Is Red Hat Enterprise Linux 9 getting security updates?
On an OS release, security comes from applied updates, not the release number. Install the fixes below with sudo dnf upgrade --security.
Recent security notices (RHSA) affecting 9
From Red Hat Security Advisories — newest first. Open for the full advisory.
RHSA-2026:48273 RHSA-2026:48273 — Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw (moderate) 1 CVE RHSA-2026:48788 RHSA-2026:48788 — pip: Arbitrary file installation via malicious package indexes (moderate) 1 CVE RHSA-2026:48780 RHSA-2026:48780 — React Router: Open Redirect vulnerability via backslashes in navigation components (moderate) 1 CVE RHSA-2026:47171 RHSA-2026:47171 — GNU Binutils: Heap-buffer-overflow in linker leads to information disclosure and denial of service (moderate) 1 CVE RHSA-2026:45779 RHSA-2026:45779 — SQLite: Arbitrary code execution via malicious SQL statement (important) 1 CVECVEs in these notices
Each links to Red Hat's CVE tracker (per-release fix status).
Other Red Hat Enterprise Linux releases
Frequently asked
Is Red Hat Enterprise Linux 9 still getting security updates?
Red Hat Enterprise Linux 9 is supported and receiving security updates until 2032-05-31. The 5 most recent Red Hat Security Advisories (RHSA) for it cover 5 CVEs. On an OS release, security comes from applied updates, not the release number — run sudo dnf upgrade --security to install these fixes.
When does Red Hat Enterprise Linux 9 reach end-of-life?
Red Hat Enterprise Linux 9 is supported until 2032-05-31.
Built from Red Hat Security Advisories and endoflife.date. An OS release's security depends on the updates you've actually applied, not its version — always verify with Red Hat's official advisories ↗ and keep your system current.