Red Hat Linux Security Advisories & CVEs
3176 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-74296] Release the HW‑provided UAR index rather than the SW one
Release the HW‑provided UAR index rather than the SW one. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-763. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74383] fix out-of-bounds access in nvme_setup_descriptor_pools
fix out-of-bounds access in nvme_setup_descriptor_pools. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
Medium [CVE-2026-74317] do not configure xps for XDP queues
do not configure xps for XDP queues. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-74298] Fix FRMR set pinned push error path
Fix FRMR set pinned push error path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.
Medium [CVE-2026-74325] use kfree_rcu for offchannel link in mt76_put_vif_phy_link
use kfree_rcu for offchannel link in mt76_put_vif_phy_link. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74304] fix NULL pointer dereference in qca_setup for non-serdev device
fix NULL pointer dereference in qca_setup() for non-serdev device. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-74335] Fix NULL pointer dereference in bpf_task_from_vpid
Fix NULL pointer dereference in bpf_task_from_vpid(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
Medium [CVE-2026-74389] Fix log flood after cmd_mbox failure
Fix log flood after cmd_mbox failure. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-779.
Medium [CVE-2026-74350] validate fast symlink target during inode read
validate fast symlink target during inode read. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-74408] fix OOB access from firmware tx status queue ID
fix OOB access from firmware tx status queue ID. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74371] fix BPF_PROG_QUERY OOB write and cgroup backward compat
fix BPF_PROG_QUERY OOB write and cgroup backward compat. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
Medium [CVE-2026-74331] Fix recursive lock in device_cache_fw_images
Fix recursive lock in device_cache_fw_images(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-833. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74431] Fix potential infinite loop in rxrpc_recvmsg
Fix potential infinite loop in rxrpc_recvmsg(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835.
Medium [CVE-2026-74407] cancel SSR work items during PCI shutdown
cancel SSR work items during PCI shutdown. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74366] fix NULL deref in change_sta_links for unready link
fix NULL deref in change_sta_links for unready link. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74282] prevent snt_unacked underflow on CONN_ACK
prevent snt_unacked underflow on CONN_ACK. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74400] fix crash in bpf_[set|remove]_dentry_xattr for negative dentries
fix crash in bpf_[set|remove]_dentry_xattr for negative dentries. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
Medium [CVE-2026-74295] Validate written enum value
Validate written enum value. Red Hat rates this low (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74302] Fix UAF in hci_unregister_dev
Fix UAF in hci_unregister_dev(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74367] fix inconsistent arvif state in vdev_create error paths
fix inconsistent arvif state in vdev_create error paths. Red Hat rates this low (CVSS 5.5). Weakness: CWE-390. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.