Red Hat Linux Security Advisories & CVEs
5652 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-81013] fix heap OOB read on empty password write
fix heap OOB read on empty password write. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-81011] pass validated element count to package parsers
pass validated element count to package parsers. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-81010] honor task_work cancellation
honor task_work cancellation. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-663. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-81009] cap user size passed to copy_struct_to_user
cap user size passed to copy_struct_to_user. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770.
Medium [CVE-2026-81006] Remove all sysfs files on registration failure
Remove all sysfs files on registration failure. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-81004] ipmi:msghandler: Cancel work cleanly on an error
ipmi:msghandler: Cancel work cleanly on an error. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.
Medium [CVE-2026-80999] use gpiod_set_value_cansleep for reset GPIO
use gpiod_set_value_cansleep for reset GPIO. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-663.
Medium [CVE-2026-80997] fix stalled modem TX queue after runtime resume
fix stalled modem TX queue after runtime resume. Red Hat rates this low (CVSS 5.5). Weakness: CWE-821. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel-rt.
Medium [CVE-2026-80998] ring the doorbell when SW USO exits early
ring the doorbell when SW USO exits early. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-841.
Medium [CVE-2026-80996] do not propagate multicast notification errors
do not propagate multicast notification errors. Red Hat rates this low (CVSS 5.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-80995] hold a reference to the route device in mctp_route_lookup
hold a reference to the route device in mctp_route_lookup(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-80993] correctly validate returned PCS in phylink_inband_caps
correctly validate returned PCS in phylink_inband_caps. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-80992] avoid dereferencing an invalid PTP clock
avoid dereferencing an invalid PTP clock. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476.
Medium [CVE-2026-80991] serialize PTP clock teardown
serialize PTP clock teardown. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-364.
Medium [CVE-2026-80990] Release the Rx HopID that was handed out on mismatch
Release the Rx HopID that was handed out on mismatch. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-80988] Fail TX enqueue when the QP link is down
Fail TX enqueue when the QP link is down. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel-rt.
Medium [CVE-2026-80987] Reject oversized TX buffers
Reject oversized TX buffers. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-80984] do not dereference an unset send buffer on the SMC-D teardown path
do not dereference an unset send buffer on the SMC-D teardown path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-80983] fix socket refcount leak in smc_switch_conns
fix socket refcount leak in smc_switch_conns(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-80980] stop killed, freed and out_of_sync sharing a byte
stop killed, freed and out_of_sync sharing a byte. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.