Red Hat Linux Security Advisories & CVEs
11619 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-90616] Arbitrary code execution via missing symlink protection
Arbitrary code execution via missing symlink protection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: flatpak.
High [CVE-2026-90560] Denial of Service via out-of-bounds read in ZstdDictDecompress
Denial of Service via out-of-bounds read in ZstdDictDecompress. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 10 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 6 more.
High [CVE-2026-90553] Remote Code Execution via LlavaOnevision2 processor ignoring trust_remote_code
Remote Code Execution via LlavaOnevision2 processor ignoring trust_remote_code. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-90555] Denial of Service due to improper audio header validation
Denial of Service due to improper audio header validation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-90554] Denial of Service via video audio extraction
Denial of Service via video audio extraction. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-89772] write-protect folios during data writeback
write-protect folios during data writeback. Red Hat rates this moderate (CVSS 7). Weakness: CWE-413. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89766] hold exec_update_lock around namespace ioctl
hold exec_update_lock around namespace ioctl. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89760] mm, swap: don't free a hibernation slot that is in the swap cache
mm, swap: don't free a hibernation slot that is in the swap cache. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.
High [CVE-2026-89758] skip non-present PMDs when queueing folios
skip non-present PMDs when queueing folios. Red Hat rates this moderate (CVSS 7). Weakness: CWE-824. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89755] clear stale mapping after freeing swapcache
clear stale mapping after freeing swapcache. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89754] fix stale walk->action escaping walk_pmd_range
fix stale walk->action escaping walk_pmd_range(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89747] Fix use-after-free in trace_pipe read on sub-buffer order change
Fix use-after-free in trace_pipe read on sub-buffer order change. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel-rt.
High [CVE-2026-89746] Fix use-after-free with same-name named triggers
Fix use-after-free with same-name named triggers. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89745] Fix lockdown check for mmap_prepare
Fix lockdown check for mmap_prepare. Red Hat rates this moderate (CVSS 7). Weakness: CWE-414. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.
High [CVE-2026-89741] Revert "media: v4l2-dev: fix error handling in __video_register_device "
Revert "media: v4l2-dev: fix error handling in __video_register_device()". Red Hat rates this moderate (CVSS 7). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-89737] Disable work before freeing tbt on remove
Disable work before freeing tbt on remove. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89729] Fix out-of-bounds write in sensor_hub_get_feature
Fix out-of-bounds write in sensor_hub_get_feature. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89727] Don't WARN on out-of-range GICV_DIR INTID
Don't WARN on out-of-range GICV_DIR INTID. Red Hat rates this moderate (CVSS 7). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel-rt.
High [CVE-2026-89719] fix out-of-bounds access in read_block_state
fix out-of-bounds access in read_block_state(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89712] restart ssc_expire_umount walk after dropping nfsd_ssc_lock
restart ssc_expire_umount walk after dropping nfsd_ssc_lock. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.