Red Hat Linux Security Advisories & CVEs
11136 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-98087] sched/rt,dl: Skip migrate-disabled tasks when picking a push candidate
In the Linux kernel, the following vulnerability has been resolved: sched/rt,dl: Skip migrate-disabled tasks when picking a push candidate A migrate_disable()'d RT task cannot be moved to another CPU, but the scheduler still keeps such a task on that CPU's pushable list (rq->rt.pushable_tasks) and still marks the runqueue RT-overloaded (rq->rt.overloaded = 1). So the RT balancer keeps treating this CPU as having a task to move away, and keeps trying to move the task, but the push can never succeed. When the head is pinned, push_rt_task() does not give up either. It falls back to pushing rq->curr instead, using the per-CPU stopper, as added by commit a7c81556ec4d ("sched: Fix migrate_disable() vs rt/dl balancing"). The CPU spends tens of milliseconds in this retry loop. The core is isolated for real-time work, but during the loop nearly half of its time is consumed by pushes that cannot succeed. An ftrace capture of the affected CPU, with sched_switch enabled and commit 94894c9c477e ("sched/rt: Skip currently executing CPU in rto_next_cpu()") applied, shows where the CPU time went. Two SCHED_FIFO tasks at equal priority shared the CPU, taskA migrate_disable()'d and queued, taskB as rq->curr. In one 89 ms window, taskB got only 52 ms of CPU. The other 37 ms went to the stopper thread.
Medium [CVE-2026-51772] Server-Side Request Forgery via image locations manipulation
A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locations attribute of an image in the queued state by sending a crafted HTTP PATCH request This vulnerability allows the attacker to induce the server into making unauthorized network requests to internal or external services, potentially exposing sensitive internal systems. This vulnerability is rated as Moderate severity because exploitation requires an authenticated user account and relies on a non-default configuration setting in OpenStack Glance. By default, the show_multiple_locations directive is disabled in Red Hat OpenStack Platform, which prevents standard deployments from being exposed. If enabled, an authenticated user can trigger unauthorized outbound network requests from the Glance service, potentially scanning or probing internal network services. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-918. Affected Red Hat products: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0. Red Hat does not currently list a fixing RHSA for this CVE.
Low [CVE-2025-1218] Denial of Service via out-of-bounds read in mysqlnd wire protocol parser
Denial of Service via out-of-bounds read in mysqlnd wire protocol parser. Red Hat rates this low (CVSS 3.7). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.
Low [CVE-2026-67420] Unauthorized user impersonation via stale OAuth token refresh
Unauthorized user impersonation via stale OAuth token refresh. Red Hat rates this low (CVSS 3.1). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0.
High [CVE-2026-57178] Authentication bypass via missing signature verification in VK App backend
Authentication bypass via missing signature verification in VK App backend. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.
High [CVE-2026-67233] Privilege escalation allows monitoring users to delete shovels
Privilege escalation allows monitoring users to delete shovels. Red Hat rates this important (CVSS 7.1). Weakness: CWE-267. Red Hat lists fixing advisory RHSA-2026:67552 with package rabbitmq-server4-3-main-4.3.6-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
High [CVE-2026-90959] file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and Pulp Container registry signing key theft
file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and Pulp Container registry signing key theft. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Satellite 6; Red Hat Update Infrastructure 5.
High [CVE-2026-97057] Denial of Service via invalid RESP protocol array length
Denial of Service via invalid RESP protocol array length. Red Hat rates this important (CVSS 7.5). Weakness: CWE-130. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Fuse 7; Red Hat Satellite 6; Self-service automation portal 2.
High [CVE-2026-95521] shell command injection via macro expansion of source/spec file basenames when installing a source RPM
shell command injection via macro expansion of source/spec file basenames when installing a source RPM. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: rpm.
High [CVE-2026-95519] Code Execution via Macro Expansion of Manifest Entries in `rpmgi` (`-q -p` / verify manifest flows)
Code Execution via Macro Expansion of Manifest Entries in `rpmgi` (`-q -p` / verify manifest flows). Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: rpm.
High [CVE-2026-97185] out-of-bounds write in GIMPressionist plugin via crafted preset file
out-of-bounds write in GIMPressionist plugin via crafted preset file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:75575 with package gimp-2:3.0.4-4.el9_8.14. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-97417] use get_unaligned_be32 in tcp_sack
use get_unaligned_be32() in tcp_sack(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-843. Red Hat lists fixing advisory RHSA-2026:75746 with package kernel-0:4.18.0-553.171.1.el8_10, kernel-rt-0:4.18.0-553.171.1.rt7.512.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-93787] bound dirent name against end of SMB response in cifs_filldir
bound dirent name against end of SMB response in cifs_filldir. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-93262] fix use-after-free in ppl_do_flush
fix use-after-free in ppl_do_flush(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-93283] Fix device_register error path
Fix device_register() error path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
High [CVE-2026-93817] Fix addr_filter_ranges lifetime
Fix addr_filter_ranges lifetime. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-93827] avoid double-free on failed queue setup
avoid double-free on failed queue setup. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
High [CVE-2026-93812] fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr
fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr. Red Hat rates this moderate (CVSS 7). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
High [CVE-2026-93800] fix use-after-free on reloc root after error in insert_dirty_subvol
fix use-after-free on reloc root after error in insert_dirty_subvol(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.
High [CVE-2026-97415] validate names in ROOT_REF and ROOT_BACKREF
validate names in ROOT_REF and ROOT_BACKREF. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: kernel-rt.