Red Hat Linux Security Advisories & CVEs
11133 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-97970] Avoid division by zero
Avoid division by zero. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-369.
Medium [CVE-2026-97974] null-check fib6_node before accessing in __ip6_del_rt_siblings
null-check fib6_node before accessing in __ip6_del_rt_siblings(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-97992] protect config_ctx from being freed under the config callback
protect config_ctx from being freed under the config callback. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-97985] Update last skb marker in manage_oob
Update last skb marker in manage_oob(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-97993] don't install the eventfd_ctx_fdget error in config_ctx
don't install the eventfd_ctx_fdget() error in config_ctx. Red Hat rates this low (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-97959] free emptied bucket on filter move
free emptied bucket on filter move. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-98082] fix the possible bioc_list memory leak during error
fix the possible bioc_list memory leak during error. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-100076] fix xmit_frame/xmit_buf leaks on mgnt-frame error paths
fix xmit_frame/xmit_buf leaks on mgnt-frame error paths. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.
Medium [CVE-2026-100071] free learned nodes on device setup failure
free learned nodes on device setup failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-100079] unregister debugfs entries on teardown
unregister debugfs entries on teardown. Red Hat rates this low (CVSS 5.5). Weakness: CWE-459. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
Medium [CVE-2026-100070] rewind offset when NAT shrinks the packet
rewind offset when NAT shrinks the packet. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-212. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-100072] Use acpi_bus_get_primary_device
Use acpi_bus_get_primary_device(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-100073] fix transaction overflow during writeback
fix transaction overflow during writeback. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-100075] Fix srpt_alloc_rw_ctxs unwind counters
Fix srpt_alloc_rw_ctxs() unwind counters. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-459. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-100077] Recover HW before retire hung submit
Recover HW before retire hung submit. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-826.
Medium [CVE-2026-98092] fix memory leak in acp6x_pdm_dma_close
fix memory leak in acp6x_pdm_dma_close(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.
Medium [CVE-2026-98101] use copy-on-write RCU updates in ip6_mc_source
use copy-on-write RCU updates in ip6_mc_source(). Red Hat rates this low (CVSS 4.4). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-98087] sched/rt,dl: Skip migrate-disabled tasks when picking a push candidate
In the Linux kernel, the following vulnerability has been resolved: sched/rt,dl: Skip migrate-disabled tasks when picking a push candidate A migrate_disable()'d RT task cannot be moved to another CPU, but the scheduler still keeps such a task on that CPU's pushable list (rq->rt.pushable_tasks) and still marks the runqueue RT-overloaded (rq->rt.overloaded = 1). So the RT balancer keeps treating this CPU as having a task to move away, and keeps trying to move the task, but the push can never succeed. When the head is pinned, push_rt_task() does not give up either. It falls back to pushing rq->curr instead, using the per-CPU stopper, as added by commit a7c81556ec4d ("sched: Fix migrate_disable() vs rt/dl balancing"). The CPU spends tens of milliseconds in this retry loop. The core is isolated for real-time work, but during the loop nearly half of its time is consumed by pushes that cannot succeed. An ftrace capture of the affected CPU, with sched_switch enabled and commit 94894c9c477e ("sched/rt: Skip currently executing CPU in rto_next_cpu()") applied, shows where the CPU time went. Two SCHED_FIFO tasks at equal priority shared the CPU, taskA migrate_disable()'d and queued, taskB as rq->curr. In one 89 ms window, taskB got only 52 ms of CPU. The other 37 ms went to the stopper thread.
Medium [CVE-2026-51772] Server-Side Request Forgery via image locations manipulation
A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locations attribute of an image in the queued state by sending a crafted HTTP PATCH request This vulnerability allows the attacker to induce the server into making unauthorized network requests to internal or external services, potentially exposing sensitive internal systems. This vulnerability is rated as Moderate severity because exploitation requires an authenticated user account and relies on a non-default configuration setting in OpenStack Glance. By default, the show_multiple_locations directive is disabled in Red Hat OpenStack Platform, which prevents standard deployments from being exposed. If enabled, an authenticated user can trigger unauthorized outbound network requests from the Glance service, potentially scanning or probing internal network services. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-918. Affected Red Hat products: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0. Red Hat does not currently list a fixing RHSA for this CVE.
Low [CVE-2025-1218] Denial of Service via out-of-bounds read in mysqlnd wire protocol parser
Denial of Service via out-of-bounds read in mysqlnd wire protocol parser. Red Hat rates this low (CVSS 3.7). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:70720 with package php-main-8.5.11-2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: php8.4.