Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-74556] Bound SCSI Response data segment to the connection buffer
Bound SCSI Response data segment to the connection buffer. Red Hat rates this important (CVSS 7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-73632] Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization state could be shared across concurrent requests, allowing response content associated with one request to become observable in another. Only the SMD / JSON-RPC handling of the JSON interceptor is affected, which is not enabled by default; applications using the json result type are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.
Medium [CVE-2026-73631] Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts
Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state could be shared across concurrent requests, allowing data associated with one request to become observable in another, and configured parsing limits not to be enforced as intended. Populating actions from a JSON request body is not enabled by default; applications that do not use the JSON plugin are not affected. This issue affects Apache Struts: 7.2.1. Users are recommended to upgrade to version 7.3.0, which fixes the issue.
Medium [CVE-2026-72428] Fix stack slot index in nospec checks
Fix stack slot index in nospec checks. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-72245] Fix device reference leak in host1x_device_parse_dt error path
Fix device reference leak in host1x_device_parse_dt() error path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-72403] Fix NULL pointer dereference in interface lookup
Fix NULL pointer dereference in interface lookup. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-72190] fix mrec_lock ABBA deadlock in rename
fix mrec_lock ABBA deadlock in rename. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.
Medium [CVE-2026-72292] Initialize KVM_S390_GET_CMMA_BITS memory
Initialize KVM_S390_GET_CMMA_BITS memory. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-908.
Medium [CVE-2026-72454] Fix race in i3c_hci_addr_to_dev
Fix race in i3c_hci_addr_to_dev(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
Medium [CVE-2026-72025] Reject buffer reuse with different data length
Reject buffer reuse with different data length. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-72396] Prevent reading uninitialized stack
Prevent reading uninitialized stack. Red Hat rates this low (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-72305] avoid leaking information to userspace
avoid leaking information to userspace. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-72309] Fix leak in trace_remote_alloc_buffer error path
Fix leak in trace_remote_alloc_buffer() error path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-911.
Medium [CVE-2026-72470] resize log->one_page_buf when adopting on-disk page size
resize log->one_page_buf when adopting on-disk page size. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-131.
Medium [CVE-2026-72011] Add missing array_index_nospec call to memtop_get_page_count
Add missing array_index_nospec() call to memtop_get_page_count(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-72490] fix stainfo check in rtw_aes_decrypt
fix stainfo check in rtw_aes_decrypt. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-72189] fail attrlist updates when the superblock is inactive
fail attrlist updates when the superblock is inactive. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.
Medium [CVE-2026-72068] Use u64 multiplication in update_rlimit_cpu
Use u64 multiplication in update_rlimit_cpu(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-72296] require ETH_HLEN to be pullable in ife_decode
require ETH_HLEN to be pullable in ife_decode(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-72458] fix NULL pointer dereference in unpack_pdb
fix NULL pointer dereference in unpack_pdb. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.