Red Hat Linux Security Advisories & CVEs
4447 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-89775] Handle negative S1 walk levels in VNCR TLB size evaluation
Handle negative S1 walk levels in VNCR TLB size evaluation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:72624 with package kernel-0:6.12.0-211.61.1.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-89846] Bound rsp_info_len to avoid OOB sense-data read
Bound rsp_info_len to avoid OOB sense-data read. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71232 with package kernel-0:6.12.0-211.59.1.el10_2, kernel-rt-0:4.18.0-553.167.1.rt7.508.el8_10, kernel-0:4.18.0-553.167.1.el8_10, kernel-0:5.14.0-687.51.1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-89972] add missing SRCU grace period in error path
add missing SRCU grace period in error path. Red Hat rates this important (CVSS 7.8). Weakness: CWE-366. Red Hat lists fixing advisory RHSA-2026:75746 with package kernel-0:4.18.0-553.171.1.el8_10, kernel-rt-0:4.18.0-553.171.1.rt7.512.el8_10. Affected product named by the advisory: Red Hat Enterprise Linux 8.
High [CVE-2026-92000] Denial of Service via crafted ZIP archives with zero declared uncompressed size
Denial of Service via crafted ZIP archives with zero declared uncompressed size. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:74609 with package cluster-observability-operator/monitoring-console-plugin-rhel9:1790854525, cluster-observability-operator/distributed-tracing-console-plugin-rhel9:1790854443, cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1790854528, cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1790854526. Affected products named by the advisory: Red Hat Build of Podman Desktop; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; and 5 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Self-service automation portal 2; Red Hat package: mozjs60; and 1 more.
High [CVE-2026-91732] Missing authorization in AppManifest
Missing authorization in AppManifest. Red Hat rates this important (CVSS 7.2). Weakness: CWE-346.
High [CVE-2026-91715] Type confusion in ServiceWorker
Type confusion in ServiceWorker. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843.
High [CVE-2026-91711] Out of bounds write in ServiceWorker
Out of bounds write in ServiceWorker. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-91745] Use after free in V8
Use after free in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-91736] Use after free in DOM
Use after free in DOM. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-91741] Type confusion in CacheStorage
Type confusion in CacheStorage. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843.
High [CVE-2026-91748] Race condition in Extensions
Race condition in Extensions. Red Hat rates this important (CVSS 8). Weakness: CWE-368.
High [CVE-2026-91720] Uninitialized resource in ANGLE
Uninitialized resource in ANGLE. Red Hat rates this important (CVSS 7.4). Weakness: CWE-824.
High [CVE-2026-91731] Type confusion in Compositing
Type confusion in Compositing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843.
High [CVE-2026-91727] Incorrect reference resolution in Extensions
Incorrect reference resolution in Extensions. Red Hat rates this important (CVSS 8.8). Weakness: CWE-386.
High [CVE-2026-91712] Race condition in Extensions
Race condition in Extensions. Red Hat rates this important (CVSS 7.5). Weakness: CWE-368.
High [CVE-2026-91724] Use after free in Input
Use after free in Input. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825.
High [CVE-2026-91728] Integer overflow in V8
Integer overflow in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190.
High [CVE-2026-91734] Incorrect authorization in Core
Incorrect authorization in Core. Red Hat rates this important (CVSS 8.8). Weakness: CWE-551.
High [CVE-2026-19774] Arbitrary Code Execution via A2DP Stack-based Buffer Overflow
Arbitrary Code Execution via A2DP Stack-based Buffer Overflow. Red Hat rates this important (CVSS 8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: bluez.
High [CVE-2026-85234] Denial of Service due to out-of-bounds read/write in remap engine
Denial of Service due to out-of-bounds read/write in remap engine. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: tftp.