Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-20216] Denial of Service via crafted InstallShield file
Denial of Service via crafted InstallShield file. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-20213] Denial of Service via crafted Portable Executable (PE) files
Denial of Service via crafted Portable Executable (PE) files. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-20214] Denial of Service via crafted FSG file parsing
Denial of Service via crafted FSG file parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-24260] Privilege escalation and code execution via race condition
Privilege escalation and code execution via race condition. Red Hat rates this important (CVSS 8.5). Weakness: CWE-367.
High [CVE-2026-5136] Privilege escalation to administrator-level access via usergroup role assignment manipulation
Privilege escalation to administrator-level access via usergroup role assignment manipulation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:34366 with package foreman-0:3.14.0.17-1.el9sat, foreman-0:3.18.0.7-1.el9sat, foreman-0:3.12.0.17-1.el9sat, foreman-0:3.12.0.17-1.el8sat. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-56016] Authentication bypass via predictable session IDs
Authentication bypass via predictable session IDs. Red Hat rates this important (CVSS 7.4). Weakness: CWE-331.
High [CVE-2026-57963] Chat UI manipulation by injection
An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1. Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-79. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9 as not affected.
High [CVE-2026-53488] Host-root command execution via unvalidated image config labels in CRI plugin
Host-root command execution via unvalidated image config labels in CRI plugin. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:37252 with package multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1784060681, rhacm2/submariner-rhel9-operator:1782933193, multicluster-engine/assisted-service-8-rhel8:1783332008, multicluster-globalhub/multicluster-globalhub-agent-rhel9:1784127491.
High [CVE-2026-53341] fix UAF due to unlocked ->mnt_ns read in may_decode_fh
fix UAF due to unlocked ->mnt_ns read in may_decode_fh(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-364.
High [CVE-2026-53354] Mitigate TLBI errata on various Arm CPUs
Mitigate TLBI errata on various Arm CPUs. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1037.
High [CVE-2026-53355] clear i_sends on setup unwind
clear i_sends on setup unwind. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-54903] Heap corruption and Denial of Service via integer overflow in JSON parsing
Heap corruption and Denial of Service via integer overflow in JSON parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-54900] Heap corruption via crafted JSON object key
Heap corruption via crafted JSON object key. Red Hat rates this important (CVSS 7.5). Weakness: CWE-131.
High [CVE-2026-54897] Use-After-Free in Oj::Doc Iterators via reentrant close
Use-After-Free in Oj::Doc Iterators via reentrant close. Red Hat rates this important (CVSS 7.8). Weakness: CWE-364.
High [CVE-2026-54896] Heap buffer overflow in exception serialization
Heap buffer overflow in exception serialization. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787.
High [CVE-2026-54592] Denial of Service via deeply nested JSON input
Denial of Service via deeply nested JSON input. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-55223] Remote code execution via deserialization vulnerability
Remote code execution via deserialization vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502.
High [CVE-2026-54672] Arbitrary code execution through AppImage library loading vulnerability
Arbitrary code execution through AppImage library loading vulnerability. Red Hat rates this important (CVSS 7.3). Weakness: CWE-427.
High [CVE-2026-58014] off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 1 more. Affected products named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-58374] Denial of Service via malformed Wi-Fi 7 Multi-Link Operation association request
Denial of Service via malformed Wi-Fi 7 Multi-Link Operation association request. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-787.