CVE coverage

Rocky Linux 9 CVE tracker

Noxen pulls Rocky Linux 9 CVE data from the same upstream sources Red Hat publishes against (RHEL 9 binary-compatible). NVD provides the upstream advisory; OSV's Red Hat ecosystem feed provides the rpm-level fix versions.

Live

Headline numbers

  • Total CVE records (all distros)Loading…
  • Last buildLoading…
  • OSV records (RH ecosystem + others)Loading…
  • NVD records (cross-platform)Loading…

How matching works

What Noxen does for a Rocky 9 host

  1. Reads /etc/os-release to confirm Rocky 9 (RHEL 9 binary-compatible).
  2. Reads rpm -qa for installed packages, including epoch and release.
  3. Filters the local feed cache to OSV records tagged with ecosystem Rocky Linux:9 / Red Hat:9, plus NVD records whose CPE matches the installed packages.
  4. Compares installed vs fix versions using rpm version semantics (epoch:version-release).
  5. Emits findings only where the installed version is strictly older than the fix.

Live listings

Top recent critical CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))

Most-recently-published critical CVEs in the Red Hat ecosystem (RHEL / Rocky / AlmaLinux). Auto-deduped to one row per CVE ID. Snapshot baked at ; live re-fetch on page load.

CVESev.CVSSSummaryPackageFix inPublished
RLSA-2026:43505critical9.1Important: mariadb-connector-c security updatemariadb-connector-c0:3.4.4-2.el10_2
RLSA-2026:40831critical9.8Important: hplip security updatehplip0:3.21.2-6.el9_8.5
RLSA-2026:40894critical9.8Important: hplip security updatehplip0:3.18.4-14.el8_10
RLSA-2026:39976critical9.8Important: hplip security updatehplip0:3.23.12-10.el10_2.5
RLSA-2026:33093critical9.9Important: mariadb10.11 security, bug fix, and enhancement updatemariadb10.113:10.11.18-1.el10_2
RLSA-2026:33412critical9.9Important: galera and mariadb11.8 security, bug fix, and enhancement updategalera0:26.4.27-1.el10_2
RLSA-2026:33481critical9.9Important: mariadb:11.8 security, bug fix, and enhancement updategalera0:26.4.27-1.module+el9.8.0+40229+87be66a2
RLSA-2026:33482critical9.9Important: mariadb:10.11 security, bug fix, and enhancement updategalera0:26.4.27-1.module+el9.8.0+40229+87be66a2

Top recent high-severity CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))

CVESev.CVSSSummaryPackageFix inPublished
RXSA-2026:45192high7.0Important: kernel security, bug fix, and enhancement updatekernel0:5.14.0-687.30.1.el9_8.cloud.1.0
RXSA-2026:45115high7.0Important: kernel security updatekernel0:4.18.0-553.147.1.el8_10.cloud.0.1
RLSA-2026:45192high7.0Important: kernel security, bug fix, and enhancement updatekernel0:5.14.0-687.30.1.el9_8
RLSA-2026:44391high8.4Important: libpq security updatelibpq0:16.14-1.el10_2
RLSA-2026:45114high7.1Important: kernel security updatekernel0:6.12.0-211.39.1.el10_2
RLSA-2026:44308high8.4Important: libpq security updatelibpq0:13.23-3.el9_8
RLSA-2026:44438high8.1Important: compat-openssl11 security updatecompat-openssl111:1.1.1k-5.el9_8.4
RLSA-2026:46397high7.5Important: libreswan security updatelibreswan0:4.15-10.el9_8

New to severity terminology? CVE, CVSS, CWE, CPE explained.

Notable

Recent CVEs that Rocky 9 homelabs care about.

FAQ

Frequently asked about Rocky 9 CVEs

How is Rocky Linux 9 different from RHEL 9 for CVE tracking?

Rocky Linux 9 is binary-compatible with RHEL 9. Fixes land in Rocky errata within days of the corresponding RHEL release. Noxen matches against the Red Hat ecosystem feed plus Rocky errata to capture both channels.

How do I check Rocky 9 CVEs on a host?

For a quick check: dnf updateinfo list security. For per-CVE detail with fix versions, Noxen reads rpm package state over SSH and matches against the live ecosystem feed using rpm version semantics.

Will Noxen flag a CVE that Rocky Linux 9 has already backported a fix for?

No. Red Hat-family distros backport security fixes without changing the upstream version number — the fix shows up as a higher release field (the part after the dash in epoch:version-release). Noxen compares the installed epoch:version-release against the fixed package version using rpm version semantics, so a host that has applied the backported errata is correctly shown as patched rather than as a false positive.

Which Rocky Linux 9 CVEs should I patch first?

Severity alone is a poor sort key. Noxen ranks findings by exposure first — a high-severity CVE in a package behind an internet-facing service outranks a critical one in a library nothing reaches — then by CVSS and EPSS. The EPSS prioritisation guide walks through the reasoning.

Scan a Rocky 9 fleet with Noxen

Add your Rocky 9 hosts via your existing ~/.ssh/config; Noxen reads rpm package state and matches against the live signed feed. No agent, no SaaS round-trip. $79 one-time.

← back to the CVE dashboard   AlmaLinux 8 →   Rocky 8 →