Red Hat Linux Security Advisories & CVEs
4700 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-18941] Default authentication mode is no_auth — shared multi-tenant instances deployed without authentication
Default authentication mode is no_auth — shared multi-tenant instances deployed without authentication. Red Hat rates this important (CVSS 7.7). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.
High [CVE-2026-15581] TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide
TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide. Red Hat rates this important (CVSS 8). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-trustyai-service-operator-rhel9:1784993206, rhoai/odh-trustyai-service-operator-rhel9:1786614608, rhoai/odh-trustyai-service-operator-rhel9:1785187521, rhoai/odh-trustyai-service-operator-rhel9:1785187119. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4. Affected products named by the advisory: Red Hat OpenShift AI 3.5.
High [CVE-2026-15467] LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override
LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override. Red Hat rates this important (CVSS 8.1). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-trustyai-service-operator-rhel9:1784993206, rhoai/odh-trustyai-service-operator-rhel9:1786614608, rhoai/odh-trustyai-service-operator-rhel9:1785187521, rhoai/odh-trustyai-service-operator-rhel9:1785187119. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4. Affected products named by the advisory: Red Hat OpenShift AI 3.5.
High [CVE-2026-13717] MaaS/llm-d inference Gateway: default allowedRoutes.namespaces.from: All allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs)
MaaS/llm-d inference Gateway: default allowedRoutes.namespaces.from: All allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs). Red Hat rates this important (CVSS 8.8). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-rhel9-operator:1786123541, rhoai/odh-maas-controller-rhel9:1787153684. Affected products named by the advisory: Red Hat OpenShift AI 3.4; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-66805] stored DOM XSS via unescaped pod logs in document.write
stored DOM XSS via unescaped pod logs in document.write. Red Hat rates this important (CVSS 8). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:54432 with package multicluster-engine/console-mce-rhel9:1787079359, rhacm2/console-rhel9:1787339248, multicluster-engine/console-mce-rhel9:1787264250, rhacm2/console-rhel9:1787339213.
High [CVE-2026-69112] Path Traversal and Denial of Service via weight_map
Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can supply relative paths with../ sequences or absolute paths to read arbitrary files, or point shard entries at named pipes to cause indefinite blocking and denial of service. This is an Important vulnerability in Hugging Face Accelerate that could lead to arbitrary file disclosure and denial of service. While requiring user interaction, an attacker could craft malicious `weight_map` entries in sharded checkpoint indexes to exploit path traversal, impacting the confidentiality and availability of systems utilizing affected Red Hat AI/ML products. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H). Weakness: CWE-22. Affected Red Hat products: Red Hat OpenShift AI 2.25; Lightspeed Core; Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI). Will not fix / out of support: Red Hat AI Inference Server; Red Hat OpenShift AI (RHOAI). Red Hat fixing advisory: RHSA-2026:65126.
High [CVE-2026-18621] V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening
V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening. Red Hat rates this important (CVSS 7.6). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-ml-pipelines-api-server-v2-rhel9:1784924951, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1787173417, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785189934, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785187920. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
High [CVE-2026-18620] User-controlled ServiceAccount for workflow pods without authorization check — confused deputy
User-controlled ServiceAccount for workflow pods without authorization check — confused deputy. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-ml-pipelines-api-server-v2-rhel9:1784924951, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1787173417, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785189934, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785187920. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4. Affected products named by the advisory: Red Hat OpenShift AI 3.5.
High [CVE-2026-18618] Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener
Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-mlmd-grpc-server-rhel9:1785260280, rhoai/odh-mlmd-grpc-server-rhel9:1785262015, rhoai/odh-mlmd-grpc-server-rhel9:1785269945. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4. Affected products named by the advisory: Red Hat OpenShift AI 3.5.
