Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-57280] Sandbox bypass leading to arbitrary code execution
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection. By exploiting a failure to properly intercept implicit type casts in typed for-each loops, an attacker can invoke arbitrary constructors, potentially leading to arbitrary code execution within the Jenkins environment. Red Hat rates this as an Important vulnerability in the Jenkins Script Security Plugin. The scope is unchanged (S:U) because the sandbox and the Jenkins controller share the same security authority — a sandbox escape executes code in the same context rather than crossing a trust boundary to a separate system. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-1287. Affected Red Hat products: OpenShift Developer Tools and Services. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-52924] purge outqueue on stale COOKIE-ECHO handling
purge outqueue on stale COOKIE-ECHO handling. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-52943] fix missing zerocopy reference in pskb_carve helpers
fix missing zerocopy reference in pskb_carve helpers. Red Hat rates this important (CVSS 7.8). Weakness: CWE-911.
High [CVE-2026-52950] fix UAF with retry loop
fix UAF with retry loop. Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-52951] handle empty bo and UAF races
handle empty bo and UAF races. Red Hat rates this important (CVSS 7). Weakness: CWE-476.
High [CVE-2026-52952] Fix WARN_ON in __iommu_group_set_domain_nofail due to reset
Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset. Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-52969] Reject wrapped offset in kvm_reset_dirty_gfn
Reject wrapped offset in kvm_reset_dirty_gfn(). Red Hat rates this important (CVSS 7). Weakness: CWE-190.
High [CVE-2026-52972] af_alg - Cap AEAD AD length to 0x80000000
af_alg - Cap AEAD AD length to 0x80000000. Red Hat rates this important (CVSS 7). Weakness: CWE-190.
High [CVE-2026-52973] Drop CLONE_THREAD requirement for private default hash alloc
Drop CLONE_THREAD requirement for private default hash alloc. Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-52976] Fix error cleanup in xe_exec_queue_create_ioctl
Fix error cleanup in xe_exec_queue_create_ioctl(). Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-52987] avoid double drm_exec_fini in userq validate
avoid double drm_exec_fini() in userq validate. Red Hat rates this important (CVSS 7). Weakness: CWE-1341.
High [CVE-2026-52989] propagate nvmet_tcp_build_pdu_iovec errors to its callers
propagate nvmet_tcp_build_pdu_iovec() errors to its callers. Red Hat rates this important (CVSS 7). Weakness: CWE-390.
High [CVE-2026-52991] fix race between file release and pressure write
fix race between file release and pressure write. Red Hat rates this important (CVSS 7). Weakness: CWE-367.
High [CVE-2026-52993] fix double-free in tipc_buf_append
fix double-free in tipc_buf_append(). Red Hat rates this important (CVSS 7). Weakness: CWE-763.
High [CVE-2026-53000] use kfree_rcu to release ops
use kfree_rcu to release ops. Red Hat rates this important (CVSS 7). Weakness: CWE-763.
High [CVE-2026-53002] remove sprintf usage
remove sprintf usage. Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-53006] fix possible UAF in icmpv6_rcv
fix possible UAF in icmpv6_rcv(). Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-53009] fix double-free of tx_buf skb
fix double-free of tx_buf skb. Red Hat rates this moderate (CVSS 7). Weakness: CWE-416.
High [CVE-2026-53016] ccp - copy IV using skcipher ivsize
ccp - copy IV using skcipher ivsize. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:39494 with package kernel-0:5.14.0-687.25.1.el9_8, kernel-0:6.12.0-211.34.1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-53071] Add missing chan lock in l2cap_ecred_reconf_rsp
Add missing chan lock in l2cap_ecred_reconf_rsp. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-416.