Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5518 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium4.0Red Hat

Medium [CVE-2026-92949] Sandbox bypass allows unauthorized data modification.

Sandbox bypass allows unauthorized data modification. Red Hat rates this moderate (CVSS 4). Weakness: CWE-807. Affected products named by the advisory: Red Hat Developer Hub; Self-service automation portal 2.

CVE-2026-92949
Unclassified
Sep 17, 2026
Medium4.2Red Hat

Medium [CVE-2026-92945] Module allowlist bypass allows access to restricted packages

Module allowlist bypass allows access to restricted packages. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-1025. Affected products named by the advisory: Red Hat Developer Hub; Self-service automation portal 2.

CVE-2026-92945
Unclassified
Sep 17, 2026
Medium5.8Red Hat

Medium [CVE-2026-92936] Information Disclosure via Error Stack Formatting

Information Disclosure via Error Stack Formatting. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-497. Affected products named by the advisory: Red Hat Developer Hub; Self-service automation portal 2.

CVE-2026-92936
Unclassified
Sep 17, 2026
Medium5.8Red Hat

Medium [CVE-2026-92933] Information Disclosure via util.getCallSites

Information Disclosure via util.getCallSites. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-497. Affected products named by the advisory: Red Hat Developer Hub; Self-service automation portal 2.

CVE-2026-92933
Unclassified
Sep 17, 2026
Medium6.1Red Hat

Medium [CVE-2026-92973] Cross-Site Scripting via OSC 8 hyperlink handling

Cross-Site Scripting via OSC 8 hyperlink handling. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-79. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.

CVE-2026-92973
Unclassified
Sep 17, 2026
Medium4.3Red Hat

Medium [CVE-2026-92904] Job output readable without object-level view_job_invocations check

Job output readable without object-level view_job_invocations check. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected product named by the advisory: Red Hat Satellite 6.

CVE-2026-92904
Unclassified
Sep 17, 2026
Medium4.1Red Hat

Medium [CVE-2026-92382] unbounded iso_packet_desc index in usbredirhost_iso_packet leads to heap out-of-bounds write

unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write. Red Hat rates this moderate (CVSS 4.1). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: usbredir.

CVE-2026-92382
Red Hat Enterprise Linux
Sep 17, 2026
Medium4.3Red Hat

Medium [CVE-2026-92894] Unscoped LookupValue deletion allows cross-model override value destruction

Unscoped LookupValue deletion allows cross-model override value destruction. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected product named by the advisory: Red Hat Satellite 6.

CVE-2026-92894
Unclassified
Sep 17, 2026
Medium5.3Red Hat

Medium [CVE-2026-90982] @fastify/static: @fastify/static: Information disclosure via route guard bypass on case-insensitive filesystems

@fastify/static: @fastify/static: Information disclosure via route guard bypass on case-insensitive filesystems. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-178.

CVE-2026-90982
Unclassified
Sep 17, 2026
Medium4.3Red Hat

Medium [CVE-2026-92893] Ansible inventory API ignores view_hosts permission filters, exposes hidden parameters

Ansible inventory API ignores view_hosts permission filters, exposes hidden parameters. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected product named by the advisory: Red Hat Satellite 6.

CVE-2026-92893
Unclassified
Sep 17, 2026
Medium5.5Red Hat

Medium [CVE-2026-93159] atmel-sha204a - fix heap info leak on I2C transfer failure

atmel-sha204a - fix heap info leak on I2C transfer failure. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-459.

CVE-2026-93159
Unclassified
Sep 17, 2026
Medium5.5Red Hat

Medium [CVE-2026-93056] remove broken string configfs attributes

remove broken string configfs attributes. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.

CVE-2026-93056
Unclassified
Sep 17, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-93116] fix resource leaks on probe failure

fix resource leaks on probe failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel-rt.

CVE-2026-93116
Linux Kernel
Sep 17, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-93136] Fix device refcount leak in the error path of MHI device creation

Fix device refcount leak in the error path of MHI device creation. Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel-rt.

CVE-2026-93136
Linux Kernel
Sep 17, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-93072] Fix generic interrupt chip leak on remove

Fix generic interrupt chip leak on remove. Red Hat rates this low (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel-rt.

CVE-2026-93072
Linux Kernel
Sep 17, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-90119] Fix the card leak at probe error with the auto-cleanup

Fix the card leak at probe error with the auto-cleanup. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-90119
Linux Kernel
Sep 17, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-92524] Prevent leak in its_vpe_irq_domain_alloc

Prevent leak in its_vpe_irq_domain_alloc(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-92524
Linux Kernel
Sep 17, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-93130] Fix resource leak on module load failure

Fix resource leak on module load failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-93130
Linux Kernel
Sep 17, 2026
Medium5.5Red Hat

Medium [CVE-2026-90407] fix overreads in ath11k_wmi_process_csa_switch_count_event

fix overreads in ath11k_wmi_process_csa_switch_count_event(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-90407
Linux Kernel
Sep 17, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-92494] fix buffer_head leak in ext4_init_orphan_info

fix buffer_head leak in ext4_init_orphan_info. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-92494
Linux Kernel
Sep 17, 2026

← All vendors