High [CVE-2026-59091] multiple vulnerabilities in file format plugins via crafted image file
A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further user interaction. It is triggered when a user opens a specially crafted image file, a common user action for image manipulation software. The local nature of the exploit is offset by the significant impact of potential system compromise or sensitive data exposure. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-18617] MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod
MySQL DSN parameter injection via CustomExtraParams enables LOCAL INFILE file exfiltration from operator pod. Red Hat rates this important (CVSS 8.8). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785189332, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1784833428, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1787002057, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785187936. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4. Affected products named by the advisory: Red Hat OpenShift AI 3.5.
High [CVE-2026-18611] Cryptographically weak secret generation (math/rand) for DB and S3 credentials
Cryptographically weak secret generation (math/rand) for DB and S3 credentials. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-338. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785189332, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1784833428, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1787002057, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785187936. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4. Affected products named by the advisory: Red Hat OpenShift AI 3.5.
High [CVE-2026-18608] Operator ClusterRole grants pods/exec:*, kubeflow.org */*, and ClusterRole/Binding CRUD cluster-wide
Operator ClusterRole grants pods/exec:*, kubeflow.org */*, and ClusterRole/Binding CRUD cluster-wide. Red Hat rates this important (CVSS 8.7). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785189332, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1784833428, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1787002057, rhoai/odh-data-science-pipelines-operator-controller-rhel9:1785187936. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4. Affected products named by the advisory: Red Hat OpenShift AI 3.5.
High [CVE-2026-72718] Arbitrary command execution via malicious Git configuration in `goose review`
goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather the diff for review without stripping attacker-controlled Git configuration. A malicious repository whose `.git/config` sets [`core] fsmonitor = ` causes Git to execute that command on the host during the index refresh performed by `git diff HEAD`. The command runs before goose contacts a model and without a submitted prompt, model call, tool approval, or trust prompt. The context-gathering Git process is not sandboxed and is outside goose's tool-permission model. Arbitrary commands run with the privileges and environment of the user running goose, allowing file access or modification and exfiltration of environment secrets and provider API keys. The vulnerable Git invocations are built by git_command() in crates/goose-cli/src/commands/review/handler.rs and are used by touched_files() and collect_diff() for `git diff --name-only HEAD` and `git diff HEAD`. This issue is fixed in version 1.44.0. A malicious Git repository can set the `core.fsmonitor` option in its configuration, causing Git to execute arbitrary commands on the host during an index refresh. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78.
High [CVE-2026-71576] Manager trusts self-asserted evt.Source for leaf-hub identity in all status handlers
Manager trusts self-asserted evt. Source() for leaf-hub identity in all status handlers. Red Hat rates this important (CVSS 8.5). Weakness: CWE-345.
High [CVE-2026-59090] arbitrary code execution in psd plugin due to unsigned underflow
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system. This is an Important severity flaw in the GIMP image manipulation program. This vulnerability primarily affects desktop environments where GIMP is installed and used to process untrusted image files. Red Hat severity: Important — CVSS 8.4 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H). Weakness: CWE-191. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-68415] clear mode callbacks after failed mode setup
In the Linux kernel, the following vulnerability has been resolved: xfrm: clear mode callbacks after failed mode setup xfrm_state_gc_task can run long after a failed IPTFS state setup. In the reproduced case, __xfrm_init_state() cached x->mode_cbs, IPTFS setup returned -ENOMEM before publishing mode_data, and the temporary module reference from xfrm_get_mode_cbs() was dropped immediately. The dead state then kept x->mode_cbs until deferred GC ran after xfrm_iptfs had been unloaded. Clear x->mode_cbs when mode init or clone fails before publishing mode_data. Those states never installed mode-specific state or the long-term IPTFS module pin, so deferred GC has nothing mode-specific to destroy and must not retain a callback table pointer past the temporary lookup reference. The buggy scenario involves two paths, with each column showing the order within that path: failed setup path: 1. cache x->mode_cbs 2. mode setup fails before mode_data 3. drop the temporary module ref 4. dead state keeps x->mode_cbs cached GC/unload path: 1. xfrm_state_put() queues GC work 2. xfrm_iptfs unloads later 3. xfrm_state_gc_task runs 4. GC dereferences stale x->mode_cbs This also covers the failed clone path where clone_state() returns before publishing mode_data.
