Red Hat Linux Security Advisories & CVEs
3176 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-74348] require a ref for locking_state debugfs open
require a ref for locking_state debugfs open. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-74277] Fix wrong scatterlist length assignment in P2PDMA path
Fix wrong scatterlist length assignment in P2PDMA path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74388] Fix UAF at handling events with embedded SysEx data
Fix UAF at handling events with embedded SysEx data. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74313] hold vduse_lock across IDR lookup in open path
hold vduse_lock across IDR lookup in open path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74279] cavium/cpt - fix DMA cleanup using wrong loop index
cavium/cpt - fix DMA cleanup using wrong loop index. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.
Medium [CVE-2026-74384] fix flex array size in struct nvme_ns_head
fix flex array size in struct nvme_ns_head. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74352] avoid post-init UAF when alloc_reserved_mem_array fails
avoid post-init UAF when alloc_reserved_mem_array() fails. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
Medium [CVE-2026-74327] fix NULL pointer dereference in is_vm_area_hugepages
fix NULL pointer dereference in is_vm_area_hugepages(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74299] Fix FRMR aging push to queue error flow
Fix FRMR aging push to queue error flow. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.
Medium [CVE-2026-74312] validate virtqueue index in mmap and fault paths
validate virtqueue index in mmap and fault paths. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74385] check return value of nvmet_tcp_set_queue_sock
check return value of nvmet_tcp_set_queue_sock. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74274] Fill first free targets slot during auto-discovery
Fill first free targets[] slot during auto-discovery. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-74339] Clear variable event pointer on read
Clear variable event pointer on read. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74387] Serialize output teardown with event_input
Serialize output teardown with event_input. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-74322] Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211
Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-74292] Validate written enum value
Validate written enum value. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74365] Handle preemption in BTT lane acquisition
Handle preemption in BTT lane acquisition. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74340] fix OOB read from firmware count in PRINT_REG_INFO indication
fix OOB read from firmware count in PRINT_REG_INFO indication. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-74290] Dont expose folded kernel pointers
Dont expose folded kernel pointers. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-201. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74410] fix OOB read from firmware RX descriptor exceeding DMA buffer
fix OOB read from firmware RX descriptor exceeding DMA buffer. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.