Red Hat Linux Security Advisories & CVEs
5812 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-56128] pfSense Plus: CE: pfSense Plus and CE: Stored Cross-Site Scripting (XSS) via firewall schedule description.
pfSense Plus: CE: pfSense Plus and CE: Stored Cross-Site Scripting (XSS) via firewall schedule description. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79.
Medium [CVE-2026-71224] stack overflow via alloca(i_height) in metadata walk
stack overflow via alloca(i_height) in metadata walk. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: gfs2-utils.
Medium [CVE-2026-71222] heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing
heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: gfs2-utils.
Medium [CVE-2026-71219] stack overflow via alloca(1<<di_depth) in hash table traversal
A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta. This vulnerability is assessed as Moderate impact because the alloca-based stack exhaustion results in a process crash (SIGSEGV) rather than controlled memory corruption. Exploitation requires local access and user interaction: an administrator must run a gfs2-utils tool (fsck.gfs2, gfs2_edit, or savemeta) on a crafted GFS2 filesystem image. The vulnerability does not affect the kernel GFS2 driver, which validates di_depth in gfs2_dinode_in(). Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gfs2-utils.
Medium [CVE-2026-85089] Information disclosure via uninitialized heap memory in Save Session Info PDU
FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) use Stream_Seek instead of Stream_Zero for reserved pad bytes (up to 576 bytes), leaving previously freed heap contents in the outgoing PDU. Because the send buffer is allocated with malloc (not zeroed), stale heap data — which may include cleartext credentials from prior sessions — can be sent to the receiving peer. FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy (which forwards these PDUs) are affected, allowing disclosure of server/proxy process memory to a downstream client. A flaw was found in FreeRDP. This vulnerability allows a remote attacker with low privileges to disclose sensitive information from the server or proxy process memory to a downstream client. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-908. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat fixing advisory: RHSA-2026:75570. Affected products named by the advisory: Red Hat package: freerdp.
Medium [CVE-2026-85090] Heap Out-of-Bounds Read in AVC444 Chroma Combine
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane. A flaw was found in FreeRDP. A remote attacker, acting as a malicious Remote Desktop Protocol (RDP) server, can exploit this by sending a specially crafted `RFX_AVC444_BITMAP_STREAM` with specific frame geometry. This can lead to an out-of-bounds memory read, potentially disclosing sensitive heap data to the client or causing a client crash, resulting in a denial of service. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: freerdp.
Medium [CVE-2026-78662] Denial of Service via channel request flooding
Denial of Service via channel request flooding. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-833. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; Confidential Compute Attestation; and 34 more. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Multicluster Engine for Kubernetes; OpenShift API for Data Protection; and 30 more.
Medium [CVE-2026-56855] Denial of Service via crafted messages
Denial of Service via crafted messages. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-833. Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Builds for Red Hat OpenShift; cert-manager Operator for Red Hat OpenShift; Confidential Compute Attestation; and 34 more. Affected products named by the advisory: Cryostat 4; External Secrets Operator for Red Hat OpenShift; Multicluster Engine for Kubernetes; OpenShift API for Data Protection; and 30 more.
Medium [CVE-2026-84380] Request Smuggling and Connection Desynchronization via Conflicting HTTP Headers
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding header because its setdefault() processing checks each default header independently rather than treating the two framing headers as mutually exclusive. Fixed-size byte, JSON, form, and known-length multipart bodies can therefore be serialized over HTTP/1.1 with both headers, allowing request smuggling or connection desynchronization when downstream intermediaries disagree about which framing header takes precedence. This could allow an attacker to bypass security controls or interfere with network traffic. This vulnerability is rated Moderate. Exploitation requires a high attack complexity, as it depends on how downstream intermediaries process these conflicting headers, leading to limited impact on confidentiality, integrity, and availability. Red Hat severity: Moderate — CVSS 5.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L). Weakness: CWE-444. Affected Red Hat products: Lightspeed Core; Red Hat OpenShift AI (RHOAI). Red Hat lists Migration Toolkit for Applications 8; Red Hat Enterprise Linux command line assistant as not affected. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-84379] Multipart header injection via unvalidated input
HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-element (filename, content, content_type) tuple and the files= four-element (filename, content, content_type, headers) tuple into multipart/form-data part headers without validating header names or values. CR or LF characters can terminate a part header, inject additional part headers, or end the part header block early, allowing a downstream multipart parser to treat attacker-supplied lines as genuine headers and potentially alter part semantics or bypass header-based checks. This issue is fixed in version 2.11.0. A remote attacker could exploit this vulnerability by sending specially crafted multipart/form-data requests. The `FileField.render_headers()` function fails to validate `Content-Type` values and custom headers, allowing the injection of Carriage Return (CR) or Line Feed (LF) characters. This could lead to the injection of arbitrary part headers, potentially altering the interpretation of multipart data or bypassing security checks by a downstream parser. This Moderate severity flaw in the `httpx2` Python library allows for multipart header injection.
