Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-60332] Group Replication GCS unspecified vulnerability (CPU Jul 2026)
Group Replication GCS unspecified vulnerability (CPU Jul 2026). Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-266.
Medium [CVE-2026-60747] Replication unspecified vulnerability (CPU Jul 2026)
Replication unspecified vulnerability (CPU Jul 2026). Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-770.
Medium [CVE-2026-47023] Replication unspecified vulnerability (CPU Jul 2026)
Replication unspecified vulnerability (CPU Jul 2026). Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-770.
Medium [CVE-2026-60183] Clone Plugin unspecified vulnerability (CPU Jul 2026)
Clone Plugin unspecified vulnerability (CPU Jul 2026). Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-266.
Medium [CVE-2026-60585] Replication unspecified vulnerability (CPU Jul 2026)
Replication unspecified vulnerability (CPU Jul 2026). Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-266.
Medium [CVE-2026-15788] Information Disclosure via Improper Handling of NTFS Directory Junctions
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process. A flaw was found in BuildKit. An untrusted user, when authoring a build on a Windows Container on Windows (WCOW) configured BuildKit daemon, can exploit a vulnerability in the cache mount source selector. Red Hat severity: Moderate — CVSS 6.3 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N). Weakness: CWE-22. Affected Red Hat products: Red Hat Hardened Images. Red Hat fixing advisory: RHSA-2026:43122, RHSA-2026:44152, RHSA-2026:46988, RHSA-2026:51065.
Medium [CVE-2026-64194] Net::DNS: Net::DNS: Denial of Service via crafted DNS compression pointers
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call stack (at least with larger TCP responses), leading to a potential Denial of Service. The guard `$link new(\$wire)` i.e. any point where the library decodes a DNS message from the network. A remote attacker can exploit this vulnerability by sending a specially crafted DNS packet with deep compression pointer chains. This can cause excessive recursion in the `Net::DNS::DomainName::decode` function, leading to stack exhaustion and a Denial of Service (DoS) for any application processing untrusted DNS data. Contrary to the CVE description, this issue does not easily trigger an application crash via stack memory exhaustion, as the Perl interpreter h… Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-26199] Denial of Service via buffer underflow in H5Iget_name
Denial of Service via buffer underflow in H5Iget_name. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-124.
Medium [CVE-2026-26197] Out-of-bounds read due to corrupted file can lead to denial of service
Out-of-bounds read due to corrupted file can lead to denial of service. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125.
Medium [CVE-2026-16277] stack buffer overflow in rpcinfo rpcbaddrlist
stack buffer overflow in rpcinfo rpcbaddrlist(). Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-121.
Medium [CVE-2026-15588] GDBusServer pre-authentication DoS via unbounded SASL line buffering
GDBusServer pre-authentication DoS via unbounded SASL line buffering. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:40485 with package glib2-main-2.89.1-1.2.hum1, glib2-main-2.89.1-1.1.hum1, glib2-main-2.89.2-2.hum1.
Medium [CVE-2026-16254] Denial of service via out-of-bounds slice in claircore's apk installed-database parser
Denial of service via out-of-bounds slice in claircore's apk installed-database parser. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125.
Medium [CVE-2026-15813] memory corruption and out-of-bounds access via malformed network packet defragmentation
memory corruption and out-of-bounds access via malformed network packet defragmentation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-787.
Medium [CVE-2026-64206] cancel pending_rx_work before taking conn->lock
cancel pending_rx_work before taking conn->lock. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.
Medium [CVE-2026-64190] fix NULL pointer dereference in team_xmit during mode change
fix NULL pointer dereference in team_xmit during mode change. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-64187] fail recovery on a committed log item with no regions
fail recovery on a committed log item with no regions. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-64205] fix hardware state machine corruption in error path
fix hardware state machine corruption in error path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-826.
Medium [CVE-2026-64173] Do not call map->ops->elt_free if elt_alloc fails
Do not call map->ops->elt_free() if elt_alloc() fails. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341.
Medium [CVE-2026-64121] report ethtool stats over num_tx_queues
report ethtool stats over num_tx_queues. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-64134] Don't setup bogus iov_iter for silencing
Don't setup bogus iov_iter for silencing. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.