Red Hat Linux Security Advisories & CVEs
5475 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-64216] Fix potential UAF in netfs_unlock_abandoned_read_pages
Fix potential UAF in netfs_unlock_abandoned_read_pages(). Red Hat rates this moderate (CVSS 7).
Medium [CVE-2026-66337] Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory. A malicious HTTP server can trigger this against any libsoup client using SoupMultipartInputStream by sending a crafted multipart response with a boundary string longer than the internal buffer. This issue is related to but distinct from CVE-2026-1761. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-66338] Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked
A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests. The practical impact is limited because libsoup servers are rarely deployed in internet-facing infrastructure behind reverse proxies. This issue is distinct from CVE-2026-1801 which covers bare LF tolerance. Red Hat severity: Low — CVSS 5.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N). Weakness: CWE-444. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-66339] Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure. This causes proxy credentials to be sent in cleartext to destination servers, which can capture and reuse them. This issue is distinct from CVE-2026-12547 which covers credential leak when switching between proxies. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-201. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-66038] Information disclosure via malformed zlib video stream
Information disclosure via malformed zlib video stream. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-908.
Medium [CVE-2026-66037] Denial of Service via uncontrolled resource consumption in IAMF demuxer
Denial of Service via uncontrolled resource consumption in IAMF demuxer. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.
Medium [CVE-2026-66035] Arbitrary code execution via heap buffer overflow during SSH negotiation
Arbitrary code execution via heap buffer overflow during SSH negotiation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:46955 with package libssh2-main-1.11.1-10.3.hum1.
Medium [CVE-2026-66034] Information disclosure and potential arbitrary code execution via heap out-of-bounds read
Information disclosure and potential arbitrary code execution via heap out-of-bounds read. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:46927 with package libssh2-main-1.11.1-10.2.hum1.
Medium [CVE-2026-66033] Denial of Service via integer underflow in AES-GCM cipher negotiation
Denial of Service via integer underflow in AES-GCM cipher negotiation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:46927 with package libssh2-main-1.11.1-10.2.hum1.
Medium [CVE-2026-66032] Arbitrary code execution via double-free in SFTP session
Arbitrary code execution via double-free in SFTP session. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1341. Red Hat lists fixing advisory RHSA-2026:46927 with package libssh2-main-1.11.1-10.2.hum1.
Medium [CVE-2026-17059] Information disclosure via role-users endpoint bypasses per-user view filter
Information disclosure via role-users endpoint bypasses per-user view filter. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-639.
Medium [CVE-2026-17048] Vault-resolved rotated client secrets leaked via Admin REST API
Vault-resolved rotated client secrets leaked via Admin REST API. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-200.
Medium [CVE-2026-16743] arbitrary file read via SetIconFile for systemd-homed users
arbitrary file read via SetIconFile for systemd-homed users. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-269.
Medium [CVE-2026-66010] Cross-Site Scripting (XSS) via custom element attribute bypass
Cross-Site Scripting (XSS) via custom element attribute bypass. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-79.
Medium [CVE-2026-16730] session bus denial of service via EMFILE during peer setup
session bus denial of service via EMFILE during peer setup. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-755.
Medium [CVE-2026-56392] GNU coreutils unexpand: Denial of Service via crafted tab stop values
GNU coreutils unexpand: Denial of Service via crafted tab stop values. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-787. Red Hat lists fixing advisory RHBA-2026:47115 with package coreutils-0:8.30-20.el8_10, coreutils-main-9.11-5.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 8.
Medium [CVE-2026-56391] GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte input
GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte input. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:46515 with package coreutils-main-9.11-5.1.hum1.
Medium [CVE-2026-16910] SSRF in Red Hat Quay notification webhooks (Slack/generic)
A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing a repository administrator to make the Quay worker issue POST requests to internal network addresses or cloud infrastructure endpoints that should not be reachable from the application. The Quay worker issues requests to attacker-specified URLs when notifications fire, but response data is not returned to the attacker, limiting exploitable impact to network probing and unauthenticated side-effects on internal services. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N). Weakness: CWE-918. Affected Red Hat products: Red Hat OpenShift Update Service; Red Hat Quay 3. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-64227] Check ACPI_COMPANION against NULL during probe
Check ACPI_COMPANION() against NULL during probe. Red Hat rates this low (CVSS 5.5).
Medium [CVE-2026-64254] Avoid pci_iounmap with offset when PEER_SPAD and CONFIG share BAR
Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR. Red Hat rates this low (CVSS 5.5).