Account Links: Cart | Register | Log In

Skip to content

Security Contacts and Procedures

Red Hat takes security very seriously and we aim to take immediate action to address any security related problems that involve our products or services.

Please report any instances of security vulnerability with any Red Hat product or service to the Red Hat Security Response Team, secalert@redhat.com. You can communicate with us securely using our GPG key.

What you should use secalert@redhat.com for:

  • If you have found a security vulnerability with a Red Hat product or service
  • If you are unsure about how a known vulnerability affects a Red Hat product or service

What you should not use secalert@redhat.com for:

  • Technical assistance (for example "how do I configure my firewall")
  • Asking for help upgrading packages due to security alerts
  • Other non security-related issues

In any of these cases please instead contact Red Hat Global Support Services.

Who reads email sent to secalert@redhat.com:

The Red Hat Security Response Team, a restricted and carefully chosen group of Red Hat employees, monitors the secalert@redhat.com address. No outside users can subscribe to this list.

What to send to secalert@redhat.com:

When you contact the list please give as much information as possible. We encourage you to encrypt any sensitive information you send to us using our public key.

How we respond to a notification

Email communications sent to secalert@redhat.com will be read and acknowledged with a non-automated response within 3 working days. We will open an investigation and will keep you informed of the progress at least every 5 working days.

Information about security issues you share with us that are not already public knowledge will be treated in confidence and we will not pass on the details to any third party without obtaining your permission in advance.

Red Hat does not provide an advance notification service. Security advisories are available from our web site and via the Red Hat Network.

Monthly Security Newsletter:

Updates on the latest open source news and tools.