Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11557 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.5Red Hat Updated

Medium [CVE-2026-89996] don't publish fd before copy_to_user succeeds

In the Linux kernel, the following vulnerability has been resolved: dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds DMA_HEAP_IOCTL_ALLOC allocates a dma-buf and installs an fd into the caller's fd table via dma_buf_fd() -> fd_install() before dma_heap_ioctl() copies the result back to userspace. If the trailing copy_to_user() fails, userspace never learns the fd number, but the fd (and the underlying dma-buf reference) are already visible to other threads in the same process and are leaked for the lifetime of the process. The obvious "close it on the failure path" fix is unsafe: once fd_install() has run, another thread can already dup() the fd, send it via SCM_RIGHTS, or close() it and let its number be reused, so a subsequent close_fd() from the ioctl path can operate on an unrelated file. This was pointed out by Christian König on v1 [1]. Restructure the allocation path so that fd_install() is the last, unfailable step of a successful ioctl: 1. heap->ops->allocate() creates the dma_buf. 2. get_unused_fd_flags() reserves an fd number in the caller's fd table without publishing it, so no other thread can observe it. 3. copy_to_user() delivers the fd number to userspace; on failure the fd is returned with put_unused_fd() and the dma_buf reference is dropped with dma_buf_put(), leaving no user- visible state behind.

CVE-2026-89996
Linux Kernel
Sep 16, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-89975] fix DHCHAP secret leak on parse failure

In the Linux kernel, the following vulnerability has been resolved: nvme-fabrics: fix DHCHAP secret leak on parse failure nvmf_parse_options() duplicates dhchap_secret and dhchap_ctrl_secret with match_strdup() before validating the DHHC-1: representation. If validation fails, the parser returns -EINVAL before the temporary string in p is assigned to opts->dhchap_secret or opts->dhchap_ctrl_secret. nvmf_create_ctrl() subsequently frees opts, but nvmf_free_options() cannot release the unassigned temporary string. Each rejected option therefore leaks one allocation. This is easy to miss because valid secrets transfer ownership to opts and are freed normally, while the malformed-secret path still returns the expected -EINVAL to userspace. With CONFIG_NVME_HOST_AUTH enabled, the leak is reachable before the required-option checks and transport lookup. No NVMe-oF target or working transport connection is required; for example, repeatedly writing dhchap_secret=BAD or dhchap_ctrl_secret=BAD to /dev/nvme-fabrics deterministically takes the leaking parse path. Free the temporary string before leaving both validation error paths. Use kfree_sensitive() because the copied option may contain secret material even when its representation is rejected, matching the sensitive cleanup used for stored DHCHAP secrets.

CVE-2026-89975
Linux Kernel
Sep 16, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-89837] fix dentry folio leak in find_in_level

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix dentry folio leak in find_in_level find_in_level() gets a dentry folio with f2fs_find_data_folio() before calling find_in_block(). If find_in_block() returns an error, the function stores the error in res_folio and breaks out of the loop without dropping the dentry folio. This leaks the folio reference on the find_in_block() error path. Drop the dentry folio before returning the error to the caller. This oversight leads to a memory leak, which can be exploited by a local attacker to cause resource exhaustion and potentially a Denial of Service (DoS) condition, making the system unresponsive. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-772. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected.

CVE-2026-89837
Unclassified
Sep 16, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-89889] Release runtime PM reference on VBLANK error

In the Linux kernel, the following vulnerability has been resolved: media: i2c: imx415: Release runtime PM reference on VBLANK error The VBLANK path returned immediately when programming VMAX failed after pm_runtime_get_if_in_use() had taken a runtime PM reference. Break out of the switch instead so the common pm_runtime_put() path is used. When programming VMAX fails, the VBLANK path returns immediately without releasing a previously acquired runtime power management (PM) reference. This oversight can lead to a resource leak, potentially allowing a local attacker to cause a denial of service (DoS) by exhausting system resources. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-772. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected.

CVE-2026-89889
Unclassified
Sep 16, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-89924] Fix old_data leak in guest debug error path

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix old_data leak in guest debug error path __import_wp_info() allocates a per-watchpoint old_data buffer to back up the original guest memory contents. If a later watchpoint of the same KVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data() jumps to the error label, which frees the wp_info array but not the old_data buffers of the entries that were imported successfully. Up to MAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes are leaked per failed request, and the request can be repeated. Create error handling for cleaning up all created old_data memory areas. A flaw was found in the Linux kernel's KVM (Kernel-based Virtual Machine) component for s390 architecture. When handling guest debug requests, a memory leak occurs if a watchpoint import fails. A local guest user could repeatedly trigger this flaw, leading to a continuous leak of memory buffers. This could eventually result in a denial of service (DoS) due to resource exhaustion. Red Hat severity: Low — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-772. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7 as not affected.

CVE-2026-89924
Linux Kernel
Sep 16, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-89824] fix i2c adapter leak on probe failure

In the Linux kernel, the following vulnerability has been resolved: drm/panel-edp: fix i2c adapter leak on probe failure Make sure to drop the i2c adapter reference on probe failure (e.g. probe deferral) and on driver unbind also if a devicetree redundantly uses the 'ddc-i2c-bus' property to point to the aux ddc bus. This resource leak could potentially lead to system instability or a Denial of Service (DoS) condition. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-772. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected.

