Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11553 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.8Red Hat

High [CVE-2026-92125] Arbitrary code execution via Groovy AST transformation bypass

Arbitrary code execution via Groovy AST transformation bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-184. Affected product named by the advisory: OpenShift Developer Tools and Services.

CVE-2026-92125
Unclassified
Sep 16, 2026
High7.5Red Hat Updated

High [CVE-2026-19667] Denial of Service via 16-bit length truncation in DNS negative cache handling

Denial of Service via 16-bit length truncation in DNS negative cache handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:75577 with package bind9.18-32:9.18.29-14.el9_8.10, bind-main-9.20.29-0.1.hum1, bind-32:9.18.33-15.el10_2.12, bind-32:9.16.23-40.el9_8.10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-19667
Unclassified
Sep 16, 2026
High7.5Red Hat Updated

High [CVE-2026-81736] Remote Denial of Service via cached SVCB/HTTPS AliasMode records

Remote Denial of Service via cached SVCB/HTTPS AliasMode records. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:75577 with package bind9.18-32:9.18.29-14.el9_8.10, bind-main-9.20.29-0.1.hum1, bind-32:9.18.33-15.el10_2.12. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-81736
Unclassified
Sep 16, 2026
High8.1Red Hat Updated

High [CVE-2026-82717] Remote Code Execution Vulnerability in CNAME Synthesis

Remote Code Execution Vulnerability in CNAME Synthesis. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:71419 with package rhcos-4.22.9.8.202609291947-0, unbound-0:1.24.2-3.el9_8.8, unbound-0:1.24.2-7.el10_2.6, unbound-main-1.26.1-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.

CVE-2026-82717
Unclassified
Sep 16, 2026
High7.5Red Hat Updated

High [CVE-2026-81634] Heap buffer overflow via malicious DNSSEC response

Heap buffer overflow via malicious DNSSEC response. Red Hat rates this important (CVSS 7.5). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:71419 with package rhcos-4.22.9.8.202609291947-0, unbound-0:1.24.2-3.el9_8.8, unbound-0:1.24.2-7.el10_2.6, unbound-main-1.26.1-1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.

CVE-2026-81634
Unclassified
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-92220] Resource consumption via argument manipulation in MoRIIO Acknowledgement Handler

Resource consumption via argument manipulation in MoRIIO Acknowledgement Handler. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-92220
Unclassified
Sep 16, 2026
High8.2Red Hat

High [CVE-2026-92218] Server-Side Template Injection via two-pass non-sandboxed Jinja render

Server-Side Template Injection via two-pass non-sandboxed Jinja render. Red Hat rates this important (CVSS 8.2). Weakness: CWE-94.

CVE-2026-92218
Unclassified
Sep 16, 2026
High8.8Red Hat

High [CVE-2026-89775] Handle negative S1 walk levels in VNCR TLB size evaluation

Handle negative S1 walk levels in VNCR TLB size evaluation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:72624 with package kernel-0:6.12.0-211.61.1.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-89775
Unclassified
Sep 16, 2026
High7.1Red Hat Updated

High [CVE-2026-89846] Bound rsp_info_len to avoid OOB sense-data read

Bound rsp_info_len to avoid OOB sense-data read. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71232 with package rhcos-4.22.9.8.202609291947-0, kernel-0:6.12.0-211.59.1.el10_2, kernel-rt-0:4.18.0-553.167.1.rt7.508.el8_10, kernel-0:4.18.0-553.167.1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-89846
Unclassified
Sep 16, 2026
High7.8Red Hat Updated

High [CVE-2026-89972] add missing SRCU grace period in error path

In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace period in error path nvme_alloc_ns() error path at out_unlink_ns removes ns from the namespace head siblings list with list_del_rcu(&ns->siblings) but does not wait for SRCU readers before freeing the namespace struct. Multipath code iterates the head->list under srcu_read_lock() in nvme_find_path() and nvme_mpath_revalidate_paths(), so a concurrent reader can still hold a reference to ns when kfree(ns) runs. The normal removal path in nvme_ns_remove() correctly calls synchronize_srcu(&ns->head->srcu) after list_del_rcu() to wait for in-progress readers. A flaw was found in the NVMe (Non-Volatile Memory Express) driver of the Linux kernel. The nvme_alloc_ns() function's error handling path fails to wait for all SRCU (Sleepable Read-Copy Update) readers to complete before freeing a namespace structure. This oversight allows a concurrent reader to access a freed memory region, leading to a use-after-free vulnerability. A local attacker could potentially exploit this to cause a system crash or achieve arbitrary code execution. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-366. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-89972
Linux Kernel
Sep 16, 2026
High7.8Red Hat Updated

