Red Hat Linux Security Advisories & CVEs
11835 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-89522] fix async notifier UAF on probe error path
fix async notifier UAF on probe error path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-89521] Handle pick_task releasing the rq lock
Handle pick_task() releasing the rq lock. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89520] Make core-sched flips wait for in-flight selections
Make core-sched flips wait for in-flight selections. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-366. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89518] Fix this_rq assumptions in dispatch kfuncs
Fix this_rq() assumptions in dispatch kfuncs. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.
Medium [CVE-2026-89519] Replace SCX_RQ_BAL_KEEP with a dispatch verdict return
Replace SCX_RQ_BAL_KEEP with a dispatch verdict return. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367.
Medium [CVE-2026-89517] Fix rq->core_pick corruption under core scheduling
Fix rq->core_pick corruption under core scheduling. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89515] Fill in DMA padding bytes in scsi_alloc_sgtables
Fill in DMA padding bytes in scsi_alloc_sgtables(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-89516] Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users
Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89514] Use GFP_ATOMIC for VLAN alloc under spinlock
Use GFP_ATOMIC for VLAN alloc under spinlock. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-663. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-89512] Fix device reference leak on failed lookup
Fix device reference leak on failed lookup. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.
Medium [CVE-2026-89513] Fix PMU event info array size overflow
Fix PMU event info array size overflow. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89511] Fix NULL pointer dereference in TPA fragment processing
Fix NULL pointer dereference in TPA fragment processing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89509] Embed counter driver data in rdma_counter allocation
Embed counter driver data in rdma_counter allocation. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89508] Lock the handler in ucma_set_ib_path
Lock the handler in ucma_set_ib_path(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89507] Lock the handler in ucma_write_cm_event
Lock the handler in ucma_write_cm_event(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89506] Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR
Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89504] fix premature of_node_put leaving dangling of_node pointer
fix premature of_node_put leaving dangling of_node pointer. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89505] Guard legacy bundles without method_elm
Guard legacy bundles without method_elm. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89503] Fix subbuf resize race with ring_buffer_alloc_read_page
Fix subbuf resize race with ring_buffer_alloc_read_page(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel-rt.
Medium [CVE-2026-89502] Free cpu_buffer::free_page with subbuf_order
Free cpu_buffer::free_page with subbuf_order. Red Hat rates this low (CVSS 5.5). Weakness: CWE-763. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel-rt.