded memory growth via unvalidated list count in FRN module
Unbounded memory growth via unvalidated list count in FRN module. Red Hat rates this important. Weakness: CWE-770.