Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11071 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium6.6Red Hat

Medium [CVE-2026-96448] FGAP v2 composite-blind role mapping allows privilege escalation

FGAP v2 composite-blind role mapping allows privilege escalation. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-285. Affected product named by the advisory: Red Hat Build of Keycloak.

CVE-2026-96448
Unclassified
Sep 25, 2026
Medium6.8Red Hat

Medium [CVE-2026-97846] Standard Token Exchange V2 bypasses mTLS holder-of-key binding

Standard Token Exchange V2 bypasses mTLS holder-of-key binding. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-287. Affected product named by the advisory: Red Hat Build of Keycloak.

CVE-2026-97846
Unclassified
Sep 25, 2026
Medium6.5Red Hat

Medium [CVE-2026-51773] Information disclosure via unvalidated external image location URI

Information disclosure via unvalidated external image location URI. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.

CVE-2026-51773
Unclassified
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-97567] prevent race between disconnect and rtx

prevent race between disconnect() and rtx. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-97567
Linux Kernel
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-97560] fix one-byte OOB read in smb2_parse_native_symlink

fix one-byte OOB read in smb2_parse_native_symlink(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.

CVE-2026-97560
Linux Kernel
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-97578] guard VPU981 AV1 divisor and tile buffer

guard VPU981 AV1 divisor and tile buffer. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-369.

CVE-2026-97578
Unclassified
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-97541] don't store usb_device_id

don't store usb_device_id. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-97541
Linux Kernel
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-98026] properly convert mglist to rcu

properly convert mglist to rcu. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-98026
Linux Kernel
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-97553] lock the healthmon when inserting unmount event

lock the healthmon when inserting unmount event. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-413.

CVE-2026-97553
Unclassified
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-98013] clamp quantum in change path

clamp quantum in change path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-606.

CVE-2026-98013
Unclassified
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-98018] serialize probe with bus removal

serialize probe with bus removal. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.

CVE-2026-98018
Unclassified
Sep 25, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-97544] don't leak dqacct if rhashtable insertion fails

don't leak dqacct if rhashtable insertion fails. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.

CVE-2026-97544
Linux Kernel
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-97536] Fix use-after-free of qpair work on queue teardown

Fix use-after-free of qpair work on queue teardown. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-97536
Linux Kernel
Sep 25, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-97592] Fix missing scrub of temp buffers with AES ctr and gcm algorithm

Fix missing scrub of temp buffers with AES ctr and gcm algorithm. Red Hat rates this low (CVSS 5.5). Weakness: CWE-459. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-97592
Linux Kernel
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-98024] folio_put after error

folio_put() after error. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-763. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.

CVE-2026-98024
Linux Kernel
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-98028] drop the replaced rule from the list when reprogramming fails

drop the replaced rule from the list when reprogramming fails. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-459.

CVE-2026-98028
Unclassified
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-98019] mark a NULL call argument precise

mark a NULL call argument precise. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1025. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-98019
Linux Kernel
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-98036] Preserve special fields in recycled rhtab elements

Preserve special fields in recycled rhtab elements. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.

CVE-2026-98036
Unclassified
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-97586] Fix missing kunmap in afs_dir_search_bucket

Fix missing kunmap in afs_dir_search_bucket(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-97586
Linux Kernel
Sep 25, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-98020] fix cmd_regs access racing BAR unmap on reset

fix cmd_regs access racing BAR unmap on reset. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.

CVE-2026-98020
Unclassified
Sep 25, 2026

← All vendors