Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11608 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-89923] Free guest debug data on vcpu destroy

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Free guest debug data on vcpu destroy kvm_s390_clear_bp_data() is only called from kvm_arch_vcpu_ioctl_set_guest_debug(), i.e. when user space changes or disables debugging. A vCPU that is destroyed while hardware breakpoints are still armed - the normal case when the VMM just exits or crashes - leaks hw_bp_info, hw_wp_info and all old_data buffers, since generic KVM frees the vCPU right after kvm_arch_vcpu_destroy(). That is bounded by MAX_BP_COUNT entries, so roughly 8 KiB per vCPU, but it is unbounded over VM lifetimes. The allocations are GFP_KERNEL_ACCOUNT, so the charge also outlives the exiting process and pins dying memcgs. Fix by clearing the debug data on vCPU destruction. Calling it unconditionally is fine: struct kvm_vcpu is zero allocated, so for a vCPU that never enabled debugging the counters are 0 and the pointers NULL. A memory leak occurs in the Kernel-based Virtual Machine (KVM) for s390 architecture when a virtual CPU (vCPU) is destroyed while hardware breakpoints are still active, as the associated debug data is not properly freed. A local attacker or a malicious guest operating system could trigger this condition. Over time, this can lead to resource exhaustion and a Denial of Service (DoS) for the host system.

CVE-2026-89923
Linux Kernel
Sep 16, 2026
Low3.3Red Hat

Low [CVE-2026-81870] github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging

github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Information disclosure via exporter configuration logging. Red Hat rates this low (CVSS 3.3). Weakness: CWE-538. Red Hat lists fixing advisory RHSA-2026:72475 with package cert-manager/cert-manager-istio-csr-rhel9:1790223719, cert-manager/cert-manager-istio-csr-rhel9:1790589914. Affected product named by the advisory: Cert Manager support for Red Hat OpenShift release 1.20.

CVE-2026-81870
Unclassified
Sep 16, 2026
Low3.7Red Hat

Low [CVE-2026-77860] Denial of Service via 'serve-expired' code path bypass

Denial of Service via 'serve-expired' code path bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-675. Red Hat lists fixing advisory RHSA-2026:68590 with package unbound-main-1.26.1-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: unbound.

CVE-2026-77860
Red Hat Enterprise Linux
Sep 16, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-91722] Use after free in Input

Use after free in Input. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-91722
Unclassified
Sep 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-91738] Improper input validation in ANGLE

Improper input validation in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-1286.

CVE-2026-91738
Unclassified
Sep 15, 2026
Critical9.6Red Hat

Critical [CVE-2026-91729] Arbitrary code execution via use-after-free in DigitalCredentials

Arbitrary code execution via use-after-free in DigitalCredentials. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825.

CVE-2026-91729
Unclassified
Sep 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-91716] Use after free in Auth

Use after free in Auth. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-91716
Unclassified
Sep 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-91718] Use after free in Core

Use after free in Core. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-91718
Unclassified
Sep 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-91710] Use after free in WebAppInstalls

Use after free in WebAppInstalls. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-91710
Unclassified
Sep 15, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-91735] Incorrect authorization in WebUI

Incorrect authorization in WebUI. Red Hat rates this important (CVSS 9). Weakness: CWE-266.

CVE-2026-91735
Unclassified
Sep 15, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-91743] Race condition in Core

Race condition in Core. Red Hat rates this important (CVSS 9). Weakness: CWE-368.

CVE-2026-91743
Unclassified
Sep 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-91749] Use after free in Workers

Use after free in Workers. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-91749
Unclassified
Sep 15, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-91721] Use after free in Internals

Use after free in Internals. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.

CVE-2026-91721
Unclassified
Sep 15, 2026
Critical9.3Red Hat

Critical [CVE-2026-91949] FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass

FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass. Red Hat rates this critical (CVSS 9.3). Weakness: CWE-358. Red Hat lists fixing advisory RHSA-2026:74471 with package freerdp-2:3.10.3-12.el10_2.13, freerdp-2:3.10.3-3.el10_0.18. Affected product named by the advisory: Red Hat Enterprise Linux 10.

CVE-2026-91949
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92000] Denial of Service via crafted ZIP archives with zero declared uncompressed size

Denial of Service via crafted ZIP archives with zero declared uncompressed size. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:74609 with package cluster-observability-operator/monitoring-console-plugin-rhel9:1790854525, cluster-observability-operator/distributed-tracing-console-plugin-rhel9:1790854443, cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1790854528, cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1790854526. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 5 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Self-service automation portal 2; Red Hat package: mozjs60; and 1 more.

CVE-2026-92000
Red Hat Enterprise Linux
Sep 15, 2026
High7.2Red Hat

High [CVE-2026-91732] Missing authorization in AppManifest

Missing authorization in AppManifest. Red Hat rates this important (CVSS 7.2). Weakness: CWE-346.

CVE-2026-91732
Unclassified
Sep 15, 2026
High8.8Red Hat

High [CVE-2026-91715] Type confusion in ServiceWorker

Type confusion in ServiceWorker. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843.

CVE-2026-91715
Unclassified
Sep 15, 2026
High8.8Red Hat

High [CVE-2026-91711] Out of bounds write in ServiceWorker

Out of bounds write in ServiceWorker. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-91711
Unclassified
Sep 15, 2026
High8.8Red Hat

High [CVE-2026-91745] Use after free in V8

Use after free in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-91745
Unclassified
Sep 15, 2026
High8.8Red Hat

High [CVE-2026-91736] Use after free in DOM

Use after free in DOM. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-91736
Unclassified
Sep 15, 2026

← All vendors