Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-15392] DBD::File: Arbitrary file read/write via symlink vulnerability
DBD::File: Arbitrary file read/write via symlink vulnerability. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-59.
Medium [CVE-2026-15697] Remote object prototype pollution
Remote object prototype pollution. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-915.
Medium [CVE-2026-15043] DBI::SQL::Nano: DBI::SQL::Nano: Incorrect SQL operator evaluation can lead to incorrect data filtering.
DBI::SQL::Nano: DBI::SQL::Nano: Incorrect SQL operator evaluation can lead to incorrect data filtering. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-480.
Medium [CVE-2026-0716 +1] incomplete fix for CVE-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path)
The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup-based client when max_incoming_payload_size is set to 0. This vulnerability is rated Moderate for Red Hat because it requires a non-default configuration where max_incoming_payload_size is explicitly set to 0 or unset in libsoup's WebSocket frame processing. In typical Red Hat deployments, this configuration is not enabled by default, limiting the exposure to memory disclosure or application instability. Red Hat severity: Moderate — CVSS 4.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-12482] Arbitrary File Operations via Malicious Tar Archive Processing
Arbitrary File Operations via Malicious Tar Archive Processing. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-22.
Medium [CVE-2026-60103] Denial of Service and information disclosure via crafted.blend file
Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or read adjacent heap memory by supplying a crafted.blend file with a malicious signed short member_index value in the SDNA block. The member_index field is used as an array index into the sdna->members[] array in sdna_expand_names() without bounds validation, allowing any value outside the allocated range to produce an invalid pointer subsequently passed to strlen(), resulting in a SIGSEGV crash or unintended heap memory disclosure. A flaw was found in Blender. A remote attacker could exploit an out-of-bounds read vulnerability by providing a specially crafted.blend file. This vulnerability occurs when the application processes a malicious member_index value without proper validation, leading to an attempt to access memory outside of its allocated boundaries. Successful exploitation can result in a denial of service, causing the application to crash, or potentially lead to the disclosure of sensitive information from the system's memory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H). Weakness: CWE-125.
Medium [CVE-2026-40468] Memory corruption via integer overflow
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below. A flaw was found in gawk. An integer overflow vulnerability could allow a local attacker to cause memory exhaustion, leading to a denial of service. This flaw may also enable an attacker to corrupt gawk's internal memory, potentially leading to system instability. This could lead to system instability or a denial of service on affected Red Hat products, requiring local access to execute a malicious gawk script. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L). Weakness: CWE-190. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:40041, RHSA-2026:49661.
Medium [CVE-2026-40467] Denial of Service due to Use After Free vulnerability in io.c
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below. A flaw was found in gawk. This vulnerability can be triggered by an attacker, potentially leading to a system crash and causing a Denial of Service (DoS). This flaw, affecting gawk in Red Hat Hardened Images, requires a local attacker with low privileges to trick a user into interacting with specially crafted input, limiting its immediate impact. Red Hat severity: Moderate — CVSS 4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-825. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat fixing advisory: RHSA-2026:40041, RHSA-2026:49661.
Medium [CVE-2026-62147] Query RBAC bypass
Query RBAC bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-863.
Medium [CVE-2026-15538] Remote attacker can modify object prototype attributes
Remote attacker can modify object prototype attributes. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-915.
Medium [CVE-2026-53365] fix zerocopy completion for multi-skb sends
fix zerocopy completion for multi-skb sends. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-911.
Medium [CVE-2026-53364] Fix memory leak in hci_le_big_terminate
Fix memory leak in hci_le_big_terminate(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772.
Medium [CVE-2026-61861] Use-after-free vulnerability leading to denial of service or code execution
Use-after-free vulnerability leading to denial of service or code execution. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-825.
Medium [CVE-2026-61465] Denial of Service via crafted image due to missing memory allocation check
Denial of Service via crafted image due to missing memory allocation check. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770.
Medium [CVE-2026-61857] Application crashes via malicious XMP profiles
Application crashes via malicious XMP profiles. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476.
Medium [CVE-2026-56372] Information Disclosure and Denial of Service
Information Disclosure and Denial of Service. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125.
Medium [CVE-2026-52747] Security rule bypass due to incorrect handling of line breaks in form data
Security rule bypass due to incorrect handling of line breaks in form data. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-179.
Medium [CVE-2026-52761] Web Application Firewall rules bypass due to incorrect UTF-8 to Unicode transformation
Web Application Firewall rules bypass due to incorrect UTF-8 to Unicode transformation. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-131.
Medium [CVE-2026-49844] Malformed JSON output due to improper encoding of floating-point values
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values. This can corrupt log records or disrupt downstream log ingestion and parsing, potentially leading to a Denial of Service (DoS) or information integrity issues.
Medium [CVE-2026-57217] Authorization bypass allows unauthorized topic writes and binds during metadata-store failures
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6. This vulnerability could enable an attacker to bypass intended topic restrictions, potentially leading to unauthorized message manipulation or access. Red Hat severity: Important — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-280. Affected Red Hat products: Red Hat Hardened Images. Red Hat lists Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0 as not affected. Red Hat fixing advisory: RHSA-2026:35939, RHSA-2026:35940.