Red Hat Linux Security Advisories & CVEs
4665 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-76219] Arbitrary File Overwrite via `git read-tree` option injection
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file content at attacker-controlled writable paths. A flaw was found in GitPython. By injecting specific options into the `git read-tree` command through methods like `IndexFile.from_tree`, `IndexFile.reset`, and `IndexFile.merge_tree`, without proper option validation or argument separation, an attacker can cause the application to write a git-index blob to any attacker-controlled writable path, leading to data destruction. Red Hat products that bundle GitPython use it as an internal build/automation-time dependency and do not expose these IndexFile treeish arguments to adversary-controlled input; the vulnerable input cannot be controlled by an attacker in these products, so they are marked not affected. GitPython as shipped in Red Hat OpenStack Platform 16.2 and 17.1 contains the vulnerable library code and retains its affected determination. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H). Weakness: CWE-88.
High [CVE-2026-76218] Remote Code Execution via malicious Git hooks
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository. A flaw was found in GitPython. This vulnerability allows a remote attacker to achieve arbitrary code execution. By supplying a specially crafted template parameter to the `Repo.init` function, an attacker can point to a directory containing malicious Git hooks. Red Hat products that bundle GitPython use it as an internal build/automation-time dependency and do not expose the Repo.init template/options parameters to adversary-controlled input; the vulnerable parameter cannot be controlled by an attacker in these products, so they are marked not affected. GitPython as shipped in Red Hat OpenStack Platform 16.2 and 17.1 contains the vulnerable library code and retains its affected determination. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-94. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9; Red Hat Ansible Automation Platform 2.5; Red Hat Ansible Automation Platform 2.6; Red Hat Ansible Automation Platform 2.7; and 1 more.
High [CVE-2020-37267] Information disclosure via unredacted logging of authorization tokens
Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot credentials. Fixed in 23.25.1; Azure DevOps users should revoke and regenerate credentials if logs may have been exposed. A flaw was found in Renovate. This flaw has an IMPORTANT impact on Renovate, which logged authorization tokens without redaction, potentially disclosing them to anyone with access to the log output. The version of Renovate shipped by Red Hat is well beyond the upstream fix (23.25.1); the unredacted-logging code is not present in the shipped version, so Red Hat's product is not affected. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-538.
High [CVE-2024-58376] Renovate 37.158.0 before 37.199.0 Command Injection via helmv3
Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed during helm repo add operations, gaining full access to Renovate's execution environment. This poses a significant risk, particularly in continuous integration/continuous delivery (CI/CD) or development workflows. While exploitation requires an attacker to have commit access to the repository, successful exploitation grants full control over the Renovate execution environment, posing a significant risk in CI/CD or development workflows. Red Hat severity: Important — CVSS 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-78.
High [CVE-2026-43961] Vimscript injection via unescaped filename in netrw s:NetrwMarkFile filter expression allows arbitrary code execution
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim. Important: This Vimscript injection flaw in netrw allows arbitrary code execution with user privileges. Exploitation requires a local attacker to place a specially crafted filename in a directory and a victim to browse that directory with netrw and interact with the malicious entry. This directly impacts the confidentiality, integrity, and availability of the user's data and environment. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-94. Under investigation: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.
High [CVE-2026-76235] unauthenticated remote memory leak via CockpitLang cookie in send_login_html
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service. Red Hat rates this issue as Moderate impact. Although cockpit-ws is reachable by an unauthenticated remote client and the resulting memory exhaustion can be sustained indefinitely, cockpit-ws is a stateless web console component: its crash or restart does not itself compromise the confidentiality or integrity of the host or of other running services, and the process is automatically restarted by systemd. Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-401. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat lists Red Hat OpenShift Dev Spaces as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cockpit.
High [CVE-2026-58081] Heap-based buffer overflow in encoding modules
Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules. A flaw was found in iconv. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-120. Red Hat lists Red Hat Enterprise Linux 9 as not affected.
High [CVE-2026-76038] Remote code execution via type confusion in crafted HTML.
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) A flaw was found in V8, the open-source JavaScript engine used in Google Chrome. Exploitation occurs when a user visits a specially crafted HTML page, leading to potential compromise of the affected system. This vulnerability is rated as Important. A type confusion flaw in the V8 JavaScript engine can lead to remote code execution when processing a specially crafted HTML page. Exploitation requires user interaction, as an attacker must entice a user to visit a malicious website. This primarily impacts desktop environments and applications that render untrusted web content, such as Chromium and applications embedding QtWebEngine. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-843.
High [CVE-2026-76041] Information leak in Skia
Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High) An information leak flaw was found in the Skia component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N). Weakness: CWE-346. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-76047] Arbitrary code execution via type confusion in V8
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) A flaw was found in chromium-browser. A remote attacker could exploit a type confusion vulnerability in the V8 JavaScript engine by enticing a user to visit a specially crafted HTML page. This could allow the attacker to execute arbitrary code within the browser's sandbox, potentially compromising the user's system. Exploitation requires user interaction, specifically visiting a specially crafted HTML page, but the potential for remote code execution elevates its severity. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-843.
