CVE coverage
Rocky Linux 8 CVE tracker
Noxen pulls Rocky Linux 8 CVE data from the same upstream sources Red Hat publishes against (RHEL 8 binary-compatible). NVD provides the upstream advisory; OSV's Red Hat ecosystem feed provides the rpm-level fix versions. Rocky 8 has active maintenance through May 2029.
Live
Headline numbers
- Total CVE records (all distros)Loading…
- Last buildLoading…
- OSV records (RH ecosystem + others)Loading…
- NVD records (cross-platform)Loading…
How matching works
What Noxen does for a Rocky 8 host
- Reads
/etc/os-releaseto confirm Rocky 8 (RHEL 9 binary-compatible). - Reads
rpm -qafor installed packages, including epoch and release. - Filters the local feed cache to OSV records tagged with ecosystem
Rocky Linux:8 / Red Hat:8, plus NVD records whose CPE matches the installed packages. - Compares installed vs fix versions using rpm version semantics (epoch:version-release).
- Emits findings only where the installed version is strictly older than the fix.
Live listings
Top recent critical CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))
Most-recently-published critical CVEs in the Red Hat ecosystem (RHEL / Rocky / AlmaLinux). Auto-deduped to one row per CVE ID. Snapshot baked at ; live re-fetch on page load.
| CVE | Sev. | CVSS | Summary | Package | Fix in | Published |
|---|---|---|---|---|---|---|
| RLSA-2026:48790 | critical | 9.1 | Important: osbuild-composer security update | osbuild-composer | 0:101.5-1.el8_10.rocky.0.6 | |
| RLSA-2026:48021 | critical | 9.1 | Important: python-pillow security update | python-pillow | 0:5.1.1-23.el8_10 | |
| RLSA-2026:43505 | critical | 9.1 | Important: mariadb-connector-c security update | mariadb-connector-c | 0:3.4.4-2.el10_2 | |
| RLSA-2026:40831 | critical | 9.8 | Important: hplip security update | hplip | 0:3.21.2-6.el9_8.5 | |
| RLSA-2026:40894 | critical | 9.8 | Important: hplip security update | hplip | 0:3.18.4-14.el8_10 | |
| RLSA-2026:39976 | critical | 9.8 | Important: hplip security update | hplip | 0:3.23.12-10.el10_2.5 | |
| RLSA-2026:33093 | critical | 9.9 | Important: mariadb10.11 security, bug fix, and enhancement update | mariadb10.11 | 3:10.11.18-1.el10_2 | |
| RLSA-2026:33412 | critical | 9.9 | Important: galera and mariadb11.8 security, bug fix, and enhancement update | galera | 0:26.4.27-1.el10_2 |
Top recent high-severity CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))
| CVE | Sev. | CVSS | Summary | Package | Fix in | Published |
|---|---|---|---|---|---|---|
| RLSA-2026:51295 | high | 7.5 | Moderate: kernel security, bug fix, and enhancement update | kernel | 0:6.12.0-211.44.1.el10_2 | |
| RLSA-2026:51035 | high | 7.1 | Moderate: kernel security, bug fix, and enhancement update | kernel | 0:5.14.0-687.36.1.el9_8 | |
| RLSA-2026:51075 | high | 7.8 | Important: gpsd security update | gpsd | 1:3.26.1-3.el10_2.1 | |
| RLSA-2026:51153 | high | 7.8 | Important: gpsd-minimal security update | gpsd-minimal | 1:3.26.1-2.el9_8.1 | |
| RLSA-2026:50979 | high | 7.0 | Important: kernel-rt security, bug fix, and enhancement update | kernel-rt | 0:4.18.0-553.153.1.rt7.494.el8_10 | |
| RLSA-2026:50978 | high | 7.0 | Important: kernel security, bug fix, and enhancement update | kernel | 0:4.18.0-553.153.1.el8_10 | |
| RLSA-2026:51105 | high | 7.3 | Important: LibRaw security update | LibRaw | 0:0.21.1-2.el9_8.1 | |
| RXSA-2026:51035 | high | 7.1 | Moderate: kernel security, bug fix, and enhancement update | kernel | 0:5.14.0-687.36.1.el9_8.cloud.1.0 |
Notable
Recent CVEs that Rocky 8 fleets care about.
- CVE-2024-6387 (regreSSHion) — OpenSSH signal-handler race producing pre-auth RCE.. Red Hat advisory · Noxen deep-dive.
- CVE-2024-1086 (nf_tables UAF) — Linux kernel privilege-escalation, observed in the wild.. Red Hat advisory.
- CVE-2024-3094 (xz backdoor) — Supply-chain backdoor in xz-utils 5.6.0 / 5.6.1.. Red Hat advisory · Noxen deep-dive.
FAQ
Frequently asked about Rocky 8 CVEs
Is Rocky Linux 8 still supported in 2026?
Yes — Rocky Linux 8 tracks RHEL 8's active maintenance phase through May 2029. Security errata land in lockstep with Red Hat; the Rocky project publishes its own errata stream cross-referenced with the RHEL channel.
How is Rocky 8 different from Rocky 9 for CVE tracking?
Different package version sets, different backport lines. The same upstream CVE typically has separate fix versions in the RHEL 8 channel and the RHEL 9 channel. Noxen reads rpm -qa and /etc/os-release to pick the right ecosystem filter automatically.
How do I check Rocky 8 CVEs on a host?
For a quick check: dnf updateinfo list security. For per-CVE detail with fix versions, Noxen reads rpm package state over SSH and matches against the live ecosystem feed using rpm version semantics.
Will Noxen flag a CVE that Rocky Linux 8 has already backported a fix for?
No. Red Hat-family distros backport security fixes without changing the upstream version number — the fix shows up as a higher release field (the part after the dash in epoch:version-release). Noxen compares the installed epoch:version-release against the fixed package version using rpm version semantics, so a host that has applied the backported errata is correctly shown as patched rather than as a false positive.
Which Rocky Linux 8 CVEs should I patch first?
Severity alone is a poor sort key. Noxen ranks findings by exposure first — a high-severity CVE in a package behind an internet-facing service outranks a critical one in a library nothing reaches — then by CVSS and EPSS. The EPSS prioritisation guide walks through the reasoning.
Scan a Rocky 8 fleet with Noxen
Add your Rocky 8 hosts via your existing
~/.ssh/config; Noxen reads rpm package state and
matches against the live signed feed. No agent, no SaaS round-trip.
$79 one-time.