Red Hat Linux Security Advisories & CVEs
11134 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-97977] Fix UAF of btusb_data by rx_work
Fix UAF of btusb_data by rx_work. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97963] initialize ptp_lock at probe time
initialize ptp_lock at probe time. Red Hat rates this low (CVSS 5.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-97956] Fix the deadlock in net_failover_slave_name_change
Fix the deadlock in net_failover_slave_name_change(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-833. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
Medium [CVE-2026-97987] reset device if input_register_device fails
reset device if input_register_device() fails. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97968] (corsair-cpro) Create debugfs entries after hwmon registration
(corsair-cpro) Create debugfs entries after hwmon registration. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-97983] return compat ioctl results directly
return compat ioctl results directly. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.
Medium [CVE-2026-97976] validate packet_len before skb_put_data
validate packet_len before skb_put_data. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
Medium [CVE-2026-97998] cope with concurrent instance destruction
cope with concurrent instance destruction. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97995] do not free control-out buffers on remove
do not free control-out buffers on remove. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97981] Count dropped frames as NAPI work
Count dropped frames as NAPI work. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770.
Medium [CVE-2026-97994] reject VRING_NUM larger than device max
reject VRING_NUM larger than device max. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-97966] reset HTB scheduler topology before freeing queues
reset HTB scheduler topology before freeing queues. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-459. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
Medium [CVE-2026-97997] fix stale descriptor flags after a failed packed add
fix stale descriptor flags after a failed packed add. Red Hat rates this low (CVSS 5.5). Weakness: CWE-459. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97962] Move representor vnic reporter to eswitch devlink port
Move representor vnic reporter to eswitch devlink port. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97972] put the "mdio" child node reference on success
put the "mdio" child node reference on success. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-911.
Medium [CVE-2026-97978] don't dereference pointers from TP_printk
don't dereference pointers from TP_printk(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-97967] (corsair-cpro) Remove debugfs entries when probe fails
(corsair-cpro) Remove debugfs entries when probe fails. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-97969] Fix clock leak and spurious timer in settimeout
Fix clock leak and spurious timer in settimeout(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-911.
Medium [CVE-2026-97971] check listing permission before taking a namespace reference
check listing permission before taking a namespace reference. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-821.
Medium [CVE-2026-97953] fix TX descriptor availability check for TSO traffic
fix TX descriptor availability check for TSO traffic. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.