Red Hat Linux Security Advisories & CVEs
5618 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-89711] remove flawed WARN_ON_ONCE from nfsd_mode_check
remove flawed WARN_ON_ONCE from nfsd_mode_check. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-89701] validate nseconds in TIME_DELEG decode paths
validate nseconds in TIME_DELEG decode paths. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1284. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89700] validate sockaddr length per family in listener_set
validate sockaddr length per family in listener_set. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89699] validate symlink target length in NFSv4 CREATE
validate symlink target length in NFSv4 CREATE. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89696] block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref
block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89692] clear CALLBACK_RUNNING on failed delegation recall queue
clear CALLBACK_RUNNING on failed delegation recall queue. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-89687] ensure nfsd_file_do_acquire does not use a non-opened file
ensure nfsd_file_do_acquire() does not use a non-opened file. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-908. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89679] fix null dereference in nfsd4_setattr for deleg timestamp attrs
fix null dereference in nfsd4_setattr for deleg timestamp attrs. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89673] fix XDR padding calculation in ff_encode_getdeviceinfo
fix XDR padding calculation in ff_encode_getdeviceinfo. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-89674] fix XDR length calculation in nfsd4_ff_encode_layoutget
fix XDR length calculation in nfsd4_ff_encode_layoutget. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-805. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89667] close shrinker/GC/fsnotify vs per-net shutdown race in filecache
close shrinker/GC/fsnotify vs per-net shutdown race in filecache. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-89661] Prevent post-shutdown use-after-free in unlock_filesystem
Prevent post-shutdown use-after-free in unlock_filesystem. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel-rt.
Medium [CVE-2026-89647] do not repeat ceph_trim_dentries if no progress possible
do not repeat ceph_trim_dentries() if no progress possible. Red Hat rates this low (CVSS 5.5). Weakness: CWE-835. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89645] drop recovered reloc root refs on recovery failure
drop recovered reloc root refs on recovery failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89646] fix leaked inode reference on writeback abort at umount
fix leaked inode reference on writeback abort at umount. Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel-rt.
Medium [CVE-2026-89644] fix extent map leak in NOCOW direct I/O write
fix extent map leak in NOCOW direct I/O write. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel-rt.
Medium [CVE-2026-89640] fix loff_t underflow in cifs_remap_file_range when len == 0
fix loff_t underflow in cifs_remap_file_range() when len == 0. Red Hat rates this low (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-89639] use cifs_invalidate_cache in cifs_do_truncate for O_TRUNC
use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-524. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89635] only rebind the reopened file's own oplock on durable reconnect
only rebind the reopened file's own oplock on durable reconnect. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-89628] clamp eeprom debugfs read to bytes actually received
clamp eeprom debugfs read to bytes actually received. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-805. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.