Red Hat Linux Security Advisories & CVEs
4426 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-88920] Authentication bypass via unsigned SAML sender-vouches assertion
Authentication bypass via unsigned SAML sender-vouches assertion. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 3 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7.
High [CVE-2026-103242] Heap-based buffer overflow write in hex2binv via a mistyped RPMTAG_FILESIGNATURES header tag
Heap-based buffer overflow write in hex2binv() via a mistyped RPMTAG_FILESIGNATURES header tag. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 16 more. Affected products named by the advisory: Red Hat package: python3-rpm; Red Hat package: rpm-apidocs; Red Hat package: rpm-build-libs; Red Hat package: rpm-cron; and 12 more.
High [CVE-2026-62146] Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket
A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape. This affects CRI-O versions that persist reserved sandbox metadata together with untrusted pod annotations/labels without validating or namespacing them separately and that reload this state as trusted after a restart, including products that bundle CRI-O as their runtime (e.g., OpenShift Container Platform nodes); exploitation requires pod-creation access plus a subsequent CRI-O restart/node reboot and container recreate, so affected-version and exposure-window details will be confirmed once upstream triage completes Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-501. Red Hat does not currently list a fixing RHSA for this CVE. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-93994] Authentication bypass via duplicate public key presentation
Authentication bypass via duplicate public key presentation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-303. Red Hat lists fixing advisory RHSA-2026:71541 with package maven3-9-main-3.9.16-0.3.hum1. Affected products named by the advisory: OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Enterprise Linux 10; and 10 more. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 6 more.
High [CVE-2026-94002] Denial of Service via unsolicited SFTP replies
Denial of Service via unsolicited SFTP replies. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apicurio Registry 3; Red Hat Fuse 7.
High [CVE-2026-92870] Denial of Service via stack-based buffer overflow
Denial of Service via stack-based buffer overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-92867] arbitrary code execution via out-of-bounds write
arbitrary code execution via out-of-bounds write. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-103111] Out-of-bounds write via crafted regular expression
Out-of-bounds write via crafted regular expression. Red Hat rates this important (CVSS 7.6). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:74972 with package pcre2-main-10.49-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 6 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: mariadb10.11; Red Hat package: mariadb11.8; and 2 more.
High [CVE-2026-102938] Arbitrary code execution via configuration injection in prompt values
Arbitrary code execution via configuration injection in prompt values. Red Hat rates this moderate (CVSS 7). Weakness: CWE-93. Affected products named by the advisory: OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 8; Red Hat OpenShift AI (RHOAI); and 4 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; Self-service automation portal 2.
High [CVE-2026-102937] Arbitrary code execution via unescaped prompt in Windows activation script
Arbitrary code execution via unescaped prompt in Windows activation script. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 8; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 3 more. Affected products named by the advisory: Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; Self-service automation portal 2.
High [CVE-2026-102930] Arbitrary code execution via unverified downloaded seed wheels
Arbitrary code execution via unverified downloaded seed wheels. Red Hat rates this important (CVSS 7.5). Weakness: CWE-494. Affected products named by the advisory: OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 8; Red Hat OpenShift AI (RHOAI); and 4 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; Self-service automation portal 2.
High [CVE-2026-102925] Arbitrary code execution via crafted paths in activation scripts
Arbitrary code execution via crafted paths in activation scripts. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94. Affected products named by the advisory: OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 8; Red Hat OpenShift AI (RHOAI); and 4 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6; Self-service automation portal 2.
High [CVE-2026-102253] Denial of Service via UDP receive worker infinite loop
Denial of Service via UDP receive worker infinite loop. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: iperf3.
High [CVE-2026-102327] Incorrect authorization in WebView
Incorrect authorization in WebView. Red Hat rates this important (CVSS 8.3). Weakness: CWE-653.
High [CVE-2026-102321] Type confusion in V8
Type confusion in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843.
High [CVE-2026-102302] Buffer overflow in V8
Buffer overflow in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-102315] Uninitialized resource in Media
Uninitialized resource in Media. Red Hat rates this important (CVSS 7.4). Weakness: CWE-908.
High [CVE-2026-102301] Out of bounds write in GPU
Out of bounds write in GPU. Red Hat rates this important (CVSS 8.3). Weakness: CWE-787.
High [CVE-2026-102329] Cross-site scripting in WebUI
Cross-site scripting in WebUI. Red Hat rates this important (CVSS 8.8). Weakness: CWE-79.
High [CVE-2026-102318] Out of bounds read in WebGL
Out of bounds read in WebGL. Red Hat rates this important (CVSS 7.4). Weakness: CWE-125.