Red Hat Linux Security Advisories & CVEs
3057 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-55833] Denial of Service via SPDY header decompression amplification
Denial of Service via SPDY header decompression amplification. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:47172 with package netty-codec-http.
High [CVE-2026-55831] Denial of Service via SPDY SETTINGS frame processing
Denial of Service via SPDY SETTINGS frame processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:47172 with package netty-codec-http.
High [CVE-2026-64624] Arbitrary code execution via malicious RDP files
Arbitrary code execution via malicious RDP files. Red Hat rates this important (CVSS 7.3). Weakness: CWE-88.
High [CVE-2026-64612] cups image filter process abort via malformed png
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-248. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-39879] SQL Injection vulnerability leading to denial of service and data manipulation
SQL Injection vulnerability leading to denial of service and data manipulation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-150.
High [CVE-2026-64621] Double-free vulnerability via crafted.rdp file leading to potential remote code execution
Double-free vulnerability via crafted.rdp file leading to potential remote code execution. Red Hat rates this important (CVSS 7.3). Weakness: CWE-1341.
High [CVE-2026-64620] Remote code execution or denial of service via heap-based buffer overflow
Remote code execution or denial of service via heap-based buffer overflow. Red Hat rates this important (CVSS 8.1). Weakness: CWE-120.
High [CVE-2026-50540] Arbitrary code execution via manipulated configuration path
Arbitrary code execution via manipulated configuration path. Red Hat rates this important (CVSS 8.8). Weakness: CWE-20.
High [CVE-2026-64191] Reject I2C block transfers with invalid length
Reject I2C block transfers with invalid length. Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-64192] Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476.
High [CVE-2026-64189] fix race between dump and ip_set_list resize
fix race between dump and ip_set_list resize. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-12484] Arbitrary code execution via unsafe deserialization of PyTorch data
Arbitrary code execution via unsafe deserialization of PyTorch data. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502.
High [CVE-2026-64098] use uninterruptible resv lock for plane updates
use uninterruptible resv lock for plane updates. Red Hat rates this moderate (CVSS 7). Weakness: CWE-413.
High [CVE-2026-64069] Fix cancellation of a DIO and single read subrequests
Fix cancellation of a DIO and single read subrequests. Red Hat rates this moderate (CVSS 7). Weakness: CWE-772.
High [CVE-2026-64174] advance loop vars in cfg80211_merge_profile
advance loop vars in cfg80211_merge_profile(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-835.
High [CVE-2026-64061] Fix early put of sink folio in netfs_read_gaps
Fix early put of sink folio in netfs_read_gaps(). Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64048] reject CHID-0 ACCEPT that matches an empty ism_dev slot
reject CHID-0 ACCEPT that matches an empty ism_dev slot. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476.
High [CVE-2026-64115] fix UAF when peer resets connection during handshake
fix UAF when peer resets connection during handshake. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787.
High [CVE-2026-64137] require net admin for CIFS SWN netlink
require net admin for CIFS SWN netlink. Red Hat rates this important (CVSS 7). Weakness: CWE-280.
High [CVE-2026-64119] use list_del_rcu in l2tp_session_unhash
use list_del_rcu in l2tp_session_unhash. Red Hat rates this moderate (CVSS 7). Weakness: CWE-835.