High [CVE-2026-89970] Synchronize timeout work during SQ teardown

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ teardown nvmet_auth_sq_free() cancels auth_expired_work with cancel_delayed_work(). If the work has already started, cancellation does not wait for the callback. Transport teardown can consequently free or reuse the queue containing struct nvmet_sq while nvmet_auth_expired_work() still accesses that SQ. Add a teardown-specific helper that synchronously drains the delayed work before freeing authentication state, and use it from nvmet_sq_destroy(). Keep the non-synchronous helper for in-band authentication state cleanup, where the SQ owner remains alive. A timing issue during the cleanup of a Submission Queue (SQ) can lead to a use-after-free vulnerability. This occurs when a delayed authentication task attempts to access memory that has already been released or repurposed. An attacker could potentially exploit this to cause a system crash (denial of service) or other memory corruption impacts. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-89970
Linux Kernel
Sep 16, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-90015] fix lost bounce buffers on TDs spanning several ring segments

In the Linux kernel, the following vulnerability has been resolved: xhci: fix lost bounce buffers on TDs spanning several ring segments When a TD reaches a link TRB with data that is not aligned to the endpoint's wMaxPacketSize, xhci_align_td() stages the unalignable tail through the bounce buffer of the ring segment holding that link TRB. xhci_unmap_td_bounce_buffer() later unmaps it and, for IN transfers, copies the data back into the URB's buffer. The enqueue path records the segment that was bounced in td->bounce_seg, under the assumption that a TD never spans more than two ring segments. That assumption does not hold: a TD large enough to span three or more segments crosses several link TRBs and can be bounced at each of them. Only the last one survives in td->bounce_seg, so every earlier bounce buffer is neither copied back nor DMA unmapped. The URB still completes with actual_length equal to the requested length and no error, so the transfer looks successful while a wMaxPacketSize sized hole in the destination buffer silently keeps its previous contents. It also leaks a DMA mapping per dropped bounce. Any sufficiently large and fragmented bulk transfer can hit this. It was found with a USB mass storage device behind xHCI backing a dm-verity target with 512 byte hash blocks, where the stale data is detected rather than silently consumed.

CVE-2026-90015
Linux Kernel
Sep 16, 2026
High7.0Red Hat Updated

High [CVE-2026-89777] clear vdev->msi_perm after freeing it on init failure

clear vdev->msi_perm after freeing it on init failure. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-89777
Linux Kernel
Sep 16, 2026
High7.0Red Hat Updated

High [CVE-2026-89791] Fix use-after-free when perf mmap revival races with the last munmap

Fix use-after-free when perf mmap() revival races with the last munmap(). Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-89791
Linux Kernel
Sep 16, 2026
High7.0Red Hat Updated

High [CVE-2026-90036] Prevent client use-after-free during blocked-lock reaping

Prevent client use-after-free during blocked-lock reaping. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-90036
Linux Kernel
Sep 16, 2026
High7.0Red Hat Updated

High [CVE-2026-89932] Always flush vpid02 on first use

Always flush vpid02 on first use. Red Hat rates this important (CVSS 7). Weakness: CWE-524. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-89932
Linux Kernel
Sep 16, 2026
High7.0Red Hat Updated

High [CVE-2026-90049] don't skb_tx_error the source skb in skb_zerocopy

don't skb_tx_error() the source skb in skb_zerocopy(). Red Hat rates this important (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-90049
Linux Kernel
Sep 16, 2026
High7.0Red Hat Updated

High [CVE-2026-90008] Limit NVMe request size to the PRP chain frame

Limit NVMe request size to the PRP chain frame. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-90008
Linux Kernel
Sep 16, 2026
High7.0Red Hat Updated

High [CVE-2026-89811] Add TLB flush after MES queue eviction/suspension

Add TLB flush after MES queue eviction/suspension. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-89811
Linux Kernel
Sep 16, 2026
High7.0Red Hat Updated

High [CVE-2026-89894] reject geometry changes while the VBI queue is busy

reject geometry changes while the VBI queue is busy. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-89894
Linux Kernel
Sep 16, 2026

← All vendors