CVE coverage

AlmaLinux 9 CVE tracker

Noxen pulls AlmaLinux 9 CVE data from the same upstream sources Red Hat publishes against (RHEL 9 binary-compatible). NVD provides the upstream advisory; OSV's Red Hat ecosystem feed provides the rpm-level fix versions. The AlmaLinux project also publishes its own errata, which we cross-reference.

Live

Headline numbers

  • Total CVE records (all distros)Loading…
  • Last buildLoading…
  • OSV records (RH ecosystem + others)Loading…
  • NVD records (cross-platform)Loading…

How matching works

What Noxen does for an AlmaLinux 9 host

  1. Reads /etc/os-release to confirm AlmaLinux 9 (RHEL 9 binary-compatible).
  2. Reads rpm -qa for installed packages, including epoch and release.
  3. Filters the local feed cache to OSV records tagged with ecosystem AlmaLinux:9 / Red Hat:9, plus NVD records whose CPE matches the installed packages.
  4. Compares installed vs fix versions using rpm version semantics (epoch:version-release).
  5. Emits findings only where the installed version is strictly older than the fix.

Live listings

Top recent critical CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))

Most-recently-published critical CVEs in the Red Hat ecosystem (RHEL / Rocky / AlmaLinux). Auto-deduped to one row per CVE ID. Snapshot baked at ; live re-fetch on page load.

CVESev.CVSSSummaryPackageFix inPublished
RLSA-2026:70564critical9.8Critical: ipa security, bug fix, and enhancement updateipa0:4.13.4-1.el9_8
RLSA-2026:70754critical9.8Critical: unbound security updateunbound0:1.16.2-5.14.el8_10.4
RLSA-2026:69098critical9.6Important: webkit2gtk3 security updatewebkit2gtk30:2.54.0-1.el9_8
RLSA-2026:64785critical9.8Critical: 389-ds-base security, bug fix, and enhancement update389-ds-base0:3.2.0-10.el10_2
RLSA-2026:64784critical9.8Critical: 389-ds-base security, bug fix, and enhancement update389-ds-base0:2.8.0-10.el9_8
RLSA-2026:64791critical9.8Critical: 389-ds:1.4 security, bug fix, and enhancement update389-ds-base0:1.4.3.39-28.module+el8.10.0+40311+cd962df1
RLSA-2026:48790critical9.1Important: osbuild-composer security updateosbuild-composer0:101.5-1.el8_10.rocky.0.6
RLSA-2026:48021critical9.1Important: python-pillow security updatepython-pillow0:5.1.1-23.el8_10

Top recent high-severity CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))

CVESev.CVSSSummaryPackageFix inPublished
RLSA-2026:70640high8.1Important: buildah security updatebuildah2:1.43.3-2.el9_8
RLSA-2026:70641high8.1Important: skopeo security updateskopeo2:1.22.2-8.el9_8
RLSA-2026:70459high7.8Important: kernel security, bug fix, and enhancement updatekernel0:5.14.0-687.50.1.el9_8
RLSA-2026:69540high7.5Important: rsyslog security updatersyslog0:8.2510.0-2.el9_8.2
RLSA-2026:70498high8.8Important: kernel security, bug fix, and enhancement updatekernel0:6.12.0-211.58.1.el10_2
RLSA-2026:70403high7.8Important: kernel-rt security, bug fix, and enhancement updatekernel-rt0:4.18.0-553.166.1.rt7.507.el8_10
RLSA-2026:70402high7.8Important: kernel security, bug fix, and enhancement updatekernel0:4.18.0-553.166.1.el8_10
RLSA-2026:70186high8.8Important: postgresql16 security updatepostgresql160:16.15-1.el10_2

New to severity terminology? CVE, CVSS, CWE, CPE explained.

Notable

Recent CVEs that AlmaLinux 9 homelabs care about.

FAQ

Frequently asked about AlmaLinux 9 CVEs

How is AlmaLinux 9 different from RHEL 9 for CVE tracking?

Functionally, very little. AlmaLinux 9 is binary-compatible with RHEL 9 and rebuilds Red Hat's source packages on the same release cadence, so a fix landing in RHEL 9 lands in AlmaLinux 9 within days. Noxen matches against the Red Hat ecosystem feed plus AlmaLinux errata to pick up both channels.

How do I check AlmaLinux 9 CVEs on a host?

For a quick check: dnf updateinfo list security. For per-CVE detail with fix versions, Noxen reads rpm package state over SSH and matches against the live ecosystem feed using rpm version semantics (epoch:version-release).

Is AlmaLinux 9 still supported in 2026?

Yes — the AlmaLinux 9 lifecycle tracks RHEL 9 (active maintenance phase through May 2032). Major and minor security errata continue throughout this window.

Will Noxen flag a CVE that AlmaLinux 9 has already backported a fix for?

No. Red Hat-family distros backport security fixes without changing the upstream version number — the fix shows up as a higher release field (the part after the dash in epoch:version-release). Noxen compares the installed epoch:version-release against the fixed package version using rpm version semantics, so a host that has applied the backported errata is correctly shown as patched rather than as a false positive.

Which AlmaLinux 9 CVEs should I patch first?

Severity alone is a poor sort key. Noxen ranks findings by exposure first — a high-severity CVE in a package behind an internet-facing service outranks a critical one in a library nothing reaches — then by CVSS and EPSS. The EPSS prioritisation guide walks through the reasoning.

Scan an AlmaLinux 9 fleet with Noxen

Add your AlmaLinux 9 hosts via your existing ~/.ssh/config; Noxen reads rpm package state and matches against the live signed feed. No agent, no SaaS round-trip. $79 one-time.

← back to the CVE dashboard   Debian 11 →   AlmaLinux 8 →