Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-63983] fix packet loop on netem when duplicate is on
fix packet loop on netem when duplicate is on. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835.
Medium [CVE-2026-63995] validate start_cmd_payload_size from module
validate start_cmd_payload_size from module. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.
Medium [CVE-2026-63977] use __dpll_device_change_ntf and remove change_work
use __dpll_device_change_ntf() and remove change_work. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-63969] fix possible infinite loop in rt6_fill_node
fix possible infinite loop in rt6_fill_node(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835.
Medium [CVE-2026-64013] Fix ACPI GPE handler leak during removal
Fix ACPI GPE handler leak during removal. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.
Medium [CVE-2026-64021] Fix exec_queue leak on width check in stream open
Fix exec_queue leak on width check in stream open. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772.
Medium [CVE-2026-63991] check skb_clone return value in send_mcast_pkt
check skb_clone() return value in send_mcast_pkt(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-45784] Heap Corruption from Incorrect Buffer Sizing
Heap Corruption from Incorrect Buffer Sizing. Red Hat rates this moderate (CVSS 5.1). Weakness: CWE-787.
Medium [CVE-2026-45309] Authentication bypass due to path traversal in username during pre-authentication
Authentication bypass due to path traversal in username during pre-authentication. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22.
Medium [CVE-2026-48487] Data integrity vulnerability via malformed DNS records
Data integrity vulnerability via malformed DNS records. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-120.
Medium [CVE-2026-48045] Unauthenticated network attacker can cause Denial of Service
Unauthenticated network attacker can cause Denial of Service. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.
Medium [CVE-2026-47184] Denial of Service via uncontrolled memory growth
Denial of Service via uncontrolled memory growth. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.
Medium [CVE-2026-47183] Denial of Service via unbounded memory growth from mDNS messages
Denial of Service via unbounded memory growth from mDNS messages. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770.
Medium [CVE-2026-47180] Denial of Service via crafted mDNS packets
Denial of Service via crafted mDNS packets. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-835.
Medium [CVE-2026-53712] Authentication downgrade via TLS man-in-the-middle attack
SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to 3.3, a flaw in com.ongres.scram:scram-client and com.ongres.scram:scram-common allows an attacker capable of a TLS man-in-the-middle attack to silently downgrade a connection from SCRAM-SHA-256-PLUS with channel binding to standard SCRAM-SHA-256 without channel binding when TlsServerEndpoint processes an X.509 certificate using a modern signature algorithm such as Ed25519; getChannelBindingData() can return an empty byte array after NoSuchAlgorithmException, and the ScramClient builder treats that as absent channel-binding data. This issue is fixed in version 3.3. This vulnerability allows the attacker to bypass the stronger SCRAM-SHA-256-PLUS authentication with channel binding, forcing a weaker SCRAM-SHA-256 authentication without channel binding, which could compromise the integrity of the authentication. While requiring a sophisticated network attack, successful exploitation bypasses stronger channel-bound authentication, potentially compromising the integrity of user sessions. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N). Weakness: CWE-303. Affected Red Hat products: Red Hat build of Quarkus; Red Hat JBoss Enterprise Application Platform Expansion Pack.
Medium [CVE-2026-16104] Authenticator config endpoint exposes raw reCAPTCHA secrets to view-only admins
Authenticator config endpoint exposes raw reCAPTCHA secrets to view-only admins. Red Hat rates this moderate (CVSS 4.3).
Medium [CVE-2026-16103 +1] Incomplete fix for CIBA brute-force lockout bypass at token redemption
Incomplete fix for CIBA brute-force lockout bypass at token redemption. Red Hat rates this moderate (CVSS 4.3).
Medium [CVE-2026-16106] Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles
Incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles. Red Hat rates this moderate (CVSS 4.9).
Medium [CVE-2026-16108] Realm default-group reads disclose hidden groups under FGAP v2
Realm default-group reads disclose hidden groups under FGAP v2. Red Hat rates this moderate (CVSS 4.3).
Medium [CVE-2026-16093] Required signed-JWT assertion policy can be bypassed with unsigned assertion headers
Required signed-JWT assertion policy can be bypassed with unsigned assertion headers. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-807.