High [CVE-2026-68409] defer link RX stats percpu free to RCU
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: defer link RX stats percpu free to RCU sta_remove_link() frees a removed MLO link's RX stats percpu buffer right away, but defers only the link container to RCU: sta_info_free_link(&alloc->info); kfree_rcu(alloc, rcu_head); The RX fast path reads link_sta under rcu_read_lock and writes the percpu stats. A reader that resolved link_sta before the removal keeps the pointer. The container stays alive from the kfree_rcu, so the read still works. But the percpu block it points to is already freed. This needs uses_rss. That is when pcpu_rx_stats exists. The full STA teardown frees the deflink stats only after synchronize_net(). The link removal path had no such barrier. The race is hard to win in practice, but the free should still wait for RCU. Free the link together with its data from a single RCU callback, so the percpu block is reclaimed only after readers drain. When an MLO (Multi-Link Operation) link is removed, the RX statistics per-CPU buffer is freed immediately, while the link container is deferred to RCU (Read-Copy-Update). This timing issue can lead to a use-after-free vulnerability, where a reader might still access the freed memory. While difficult to exploit in practice, this could potentially lead to system instability or denial of service.
High [CVE-2026-68404] use wiphy work for socket owner autodisconnect
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: use wiphy work for socket owner autodisconnect nl80211_netlink_notify() walks the cfg80211 wireless device list when a NETLINK_GENERIC socket is released. If the socket owns a connection, the notifier queues the embedded wdev->disconnect_wk work item. That work is a plain work_struct today. NETDEV_GOING_DOWN cancels it, but a NETLINK_URELEASE notifier that already observed conn_owner_nlportid can queue it after that cancel returns. _cfg80211_unregister_wdev() then removes the wdev from the list and waits for RCU readers, but synchronize_net() does not drain work queued by such a reader. Make the autodisconnect work a wiphy_work instead. The callback already needs the wiphy mutex, and wiphy_work runs under that mutex. This lets teardown cancel pending autodisconnect work while holding the mutex, without a cancel_work_sync() vs. worker locking concern. Any NETLINK_URELEASE notifier that had already reached the wdev list has then either queued the work and it is removed, or can no longer find the wdev. This vulnerability involves a race condition during the process of disconnecting a wireless device, where a work item can be improperly queued after it has been cancelled. This could allow a local attacker to trigger a system crash, resulting in a Denial of Service (DoS).
High [CVE-2026-68402] Linux kernel: Wi-Fi subsystem out-of-bounds read via crafted frames
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking non-inheritance cfg80211_is_element_inherited() reads the first data octet of the candidate element (id = elem->data[0]) to look it up in an extension non-inheritance list. It does so after testing elem->id, but without verifying that the element actually has a data octet. A zero-length extension element (WLAN_EID_EXTENSION with length 0) therefore makes it read one octet past the end of the element. _ieee802_11_parse_elems_full() runs this check for every element of a frame once a non-inheritance context exists -- e.g. while parsing a per-STA profile of a Multi-Link element in a (re)association response, or a non-transmitted BSS profile -- so a crafted frame from an AP can trigger a one-octet slab-out-of-bounds read during element parsing: BUG: KASAN: slab-out-of-bounds in cfg80211_is_element_inherited Read of size 1... in net/wireless/scan.c Return early (treat the element as inherited) when an extension element carries no data, mirroring the existing handling of empty ID lists. The bug was found by fuzzing ieee802_11_parse_elems_full() under KASAN. The `cfg80211_is_element_inherited()` function does not properly validate the length of extension elements. This could lead to information disclosure or potentially other impacts.