Red Hat Linux Security Advisories & CVEs
5472 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Low [CVE-2026-60190] Replication unspecified vulnerability (CPU Jul 2026)
Replication unspecified vulnerability (CPU Jul 2026). Red Hat rates this low (CVSS 2.2). Weakness: CWE-770.
Low [CVE-2026-61096] Pluggable Auth unspecified vulnerability (CPU Jul 2026)
Pluggable Auth unspecified vulnerability (CPU Jul 2026). Red Hat rates this low (CVSS 2.9). Weakness: CWE-266.
Critical [CVE-2026-64193] Net::DNS: Net::DNS: Arbitrary code execution via EDNS EXTENDED ERROR handling
Net::DNS: Net::DNS: Arbitrary code execution via EDNS EXTENDED ERROR handling. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-78.
Critical [CVE-2026-12701] relative_path_validator bypass via directory traversal in FilesystemExport
relative_path_validator bypass via directory traversal in FilesystemExport. Red Hat rates this important (CVSS 9). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:42079 with package python3.12-pulpcore-0:3.49.63-2.el9ap, ansible-automation-platform-26/hub-rhel9:1783979593, python-pulpcore-0:3.49.39-2.el9pc, python3.12-pulpcore-0:3.85.15-5.el9pc. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
Critical [CVE-2026-16242] Konnectivity proxy-server accepts agent connections without validating client certificates
Konnectivity proxy-server accepts agent connections without validating client certificates. Red Hat rates this critical (CVSS 9.4). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:48284 with package multicluster-engine/hypershift-rhel9-operator:1784856942, multicluster-engine/hypershift-rhel9-operator:1784905769, openshift4/ose-hypershift-rhel9:1785192936, multicluster-engine/hypershift-rhel9-operator:1784905804.
High [CVE-2026-55833] Denial of Service via SPDY header decompression amplification
Denial of Service via SPDY header decompression amplification. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:47172 with package netty-codec-http.
High [CVE-2026-55831] Denial of Service via SPDY SETTINGS frame processing
Denial of Service via SPDY SETTINGS frame processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:47172 with package netty-codec-http.
High [CVE-2026-64624] Arbitrary code execution via malicious RDP files
Arbitrary code execution via malicious RDP files. Red Hat rates this important (CVSS 7.3). Weakness: CWE-88.
High [CVE-2026-64612] Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malformed png
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-248. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-39879] SQL Injection vulnerability leading to denial of service and data manipulation
SQL Injection vulnerability leading to denial of service and data manipulation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-150.
High [CVE-2026-64621] Double-free vulnerability via crafted.rdp file leading to potential remote code execution
Double-free vulnerability via crafted.rdp file leading to potential remote code execution. Red Hat rates this important (CVSS 7.3). Weakness: CWE-1341.
High [CVE-2026-64620] Remote code execution or denial of service via heap-based buffer overflow
Remote code execution or denial of service via heap-based buffer overflow. Red Hat rates this important (CVSS 8.1). Weakness: CWE-120.
High [CVE-2026-50540] Arbitrary code execution via manipulated configuration path
Arbitrary code execution via manipulated configuration path. Red Hat rates this important (CVSS 8.8). Weakness: CWE-20.
High [CVE-2026-64191] Reject I2C block transfers with invalid length
Reject I2C block transfers with invalid length. Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-64192] Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476.
High [CVE-2026-64189] fix race between dump and ip_set_list resize
fix race between dump and ip_set_list resize. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
Medium [CVE-2026-15788] Information Disclosure via Improper Handling of NTFS Directory Junctions
Information Disclosure via Improper Handling of NTFS Directory Junctions. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:44152 with package trivy-main-0.72.0-0.1.2.hum1, buildah-main-1.44.0-3.2.hum1, buildah-main-1.45.0-2.hum1, podman-main-6.0.2-2.1.hum1.
Medium [CVE-2026-64194] Net::DNS: Net::DNS: Denial of Service via crafted DNS compression pointers
Net::DNS: Net::DNS: Denial of Service via crafted DNS compression pointers. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-770.
Medium [CVE-2026-26199] Denial of Service via buffer underflow in H5Iget_name
Denial of Service via buffer underflow in H5Iget_name. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-124.
Medium [CVE-2026-26197] Out-of-bounds read due to corrupted file can lead to denial of service
Out-of-bounds read due to corrupted file can lead to denial of service. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125.