Red Hat Linux Security Advisories & CVEs
4597 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-89478] drop a chunk if its transport was removed
drop a chunk if its transport was removed. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-89476] fix stream->outcnt underflow on duplicate RECONF responses
fix stream->outcnt underflow on duplicate RECONF responses. Red Hat rates this moderate (CVSS 7). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-89477] fix NULL deref on untransmitted RECONF completion
fix NULL deref on untransmitted RECONF completion. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89458] Do not complete a failed ESE read as successful
Do not complete a failed ESE read as successful. Red Hat rates this moderate (CVSS 7). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-89456] Propagate partial completion length across ERP recovery
Propagate partial completion length across ERP recovery. Red Hat rates this moderate (CVSS 7). Weakness: CWE-908. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89450] Reject a vSID wider than the SID_MATCH field
Reject a vSID wider than the SID_MATCH field. Red Hat rates this important (CVSS 7.8). Weakness: CWE-681. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-89448] Force requesting ACS when tboot is enabled
Force requesting ACS when tboot is enabled. Red Hat rates this moderate (CVSS 7). Weakness: CWE-358. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-89445] Fix UAF in selftest IOPF reporting
Fix UAF in selftest IOPF reporting. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89444] Don't hex dump attribute security buffer
Don't hex dump attribute security buffer. Red Hat rates this moderate (CVSS 7). Weakness: CWE-256. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-89440] stop card-detect handling on probe failure
stop card-detect handling on probe failure. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-81015] Fix LPS0 and debugfs leaks when STB init fails
Fix LPS0 and debugfs leaks when STB init fails. Red Hat rates this moderate (CVSS 7). Weakness: CWE-459. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-81008] Fix use after free in icc_get and of_icc_get_by_index
Fix use after free in icc_get() and of_icc_get_by_index(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-81002] fix zero-copy frame layout
fix zero-copy frame layout. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-81000] bound receive headroom
bound receive headroom. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:71592 with package kernel-rt-0:3.10.0-1160.164.1.rt56.1316.el7, kernel-0:6.12.0-211.59.1.el10_2, kernel-0:6.12.0-55.107.1.el10_0, kernel-0:4.18.0-305.209.1.el8_4. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-81001] fix use-after-free in sl_sync
fix use-after-free in sl_sync(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-80994] fix flow mask use-after-free on flow deletion
fix flow mask use-after-free on flow deletion. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-80989] Mark the connection down when bringing it up fails
Mark the connection down when bringing it up fails. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-80986] bound the peer rkey counts in SMC-Rv2 LLC messages
bound the peer rkey counts in SMC-Rv2 LLC messages. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-80985] carry oversized SMC-Rv2 LLC messages in the queue entry
carry oversized SMC-Rv2 LLC messages in the queue entry. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-80982] fix use-after-free in smc_rx_pipe_buf_release
fix use-after-free in smc_rx_pipe_buf_release(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.