RHSA
Red Hat Security Advisory
Red-Hat-Sicherheitshinweis
An RHSA is Red Hat's official security advisory for vulnerabilities in Red Hat products, primarily Red Hat Enterprise Linux. It links affected packages to the associated Common Vulnerabilities and Exposures (CVE)-IDs, a severity rating and the corrected versions. For Red Hat environments it is the authoritative patch reference.
History & facts. RHSA identifiers follow the pattern RHSA-YEAR:NUMBER. Red Hat runs its own product security team and uses a four-level severity scale (Critical, Important, Moderate, Low) that does not necessarily follow the raw Common Vulnerability Scoring System (CVSS) value but accounts for concrete exploitability in the product context. The data is also provided machine-readable (e.g. as OVAL).
Outlook & recommendation. The vendor's own severity rating is often more meaningful than the generic Common Vulnerability Scoring System (CVSS) value because it incorporates the actual attackability within the distribution. In vulnerability management, RHSA rating, CVSS and Exploit Prediction Scoring System (EPSS) should be considered together — the vendor rating answers „how urgent for me“, while EPSS adds „how likely to be exploited“.