Red Hat Linux Security Advisories & CVEs
2967 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-72381] fix use-after-free of fp->owner.name in durable handle owner check
fix use-after-free of fp->owner.name in durable handle owner check. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
High [CVE-2026-72422] fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE
fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
High [CVE-2026-72218] Plug nlm_file refcount leak on cached nlm_do_fopen failure
Plug nlm_file refcount leak on cached nlm_do_fopen() failure. Red Hat rates this moderate (CVSS 7). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-72436] Don't use test_bit in lockless RCU readers in hash types
Don't use test_bit() in lockless RCU readers in hash types. Red Hat rates this moderate (CVSS 7). Weakness: CWE-821. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-72242] avoid sk_socket dereference in selinux_sctp_bind_connect
avoid sk_socket dereference in selinux_sctp_bind_connect(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-72382] reject undersized DACLs before parsing ACEs
reject undersized DACLs before parsing ACEs. Red Hat rates this moderate (CVSS 7). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
High [CVE-2026-72135] Make the TPM character devices non-seekable
Make the TPM character devices non-seekable. Red Hat rates this moderate (CVSS 7). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-72136] require CAP_NET_ADMIN in the device netns for changelink
require CAP_NET_ADMIN in the device netns for changelink. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1220. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-72222] pin svc_xprt across the asynchronous TLS handshake callback
pin svc_xprt across the asynchronous TLS handshake callback. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-72284] Ignore pending PV EOI if the vCPU has since disabled PV EOIs
Ignore pending PV EOI if the vCPU has since disabled PV EOIs. Red Hat rates this moderate (CVSS 7). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-72329] drop cached VF pci_dev LUT
drop cached VF pci_dev LUT. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat package: kernel-rt.
High [CVE-2026-72252] don't leak bad clone into future transaction
don't leak bad clone into future transaction. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-72249] use dst in this direction when pushing IPIP header
use dst in this direction when pushing IPIP header. Red Hat rates this moderate (CVSS 7). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
High [CVE-2026-72318] validate DFS referral string offsets
validate DFS referral string offsets. Red Hat rates this important (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-72283] Nullify irqfd->producer if updating IRTE for bypass fails
Nullify irqfd->producer if updating IRTE for bypass fails. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.
High [CVE-2026-72221] wait for in-flight TLS handshake callback when cancel loses race
wait for in-flight TLS handshake callback when cancel loses race. Red Hat rates this important (CVSS 7). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-72339] fix off-by-one in BD ring consumption on build_skb failure
fix off-by-one in BD ring consumption on build_skb failure. Red Hat rates this important (CVSS 7). Weakness: CWE-193. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-72253] validate skb_dst before accessing it
validate skb_dst() before accessing it. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-72419] avoid invalid nat_net pointer use on failed nf_nat_init
avoid invalid nat_net pointer use on failed nf_nat_init(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-72251] reload possible stale data pointer
reload possible stale data pointer. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.