CVE coverage
AlmaLinux 9 CVE tracker
Noxen pulls AlmaLinux 9 CVE data from the same upstream sources Red Hat publishes against (RHEL 9 binary-compatible). NVD provides the upstream advisory; OSV's Red Hat ecosystem feed provides the rpm-level fix versions. The AlmaLinux project also publishes its own errata, which we cross-reference.
Live
Headline numbers
- Total CVE records (all distros)Loading…
- Last buildLoading…
- OSV records (RH ecosystem + others)Loading…
- NVD records (cross-platform)Loading…
How matching works
What Noxen does for an AlmaLinux 9 host
- Reads
/etc/os-releaseto confirm AlmaLinux 9 (RHEL 9 binary-compatible). - Reads
rpm -qafor installed packages, including epoch and release. - Filters the local feed cache to OSV records tagged with ecosystem
AlmaLinux:9 / Red Hat:9, plus NVD records whose CPE matches the installed packages. - Compares installed vs fix versions using rpm version semantics (epoch:version-release).
- Emits findings only where the installed version is strictly older than the fix.
Live listings
Top recent critical CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))
Most-recently-published critical CVEs in the Red Hat ecosystem (RHEL / Rocky / AlmaLinux). Auto-deduped to one row per CVE ID. Snapshot baked at ; live re-fetch on page load.
| CVE | Sev. | CVSS | Summary | Package | Fix in | Published |
|---|---|---|---|---|---|---|
| RLSA-2026:76763 | critical | 9.1 | Important: dovecot security, bug fix, and enhancement update | dovecot | 1:2.3.16-16.el8_10 | |
| RLSA-2026:75673 | critical | 9.1 | Important: mariadb-connector-c security update | mariadb-connector-c | 0:3.2.6-2.el9_8 | |
| RLSA-2026:75674 | critical | 9.1 | Important: mariadb-connector-c security update | mariadb-connector-c | 0:3.1.11-3.el8_10 | |
| RLSA-2026:73979 | critical | 9.3 | Critical: freerdp security update | freerdp | 2:3.10.3-12.el10_2.13 | |
| RLSA-2026:74084 | critical | 9.6 | Critical: webkit2gtk3 security update | webkit2gtk3 | 0:2.54.0-1.el8_10 | |
| RLSA-2026:72279 | critical | 9.8 | Critical: ipa security, bug fix, and enhancement update | ipa | 0:4.13.4-1.el10_2 | |
| RLSA-2026:71487 | critical | 9.8 | Critical: unbound security update | unbound | 0:1.24.2-3.el9_8.8 | |
| RLSA-2026:71419 | critical | 9.8 | Critical: unbound security update | unbound | 0:1.24.2-7.el10_2.6 |
Top recent high-severity CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))
| CVE | Sev. | CVSS | Summary | Package | Fix in | Published |
|---|---|---|---|---|---|---|
| RLSA-2026:76737 | high | 7.4 | Important: rust-sequoia-sq security, bug fix, and enhancement update | rust-sequoia-sq | 0:1.4.0.1-2.el10_2 | |
| RLSA-2026:76734 | high | 7.4 | Important: rust-rpm-sequoia security, bug fix, and enhancement update | rust-rpm-sequoia | 0:1.10.2.1-1.el10_2 | |
| RLSA-2026:76743 | high | 7.5 | Important: opentelemetry-collector security update | opentelemetry-collector | 0:0.158.0-1.el10_2 | |
| RLSA-2026:76762 | high | 7.5 | Important: perl-DBI security update | perl-DBI | 0:1.643-26.el10_2.7 | |
| RLSA-2026:76735 | high | 7.4 | Important: rust-sequoia-sqv security update | rust-sequoia-sqv | 0:1.3.0.2-1.el10_2 | |
| RLSA-2026:76733 | high | 7.4 | Important: rust-rpm-sequoia security update | rust-rpm-sequoia | 0:1.10.2.1-1.el9_8 | |
| RLSA-2026:75768 | high | 7.3 | Important: vim security update | vim | 2:8.2.2637-26.el9_8.23 | |
| RLSA-2026:76747 | high | 8.8 | Important: freerdp security update | freerdp | 2:2.11.7-14.el8_10 |
Notable
Recent CVEs that AlmaLinux 9 homelabs care about.
- CVE-2024-6387 (regreSSHion) - OpenSSH signal-handler race producing pre-auth RCE.. Red Hat advisory · Noxen deep-dive.
- CVE-2024-1086 (nf_tables UAF) - Linux kernel privilege-escalation, observed in the wild.. Red Hat advisory.
- CVE-2024-3094 (xz backdoor) - Supply-chain backdoor in xz-utils 5.6.0 / 5.6.1.. Red Hat advisory · Noxen deep-dive.
FAQ
Frequently asked about AlmaLinux 9 CVEs
How is AlmaLinux 9 different from RHEL 9 for CVE tracking?
Functionally, very little. AlmaLinux 9 is binary-compatible with RHEL 9 and rebuilds Red Hat's source packages on the same release cadence, so a fix landing in RHEL 9 lands in AlmaLinux 9 within days. Noxen matches against the Red Hat ecosystem feed plus AlmaLinux errata to pick up both channels.
How do I check AlmaLinux 9 CVEs on a host?
For a quick check: dnf updateinfo list security. For per-CVE detail with fix versions, Noxen reads rpm package state over SSH and matches against the live ecosystem feed using rpm version semantics (epoch:version-release).
Is AlmaLinux 9 still supported in 2026?
Yes - the AlmaLinux 9 lifecycle tracks RHEL 9 (active maintenance phase through May 2032). Major and minor security errata continue throughout this window.
Will Noxen flag a CVE that AlmaLinux 9 has already backported a fix for?
No. Red Hat-family distros backport security fixes without changing the upstream version number - the fix shows up as a higher release field (the part after the dash in epoch:version-release). Noxen compares the installed epoch:version-release against the fixed package version using rpm version semantics, so a host that has applied the backported errata is correctly shown as patched rather than as a false positive.
Which AlmaLinux 9 CVEs should I patch first?
Severity alone is a poor sort key. Noxen ranks findings by exposure first - a high-severity CVE in a package behind an internet-facing service outranks a critical one in a library nothing reaches - then by CVSS and EPSS. The EPSS prioritisation guide walks through the reasoning.
Scan an AlmaLinux 9 fleet with Noxen
Add your AlmaLinux 9 hosts via your existing
~/.ssh/config; Noxen reads rpm package state and
matches against the live signed feed. No agent, no SaaS round-trip.
$12/month, or $120/year.