Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-12259] Installation of attacker-controlled packages due to improper checksum validation
Installation of attacker-controlled packages due to improper checksum validation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-354. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-6695] remote code execution via crafted paa file
A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system. Red Hat Enterprise Linux systems where GIMP is installed and used to process untrusted image files are affected. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-805. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-6694] gimp file-png plugin: denial of service via oversized apng trns chunk
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. When processing a specially crafted APNG image, the plugin may crash due to a stack buffer overflow. As GIMP executes plugins in separate processes, the main application remains unaffected, limiting the impact to the plugin's functionality. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-59652] LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
LDAP filter injection in legacy jdk1.4 LDAPStoreHelper. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-90.
Medium [CVE-2026-18573] Client access-type policy condition bypass during client update
Client access-type policy condition bypass during client update. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862.
Medium [CVE-2026-18572] UMA claim token can override authorization time-policy evaluation attributes
UMA claim token can override authorization time-policy evaluation attributes. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-863.
Medium [CVE-2026-18571] FGAP V2 group assignment bypass during user creation
FGAP V2 group assignment bypass during user creation. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-862.
Medium [CVE-2026-18570] Full-scope-disabled client policy validation bypass via omitted fullScopeAllowed
Full-scope-disabled client policy validation bypass via omitted fullScopeAllowed. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-862.
Medium [CVE-2026-67302] Denial of service in camera redirection due to divide-by-zero
Denial of service in camera redirection due to divide-by-zero. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-369.
Medium [CVE-2026-67306] Out-of-bounds read vulnerability via crafted RDP messages
Out-of-bounds read vulnerability via crafted RDP messages. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-125.
Medium [CVE-2026-67295] Unauthorized File Access via Drive Redirection Vulnerability
Unauthorized File Access via Drive Redirection Vulnerability. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-22.
Medium [CVE-2026-67300] Use-After-Free vulnerability leading to denial of service
Use-After-Free vulnerability leading to denial of service. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-825.
Medium [CVE-2026-67292] Information Disclosure and Denial of Service via WebSocket Ping
Information Disclosure and Denial of Service via WebSocket Ping. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-805.
Medium [CVE-2026-67299] Denial of Service via crafted WindowIcon async message
Denial of Service via crafted WindowIcon async message. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:54487 with package freerdp-2:2.11.7-11.el8_10, freerdp-2:2.11.7-7.el9_8.5, freerdp-2:3.10.3-12.el10_2.8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
Medium [CVE-2026-67318] Denial of Service due to maxBodyLength bypass in HTTP/2 requests
Denial of Service due to maxBodyLength bypass in HTTP/2 requests. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.
Medium [CVE-2026-67315] NO_PROXY bypass allows exposure of local services
NO_PROXY bypass allows exposure of local services. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-115. Red Hat lists fixing advisory RHSA-2026:50826 with package grafana13-1-main-13.1.1-0.5.2.hum1, grafana13-1-main-13.1.1-0.5.hum1.
Medium [CVE-2026-67319] Information disclosure and data manipulation via prototype pollution
Information disclosure and data manipulation via prototype pollution. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:49387 with package grafana13-1-main-13.1.1-0.4.hum1, grafana12-4-main-12.4.6-0.3.hum1.
Medium [CVE-2026-67291] Denial of Service via heap out-of-bounds read
Denial of Service via heap out-of-bounds read. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125.
Medium [CVE-2026-67303] Denial of Service via unsupported serial device control request
Denial of Service via unsupported serial device control request. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-617.
Medium [CVE-2026-67288] Denial of Service via crafted smartcard cache requests
Denial of Service via crafted smartcard cache requests. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.