Red Hat Linux Security Advisories & CVEs
5455 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2026-43713] Visiting a website may leak sensitive data
Visiting a website may leak sensitive data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-43721] A malicious website may silently hijack clipboard data
A malicious website may silently hijack clipboard data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-732. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-43732] Maliciously crafted web content may disclose sensitive user information
Maliciously crafted web content may disclose sensitive user information. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-43740] Maliciously crafted web content may disclose process memory
Maliciously crafted web content may disclose process memory. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-59180] Information disclosure via HTTP redirect following with credential resending
Information disclosure via HTTP redirect following with credential resending. Red Hat rates this low (CVSS 3.1). Weakness: CWE-201.
Low [CVE-2026-56366] Denial of Service via memory leak in APP1JPEG image processing
Denial of Service via memory leak in APP1JPEG image processing. Red Hat rates this low (CVSS 3.3). Weakness: CWE-772.
Unknown [CVE-2026-53363] preserve shared-frag marker in iptfs_consume_frags
preserve shared-frag marker in iptfs_consume_frags(). Red Hat rates this a security issue. Weakness: CWE-821.
High [CVE-2026-15308] CPU Denial of Service in HTML parser via repeated unterminated markup declarations
CPU Denial of Service in HTML parser via repeated unterminated markup declarations. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:44481 with package discovery/discovery-ui-rhel9:1784821750, python3-12-main-3.12.13-3.5.hum1, python3.12-0:3.12.13-3.el8_10, python3.12-0:3.12.13-3.el9_8.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
High [CVE-2026-58459] Command Injection via GPS device subtype allows arbitrary code execution
Command Injection via GPS device subtype allows arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.
High [CVE-2026-12080] Local privilege escalation via symlink attack in guest-ssh-add-authorized-keys
Local privilege escalation via symlink attack in guest-ssh-add-authorized-keys. Red Hat rates this important (CVSS 7.3). Weakness: CWE-61.
High [CVE-2026-39246] arbitrary symlink creation during archive extraction leads to information disclosure
arbitrary symlink creation during archive extraction leads to information disclosure. Red Hat rates this important (CVSS 7.5). Weakness: CWE-61.
High [CVE-2026-56818] Memory leak in netty-codec-redis
A flaw was found in the Netty `netty-codec-redis` component. This vulnerability allows a remote attacker to cause a denial of service (DoS) by sending specially crafted Redis protocol frames over long-lived connections. The Redis decoder fails to properly release allocated memory, leading to memory exhaustion and application instability. The memory leak in long-lived Redis connections can lead to JVM heap exhaustion, making the service unavailable. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-772. Affected Red Hat products: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7. Will not fix / out of support: Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-56822] Time-of-check/time-of-use in netty-handler-ssl-ocsp
A flaw was found in Netty's `netty-handler-ssl-ocsp` component. This vulnerability involves a time-of-check/time-of-use (TOCTOU) race condition within the OCSP stapling validator. A remote attacker could exploit this timing window, allowing them to use a certificate that has been revoked for authentication purposes. This could lead to unauthorized access or bypass of security controls. The impact is considered Moderate due to the specific timing window required for exploitation. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-367. Affected Red Hat products: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform Expansion Pack. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-59901] Infinite loop in netty-codec-compression (bzip2)
A flaw was found in the netty-codec-compression component of Netty. This vulnerability, caused by a logic error in the bzip2 decoder, allows a remote attacker to send specially crafted bzip2-compressed data. Processing this malformed data can trigger an infinite loop, causing the decoder thread to consume excessive CPU resources. This leads to a denial of service (DoS), requiring manual intervention to restore service. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-835. Affected Red Hat products: Red Hat build of Apache Camel - HawtIO 4; Red Hat Data Grid 8; Red Hat OpenShift Dev Spaces; streams for Apache Kafka 3. Red Hat lists Red Hat JBoss Enterprise Application Platform Expansion Pack as not affected. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-59899] Memory exhaustion in netty-codec-http (decompression bomb)
A flaw was found in the Netty netty-codec-http component. A remote attacker can send HTTP requests containing highly compressed data. This can lead to memory exhaustion and a denial of service (DoS), making the service unavailable to legitimate users. This is an Important vulnerability in Netty's HTTP decoder, which could lead to a denial of service. Red Hat products utilizing `netty-codec-http` are susceptible to memory exhaustion when processing specially crafted, highly compressed HTTP payloads. This allows a remote attacker to trigger excessive memory allocation, impacting system availability. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-409. Affected products named by the advisory: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33; Red Hat build of Quarkus 3.27.4.SP3; Red Hat build of Quarkus 3.33.2.SP3; Cryostat 4; and 19 more.
Medium [CVE-2026-59856] Arbitrary code execution via crafted PHP file in omni-completion
Arbitrary code execution via crafted PHP file in omni-completion. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:47982 with package vim-2:8.2.2637-26.el9_8.13, vim-main-9.2.780-1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 9.
Medium [CVE-2026-59858] Arbitrary command execution via crafted tags file in C omni-completion
Arbitrary command execution via crafted tags file in C omni-completion. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:47982 with package vim-2:8.2.2637-26.el9_8.13, vim-main-9.2.780-1.hum1. Affected product named by the advisory: Red Hat Enterprise Linux 9.
Medium [CVE-2026-59857] Denial of Service via out-of-bounds write in spell sound-folding
Denial of Service via out-of-bounds write in spell sound-folding. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:35387 with package vim-main-9.2.780-1.hum1.
Medium [CVE-2026-55689] OIDC audience validation skipped when --authn-oidc-audience is unset
OIDC audience validation skipped when --authn-oidc-audience is unset. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-287.
Medium [CVE-2026-55170] Incorrect authorization decisions due to case-insensitive comparisons in MySQL datastore
Incorrect authorization decisions due to case-insensitive comparisons in MySQL datastore. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-178.