Red Hat Linux Security Advisories & CVEs
11835 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-89576] fix shadowed superblock leak on take-snap failure
fix shadowed superblock leak on take-snap failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89574] dm array: validate array block headers on read
dm array: validate array block headers on read. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89573] dm array: reject an array block whose value size is not the caller's
dm array: reject an array block whose value size is not the caller's. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-843. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89572] Fix OPP table cleanup
Fix OPP table cleanup. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89571] bound fwctl command payload to the input buffer
bound fwctl command payload to the input buffer. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89568] fix size calculation in kho_preserved_memory_reserve
fix size calculation in kho_preserved_memory_reserve(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1335. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89567] bound shrinker scans by examined checkpoint buffers
bound shrinker scans by examined checkpoint buffers. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-89566] check need_resched when skipping busy checkpoint buffers
check need_resched() when skipping busy checkpoint buffers. Red Hat rates this low (CVSS 5.5). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-89565] fix skb leak in collect_md mode when metadata_dst allocation fails
fix skb leak in collect_md mode when metadata_dst allocation fails. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89561] fix NULL dereference of idev in ipv6_rpl_srh_rcv
fix NULL dereference of idev in ipv6_rpl_srh_rcv(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-89557] do overflow check for sb->bblog_shift in super_1_load
do overflow check for sb->bblog_shift in super_1_load(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89556] validate string table section types
validate string table section types. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-89554] fix uninitialized local_id in syncookie MP_JOIN reconstruction
fix uninitialized local_id in syncookie MP_JOIN reconstruction. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-89552] fix charp corruption on allocation failure
fix charp corruption on allocation failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89549] route to a populated pool in svc_pool_for_cpu
route to a populated pool in svc_pool_for_cpu(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-821. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89544] fix gssx_dec_option_array error path bugs
fix gssx_dec_option_array error path bugs. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-89539] reject duplicate CREDS_VALUE options
reject duplicate CREDS_VALUE options. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-89527] Use svc_xprt_put to free listener on create failure
Use svc_xprt_put to free listener on create failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-89525] reject VAT indexes equal to the entry count
reject VAT indexes equal to the entry count. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-89524] clamp assoc request/response lengths before subtracting IE offsets
clamp assoc request/response lengths before subtracting IE offsets. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.