Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-14380] Arbitrary code execution via caller-influenced Profile attribute
Arbitrary code execution via caller-influenced Profile attribute. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94.
High [CVE-2026-11610] Heap buffer overflow in sasl_io_recv via padded SASL UNBIND
Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:36209 with package redhat-ds:11-8060020260702180044.0ca98e7e, 389-ds:1.4-8060020260626130540.824efc52, redhat-ds:12-9040020260703055735.1674d574, redhat-ds:11-8100020260702145313.37ed7c03. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.
High [CVE-2026-14474] sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation
sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1188. Red Hat lists fixing advisory RHSA-2026:42122 with package sssd-0:2.9.4-5.el8_10.5, sssd-0:2.9.8-4.el9_8.1, sssd-0:2.12.0-3.el10_2.1, sssd-0:2.10.2-3.el10_0.5. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-14476] GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass
GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass. Red Hat rates this moderate (CVSS 8). Weakness: CWE-23. Red Hat lists fixing advisory RHSA-2026:42122 with package sssd-0:2.9.4-5.el8_10.5, sssd-0:2.9.8-4.el9_8.1, sssd-0:2.12.0-3.el10_2.1, sssd-0:2.10.2-3.el10_0.5. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-58384] integer overflow in read_rle_channel
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-33630] Use-after-free / double-free in query-completion handling
Use-after-free / double-free in query-completion handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42096 with package c-ares-0:1.34.6-2.el10_2, c-ares-main-1.34.7-1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2026-54765] Unauthorized filter context application in Kubernetes Gateway API provider
Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route's filter context to be applied to another route's requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6. The system may incorrectly apply the attacker's route filter context to another route's requests, potentially allowing unauthorized access or information disclosure across different namespaces. This could lead to the application of security-sensitive headers from the attacker's route to legitimate requests, bypassing intended security controls. This Moderate flaw in Traefik's Kubernetes Gateway API provider, as deployed in Red Hat OpenShift Dev Spaces, could allow an attacker to apply their route's filter context to other requests.
High [CVE-2026-55574] Denial of Service via adversarial regular expression in structured outputs API
Denial of Service via adversarial regular expression in structured outputs API. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333.
High [CVE-2026-54234] Denial of Service via malformed speculative decoding workload
Denial of Service via malformed speculative decoding workload. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125.
High [CVE-2026-55379] Denial of Service via crafted BDF font file
Denial of Service via crafted BDF font file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:39127 with package python-pillow-0:5.1.1-22.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-55380] Denial of Service via crafted GD 2.x image file
Denial of Service via crafted GD 2.x image file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1285. Red Hat lists fixing advisory RHSA-2026:39127 with package python-pillow-0:5.1.1-22.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-54060] Denial of Service via excessive memory allocation when processing font files
Denial of Service via excessive memory allocation when processing font files. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:39127 with package python-pillow-0:5.1.1-22.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-54059] Denial of Service via crafted PCF font data
Denial of Service via crafted PCF font data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Red Hat lists fixing advisory RHSA-2026:39127 with package python-pillow-0:5.1.1-22.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-43825] Remote code execution via untrusted Java deserialization
Remote code execution via untrusted Java deserialization. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-502.
High [CVE-2026-59195] Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config. Red Hat rates this important (CVSS 8.2).
High [CVE-2026-59194] patch-remove could delete project-selected files outside the patches directory
patch-remove could delete project-selected files outside the patches directory. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22.
High [CVE-2026-58380] stack buffer overflow in pnmscanner_gettoken
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.
High [CVE-2026-9165] Unbounded GraphQL query depth allows authenticated denial of service
Unbounded GraphQL query depth allows authenticated denial of service. Red Hat rates this important (CVSS 7.7). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:36319 with package advanced-cluster-security/rhacs-main-rhel8:1783357140, advanced-cluster-security/rhacs-main-rhel9:1783352589, advanced-cluster-security/rhacs-main-rhel8:1783357116.
High [CVE-2026-43866] Apache Camel JMS components: Arbitrary Exchange state injection
Apache Camel JMS components: Arbitrary Exchange state injection. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502.
High [CVE-2026-46726] Server-Side Request Forgery and sensitive data exposure
Server-Side Request Forgery and sensitive data exposure. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918.