Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4450 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.0Vendor: MediumRed Hat

High [CVE-2026-89707] release path refs on follow_down error

release path refs on follow_down() error. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-89707
Linux Kernel
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89706] Reset write verifier when async COPY writeback fails

Reset write verifier when async COPY writeback fails. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-89706
Linux Kernel
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89704] sample writeback error cursor before async COPY loop

sample writeback error cursor before async COPY loop. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89704
Unclassified
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89705] restore rq_status_counter to even on all nfsd_dispatch exit paths

restore rq_status_counter to even on all nfsd_dispatch() exit paths. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-89705
Linux Kernel
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89703] set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations

set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-89703
Linux Kernel
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89702] size fh_verify server sockaddr slot by xpt_locallen

size fh_verify server sockaddr slot by xpt_locallen. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-89702
Linux Kernel
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89698] widen nfsd_genl_rqstp address fields to sockaddr_storage

widen nfsd_genl_rqstp address fields to sockaddr_storage. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89698
Unclassified
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89697] add fh_want_write for early-verified SETATTR in nfsd_proc_setattr

add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-89697
Linux Kernel
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89695] cap decoded POSIX ACL count to bound sort cost

cap decoded POSIX ACL count to bound sort cost. Red Hat rates this moderate (CVSS 7). Weakness: CWE-606. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89695
Unclassified
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89694] check client ownership when cancelling a copy-notify stateid

check client ownership when cancelling a copy-notify stateid. Red Hat rates this moderate (CVSS 7). Weakness: CWE-639. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-89694
Linux Kernel
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89693] check nfsd4_acl_to_attr return value in nfsd4_create

check nfsd4_acl_to_attr() return value in nfsd4_create(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-252. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-89693
Linux Kernel
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89691] clear opcnt on compound arg release to prevent OOB read

clear opcnt on compound arg release to prevent OOB read. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89691
Unclassified
Sep 11, 2026
High7.0Red Hat

High [CVE-2026-89690] defer vfree of compound ops to fix rpc_status UAF

defer vfree of compound ops to fix rpc_status UAF. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89690
Unclassified
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89688] drop the stateid, not the stateowner, on seqid_op replay retry

drop the stateid, not the stateowner, on seqid_op replay retry. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-89688
Linux Kernel
Sep 11, 2026
High7.0Red Hat

High [CVE-2026-89689] don't free session slots that are still in use

don't free session slots that are still in use. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel-rt.

CVE-2026-89689
Linux Kernel
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89686] fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke

fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89686
Unclassified
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89685] fix clock domain mismatch in clients_still_reclaiming

fix clock domain mismatch in clients_still_reclaiming(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-1025. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89685
Unclassified
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89684] fix cpntf publish race in nfs4_init_cp_state

fix cpntf publish race in nfs4_init_cp_state. Red Hat rates this moderate (CVSS 7). Weakness: CWE-824. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89684
Unclassified
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89683] fix dentry ref leak on V4ROOT export filehandle lookup

fix dentry ref leak on V4ROOT export filehandle lookup. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel-rt.

CVE-2026-89683
Linux Kernel
Sep 11, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-89682] fix fcache_disposal UAF by inlining dispose state into nfsd_net

fix fcache_disposal UAF by inlining dispose state into nfsd_net. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-89682
Linux Kernel
Sep 11, 2026

← All vendors