Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

3176 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.5Red Hat Updated

Medium [CVE-2026-74273] Block region delete during region creation

Block region delete during region creation. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74273
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-74432] Fix leak of released call in recvmsg(MSG_PEEK)

Fix leak of released call in recvmsg(MSG_PEEK). Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-74432
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-74419] Adjust size for copy_to_user

Adjust size for copy_to_user(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-125.

CVE-2026-74419
Unclassified
Aug 15, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-74284] Don't make class passive twice

Don't make class passive twice. Red Hat rates this low (CVSS 5.5). Weakness: CWE-821. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74284
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74395] Fix devx subscribe-event unwind NULL dereference

Fix devx subscribe-event unwind NULL dereference. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74395
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74393] Fix memory leak in drm_syncobj_find_fence

Fix memory leak in drm_syncobj_find_fence(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-771. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74393
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74285] Stop leased rxq before uninstalling its memory provider

Stop leased rxq before uninstalling its memory provider. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.

CVE-2026-74285
Unclassified
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74288] Don't dump dying fib_rule in fib_rules_dump

Don't dump dying fib_rule in fib_rules_dump(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74288
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74361] fix FDP fdpcidx bounds check

fix FDP fdpcidx bounds check. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74361
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-74326] fix resource leak in probe error path

fix resource leak in probe error path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74326
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-74308] fix kernel BUG in ext4_write_inline_data_end

fix kernel BUG in ext4_write_inline_data_end. Red Hat rates this low (CVSS 5.5). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74308
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74344] Clear rb node linkage when freeing bpf_rb_root

Clear rb node linkage when freeing bpf_rb_root. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74344
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74363] fix UAF by restoring RCU-delayed inode freeing in bpffs

fix UAF by restoring RCU-delayed inode freeing in bpffs. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-821. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-74363
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74349] reject FITRIM ranges shorter than a cluster

reject FITRIM ranges shorter than a cluster. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.

CVE-2026-74349
Unclassified
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74329] unregister PM notifier on watchdog unregister

unregister PM notifier on watchdog unregister. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74329
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74286] allocate per-cpu tstats for PFCP netdevs

allocate per-cpu tstats for PFCP netdevs. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.

CVE-2026-74286
Unclassified
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74489] fix tid_tx use-after-free on BA session stop

fix tid_tx use-after-free on BA session stop. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74489
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-74527] Block VFs from clobbering special CGX PKIND state

Block VFs from clobbering special CGX PKIND state. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1220. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74527
Linux Kernel
Aug 15, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-74558] reclaim invalid Tx descriptors in ZC batch path

reclaim invalid Tx descriptors in ZC batch path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74558
Linux Kernel
Aug 15, 2026
Medium5.5Red Hat

Medium [CVE-2026-74438] sun4i-ss - Remove insecure and unused rng_alg

In the Linux kernel, the following vulnerability has been resolved: crypto: sun4i-ss - Remove insecure and unused rng_alg Remove sun4i_ss_rng, as it is insecure and unused: - It has multiple vulnerabilities. sun4i_ss_prng_seed() is missing locking and has a buffer overflow. sun4i_ss_prng_generate() fails to fill the entire buffer with cryptographic random bytes, because it rounds the destination length down and also doesn't actually wait for the hardware to be ready before pulling bytes from it. - No user of this code is known. It's usable only theoretically via the "rng" algorithm type of AF_ALG. But userspace actually just uses the actual Linux RNG (/dev/random etc) instead. And rng_algs don't contribute entropy to the actual Linux RNG either. (This may have been confused with hwrng, which does contribute entropy.) The sun4i_ss_prng_seed() buffer overflow was reported by Tianchu Chen and discovered by Atuin - Automated Vulnerability Discovery Engine There's no point in fixing all these vulnerabilities individually when this is unused code, so let's just remove it. This component contains multiple vulnerabilities, including a buffer overflow in the sun4i_ss_prng_seed() function that could lead to a denial of service.

CVE-2026-74438
Unclassified
Aug 15, 2026

← All vendors