CVE-2026-89824
Unclassified
Sep 16, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-89909] Free init resources if kvm_init fails

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Free init resources if kvm_init() fails kvm_loongarch_init() calls kvm_loongarch_env_init() to allocate the per-CPU kvm_context (vmcs) and kvm_loongarch_ops and to register the perf callbacks, and then calls kvm_init(). If kvm_init() fails its result is returned directly, but since module_init() does not run the module_exit() stuff on failure, so kvm_loongarch_env_exit() is never called and those resources are leaked. So call kvm_loongarch_env_exit() when kvm_init() fails, matching the teardown-on-failure pattern used by riscv_kvm_init(). A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) for LoongArch architecture. During initialization, if a specific setup function fails, critical resources are not properly released. This can lead to a resource leak, potentially allowing a local attacker to cause a denial of service by exhausting system resources. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-772. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected.

CVE-2026-89909
Unclassified
Sep 16, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-89867] Defer job_finish only when a DEC_PIC was queued

In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued Decoder instances sharing a VPU also share one v4l2_m2m job slot, released when the running context calls v4l2_m2m_job_finish(). While draining, device_run() defers job_finish() once EOS is sent (sent_eos), expecting a later finish_decode() (from a DEC_PIC completion IRQ) to release the slot. But the m2m core checks job_ready() only when a job is queued, not when it is dispatched. With several v4l2h264dec instances in parallel, GStreamer hangs at EOS. Track whether the run actually queued a DEC_PIC (cmd_issued) and defer job_finish() only then. Otherwise finish the job immediately This vulnerability occurs when multiple video decoder instances share a video processing unit (VPU) and a job slot is not properly released during the draining process, particularly if a decode picture (DEC_PIC) is not queued. This resource leak can cause the shared job slot to become unavailable, leading to instances stalling and potentially resulting in a system hang, effectively causing a Denial of Service (DoS). Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-772.

CVE-2026-89867
Unclassified
Sep 16, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-89815] Drop tt->restore after successful restore

In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Drop tt->restore after successful restore ttm_pool_restore_and_alloc() can successfully complete the restore process via ttm_pool_restore_commit(), but tt->restore is not dropped afterward. As a result, subsequent backup/restore flows observe what appears to be a completed restore, while in reality shmem handles are still installed in tt->pages, leading to the stack trace below. Fix this by freeing and dropping tt->restore in ttm_pool_restore_and_alloc() upon successful completion of the restore. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-89815
Linux Kernel
Sep 16, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-89923] Free guest debug data on vcpu destroy

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Free guest debug data on vcpu destroy kvm_s390_clear_bp_data() is only called from kvm_arch_vcpu_ioctl_set_guest_debug(), i.e. when user space changes or disables debugging. A vCPU that is destroyed while hardware breakpoints are still armed - the normal case when the VMM just exits or crashes - leaks hw_bp_info, hw_wp_info and all old_data buffers, since generic KVM frees the vCPU right after kvm_arch_vcpu_destroy(). That is bounded by MAX_BP_COUNT entries, so roughly 8 KiB per vCPU, but it is unbounded over VM lifetimes. The allocations are GFP_KERNEL_ACCOUNT, so the charge also outlives the exiting process and pins dying memcgs. Fix by clearing the debug data on vCPU destruction. Calling it unconditionally is fine: struct kvm_vcpu is zero allocated, so for a vCPU that never enabled debugging the counters are 0 and the pointers NULL. A memory leak occurs in the Kernel-based Virtual Machine (KVM) for s390 architecture when a virtual CPU (vCPU) is destroyed while hardware breakpoints are still active, as the associated debug data is not properly freed. A local attacker or a malicious guest operating system could trigger this condition. Over time, this can lead to resource exhaustion and a Denial of Service (DoS) for the host system.

CVE-2026-89923
Linux Kernel
Sep 16, 2026
Low3.3Red Hat

Low [CVE-2026-81870] github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging

github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging. Red Hat rates this low (CVSS 3.3). Weakness: CWE-538. Red Hat lists fixing advisory RHSA-2026:72475 with package cert-manager/cert-manager-istio-csr-rhel9:1790223719, cert-manager/cert-manager-istio-csr-rhel9:1790589914. Affected product named by the advisory: Cert Manager support for Red Hat OpenShift release 1.20.

CVE-2026-81870
Unclassified
Sep 16, 2026
Low3.7Red Hat

Low [CVE-2026-77860] Denial of Service via 'serve-expired' code path bypass

Denial of Service via 'serve-expired' code path bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-675. Red Hat lists fixing advisory RHSA-2026:68590 with package unbound-main-1.26.1-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: unbound.

CVE-2026-77860
Red Hat Enterprise Linux
Sep 16, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-91722] Use after free in Input

Use after free in Input. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-91722
Unclassified
Sep 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-91738] Improper input validation in ANGLE

Improper input validation in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-1286.

CVE-2026-91738
Unclassified
Sep 15, 2026
Critical9.6Red Hat

Critical [CVE-2026-91729] Arbitrary code execution via use-after-free in DigitalCredentials

Arbitrary code execution via use-after-free in DigitalCredentials. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825.

CVE-2026-91729
Unclassified
Sep 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-91716] Use after free in Auth

Use after free in Auth. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-91716
Unclassified
Sep 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-91718] Use after free in Core

Use after free in Core. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-91718
Unclassified
Sep 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-91710] Use after free in WebAppInstalls

Use after free in WebAppInstalls. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-91710
Unclassified
Sep 15, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-91735] Incorrect authorization in WebUI

Incorrect authorization in WebUI. Red Hat rates this important (CVSS 9). Weakness: CWE-266.

CVE-2026-91735
Unclassified
Sep 15, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-91743] Race condition in Core

Race condition in Core. Red Hat rates this important (CVSS 9). Weakness: CWE-368.

CVE-2026-91743
Unclassified
Sep 15, 2026

← All vendors