Red Hat Linux Security Advisories & CVEs
5472 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2024-5300] Canonical snapd: Information disclosure of system password hashes via AppArmor bypass
Canonical snapd: Information disclosure of system password hashes via AppArmor bypass. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-1220. Red Hat lists fixing advisory RHSA-2026:29009 with package systemd-main-261-2.hum1.
Medium [CVE-2026-59848] denial of service via SFTP responses with unknown request IDs
denial of service via SFTP responses with unknown request IDs. Red Hat rates this moderate (CVSS 5.3). Red Hat lists fixing advisory RHSA-2026:42922 with package libssh-main-0.12.1-4.hum1.
Medium [CVE-2026-59847] integrity downgrade via OpenSSL AES-GCM tag verification
integrity downgrade via OpenSSL AES-GCM tag verification. Red Hat rates this moderate (CVSS 5.9). Red Hat lists fixing advisory RHSA-2026:42922 with package libssh-main-0.12.1-4.hum1.
Medium [CVE-2026-16401] Privilege escalation in the Data Loss Prevention component
Privilege escalation in the Data Loss Prevention component. Red Hat rates this moderate (CVSS 6.1).
Medium [CVE-2026-16402] Integer overflow in the Graphics: ImageLib component
Integer overflow in the Graphics: ImageLib component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-190.
Medium [CVE-2026-16400] Information disclosure in the DOM: Security component
Information disclosure in the DOM: Security component. Red Hat rates this moderate (CVSS 6.1).
Medium [CVE-2026-16399] Site isolation issue in the DOM: Navigation component
Site isolation issue in the DOM: Navigation component. Red Hat rates this moderate (CVSS 6.1).
Medium [CVE-2026-16398] Site isolation issue in the Graphics component
Site isolation issue in the Graphics component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-653.
Medium [CVE-2026-16397] Clickjacking issue in the WebExtensions component in Firefox for Android
Clickjacking issue in the WebExtensions component in Firefox for Android. Red Hat rates this moderate (CVSS 6.1).
Medium [CVE-2026-16396] Privilege escalation in WebExtensions
Privilege escalation in WebExtensions. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10, firefox-0:140.13.0-1.el9_8, thunderbird-0:140.13.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-16395] Integer overflow in the Audio/Video component
Integer overflow in the Audio/Video component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-190.
Medium [CVE-2026-16394] Mitigation bypass in the DOM: Security component
Mitigation bypass in the DOM: Security component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-358.
Medium [CVE-2026-16359] Incorrect boundary conditions in the Audio/Video: GMP component
Incorrect boundary conditions in the Audio/Video: GMP component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10, firefox-0:140.13.0-1.el9_8, thunderbird-0:140.13.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-16393] Incorrect boundary conditions in the Graphics: WebGPU component
Incorrect boundary conditions in the Graphics: WebGPU component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125.
Medium [CVE-2026-16392] JIT miscompilation in the JavaScript Engine: JIT component
JIT miscompilation in the JavaScript Engine: JIT component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-733.
Medium [CVE-2026-16390] Mitigation bypass in the Enterprise Policies component
Mitigation bypass in the Enterprise Policies component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-1220. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10, firefox-0:140.13.0-1.el9_8, thunderbird-0:140.13.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-16391] Information disclosure in the Storage: IndexedDB component
Information disclosure in the Storage: IndexedDB component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-312. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10, firefox-0:140.13.0-1.el9_8, thunderbird-0:140.13.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-16389] Incorrect boundary conditions, integer overflow in the Libraries component in NSS
Incorrect boundary conditions, integer overflow in the Libraries component in NSS. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787.
Medium [CVE-2026-16388] Sandbox escape in the DOM: Networking component
Sandbox escape in the DOM: Networking component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-653.
Medium [CVE-2026-16387] Site isolation issue in the Networking component
Site isolation issue in the Networking component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10, firefox-0:140.13.0-1.el9_8, thunderbird-0:140.13.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.