Red Hat Linux Security Advisories & CVEs
11177 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-93287] reject oversized block transfers in the common path
reject oversized block transfers in the common path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-97514] Fix Reports from Kernel Lock Validator
Fix Reports from Kernel Lock Validator. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-413.
Medium [CVE-2026-93806] validate assoc response length before status and IE access
validate assoc response length before status and IE access. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97513] Release m2m_ctx after Instance Removed from List
Release m2m_ctx after Instance Removed from List. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-93822] Protect root bus removal with rescan lock
Protect root bus removal with rescan lock. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-413. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97414] fix possible NULL-pointer dereferences in mt8365_afe_suspend
fix possible NULL-pointer dereferences in mt8365_afe_suspend(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-97515] Prevent IRQ storm from false SLVSTART on NPCM845
Prevent IRQ storm from false SLVSTART on NPCM845. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835.
Medium [CVE-2026-93285] embed f2fs_gc_kthread in f2fs_sb_info
embed f2fs_gc_kthread in f2fs_sb_info. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-97409] Do not cancel requests in io target before it is initialized
Do not cancel requests in io target before it is initialized. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-93815] move free_irq out of the close-time spinlocked section
move free_irq out of the close-time spinlocked section. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-821.
Medium [CVE-2026-97412] quiesce DMA before freeing resources
quiesce DMA before freeing resources. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-93808] validate EP1 reply lengths
validate EP1 reply lengths. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-93828] fix handling of damaged volume in exfat_create_upcase_table
fix handling of damaged volume in exfat_create_upcase_table(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97521] fix quota init duplicate scan
fix quota init duplicate scan. Red Hat rates this low (CVSS 5.5). Weakness: CWE-821. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97410] take target_cleanup_list_lock in drop_netconsole_target
take target_cleanup_list_lock in drop_netconsole_target(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-413. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-93829] fix races in cifsd thread creation
fix races in cifsd thread creation. Red Hat rates this low (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-93807] avoid reading TKIP MIC keys for non-TKIP ciphers
avoid reading TKIP MIC keys for non-TKIP ciphers. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-93825] Add NULL check for spi_get_device_id in spi_get_device_match_data
Add NULL check for spi_get_device_id() in spi_get_device_match_data(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.
Medium [CVE-2026-97507] fix missing error check for dma_alloc_coherent
fix missing error check for dma_alloc_coherent. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-97419] broadcast netlink notifications in the device's net namespace
broadcast netlink notifications in the device's net namespace. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-941. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.