Red Hat Linux Security Advisories & CVEs
4620 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-76594] Unauthenticated /private/import_content/ endpoint allows global rule-catalogue overwrite
Unauthenticated /private/import_content/ endpoint allows global rule-catalogue overwrite. Red Hat rates this important (CVSS 8.1). Weakness: CWE-306.
High [CVE-2026-76642] failed external mount helper still runs privileged X-mount post-hooks
util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation. When an external mount. helper runs but exits with a nonzero status, libmount still treats the helper invocation as successful and runs privileged post-mount hooks. A local unprivileged user with an /etc/fstab entry that uses the user option together with X-mount.idmap or X-mount.owner/group/mode can cause those hooks to clone or re-own the underlying filesystem after the helper fails, leading to local privilege escalation. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-390. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10. Red Hat lists Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:63162. Affected products named by the advisory: Red Hat package: util-linux.
High [CVE-2026-14199] Session takeover via Auth Proxy cache key collision
Session takeover via Auth Proxy cache key collision. Red Hat rates this important (CVSS 7.1). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:66008 with package grafana13-1-main-13.1.6-0.2.hum1, grafana12-4-main-12.4.10-0.2.hum1. Affected products named by the advisory: Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 3 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; Red Hat Hardened Images.
High [CVE-2026-84335] Incorrect authorization in TabStrip
Incorrect authorization in TabStrip. Red Hat rates this moderate (CVSS 8). Weakness: CWE-272.
High [CVE-2026-84334] Incorrect authorization in Chromoting
Incorrect authorization in Chromoting. Red Hat rates this moderate (CVSS 8.8). Weakness: CWE-266.
High [CVE-2026-84351] Buffer overflow in GPU
Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-787.
High [CVE-2026-84326] Uninitialized resource in V8
Uninitialized resource in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-824.
High [CVE-2026-84347] Use after free in WebRTC
Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.
High [CVE-2026-84349] Use after free in Browser
Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8 (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-416.
High [CVE-2026-84357] Improper input validation in Omnibox
Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High) An improper input validation flaw was found in the Omnibox component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N). Weakness: CWE-346.
High [CVE-2026-81928] Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records
Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:68787 with package perl-Net-DNS-0:1.15-2.el8_10, perl-Net-DNS-0:1.29-6.el9_8.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-84375] Denial of Service vulnerability in YAML parsing
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N * K) processing while totalMergeKeys remains unchanged and the configured resource limit is never reached. A relatively small YAML document can therefore cause prolonged CPU consumption in applications that parse untrusted YAML, and merge processing is enabled by default on these release lines. This issue is fixed in versions 3.15.2 and 4.3.2. An attacker can exploit this by providing a specially crafted YAML document that causes the parser to perform excessive processing when handling merge keys with empty sources. This can lead to prolonged CPU consumption, effectively causing a denial of service (DoS) for applications that process untrusted YAML input. The flaw allows an attacker to craft a small YAML document that, when parsed, can lead to prolonged CPU consumption due to inefficient merge key processing, potentially exhausting system resources. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835.
High [CVE-2026-84639] Uninitialized memory in MIME parsing
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-824. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: thunderbird.
High [CVE-2026-84637] Arbitrary code execution via malicious calendar invitation attachments
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2. This bypasses Thunderbird's built-in protections for executable attachments, potentially leading to arbitrary code execution. Additionally, the attachment could be disguised with a misleading filename, increasing the risk of exploitation. This Important flaw in Thunderbird allows arbitrary code execution when processing malicious calendar invitation attachments. While the vulnerability description highlights a Windows-specific exploitation vector, the underlying issue could still affect Red Hat systems running Thunderbird, potentially leading to system compromise through user interaction with crafted invitations. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-59. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
High [CVE-2026-84361] Arbitrary code execution via malicious Perforce source URL
Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url to an rsh: or jsh: P4PORT value. When the Perforce p4 client was installed and Composer installed the package from source through composer install or composer update, including --prefer-source, Composer\Util\Perforce passed the address to p4 without validation, causing p4 to run a local command with the privileges of the user or CI account. Packagist.org does not permit Perforce source metadata. This issue is fixed in versions 2.2.30 and 2.10.3. By setting `source.type` to `perforce` and `source.url` to an `rsh:` or `jsh:` P4PORT value, an attacker could cause the Perforce `p4` client to execute arbitrary local commands. This could lead to arbitrary code execution with the privileges of the user or continuous integration (CI) account running Composer. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Hardened Images. Red Hat fixing advisory: RHSA-2026:63151.
High [CVE-2022-32149 +1] Quadratic-time DoS via Accept-Language header underscore bypass on unauthenticated login endpoints
A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language. ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' characters but the internal BCP 47 scanner aliases '_' to '-' after the guard check. An unauthenticated attacker can send a crafted Accept-Language header using '_' separators to trigger quadratic-time parsing, consuming excessive CPU and denying authentication to all cluster users. This is an Important denial of service vulnerability in OpenShift Container Platform. Unauthenticated remote attackers can exploit it by sending oversized Accept-Language headers to the OAuth server's login endpoints. This triggers a quadratic-time parsing process, consuming excessive CPU resources and potentially disrupting service availability. The HAProxy ingress router, configured for TLS passthrough on OAuth routes, does not limit HTTP header sizes, allowing the malicious headers to reach the vulnerable component. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-407.
High [CVE-2026-84202] Arbitrary code execution via unsafe YAML deserialization
ModelScope uses PyYAML's unsafe yaml. Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users. A flaw was found in ModelScope. When these files are loaded by a user, it can lead to arbitrary code execution. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-94. Red Hat lists Red Hat OpenShift AI (RHOAI) as not affected.
High [CVE-2026-84268] Gvfs: sftp: heap-based buffer overflow in read_reply
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution. To exploit this issue, an attacker needs a user to connect to a malicious SFTP share (for example, by clicking a crafted sftp:// link or intercepting an unverified connection), limiting its exposure. For these reasons, this vulnerability has been rated with an important severity. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) memory protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-122.
High [CVE-2026-69664] Erlang/OTP inets httpd: Denial of Service via malformed chunked HTTP request
Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hexadecimal number. The worker serving the connection is never released and no timeout reclaims it, so repeating the request across connections occupies every available worker and denies service to legitimate clients. No authentication is required and the default configuration is affected. The chunk-size line must arrive in a write separate from the headers. When the body accompanies the headers, httpd_request_handler:handle_body/3 calls http_chunk:decode/3 inside a try... catch throw:Error, so the {error, {chunk_size, _}} thrown by http_chunk:decode_size/4 is answered with 400 Bad Request. When the chunk size arrives later, the decoder is resumed through a bare catch in httpd_request_handler:handle_info/2, which converts the throw into a return value rather than raising it; the resulting error tuple is then treated as the next decoder continuation, the socket is re-armed, and the worker waits for data that never comes. The request timeout has already been cancelled at the point the headers were accepted, and the periodic byte-rate check is only armed when minimum_bytes_per_second is configured, which it is not by default.
High [CVE-2026-83619] @xmldom/xmldom: xmldom: Denial of Service via crafted XML input
@xmldom/xmldom: xmldom: Denial of Service via crafted XML input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:69248 with package rhdh/rhdh-hub-rhel9:1789554285. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat OpenShift AI (RHOAI); Red Hat package: grafana.