Red Hat Linux Security Advisories & CVEs
5466 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-58659] Remote code execution via malicious checkpoint files
Remote code execution via malicious checkpoint files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502.
High [CVE-2026-45804] Arbitrary code execution due to trust_remote_code guard bypass
Arbitrary code execution due to trust_remote_code guard bypass. Red Hat rates this important (CVSS 7.5). Weakness: CWE-94.
High [CVE-2026-60005] Memory disclosure and denial of service in ngx_http_slice_module
Memory disclosure and denial of service in ngx_http_slice_module. Red Hat rates this important (CVSS 8.2). Weakness: CWE-824. Red Hat lists fixing advisory RHSA-2026:46012 with package nginx-main-1.30.4-2.hum1.
High [CVE-2026-42533] Arbitrary code execution via crafted HTTP requests
Arbitrary code execution via crafted HTTP requests. Red Hat rates this important (CVSS 7). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:46012 with package nginx-main-1.30.4-2.hum1.
High [CVE-2022-4318 +1] Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env
Fix Bypass for CVE-2022-4318 — /etc/passwd Injection via HOME env. Red Hat rates this important (CVSS 7.8). Weakness: CWE-134.
High [CVE-2026-14251] Missing allowedNamespace check in ReconcilerHook for ClusterRole/Role cases enables potential privilege escalation and DoS
Missing allowedNamespace check in ReconcilerHook for ClusterRole/Role cases enables potential privilege escalation and DoS. Red Hat rates this important (CVSS 7.7). Weakness: CWE-862.
High [CVE-2026-30623] Remote code execution via unvalidated MCP server configuration
Remote code execution via unvalidated MCP server configuration. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78.
High [CVE-2026-38974] Missing SSH host key verification allows potential impersonation
Missing SSH host key verification allows potential impersonation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-322.
High [CVE-2026-14957] badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process
badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-617. Red Hat lists fixing advisory RHSA-2026:46397 with package libreswan-0:5.3.2-1.el9fdp, libreswan-0:5.3.2-1.el10_2, libreswan-0:4.15-10.el9_8, libreswan-0:4.12-2.el8_10.6. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.
Medium [CVE-2026-56434] Heap buffer over-read allows memory modification or denial of service
Heap buffer over-read allows memory modification or denial of service. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:46012 with package nginx-main-1.30.4-2.hum1.
Medium [CVE-2026-15779] pam_winbind mkhomedir chowns critical system paths without validation
pam_winbind mkhomedir chowns critical system paths without validation. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-732.
Medium [CVE-2026-15812] access control list bypass via link ID spoofing on unencrypted dynamic links
access control list bypass via link ID spoofing on unencrypted dynamic links. Red Hat rates this low (CVSS 4.8). Weakness: CWE-290.
Medium [CVE-2026-15811] encryption key exposure in memory after cryptographic configuration changes
encryption key exposure in memory after cryptographic configuration changes. Red Hat rates this low (CVSS 5.8). Weakness: CWE-212.
Medium [CVE-2026-38755] Denial of Service via heap overflow in evalcommand function
Denial of Service via heap overflow in evalcommand() function. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:42074 with package busybox-main-1.37.0-8.2.hum1.
Medium [CVE-2026-38752] Denial of Service via crafted AWK script
Denial of Service via crafted AWK script. Red Hat rates this moderate (CVSS 6.5). Red Hat lists fixing advisory RHSA-2026:42074 with package busybox-main-1.37.0-8.2.hum1.
Low [CVE-2026-61872] Denial of Service due to memory leak in TIFF encoder
Denial of Service due to memory leak in TIFF encoder. Red Hat rates this low (CVSS 2.5). Weakness: CWE-772.
Low [CVE-2026-61871] Denial of Service via memory leak in ICON decoder
Denial of Service via memory leak in ICON decoder. Red Hat rates this low (CVSS 3.7). Weakness: CWE-772.
Low [CVE-2026-61869] Denial of Service via memory leak in MIFF encoder
Denial of Service via memory leak in MIFF encoder. Red Hat rates this low (CVSS 2.9). Weakness: CWE-770.
Low [CVE-2026-61868] Denial of Service due to memory leak in YUV decoder
Denial of Service due to memory leak in YUV decoder. Red Hat rates this low (CVSS 3.7). Weakness: CWE-772.
Low [CVE-2026-61867] Denial of Service due to memory leak in TIFF encoder
Denial of Service due to memory leak in TIFF encoder. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.