Skip to content
VulniPulse

Red Hat Linux Linux Kernel Vulnerabilities & Security Advisories

2107 advisories tracked · Red Hat Security Data API · 1 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Linux Kernel, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 765 high, 1338 medium, 1 low.

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat Linux Kernel advisories

High7.0Red Hat

High [CVE-2026-74662] publish queues before arming timer

publish queues before arming timer. Red Hat rates this important (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74662
Linux Kernel
Aug 22, 2026
High7.0Red Hat

High [CVE-2026-74611] restore msg_iter before TLS 1.3 optimistic retry

restore msg_iter before TLS 1.3 optimistic retry. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74611
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74639] re-anchor capture URBs on resubmission

re-anchor capture URBs on resubmission. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74639
Linux Kernel
Aug 22, 2026
High7.0Red Hat

High [CVE-2026-74630] prevent in6_dev_get from resurrecting inet6_dev

prevent in6_dev_get() from resurrecting inet6_dev. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74630
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74697] Disable EOP for TPA on all chips to prevent data corruption

Disable EOP for TPA on all chips to prevent data corruption. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74697
Linux Kernel
Aug 22, 2026
High7.0Red Hat

High [CVE-2026-74640] fix OOB write in fcp_meter_ctl_get

fix OOB write in fcp_meter_ctl_get(). Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74640
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74674] fix incorrect flush address in direct page table reclaim

fix incorrect flush address in direct page table reclaim. Red Hat rates this moderate (CVSS 7). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.

CVE-2026-74674
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74724] avoid out-of-bounds write in ip_vs_nat_icmp

avoid out-of-bounds write in ip_vs_nat_icmp. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74724
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74612] fix skb length accounting after XDP frag adjustment

fix skb length accounting after XDP frag adjustment. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74612
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74660] pin the NFLOG backend

pin the NFLOG backend. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74660
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74692] fix TOCTOU race between smc_listen_out and listener close

fix TOCTOU race between smc_listen_out() and listener close. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74692
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74610] don't leave a full plaintext sk_msg ring unpushed

don't leave a full plaintext sk_msg ring unpushed. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-74610
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74705] fix potential use-after-free in tunnel segmentation

fix potential use-after-free in tunnel segmentation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74705
Linux Kernel
Aug 22, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-74637] Fix group leader use-after-free after sibling detach

Fix group leader use-after-free after sibling detach. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74637
Linux Kernel
Aug 22, 2026
High7.8Red Hat

High [CVE-2026-74583] fix fastmap use-after-free on filter

fix fastmap use-after-free on filter. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat package: kernel-rt.

CVE-2026-74583
Linux Kernel
Aug 21, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72310] fix overflow in passthrough ioctl bounds check

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix overflow in passthrough ioctl bounds check smb2_ioctl_query_info() validates the PASSTHRU_FSCTL response payload before copying it to userspace. The payload offset and length both come from 32-bit fields. The bounds check currently adds OutputOffset and qi.input_buffer_length directly, so the addition can wrap in 32-bit arithmetic before the result is compared against the response buffer length. A malicious server can use a large OutputOffset and a small OutputCount to make the wrapped sum pass the bounds check. The later copy_to_user() then reads from io_rsp + OutputOffset, outside the response buffer. Use size_add() for the offset plus length check so overflow is treated as out of bounds. By sending a specially crafted response with a large offset, the server can cause the client to read data beyond the allocated buffer. This out-of-bounds read could lead to information disclosure from the kernel memory. Red Hat severity: Moderate — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-72310
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72069] Fix the incorrect RCU protection in rt_spin_unlock

In the Linux kernel, the following vulnerability has been resolved: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() rt_spin_unlock() releases the RCU protection before unlocking the lock. That opens the door for the following UAF scenario: T1T2 spin_lock(&p->lock);rcu_read_lock(); invalidate(p);p = rcu_dereference(ptr); rcu_assign_pointer(ptr, NULL);if (!p) return; spin_unlock(&p->lock);spin_lock(&p->lock) lock(&lock->lock); rcu_read_lock(); kfree_rcu(p);rcu_read_unlock();.... spin_unlock(&p->lock) rcu_read_unlock(); // Ends grace period rcu_do_batch() kfree(p); UAF -> rt_mutex_cmpxchg_release(&lock->lock...) Regular spinlocks keep preemption disabled accross the unlock operation, which provides full RCU protection, but the RT substitution fails to resemble that. Same applies for the rwlock substitution. Move the rcu_read_unlock() invocation past the unlock operations to match the non-RT semantics. This makes it asymmetric vs. rt_xxx_lock(), but that's harmless as the caller needs to hold RCU read lock across the lock operation. The migrate_enable() call stays before the unlock operation because there is no per CPU operation in the unlock path which would require migration to be kept disabled. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72069
Linux Kernel
Aug 15, 2026
High7.0Red Hat

