Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5648 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.5Red Hat

Medium [CVE-2026-89549] route to a populated pool in svc_pool_for_cpu

route to a populated pool in svc_pool_for_cpu(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-821. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89549
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89544] fix gssx_dec_option_array error path bugs

fix gssx_dec_option_array error path bugs. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-89544
Linux Kernel
Sep 11, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-89539] reject duplicate CREDS_VALUE options

reject duplicate CREDS_VALUE options. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-89539
Linux Kernel
Sep 11, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-89527] Use svc_xprt_put to free listener on create failure

Use svc_xprt_put to free listener on create failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-89527
Linux Kernel
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89525] reject VAT indexes equal to the entry count

reject VAT indexes equal to the entry count. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-89525
Linux Kernel
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89524] clamp assoc request/response lengths before subtracting IE offsets

clamp assoc request/response lengths before subtracting IE offsets. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.

CVE-2026-89524
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89522] fix async notifier UAF on probe error path

fix async notifier UAF on probe error path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.

CVE-2026-89522
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89521] Handle pick_task releasing the rq lock

Handle pick_task() releasing the rq lock. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89521
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89520] Make core-sched flips wait for in-flight selections

Make core-sched flips wait for in-flight selections. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-366. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89520
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89518] Fix this_rq assumptions in dispatch kfuncs

Fix this_rq() assumptions in dispatch kfuncs. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833.

CVE-2026-89518
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89519] Replace SCX_RQ_BAL_KEEP with a dispatch verdict return

Replace SCX_RQ_BAL_KEEP with a dispatch verdict return. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367.

CVE-2026-89519
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89517] Fix rq->core_pick corruption under core scheduling

Fix rq->core_pick corruption under core scheduling. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89517
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89515] Fill in DMA padding bytes in scsi_alloc_sgtables

Fill in DMA padding bytes in scsi_alloc_sgtables(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-89515
Linux Kernel
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89516] Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users

Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89516
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89514] Use GFP_ATOMIC for VLAN alloc under spinlock

Use GFP_ATOMIC for VLAN alloc under spinlock. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-663. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-89514
Linux Kernel
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89512] Fix device reference leak on failed lookup

Fix device reference leak on failed lookup. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.

CVE-2026-89512
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89513] Fix PMU event info array size overflow

Fix PMU event info array size overflow. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89513
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89511] Fix NULL pointer dereference in TPA fragment processing

Fix NULL pointer dereference in TPA fragment processing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89511
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89509] Embed counter driver data in rdma_counter allocation

Embed counter driver data in rdma_counter allocation. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89509
Unclassified
Sep 11, 2026
Medium5.5Red Hat

Medium [CVE-2026-89508] Lock the handler in ucma_set_ib_path

Lock the handler in ucma_set_ib_path(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-89508
Unclassified
Sep 11, 2026

← All vendors