CVE coverage

AlmaLinux 9 CVE tracker

Noxen pulls AlmaLinux 9 CVE data from the same upstream sources Red Hat publishes against (RHEL 9 binary-compatible). NVD provides the upstream advisory; OSV's Red Hat ecosystem feed provides the rpm-level fix versions. The AlmaLinux project also publishes its own errata, which we cross-reference.

Live

Headline numbers

  • Total CVE records (all distros)Loading…
  • Last buildLoading…
  • OSV records (RH ecosystem + others)Loading…
  • NVD records (cross-platform)Loading…

How matching works

What Noxen does for an AlmaLinux 9 host

  1. Reads /etc/os-release to confirm AlmaLinux 9 (RHEL 9 binary-compatible).
  2. Reads rpm -qa for installed packages, including epoch and release.
  3. Filters the local feed cache to OSV records tagged with ecosystem AlmaLinux:9 / Red Hat:9, plus NVD records whose CPE matches the installed packages.
  4. Compares installed vs fix versions using rpm version semantics (epoch:version-release).
  5. Emits findings only where the installed version is strictly older than the fix.

Live listings

Top recent critical CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))

Most-recently-published critical CVEs in the Red Hat ecosystem (RHEL / Rocky / AlmaLinux). Auto-deduped to one row per CVE ID. Snapshot baked at ; live re-fetch on page load.

CVESev.CVSSSummaryPackageFix inPublished
RLSA-2026:10217critical9.0Important: golang security updategolang0:1.25.9-3.el10_1
RLSA-2026:10219critical9.0Important: golang security updategolang0:1.25.9-1.el9_7
RLSA-2026:10704critical9.0Important: go-toolset:rhel8 security updatedelve0:1.25.2-1.module+el8.10.0+40035+ee0a7047
RLSA-2025:17129critical9.1Important: idm:DL1 security updatebind-dyndb-ldap0:11.6-6.module+el8.10.0+1960+1ed527b3
RLSA-2026:2224critical9.4Critical: keylime security updatekeylime0:7.12.1-11.el9_7.4
RLSA-2026:2225critical9.4Critical: keylime security updatekeylime0:7.12.1-11.el10_1.4
RLSA-2026:1472critical9.8Important: openssl security updateopenssl1:3.5.1-7.el10_1
RLSA-2026:1473critical9.8Important: openssl security updateopenssl1:3.5.1-7.el9_7

Top recent high-severity CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))

CVESev.CVSSSummaryPackageFix inPublished
RLSA-2026:14790high7.6Moderate: libpng security updatelibpng2:1.6.40-8.el10_1.3
RLSA-2026:14819high8.8Moderate: freeipmi security updatefreeipmi0:1.6.17-1.el9_7
RLSA-2026:14791high7.6Moderate: libpng security updatelibpng2:1.6.37-12.el9_7.3
RLSA-2026:14929high7.8Important: mingw-libtiff security updatemingw-libtiff0:4.0.9-4.el8_10
RLSA-2026:14200high7.8Important: git-lfs security updategit-lfs0:3.6.1-8.el9_7.1
RLSA-2026:12285high7.5Important: thunderbird security updatethunderbird0:140.10.0-1.el10_1
RLSA-2026:13916high7.5Important: fence-agents security updatefence-agents0:4.16.0-13.el10_1.4
RLSA-2026:13857high7.5Important: dovecot security updatedovecot1:2.3.16-15.el9_7.1

New to severity terminology? CVE, CVSS, CWE, CPE explained.

Notable

Recent CVEs that AlmaLinux 9 homelabs care about.

Scan an AlmaLinux 9 fleet with Noxen

Add your AlmaLinux 9 hosts via your existing ~/.ssh/config; Noxen reads rpm package state and matches against the live signed feed. No agent, no SaaS round-trip. $79 one-time.

← back to the CVE dashboard   Debian 12 →   Rocky 9 →