CVE coverage

Rocky Linux 9 CVE tracker

Noxen pulls Rocky Linux 9 CVE data from the same upstream sources Red Hat publishes against (RHEL 9 binary-compatible). NVD provides the upstream advisory; OSV's Red Hat ecosystem feed provides the rpm-level fix versions.

Live

Headline numbers

  • Total CVE records (all distros)Loading…
  • Last buildLoading…
  • OSV records (RH ecosystem + others)Loading…
  • NVD records (cross-platform)Loading…

How matching works

What Noxen does for a Rocky 9 host

  1. Reads /etc/os-release to confirm Rocky 9 (RHEL 9 binary-compatible).
  2. Reads rpm -qa for installed packages, including epoch and release.
  3. Filters the local feed cache to OSV records tagged with ecosystem Rocky Linux:9 / Red Hat:9, plus NVD records whose CPE matches the installed packages.
  4. Compares installed vs fix versions using rpm version semantics (epoch:version-release).
  5. Emits findings only where the installed version is strictly older than the fix.

Live listings

Top recent critical CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))

Most-recently-published critical CVEs in the Red Hat ecosystem (RHEL / Rocky / AlmaLinux). Auto-deduped to one row per CVE ID. Snapshot baked at ; live re-fetch on page load.

CVESev.CVSSSummaryPackageFix inPublished
RLSA-2026:22963critical9.0Critical: samba security updatesamba0:4.23.5-109.el10_2
RLSA-2026:22714critical9.1Important: osbuild-composer security updateosbuild-composer0:165.1-2.el9_8.rocky.0.1
RLSA-2026:22644critical9.0Important: samba security updatesamba0:4.19.4-16.el8_10
RLSA-2026:22450critical9.1Important: osbuild-composer security updateosbuild-composer0:165.1-2.el10_2.rocky.0.1
RLSA-2026:22937critical9.1Important: image-builder security updateimage-builder0:52.1-1.el10_2.rocky.0.1
RLSA-2026:23228critical9.1Important: image-builder security updateimage-builder0:52.1-1.el9_8
RLSA-2026:21755critical9.0Important: flatpak security updateflatpak0:1.12.9-4.el9_8.1
RLSA-2026:20606critical9.1Important: ruby4.0 security updateruby4.00:4.0.3-34.el10_2

Top recent high-severity CVEs (Red Hat ecosystem (RHEL / Rocky / AlmaLinux))

CVESev.CVSSSummaryPackageFix inPublished
RLSA-2026:25120high8.8Critical: kernel-rt security updatekernel-rt0:4.18.0-553.132.1.rt7.473.el8_10
RLSA-2026:25121high8.8Critical: kernel security updatekernel0:4.18.0-553.132.1.el8_10
RLSA-2026:24984high7.8Important: poppler security updatepoppler0:20.11.0-14.el8_10
RLSA-2026:25110high7.5Important: .NET 8.0 security updatedotnet8.00:8.0.128-1.el8_10
RLSA-2026:25113high7.5Important: .NET 9.0 security updatedotnet9.00:9.0.118-1.el8_10
RLSA-2026:25114high7.5Important: .NET 10.0 security updatedotnet10.00:10.0.109-1.el8_10
RLSA-2026:24331high8.2Important: cockpit-image-builder security updatecockpit-image-builder0:94.3-1.el10_2
RLSA-2026:24716high7.8Important: yggdrasil security updateyggdrasil0:0.4.9-5.el10_2

New to severity terminology? CVE, CVSS, CWE, CPE explained.

Notable

Recent CVEs that Rocky 9 homelabs care about.

FAQ

Frequently asked about Rocky 9 CVEs

How is Rocky Linux 9 different from RHEL 9 for CVE tracking?

Rocky Linux 9 is binary-compatible with RHEL 9. Fixes land in Rocky errata within days of the corresponding RHEL release. Noxen matches against the Red Hat ecosystem feed plus Rocky errata to capture both channels.

How do I check Rocky 9 CVEs on a host?

For a quick check: dnf updateinfo list security. For per-CVE detail with fix versions, Noxen reads rpm package state over SSH and matches against the live ecosystem feed using rpm version semantics.

Will Noxen flag a CVE that Rocky Linux 9 has already backported a fix for?

No. Red Hat-family distros backport security fixes without changing the upstream version number — the fix shows up as a higher release field (the part after the dash in epoch:version-release). Noxen compares the installed epoch:version-release against the fixed package version using rpm version semantics, so a host that has applied the backported errata is correctly shown as patched rather than as a false positive.

Which Rocky Linux 9 CVEs should I patch first?

Severity alone is a poor sort key. Noxen ranks findings by exposure first — a high-severity CVE in a package behind an internet-facing service outranks a critical one in a library nothing reaches — then by CVSS and EPSS. The EPSS prioritisation guide walks through the reasoning.

Scan a Rocky 9 fleet with Noxen

Add your Rocky 9 hosts via your existing ~/.ssh/config; Noxen reads rpm package state and matches against the live signed feed. No agent, no SaaS round-trip. $79 one-time.

← back to the CVE dashboard   AlmaLinux 8 →   Rocky 8 →