Red Hat Linux Linux Kernel Vulnerabilities & Security Advisories
2113 advisories tracked · Red Hat Security Data API · 1 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as Linux Kernel, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 767 high, 1343 medium, 1 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat Linux Kernel advisories
High [CVE-2026-74509] Fix advertising data UAFs
Fix advertising data UAFs. Red Hat rates this important (CVSS 8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74510] fix UAF in pair command cancellation
fix UAF in pair command cancellation. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-74574] fix fdev setup failure cleanup in idxd_cdev_open
fix fdev setup failure cleanup in idxd_cdev_open(). Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-833. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74533] fix race of kfree vs kref_get_unless_zero
fix race of kfree vs kref_get_unless_zero. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74447] fix uint32_t overflow in EOP ring buffer size alignment
fix uint32_t overflow in EOP ring buffer size alignment. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74443] bound DMA command body size against suffix pointer
bound DMA command body size against suffix pointer. Red Hat rates this moderate (CVSS 7). Weakness: CWE-124. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74441] Fix race condition and ordering in port unregistration
Fix race condition and ordering in port unregistration. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74568] Fix race between LPI release and re-registration
Fix race between LPI release and re-registration. Red Hat rates this moderate (CVSS 7). Weakness: CWE-821. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74537] hold sk properly in iso_conn_ready
hold sk properly in iso_conn_ready. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74474] use pskb_network_may_pull for transmit path header pulls
use pskb_network_may_pull() for transmit path header pulls. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74502] fix double free of out_cvts on rawmidi error
fix double free of out_cvts on rawmidi error. Red Hat rates this important (CVSS 7). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74517] Cancel delayed I/O APIC EOI handling before destroying vCPUs
Cancel delayed I/O APIC EOI handling before destroying vCPUs. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74554] fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup
fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74496] Fix use-after-free in fou_create
Fix use-after-free in fou_create(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74575] Prevent XDomain delayed work use-after-free on disconnect
Prevent XDomain delayed work use-after-free on disconnect. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74516] Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active
Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74534] fix refcounting of iso_conn
fix refcounting of iso_conn. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74518] fix list corruption in allocate_file_region_entries
fix list corruption in allocate_file_region_entries(). Red Hat rates this important (CVSS 7.8). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74556] Bound SCSI Response data segment to the connection buffer
Bound SCSI Response data segment to the connection buffer. Red Hat rates this important (CVSS 7.2). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68453] Fix buffer over-read in cca_cipher2protkey
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in cca_gencipherkey() for possible underflow with returned key size. The CCA token structures contain user-controlled len fields that were used in operations without proper validation against both the actual buffer size and minimum token structure size. An attacker could set this field larger than the actual buffer size, leading to reading beyond buffer boundaries. This may result in a kernel crash or exposure of memory via sending this as part of a request down to the crypto card. Also an attacker could have used a very small len value and thus enforce a buffer under-run which may produce similar effects as a over-read. So now a key must - key buf length must be at least sizeof the token struct - the key len field inside the token must fit into the range of sizeof key token struct... key buf length This vulnerability arises from insufficient validation of user-controlled length fields within the Common Cryptographic Architecture (CCA) token structures. This could lead to a kernel crash, resulting in a denial of service, or the exposure of sensitive memory information.