Red Hat Linux Security Advisories & CVEs
11137 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-88387] Denial of Service via improper numeric conversion
Denial of Service via improper numeric conversion. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-681.
Medium [CVE-2026-88360] Denial of Service via Malformed PFM Image Processing
Denial of Service via Malformed PFM Image Processing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1102.
Medium [CVE-2026-93789] bound aligned TLV advance in FW parser
bound aligned TLV advance in FW parser. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-93790] fix out-of-bounds tid_data access in BA notif
fix out-of-bounds tid_data access in BA notif. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-93786] preserve VFS inherited POSIX ACL mask
preserve VFS inherited POSIX ACL mask. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-281.
Medium [CVE-2026-93782] flush backend after device ioctls
flush backend after device ioctls. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-93788] validate WGDS table revision index
validate WGDS table revision index. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1335. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-93785] validate idmap key payload length
validate idmap key payload length. Red Hat rates this low (CVSS 5.5). Weakness: CWE-681. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-93266] fix field-spanning write warning in attestation token init
fix field-spanning write warning in attestation token init. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.
Medium [CVE-2026-93272] Fix handling the lack of PD regulators in v3
Fix handling the lack of PD regulators in v3. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-93280] bound the topology section sizes against the fetched size
bound the topology section sizes against the fetched size. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-93274] Don't remove an unregistered GPIO chip
Don't remove an unregistered GPIO chip. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
Medium [CVE-2026-93278] add missing napi_disable in cvm_oct_rx_shutdown
add missing napi_disable in cvm_oct_rx_shutdown. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-93268] skip extra isize expansion during mount to prevent deadlock
skip extra isize expansion during mount to prevent deadlock. Red Hat rates this low (CVSS 5.5). Weakness: CWE-833. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-93261] Fix NULL pointer dereference in __lock_set_class
Fix NULL pointer dereference in __lock_set_class(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-93271] cap out-of-range rx MCS instead of leaving bogus rate
cap out-of-range rx MCS instead of leaving bogus rate. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1284. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-93282] fix maximum allowed access checks
fix maximum allowed access checks. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-266.
Medium [CVE-2026-93277] Validate udata before executing commands
Validate udata before executing commands. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-93275] Fix stop/start with no update
Fix stop/start with no update. Red Hat rates this low (CVSS 5.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-93281] fix HE extended capability length check
fix HE extended capability length check. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.