Red Hat Linux Security Advisories & CVEs
277 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Low [CVE-2026-6879] Performance degradation in XML processing due to quadratic time complexity
Performance degradation in XML processing due to quadratic time complexity. Red Hat rates this low (CVSS 2.2). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:54534 with package python3-12-main-3.12.13-3.8.hum1, python3-10-main-3.10.20-3.2.hum1, python3-14-main-3.14.7-1.hum1, python3-14-main-3.14.6-2.2.hum1.
Low [CVE-2026-58341] CSRF risk in group messaging state toggle
CSRF risk in group messaging state toggle. Red Hat rates this moderate (CVSS 3.5). Weakness: CWE-22.
Low [CVE-2026-17072] 4-byte heap over-read in gst_matroska_parse_flac_stream_headers when parsing FLAC codec data in Matroska containers
4-byte heap over-read in gst_matroska_parse_flac_stream_headers when parsing FLAC codec data in Matroska containers. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125.
Low [CVE-2026-64647] Information disclosure via server-side request caching
Information disclosure via server-side request caching. Red Hat rates this low (CVSS 3.7). Weakness: CWE-524.
Low [CVE-2026-17513] Denial of Service via ftype argument manipulation
Denial of Service via ftype argument manipulation. Red Hat rates this low (CVSS 3.3). Weakness: CWE-617.
Low [CVE-2026-17512] Information disclosure via out-of-bounds read
Information disclosure via out-of-bounds read. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125.
Low [CVE-2026-66011] ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options
ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options. Red Hat rates this low (CVSS 3.3). Weakness: CWE-772.
Low [CVE-2026-64317] bound Rock Ridge symlink components to the SL record
bound Rock Ridge symlink components to the SL record. Red Hat rates this low (CVSS 3.9). Weakness: CWE-125.
Low [CVE-2026-17039] CA renewal request processing omits realm authorization check performed by enrollment path
CA renewal request processing omits realm authorization check performed by enrollment path. Red Hat rates this low (CVSS 3.1). Weakness: CWE-863.
Low [CVE-2026-52686] DNSSEC validation bypass due to unsigned wildcard expansion proofs
DNSSEC validation bypass due to unsigned wildcard expansion proofs. Red Hat rates this low (CVSS 3.7). Weakness: CWE-347.
Low [CVE-2026-56444] Denial of Service due to incorrect client reply accounting with specific serve-expired configuration
Denial of Service due to incorrect client reply accounting with specific serve-expired configuration. Red Hat rates this low (CVSS 3.7). Weakness: CWE-772. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Low [CVE-2026-54478] DNS Cookie security bypass via incorrect server cookie calculation
DNS Cookie security bypass via incorrect server cookie calculation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Low [CVE-2026-50046] Denial of Service due to freed pointer dereference in DNS-over-TLS handling
Denial of Service due to freed pointer dereference in DNS-over-TLS handling. Red Hat rates this low (CVSS 3.7). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Low [CVE-2026-46582] Information disclosure via DNSSEC wildcard replay
Information disclosure via DNSSEC wildcard replay. Red Hat rates this low (CVSS 3.7). Weakness: CWE-358. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Low [CVE-2026-42955] DNS cache integrity issue
DNS cache integrity issue. Red Hat rates this low (CVSS 3.7). Weakness: CWE-354. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Low [CVE-2026-41637] Denial of Service via terminated DNS-over-QUIC queries
Denial of Service via terminated DNS-over-QUIC queries. Red Hat rates this low (CVSS 3.7). Weakness: CWE-911. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Low [CVE-2026-44187] Ansible Lightspeed extension for Visual Studio Code: Information disclosure of Google Gemini API key
Ansible Lightspeed extension for Visual Studio Code: Information disclosure of Google Gemini API key. Red Hat rates this low (CVSS 3.3). Weakness: CWE-256.
Low [CVE-2026-16517] Signed Integer Overflow in archive_write_zip_header
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption. Red Hat Product Security rates this issue as Low severity. The vulnerability is in the ZIP write path only and requires both ZIP encryption to be enabled and a file size near INT64_MAX, making real-world exploitation highly unlikely. The resulting undefined behavior could theoretically cause incorrect Zip64 extension decisions or a crash, but the conditions are too contrived for practical exploitation. Weakness: CWE-190. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:43818.
Low [CVE-2026-47010] Enhance JPEG handling (Oracle CPU 2026-07)
Enhance JPEG handling (Oracle CPU 2026-07). Red Hat rates this low (CVSS 3.7). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:50281 with package java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-25-openjdk-main-25.0.4.0.7-1.1.1.hum1, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7.
Low [CVE-2026-47059] Enhance AWT ImagingLib (Oracle CPU 2026-07)
Enhance AWT ImagingLib (Oracle CPU 2026-07). Red Hat rates this low (CVSS 3.7). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:50281 with package java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-25-openjdk-main-25.0.4.0.7-1.1.1.hum1, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7.