Red Hat Linux Security Advisories & CVEs
11134 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-97600] fix FIFOP work use-after-free
fix FIFOP work use-after-free. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-97923] Free histogram the var ref when its initialization fails
Free histogram the var ref when its initialization fails. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97944] Fix FineIBT hash offset in cfi_get_func_hash
Fix FineIBT hash offset in cfi_get_func_hash(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
Medium [CVE-2026-97946] Fix PCI device reference counting in amd_smn_init
Fix PCI device reference counting in amd_smn_init(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-911.
Medium [CVE-2026-97915] Limit firmware log name prints to field size
Limit firmware log name prints to field size. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-97616] release all action references on NEWACTION failure
release all action references on NEWACTION failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97596] reject invalid states in connection template sync records
reject invalid states in connection template sync records. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-97613] Reserve extra CQ slot for the fence completion CQE
Reserve extra CQ slot for the fence completion CQE. Red Hat rates this low (CVSS 5.5). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-97942] Exclude text poking against change_page_attr
Exclude text poking against change_page_attr(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-97905] zero-initialize policy cpumask before sysfs publication
zero-initialize policy cpumask before sysfs publication. Red Hat rates this low (CVSS 5.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97603] disable DIM work before freeing q_vectors
disable DIM work before freeing q_vectors. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-97928] skip the VMID 0 flush for VRAM
skip the VMID 0 flush for VRAM. Red Hat rates this low (CVSS 5.5). Weakness: CWE-440. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-97904] initialize policy rwsem before sysfs publication
initialize policy rwsem before sysfs publication. Red Hat rates this low (CVSS 5.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97599] serialize pib updates to fix double-free
serialize pib updates to fix double-free. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341.
Medium [CVE-2026-97950] pin the symlink target's dirent instead of chasing ->ci_dentry
pin the symlink target's dirent instead of chasing ->ci_dentry. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-97604] defer cleanup until the last reference
defer cleanup until the last reference. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-97927] create the root dentry after loading cylinder metadata
create the root dentry after loading cylinder metadata. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-97601] fix NULL dereference in lowpan_newlink
fix NULL dereference in lowpan_newlink. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97607] Put device on unsupported feature error
Put device on unsupported feature error. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
Medium [CVE-2026-97979] add missing xa_destroy for sched_node_ids
add missing xa_destroy for sched_node_ids. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.