High [CVE-2026-72220] harden rq_procinfo lifecycle to prevent double-free

In the Linux kernel, the following vulnerability has been resolved: sunrpc: harden rq_procinfo lifecycle to prevent double-free The svc_release_rqst() function executes the callback inside rqstp->rq_procinfo->pc_release. However, if a worker thread begins processing a new request and encounters an early error path (e.g., unsupported protocol, short frame, or bad auth) before a valid rq_procinfo is installed, a stale release hook can be re-triggered against reused state from the previous RPC, resulting in a double-free or use-after-free vulnerability. Ensuring svc_release_rqst() always clears rq_procinfo after the optional pc_release() call, regardless of whether the hook exists. 2. Explicitly clearing rq_procinfo at request entry in svc_process() before any early decode or drop paths. 3. Ensuring svc_process_bc() does the same at backchannel entry. This guarantees that error flows will not encounter a non-NULL stale rq_procinfo pointer when there is nothing to release. This can lead to a double-free or use-after-free vulnerability, potentially allowing an attacker to cause a denial of service or execute arbitrary code. Red Hat severity: Important — CVSS 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-1341. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-72220
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72287] Move vTPR vs. TPR Threshold consistency check into "normal" checks

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks Move the off-by-default consistency check for vmcs12.tpr_threshold vs. the virtual APIC vTPR into the "normal" controls checks, as waiting until KVM has loaded some amount of state is unnecessary and actively dangerous. Specifically, failure to unwind vmcs01.GUEST_CR3 to KVM's value when EPT is disabled results in KVM running L1 with an L1-controlled CR3, not with KVM's CR3! Alternatively, KVM could simply reset the MMU to force a reload of vmcs01.GUEST_CR3, but the _only_ reason the check was shoved into a "late" flow was to wait until the vmcs12 pages were retrieved. Rather than build up more crusty code, simply access vTPR using a regular guest memory access (performance isn't a concern). To circumvent the restrictions that led to KVM deferring nested_get_vmcs12_pages(), (a) use a VM-scoped API to read guest memory so that it always hits non-SMM memslots (for RSM), and (b) skip the check (since its off-by-default anyways) when the vCPU doesn't want to run, i.e. when userspace is restoring/stuffing state. If reading guest memory fails, simply skip the consistency check, as KVM's de facto ABI is that VMX instruction accesses to non-existent memory get PCI Bus Error semantics, where reads return 0xFFs.

CVE-2026-72287
Linux Kernel
Aug 15, 2026
High7.0Red Hat

High [CVE-2026-72248] support IPIP tunnel with direct xmit

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: support IPIP tunnel with direct xmit The combination of IPIP tunnel with direct xmit, eg. bridge device, breaks because no dst_entry is provided to check the skb headroom and to set the iph->frag_off field. This leads to invalid dst usage and can trigger a crash in the tunnel transmit path. Fix this by moving dst_cache and dst_cookie out of the runtime union so that they can be shared by neighbour, xfrm, and direct tunnel flows. For FLOW_OFFLOAD_XMIT_DIRECT tuples carrying tunnel metadata, preserve route state in these shared fields and release it through the common dst release path. Since dst_entry is now available to the three supported xmit modes and dst_release() already deals with NULL dst, remove the xmit type check in nft_flow_dst_release(). Moreover, skip the check if the dst entry is NULL in nf_flow_dst_check() which is now the case for the direct xmit case. Based on patch from Rein Wei. When an Internet Protocol over Internet Protocol (IPIP) tunnel is used with direct transmit (xmit), such as with a bridge device, the system fails to properly handle network packet destination entries. This improper handling can lead to a system crash in the tunnel transmit path, resulting in a Denial of Service (DoS).

CVE-2026-72248
Linux Kernel
Aug 15, 2026

← All Red Hat advisories