Red Hat Linux Security Advisories & CVEs
4619 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-85396] Arbitrary file write via path traversal
Arbitrary file write via path traversal. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22.
High [CVE-2026-85393] Signature forgery vulnerability in RSA PKCS#1 v1.5 verification
Signature forgery vulnerability in RSA PKCS#1 v1.5 verification. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1284. Red Hat lists fixing advisory RHSA-2026:71210 with package ansible-automation-platform-25/lightspeed-rhel8:1789685837, ansible-automation-platform-26/lightspeed-rhel9:1789656884. Affected products named by the advisory: Gatekeeper 3; Node HealthCheck Operator; OpenShift Pipelines; Red Hat Ansible Automation Platform 2; and 19 more. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Build of Podman Desktop; Red Hat Ceph Storage 4; Red Hat Developer Hub; and 15 more.
High [CVE-2026-71221] stack out-of-bounds write via unchecked height in savemeta
stack out-of-bounds write via unchecked height in savemeta. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: gfs2-utils.
High [CVE-2026-71220] stack out-of-bounds write via unchecked di_height in gfs2_edit
stack out-of-bounds write via unchecked di_height in gfs2_edit. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-71223] integer overflow in resource group allocation size on 32-bit platforms
integer overflow in resource group allocation size on 32-bit platforms. Red Hat rates this moderate (CVSS 7). Weakness: CWE-190.
High [CVE-2026-85124] @fastify/http-proxy: @fastify/http-proxy: Information disclosure via path traversal with backslash dot-segments
@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects forward-slash traversal, so a request containing backslash dot-segments can escape the boundary set by the prefix and rewritePrefix options. An unauthenticated network attacker can use this to reach upstream paths that were meant to stay hidden behind the proxy, resulting in disclosure of internal endpoints. Users should upgrade to @fastify/http-proxy 11.6.2 or later. This component, designed to proxy HTTP requests, does not correctly validate incoming request paths, specifically failing to account for backslash-based dot-segments. This allows them to access internal network endpoints that should be protected, leading to the disclosure of sensitive information. This Important flaw in `@fastify/http-proxy` allows an unauthenticated network attacker to bypass proxy path validation using backslash dot-segments. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-22. Affected Red Hat products: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-85150] NULL/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials when parsing a crafted Digest Authorization/WWW-Authenticate header
NULL/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted Digest Authorization/WWW-Authenticate header. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:67145 with package gstreamer1-plugins-base-0:1.16.1-7.el8_10, gstreamer1-plugins-base-0:1.22.12-8.el9_8.2, gstreamer1-plugins-base-0:1.26.7-2.el10_2.2. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-85218] AVRCP ListPlayerAttributes double stack overflow in avrcp_list_player_attributes_rsp/avrcp_get_current_player_value
AVRCP ListPlayerAttributes double stack overflow in avrcp_list_player_attributes_rsp/avrcp_get_current_player_value. Red Hat rates this important (CVSS 7.1). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: bluez.
High [CVE-2026-80726] WARN and clear role.invalid when creating a child shadow page
WARN and clear role.invalid when creating a child shadow page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-84394] Host confusion via unbalanced URI brackets can bypass security policies
Host confusion via unbalanced URI brackets can bypass security policies. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1289. Red Hat lists fixing advisory RHSA-2026:68044 with package grafana13-1-main-13.1.3-0.6.hum1, openshift4/nmstate-console-plugin-rhel9:1789567849, rhmtc/openshift-migration-ui-rhel8:1789546373, devspaces/dashboard-rhel9:1789162884. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.1; Red Hat Ansible Automation Platform 2.2; Red Hat Hardened Images; Migration Toolkit for Applications 8; and 22 more. Affected products named by the advisory: Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; OpenShift Lightspeed; and 18 more.
High [CVE-2026-84292] Authority Injection via Unvalidated Port Serialization
Authority Injection via Unvalidated Port Serialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-140. Red Hat lists fixing advisory RHSA-2026:68044 with package grafana13-1-main-13.1.3-0.6.hum1, openshift4/nmstate-console-plugin-rhel9:1789567849, rhmtc/openshift-migration-ui-rhel8:1789546373, devspaces/dashboard-rhel9:1789162884. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.1; Red Hat Ansible Automation Platform 2.2; Red Hat Hardened Images; Migration Toolkit for Applications 8; and 28 more. Affected products named by the advisory: Migration Toolkit for Containers; Multicluster Engine for Kubernetes; Network Observability Operator; OpenShift Lightspeed; and 24 more.
High [CVE-2026-84382] Denial of Service via streaming response decompression memory amplification
Denial of Service via streaming response decompression memory amplification. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected products named by the advisory: Lightspeed Core; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-84381] WebSocket traffic sent in plaintext via SOCKS5 proxy due to TLS failure
WebSocket traffic sent in plaintext via SOCKS5 proxy due to TLS failure. Red Hat rates this important (CVSS 8.1). Weakness: CWE-319. Affected products named by the advisory: Lightspeed Core; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-84649] Cross-site request forgery token disclosure allows session hijacking
Cross-site request forgery token disclosure allows session hijacking. Red Hat rates this important (CVSS 8.1). Weakness: CWE-201. Affected product named by the advisory: OpenShift Developer Tools and Services.
High [CVE-2026-84647] Unintended configuration object instantiation via form data binding
Unintended configuration object instantiation via form data binding. Red Hat rates this important (CVSS 8.5). Weakness: CWE-915. Affected product named by the advisory: OpenShift Developer Tools and Services.
High [CVE-2026-84838] Command injection in rpmuncompress via unescaped filenames passed to popen
Command injection in rpmuncompress via unescaped filenames passed to popen(). Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Hardened Images; Red Hat package: rpm.
High [CVE-2026-84837] Command Injection in `rpmbuild -t*` (`getTarSpec`) via Unescaped Tarball Path
Command Injection in `rpmbuild -t*` (`getTarSpec`) via Unescaped Tarball Path. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: rpm.
High [CVE-2026-78409] X-mount.subdir detached-tree resolution can escape via intermediate symlinks
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint. Affected versions: util-linux v2.42 through v2.42.2. Earlier releases, including v2.40 and v2.41, are not affected. Restricted-user SUID mount(8) reproduction also requires Linux >= 6.15. Fixed in v2.41.6 and v2.42.3. Red Hat severity: Important — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-59. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:63162.
High [CVE-2026-78410] restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode. X-mount.owner/group/mode was introduced in v2.39; earlier releases are not affected. Fixed in v2.41.6 and v2.42.3. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-367. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10. Red Hat lists Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:63162. Affected products named by the advisory: Red Hat package: util-linux.
High [CVE-2026-78408] nsenter --join-cgroup leaks root cgroup migration authority
The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes. Affected versions: util-linux v2.40 through v2.42.2. Fixed in v2.41.6 and v2.42.3. Red Hat severity: Important — CVSS 7.9 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H). Weakness: CWE-775. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10. Red Hat lists Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:63162. Affected products named by the advisory: Red Hat package: util-linux.