Red Hat Linux Security Advisories & CVEs
5616 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-90463] Local OOB Read in NSS Service Request Parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`)
Local OOB Read in NSS Service Request Parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`). Red Hat rates this low (CVSS 4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-88932] Denial of Service via orphaned disk writes on aborted uploads
Denial of Service via orphaned disk writes on aborted uploads. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-459. Red Hat lists fixing advisory RHSA-2026:72722 with package ansible-automation-platform/automation-portal:1790254963, ansible-automation-platform/automation-portal:1790256405. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Developer Hub; Self-service automation portal 2.
Medium [CVE-2026-90698] Denial of Service due to out-of-bounds read
Denial of Service due to out-of-bounds read. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:63224 with package memcached-main-1.6.45-1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2025-64031] Denial of Service via heap-based buffer overflow in gzip writer
Denial of Service via heap-based buffer overflow in gzip writer. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:43818 with package libarchive-main-3.8.8-3.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-90781] Denial of Service via off-by-one stack buffer overflow
Denial of Service via off-by-one stack buffer overflow. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:40573 with package alsa-lib-main-1.2.16.1-2.hum1, alsa-lib-main-1.2.16.1-2.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: alsa-lib.
Medium [CVE-2026-90771] Prototype Pollution via custom messages
Prototype Pollution via custom messages. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:67610 with package grafana13-1-main-13.1.3-0.9.hum1, grafana13-2-main-13.2.1-0.4.hum1, grafana12-4-main-12.4.10-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Gatekeeper 3; Migration Toolkit for Containers; Red Hat Build of Podman Desktop; and 8 more. Affected products named by the advisory: Red Hat Data Grid 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 4 more.
Medium [CVE-2022-42917] Privilege escalation via TOCTOU race condition
Privilege escalation via TOCTOU race condition. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: frr.
Medium [CVE-2024-53922] Denial of Service in buffer queue driver
Denial of Service in buffer queue driver. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-120. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-52296] out-of-bounds read due to missing required padding in WMA extradata allocation paths
out-of-bounds read due to missing required padding in WMA extradata allocation paths. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-52297] out-of-bounds read due to insufficiently padded extradata in the MOV parsing path
out-of-bounds read due to insufficiently padded extradata in the MOV parsing path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-90555] Denial of Service due to improper audio header validation
Denial of Service due to improper audio header validation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-90554] Denial of Service via video audio extraction
Denial of Service via video audio extraction. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-90461] Information disclosure via unexpected credential transmission
Information disclosure via unexpected credential transmission. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-201. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-89773] Skip Update HDCP Config In Transition State
Skip Update HDCP Config In Transition State. Red Hat rates this low (CVSS 5.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-89771] Fix subbuf resize race with ring buffer readers
Fix subbuf resize race with ring buffer readers. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-89770] don't free integrity payload that doesn't exist
don't free integrity payload that doesn't exist. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89769] Fix IRQ leak on cpuhp_setup_state error path
Fix IRQ leak on cpuhp_setup_state error path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89768] fix user path of nested backing files
fix user path of nested backing files. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-41. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89767] fix double end_creating on the casefold-mismatch path
fix double end_creating() on the casefold-mismatch path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341.
Medium [CVE-2026-89765] Zero-init old itimerval before copy to userspace
Zero-init old itimerval before copy to userspace. Red Hat rates this low (CVSS 5.5). Weakness: CWE-201. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.