Red Hat Linux Security Advisories & CVEs
5475 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-11622] Potential memory usage beyond configured limits
Potential memory usage beyond configured limits. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400.
High [CVE-2026-11721] Cache poisoning via label count discrepancy, RRSIG, wildcards
Cache poisoning via label count discrepancy, RRSIG, wildcards. Red Hat rates this important (CVSS 7.5). Weakness: CWE-345.
High [CVE-2026-12617] Record ordering based unexpected exit with CNAME or DNAME
Record ordering based unexpected exit with CNAME or DNAME. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617.
High [CVE-2026-13204] Unexpected exit with NSEC and NSEC3 both present
Unexpected exit with NSEC and NSEC3 both present. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617.
High [CVE-2026-32665] Denial of Service via improper validation of DNS-over-QUIC client length
Denial of Service via improper validation of DNS-over-QUIC client length. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
High [CVE-2026-44690] Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes
Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes. Red Hat rates this important (CVSS 8.6). Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
High [CVE-2026-55973] Denial of Service via malformed EDNS Report-Channel option
Denial of Service via malformed EDNS Report-Channel option. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
High [CVE-2025-50327] Privilege escalation and arbitrary code execution via Mark-of-the-Web bypass
Privilege escalation and arbitrary code execution via Mark-of-the-Web bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1289.
Medium [CVE-2026-16631] Arbitrary Command Execution via OS Command Injection
Arbitrary Command Execution via OS Command Injection. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-78.
Medium [CVE-2026-14899] Off-by-one out of bounds read in MIME header parser for forwarding
Off-by-one out of bounds read in MIME header parser for forwarding. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:49921 with package thunderbird-0:140.13.0-1.el10_2, thunderbird-0:140.13.0-1.el8_10, thunderbird-0:140.13.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-16615] Librest: weak random number generation in pkce implementation
A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random number generator (PRNG) seed to predict or reconstruct the code verifier string, allowing an attacker to bypass PKCE protections and successfully impersonate the client during the OAuth 2.0 authorization flow. This allows the attacker to hold a valid access token and impersonate the user, access their protected data and perform actions on their behalf. Due to these reasons, this vulnerability has been rated with an important severity. Red Hat severity: Important — CVSS 6.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N). Weakness: CWE-338. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:47085.
Medium [CVE-2026-16552] systemd-tmpfiles symlink-redirected arbitrary file overwrite via a CHASE_SAFE root-to-unprivileged ownership transition bypass
systemd-tmpfiles symlink-redirected arbitrary file overwrite via a CHASE_SAFE root-to-unprivileged ownership transition bypass. Red Hat rates this a security issue. Weakness: CWE-59.
Medium [CVE-2026-53910] heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations
heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Red Hat rates this low (CVSS 5.3). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:45327 with package diffutils-main-3.12-6.1.hum1.
Medium [CVE-2026-56416] Heap buffer overflow via malformed DNSSEC record
Heap buffer overflow via malformed DNSSEC record. Red Hat rates this moderate (CVSS 4.8). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Medium [CVE-2026-55991] Denial of Service via crafted DNS-over-QUIC connection
Denial of Service via crafted DNS-over-QUIC connection. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Medium [CVE-2026-55990] Denial of Service via faulty DNSCrypt configuration
Denial of Service via faulty DNSCrypt configuration. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Medium [CVE-2026-52863] Denial of service due to memory corruption under specific configurations.
Denial of service due to memory corruption under specific configurations. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-1098. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Medium [CVE-2026-50251] Denial of Service via crafted DNS glue records
Denial of Service via crafted DNS glue records. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Medium [CVE-2026-14586] Denial of Service via assertion failure in DNS-over-QUIC environments
Denial of Service via assertion failure in DNS-over-QUIC environments. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-617. Red Hat lists fixing advisory RHSA-2026:43588 with package unbound-main-1.25.2-0.1.hum1.
Medium [CVE-2026-16560] heap-buffer-overflow in rdn_av_swap on quoted multivalued RDN
heap-buffer-overflow in rdn_av_swap on quoted multivalued RDN. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1220.