Red Hat Linux Security Advisories & CVEs
3200 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-53349] destroy stale expectfn expectations on unregister
destroy stale expectfn expectations on unregister. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-53352] clear JOBCTL_PENDING_MASK for caller in zap_other_threads
clear JOBCTL_PENDING_MASK for caller in zap_other_threads(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-617.
Medium [CVE-2026-53348] fix NULL pointer dereference in sdca_dev_unregister_functions
fix NULL pointer dereference in sdca_dev_unregister_functions. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-53344] Initialize mcp->dev and mcp->addr before regmap init
Initialize mcp->dev and mcp->addr before regmap init. Red Hat rates this moderate. Weakness: CWE-476.
Medium [CVE-2026-53342] call pagetable dtor when freeing hot-removed page tables
call pagetable dtor when freeing hot-removed page tables. Red Hat rates this moderate. Weakness: CWE-459.
Medium [CVE-2026-53326] Don't call fill_pool in early boot hardirq context
Don't call fill_pool() in early boot hardirq context. Red Hat rates this low (CVSS 5.5). Weakness: CWE-833.
Medium [CVE-2026-53339] Fix NULL pointer dereference in cci_remove
Fix NULL pointer dereference in cci_remove(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-53331] Avoid ABBA on tx_lock/ctrl->lock
Avoid ABBA on tx_lock/ctrl->lock. Red Hat rates this moderate. Weakness: CWE-833.
Medium [CVE-2026-53327] Do not fill_pool if pi_blocked_on
Do not fill_pool() if pi_blocked_on. Red Hat rates this low (CVSS 5.5). Weakness: CWE-367.
Medium [CVE-2026-53350] Fix NULL dereference when removing firmware controls
Fix NULL dereference when removing firmware controls. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-53347] Fix driver removal with disabled KMS
Fix driver removal with disabled KMS. Red Hat rates this low (CVSS 5.5). Weakness: CWE-824.
Medium [CVE-2026-53340] fix clock and pinctrl state inconsistency in runtime PM
fix clock and pinctrl state inconsistency in runtime PM. Red Hat rates this low (CVSS 5.5). Weakness: CWE-367.
Medium [CVE-2026-53337] fix NULL pointer dereference in bond_do_ioctl
fix NULL pointer dereference in bond_do_ioctl(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-54902] Use-After-Free in Oj::Parser SAJ Long Key Callback
Use-After-Free in Oj::Parser SAJ Long Key Callback. Red Hat rates this moderate.
Medium [CVE-2026-54901] Use-After-Free in Oj::Parser array_class/hash_class GC Marking
Use-After-Free in Oj::Parser array_class/hash_class GC Marking. Red Hat rates this moderate.
Medium [CVE-2026-54898] Denial of Service via input string mutation during JSON parsing
Denial of Service via input string mutation during JSON parsing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-825.
Medium [CVE-2026-54502] Stack Buffer Overflow in Oj.dump via Large Indent
Stack Buffer Overflow in Oj.dump via Large Indent. Red Hat rates this moderate.
Medium [CVE-2026-54500] Information disclosure via uninitialized stack memory read
Information disclosure via uninitialized stack memory read. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-125.
Medium [CVE-2026-54899] Use-After-Free in parser symbol key cache toggle
Use-After-Free in parser symbol key cache toggle. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-825.
Medium [CVE-2026-54673] Information disclosure via unstripped credential headers during HTTP redirects
Information disclosure via unstripped credential headers during HTTP redirects. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201.