Red Hat Linux Security Advisories & CVEs
5648 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-89589] Use raw_spinlock_t for CXL CPER work locks
Use raw_spinlock_t for CXL CPER work locks. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89588] fix ARM section length accounting after header
fix ARM section length accounting after header. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-89586] fix DSM TRIM for sector sizes larger than 2048 bytes
fix DSM TRIM for sector sizes larger than 2048 bytes. Red Hat rates this low (CVSS 5.5). Weakness: CWE-130. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-89585] cancel backlight work on registration failure
cancel backlight work on registration failure. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89579] Harden bloom filter sizing and indexing on 32-bit kernels
Harden bloom filter sizing and indexing on 32-bit kernels. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-89578] clone the source bio instead of copying its biovec
clone the source bio instead of copying its biovec. Red Hat rates this low (CVSS 5.5). Weakness: CWE-835. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89576] fix shadowed superblock leak on take-snap failure
fix shadowed superblock leak on take-snap failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89574] dm array: validate array block headers on read
dm array: validate array block headers on read. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89573] dm array: reject an array block whose value size is not the caller's
dm array: reject an array block whose value size is not the caller's. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-843. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89572] Fix OPP table cleanup
Fix OPP table cleanup. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89571] bound fwctl command payload to the input buffer
bound fwctl command payload to the input buffer. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89568] fix size calculation in kho_preserved_memory_reserve
fix size calculation in kho_preserved_memory_reserve(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1335. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89567] bound shrinker scans by examined checkpoint buffers
bound shrinker scans by examined checkpoint buffers. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-89566] check need_resched when skipping busy checkpoint buffers
check need_resched() when skipping busy checkpoint buffers. Red Hat rates this low (CVSS 5.5). Weakness: CWE-606. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-89565] fix skb leak in collect_md mode when metadata_dst allocation fails
fix skb leak in collect_md mode when metadata_dst allocation fails. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89561] fix NULL dereference of idev in ipv6_rpl_srh_rcv
fix NULL dereference of idev in ipv6_rpl_srh_rcv(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-89557] do overflow check for sb->bblog_shift in super_1_load
do overflow check for sb->bblog_shift in super_1_load(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-89556] validate string table section types
validate string table section types. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-89554] fix uninitialized local_id in syncookie MP_JOIN reconstruction
fix uninitialized local_id in syncookie MP_JOIN reconstruction. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-89552] fix charp corruption on allocation failure
fix charp corruption on allocation failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.