Red Hat Linux Security Advisories & CVEs
11218 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-63278] Information disclosure via crafted URLs expanding environment variables
Information disclosure via crafted URLs expanding environment variables. Red Hat rates this moderate (CVSS 5). Weakness: CWE-914.
Medium [CVE-2026-63273] Denial of Service via malformed encrypted PDF import
Denial of Service via malformed encrypted PDF import. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-120.
Medium [CVE-2026-63272] Heap buffer overflow in WMF text record import
Heap buffer overflow in WMF text record import. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-787.
Medium [CVE-2026-95503] Potential KDC spoofing bypass when Kerberos password authentication is enabled
Potential KDC spoofing bypass when Kerberos password authentication is enabled. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-347. Affected products named by the advisory: Red Hat Build of Keycloak; Red Hat Single Sign-On 7.
Medium [CVE-2026-95507] out-of-bounds read in NC-SI OEM response handler discloses host memory to guest
out-of-bounds read in NC-SI OEM response handler discloses host memory to guest. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125.
Medium [CVE-2026-74765] Net::IDN::Punycode: Net::IDN::Punycode: Information disclosure or denial of service via integer overflow
Net::IDN::Punycode: Net::IDN::Punycode: Information disclosure or denial of service via integer overflow. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125.
Medium [CVE-2026-95516] heap-buffer-overflow write in Structured-Append QR text extraction
heap-buffer-overflow write in Structured-Append QR text extraction. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.
Medium [CVE-2026-88340] Memory corruption and denial of service via specially crafted rule files
Memory corruption and denial of service via specially crafted rule files. Red Hat rates this moderate (CVSS 5). Weakness: CWE-763. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: yara.
Medium [CVE-2026-88341] Denial of Service via crafted compiled rule file
Denial of Service via crafted compiled rule file. Red Hat rates this moderate (CVSS 5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: yara.
Medium [CVE-2026-75432] Sensitive information disclosure via scanner component
Sensitive information disclosure via scanner component. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201.
Medium [CVE-2026-79312] Missing session ID rotation after authentication leads to session fixation
Missing session ID rotation after authentication leads to session fixation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-384.
Medium [CVE-2026-79311] Missing autoescape in render_jinja leads to Cross-Site Scripting (XSS)
Missing autoescape in render_jinja leads to Cross-Site Scripting (XSS). Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-79.
Low [CVE-2026-93402] imdtls permitted-peer authorization bypass
imdtls permitted-peer authorization bypass. Red Hat rates this low (CVSS 3.1). Weakness: CWE-287.
Critical [CVE-2026-78847] arbitrary code execution via eval in front matter parsing
arbitrary code execution via eval in front matter parsing. Red Hat rates this important (CVSS 9.8). Weakness: CWE-94. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-94627] Denial of Service via GPU memory exhaustion
Denial of Service via GPU memory exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-94626] Denial of Service via unvalidated memory allocation parameter
Denial of Service via unvalidated memory allocation parameter. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-94625] Resource exhaustion via rejected prefill requests
Resource exhaustion via rejected prefill requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-94624] Denial of Service via unbounded P2P KV offloading sessions
Denial of Service via unbounded P2P KV offloading sessions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-94623] Denial of Service via NIXL multi-prompt assertion failure
Denial of Service via NIXL multi-prompt assertion failure. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-94622] Denial of Service via Incomplete NIXL KV Transfer Metadata
Denial of Service via Incomplete NIXL KV Transfer Metadata. Red Hat rates this important (CVSS 7.5). Weakness: CWE-248. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).