Red Hat Linux Security Advisories & CVEs
5466 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Low [CVE-2026-61865] Memory leak in hough lines operation can lead to denial of service
Memory leak in hough lines operation can lead to denial of service. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.
Low [CVE-2026-61866] Memory leak in JNG encoder can lead to denial of service
Memory leak in JNG encoder can lead to denial of service. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.
Low [CVE-2026-61864] Memory leak in color transformation to log colorspace
Memory leak in color transformation to log colorspace. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.
Low [CVE-2026-61863] Memory leak in TIFF encoder
Memory leak in TIFF encoder. Red Hat rates this low (CVSS 2.9). Weakness: CWE-772.
Low [CVE-2026-61862] Information disclosure via out-of-bounds read when displaying profiles with debug enabled
Information disclosure via out-of-bounds read when displaying profiles with debug enabled. Red Hat rates this low (CVSS 2.9). Weakness: CWE-125.
Low [CVE-2026-61860] Denial of Service via use-after-free during freetype initialization
Denial of Service via use-after-free during freetype initialization. Red Hat rates this low (CVSS 3.7). Weakness: CWE-825.
Low [CVE-2026-61464] ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11
ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11. Red Hat rates this low.
Low [CVE-2026-61859] Information disclosure via policy bypass in -script operation
Information disclosure via policy bypass in -script operation. Red Hat rates this low (CVSS 3.3). Weakness: CWE-639.
Low [CVE-2026-56764] Hono - Timing Attack in basicAuth and bearerAuth Middleware
Hono - Timing Attack in basicAuth and bearerAuth Middleware. Red Hat rates this low (CVSS 3.7). Weakness: CWE-208. Red Hat lists fixing advisory RHSA-2026:47618 with package grafana13-1-main-13.1.1-0.2.hum1, grafana12-4-main-12.4.6-0.2.hum1.
Low [CVE-2026-56375] Magick.NET-Q16-OpenMP-arm64: Magick.NET-Q16-OpenMP-x64: Magick.NET-Q16-OpenMP-x86: Magick.NET-Q16-arm64: Magick.NET-Q16-x64: Magick.NET-Q16-x86: Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm64: Ma…
Magick.NET-Q16-OpenMP-arm64: Magick.NET-Q16-OpenMP-x64: Magick.NET-Q16-OpenMP-x86: Magick.NET-Q16-arm64: Magick.NET-Q16-x64: Magick.NET-Q16-x86: Magick.NET-Q8-AnyCPU: Magick.NET-Q8-OpenMP-arm64: Magick.NET-Q8-OpenMP-x64: Magick.NET-Q8-arm64: Magick.NET-Q8-x64: Magick.NET-Q8-x86: ImageMagick: Denial of Service due to memory leak in ASHLAR coder. Red Hat rates this low (CVSS 3.3). Weakness: CWE-770.
Critical [CVE-2026-15773] Use after free in Core
Use after free in Core. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.
Critical [CVE-2026-15775] Insufficient policy enforcement in V8
Insufficient policy enforcement in V8. Red Hat rates this important (CVSS 9.3). Weakness: CWE-346.
Critical [CVE-2026-15774] Use after free in Skia
Use after free in Skia. Red Hat rates this important (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-54058] Memory disclosure or denial of service via crafted McIdas AREA image
Memory disclosure or denial of service via crafted McIdas AREA image. Red Hat rates this important (CVSS 9.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:48021 with package quay/quay-rhel8:1785261506, python-pillow-0:5.1.1-23.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-59733] Unauthorized access to private repositories via directory traversal
Unauthorized access to private repositories via directory traversal. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-22.
High [CVE-2026-50651] SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM
SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41895 with package dotnet8-0-main-8.0.129-2.1.hum1, dotnet9.0-0:9.0.119-1.el9_8, dotnet9.0-0:9.0.119-1.el8_10, dotnet8.0-0:8.0.129-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1.
High [CVE-2026-54572] Arbitrary file write via malicious symbolic link handling
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as.rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4. A remote attacker could exploit this by providing a malicious symlink, allowing subsequent file writes to occur outside the intended destination with content chosen by the attacker. This could lead to unauthorized modification of files on the system. Rclone's -l/--links option serializes symbolic links encountered during a sync as `.rclonelink` text objects containing the link target, and later recreates those links on the destination. Prior to 1.74.4, rclone did not validate that a stored link target stays within the intended destination tree before recreating it. A remote storage backend under an attacker's control can therefore supply a crafted `.rclonelink` object whose target escapes the destination directory (e.g. via a `../` traversal or an absolute path), causing a subsequent write during the same or a later sync to be redirected outside the intended destination with attacker-chosen content.
High [CVE-2026-45363] Authentication bypass due to empty key in HMAC verification
Authentication bypass due to empty key in HMAC verification. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347.
High [CVE-2026-49477] Denial of Service via crafted CSS selector strings
Denial of Service via crafted CSS selector strings. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:34119 with package python-rpds-py-main-2026.6.3-1.hum1, python-attrs-main-26.1.0-3.hum1.
High [CVE-2026-15777] Use after free in UI
Use after free in UI. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.