Medium [CVE-2026-84378] Denial of Service via crafted Server-Sent Events stream
HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an attacker-controlled or compromised SSE endpoint splits one unterminated line across many response chunks. The behavior affects httpx2.Client.sse() and httpx2.AsyncClient.sse(), and the total processing work grows quadratically with the line length, allowing a crafted stream to consume excessive CPU and block a synchronous worker or asynchronous event loop. This issue is fixed in version 2.10.0. This quadratic processing work consumes excessive CPU resources, leading to a Denial of Service (DoS) by blocking synchronous workers or asynchronous event loops. Moderate: A denial of service vulnerability exists in the HTTPX2 Python client library, affecting Red Hat products such as Lightspeed Core and Red Hat OpenShift AI. This flaw allows a remote attacker to consume excessive CPU resources by sending a specially crafted Server-Sent Events (SSE) stream, leading to resource exhaustion. The impact is limited to availability and requires interaction with a malicious or compromised SSE endpoint. Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-606.
Medium [CVE-2026-84377] Authenticated Server-Side Request Forgery and credential exposure
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination the user controls and cause the proxy to send its configured provider credentials to that destination. Request validation in litellm/proxy/auth/auth_utils.py, litellm/proxy/common_request_processing.py, litellm/proxy/health_endpoints/_health_endpoints.py, litellm/proxy/image_endpoints/endpoints.py, and litellm/proxy/litellm_pre_call_utils.py used incomplete checks that did not cover every sensitive parameter or inspect equivalent values across nested request fields, path values, and bracket-notation form data. Routing and credential parameters including api_base, base_url, model_list, fallbacks, and litellm_credential_name could therefore be applied without clearing the operator's stored key, exposing upstream provider credentials and other configured secrets and permitting server-side requests to internal services reachable by the proxy. This issue is fixed in versions 1.88.6 and 1.96.2. A flaw was found in LiteLLM, a proxy server for Large Language Model (LLM) APIs. An authenticated remote attacker could exploit incomplete request validation to redirect outbound provider calls to an attacker-controlled destination.
Medium [CVE-2026-53600] Tar entry/content smuggling via PAX extension-header desynchronization
async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension header (a GNU longname L, a GNU longlink K, or a PAX x/g header) instead of to the next file entry. POSIX requires a PAX extended-header record set to describe the next file entry, never an intervening extension header. Because poll_next_raw (src/archive.rs) threads the buffered PAX records into the size computation of whatever raw header it reads next — and that header can be an intermediary L — the stream cursor is advanced by an attacker-chosen amount when the L body is consumed. The parser then desyncs relative to a POSIX-correct tar parser (e.g. GNU tar), reading subsequent bytes at the wrong block boundary. This issue has been patched in version 0.6.1. This allows an attacker to craft a malicious tar archive that manipulates the stream cursor, causing the parser to desynchronize. This desynchronization can lead to differential extraction or tar entry/content smuggling, where async-tar extracts different files or contents than a POSIX-compliant tar parser, potentially allowing an attacker to hide malicious payloads or alter expected file contents. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-1286.
Medium [CVE-2026-84646] Unauthorized creation of user objects via deserialization vulnerability
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML. A flaw was found in Jenkins. While these created user objects are not actual Jenkins accounts and cannot be used for login, their unauthorized creation could lead to unexpected behavior or resource manipulation within the Jenkins environment. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-502. Affected Red Hat products: OpenShift Developer Tools and Services. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-53683] IdM/FreeIPA Web UI - Client-side open redirect in reset_password.html
reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow. Rated Moderate because exploitation requires a victim to follow a crafted link, and the direct technical impact is limited to a client-side redirect with no data disclosure or modification. The practical risk is phishing/social-engineering enablement rather than a direct technical compromise. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N). Weakness: CWE-601. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: ipa.
Medium [CVE-2026-82968] Cross-session email verification proof not bound to upstream identity for social providers
A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This allows an attacker with a different account on the same social provider to intercept the process and link their own account to the victim's local profile, gaining unauthorized access. The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires specific timing and user interaction during an active account-linking process. The vulnerability's root cause is the failure to bind the cross-session verification proof to the specific upstream identity for social providers. Weakness: CWE-639. Affected Red Hat products: Red Hat Build of Keycloak; Red Hat Single Sign-On 7. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-12704] SAML assertion replay via skipped InResponseTo validation
SAML assertion replay via skipped InResponseTo validation. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-294.
Medium [CVE-2026-84356] UI misrepresentation in FullScreen
UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low) An ui misrepresentation flaw was found in the FullScreen component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Low — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N). Weakness: CWE-1021.
Medium [CVE-2026-84327] Incorrect authorization in Autofill
Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) An incorrect authorization flaw was found in the Autofill component of the Chromium browser. Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N). Weakness: CWE-551.
Medium [CVE-2026-84323] Missing authorization in FileSystem
Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Moderate — CVSS 5.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-425.