Red Hat Linux Security Advisories & CVEs
5547 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-64570] fix fils_discovery double free on alloc failure
fix fils_discovery double free on alloc failure. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9.
Low [CVE-2026-18839] size_t underflow in singleOptionHelp
size_t underflow in singleOptionHelp. Red Hat rates this low (CVSS 2.2). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
Unknown [CVE-2026-64566] propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags
propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags(). Red Hat rates this a security issue. Weakness: CWE-821.
Unknown [CVE-2026-64571] validate RX frame length in p54_rx_eeprom_readback
validate RX frame length in p54_rx_eeprom_readback(). Red Hat rates this a security issue. Weakness: CWE-125.
Unknown [CVE-2026-64578] validate compound request size before reading StructureSize2
validate compound request size before reading StructureSize2. Red Hat rates this a security issue. Weakness: CWE-125.
High [CVE-2026-56848] Heap-use-after-free in HTTP/2 handling can lead to denial of service
Heap-use-after-free in HTTP/2 handling can lead to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-15307] Remote code execution via GeoDjango spatial lookups
Remote code execution via GeoDjango spatial lookups. Red Hat rates this important (CVSS 8.8). Weakness: CWE-434. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 5 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; Red Hat Update Infrastructure 5; and 1 more.
High [CVE-2026-68494] Denial of Service via incomplete fix in async JSON parser
Denial of Service via incomplete fix in async JSON parser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Cryostat 4; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 28 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel 4 for Quarkus 3; and 24 more.
High [CVE-2026-42169] GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c)
GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c). Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:50817 with package gimp-2:3.0.4-4.el9_8.9. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-56846] Remote memory exhaustion via HTTP/2 retained header blocks
Remote memory exhaustion via HTTP/2 retained header blocks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:48305 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.
High [CVE-2026-42170] GIMP DDS plug-in heap-based buffer overflow via BPP mismatch in load_layer (ddsread.c)
GIMP DDS plug-in heap-based buffer overflow via BPP mismatch in load_layer() (ddsread.c). Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.
High [CVE-2026-64561] Check for invalid/obsolete root *after* making MMU pages available
Check for invalid/obsolete root *after* making MMU pages available. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:45192 with package kernel-0:5.14.0-687.30.1.el9_8, kernel-0:6.12.0-55.94.1.el10_0, kernel-0:4.18.0-553.147.1.el8_10, kernel-0:5.14.0-427.141.1.el9_4. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; and 1 more.
High [CVE-2026-67855] Denial of Service via heap use-after-free
Denial of Service via heap use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.
High [CVE-2026-67857] Denial of Service via out-of-bounds read in client-side function
Denial of Service via out-of-bounds read in client-side function. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125.
High [CVE-2026-51401] Arbitrary code execution via vms_fixfilename function
Arbitrary code execution via vms_fixfilename() function. Red Hat rates this important (CVSS 7.8). Weakness: CWE-641.
High [CVE-2026-67858] Denial of Service via buffer overflow in Local Discovery Server
Denial of Service via buffer overflow in Local Discovery Server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-67859] Denial of Service via Discovery/LDS handling
Denial of Service via Discovery/LDS handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-67862] Denial of Service via buffer-overflow
Denial of Service via buffer-overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-8400] Arbitrary class loading and instantiation via malicious IIOP server
Arbitrary class loading and instantiation via malicious IIOP server. Red Hat rates this important (CVSS 8.1). Weakness: CWE-470. Red Hat lists fixing advisory RHSA-2026:52949 with package java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-64564] don't free the ASCONF's own transport in DEL-IP processing
don't free the ASCONF's own transport in DEL-IP processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825.