Red Hat Linux Security Advisories & CVEs
5409 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-98074] do not clear curr_active_slave prematurely when releasing all slaves
do not clear curr_active_slave prematurely when releasing all slaves. Red Hat rates this low (CVSS 5.5). Weakness: CWE-459. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-98064] Fix NULL-ptr-deref when showing a void BTF type
Fix NULL-ptr-deref when showing a void BTF type. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-97559] fail DACL rewrite when the new DACL exceeds 64K
fail DACL rewrite when the new DACL exceeds 64K. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-97565] reject short READ responses in CIFSSMBRead
reject short READ responses in CIFSSMBRead(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-98007] Reject non-scalar bpf_loop iteration counts
Reject non-scalar bpf_loop iteration counts. Red Hat rates this low (CVSS 5.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
Medium [CVE-2026-98062] Mark signal tracepoint siginfo arguments as scalar
Mark signal tracepoint siginfo arguments as scalar. Red Hat rates this low (CVSS 5.5). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
Medium [CVE-2026-98065] Reject key-less BTF for hash maps
Reject key-less BTF for hash maps. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-97579] bound AV1 tile-start copy to the array capacity
bound AV1 tile-start copy to the array capacity. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.
Medium [CVE-2026-98021] reject oversized tx_queue_len at netlink parse time
reject oversized tx_queue_len at netlink parse time. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1284. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97551] initialise args->total for parent pointer updates
initialise args->total for parent pointer updates. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
Medium [CVE-2026-98006] Decoupling ep1_in_urb in caiaq dev
Decoupling ep1_in_urb in caiaq dev. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-98029] bound the ntuple rule dump by the caller's buffer size
bound the ntuple rule dump by the caller's buffer size. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.
Medium [CVE-2026-98051] fix tx_spb_ring_full checking same slot cnt times
fix tx_spb_ring_full() checking same slot cnt times. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-120.
Medium [CVE-2026-98055] Clean up the bus when fetching ML caps fails
Clean up the bus when fetching ML caps fails. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-98103] convert struct ip_sf_list to RCU
convert struct ip_sf_list to RCU. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-764. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-98127] validate new EOF for insert range
validate new EOF for insert range. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1284. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-98112] fix listener task lifetime on netdev events
fix listener task lifetime on netdev events. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-98126] validate new EOF for zero range
validate new EOF for zero range. Red Hat rates this low (CVSS 5.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-98136] bound $AttrDef table walk to the loaded table size
bound $AttrDef table walk to the loaded table size. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-98150] Fix BPF_F_CPU validation for sparse CPU IDs
Fix BPF_F_CPU validation for sparse CPU IDs. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.