High [CVE-2026-76045] Arbitrary code execution via use-after-free
Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) This can be achieved by enticing a user to visit a specially crafted HTML page, leading to a high-severity security risk. This vulnerability is rated Important as it allows a remote attacker to execute arbitrary code within the browser's sandbox by enticing a user to visit a specially crafted HTML page. The use-after-free flaw in WebGL affects the Chromium browser, which is available in Red Hat Community Projects. Successful exploitation could lead to significant impact on confidentiality, integrity, and availability. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-825.
High [CVE-2026-76043] Arbitrary code execution via incorrect calculation in HTML processing
Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) This could lead to arbitrary code execution within the browser's sandbox environment. Exploitation requires user interaction, where a remote attacker could entice a user to visit a specially crafted HTML page. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-190.
High [CVE-2026-76039] Information disclosure via incorrect reference resolution
Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High) A flaw was found in Chromium, specifically in its Core component on Android. By leveraging social engineering and a specially crafted HTML page, an attacker could exploit this flaw to disclose confidential data. While exploitation requires user interaction via social engineering and a crafted HTML page, successful attacks could expose sensitive user information in Red Hat environments utilizing Chromium-based browsers. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N). Weakness: CWE-386.
High [CVE-2026-76040] Arbitrary code execution via use-after-free vulnerability
Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) This could lead to a complete compromise of the affected system. Exploitation requires social engineering to entice a user to visit a specially crafted HTML page, making user interaction a prerequisite for a successful attack. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.
High [CVE-2026-76037] Arbitrary Code Execution via Link Following
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) This vulnerability affects Chromium-based browsers and applications utilizing QtWebEngine in Red Hat Community Projects. Exploitation requires user interaction, such as clicking a malicious link. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-59.
High [CVE-2026-76033] Site isolation bypass due to inappropriate CORS implementation
Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) A flaw was found in Google Chrome's handling of Cross-Origin Resource Sharing (CORS). This could allow the attacker to bypass site isolation, a security feature designed to prevent malicious websites from accessing data from other websites, potentially leading to unauthorized data access. This could lead to unauthorized access to sensitive data from other websites, significantly undermining a core browser security boundary. Red Hat severity: Important — CVSS 8.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-653.
High [CVE-2026-76036] Dawn in Google Chrome: Arbitrary code execution via crafted HTML page
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) This can be achieved by enticing a user to visit a specially crafted HTML page. This occurs when a user visits a specially crafted HTML page, leading to a buffer overflow. The impact is significant due to the potential for arbitrary code execution, even though user interaction is required. Red Hat severity: Important — CVSS 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-120.
High [CVE-2026-15571] Predictable account-linking hash enables account takeover via malicious OIDC client
A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a hash that can be predicted by a malicious OIDC client. By tricking a user into authenticating, an attacker-controlled client can forge a valid linking URL to connect the victim's account to an attacker's external identity. This results in a full account takeover, allowing the attacker to log in as the victim. The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that it enables full account takeover through a predictable security hash. Successful exploitation allows an attacker to link an unauthorized identity to a victim's account and subsequently impersonate that user across the realm. The vulnerability's root cause is the use of predictable session identifiers and client-known metadata in the construction of the account-linking CSRF protection hash. Weakness: CWE-341. Affected Red Hat products: Red Hat build of Keycloak 26.6; Red Hat build of Keycloak 26.6.6. Red Hat lists Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7 as not affected. Red Hat fixing advisory: RHSA-2026:56524, RHSA-2026:56523.
High [CVE-2026-17106] Arbitrary file write via link following in tar extraction
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process. This could lead to unauthorized modification of system files or potentially arbitrary code execution. This Important severity vulnerability in `moby/go-archive` allows for arbitrary file writes during tar extraction. An attacker providing a specially crafted tar archive can exploit symlink following to create or overwrite files outside the intended directory, potentially leading to system compromise in environments processing untrusted archives, such as container build systems. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Logging Subsystem for Red Hat OpenShift 6.6; Multicluster Global Hub 1.8.2; Red Hat Advanced Cluster Management for Kubernetes 2.17; and 18 more.
High [CVE-2026-54552] Incomplete privilege drop allows child processes to retain privileged group access.
sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. When sh runs from an elevated process and launches a command with _uid set to an unprivileged user, the child changes its UID but can retain the parent process's supplementary groups because the privilege-drop sequence does not fully establish the target user's UID, primary GID, and supplementary groups. The child can therefore retain access to files or resources granted to privileged groups such as root, docker, disk, shadow, or sudo, violating the expected _uid privilege boundary. This issue is fixed in version 2.2.4. This incomplete privilege drop can allow the child process to retain access to files or resources granted to privileged groups, leading to unauthorized access and potential privilege escalation. Red Hat severity: Important — CVSS 7.9 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N). Weakness: CWE-273. Red Hat lists Red Hat OpenShift Virtualization 4 as not affected.