Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11552 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.5Red Hat Updated

Medium [CVE-2026-90087] do not leak an hci_conn when a second LE connect is rejected

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: do not leak an hci_conn when a second LE connect is rejected create_le_conn_complete() decides whether the failed connection is still pending by comparing it against hci_lookup_le_connect(), which returns the first LE connection in BT_CONNECT. That is the same connection only while at most one is pending. Two can be pending. Connections created on the passive scan path sit in BT_CONNECT with HCI_CONN_SCANNING set and are invisible to hci_lookup_le_connect() until hci_le_create_conn_sync() clears the flag when their command is issued, so the -EBUSY guard in hci_connect_le() does not prevent a second connection from being queued while the first is still on the scan path. Whenever two connections are in BT_CONNECT at once, the lookup may return one connection while create_le_conn_complete() is reporting the failure of the other; the early exit then drops the error and hci_conn_failed() never runs on the connection that failed. The controller also rejects a second HCI_OP_LE_CREATE_CONN issued while another connection creation is still outstanding, per Core Spec Vol 4, Part E. The spec calls for Command Disallowed there; the bcm43438 observed here answers with an LMP/LL error code instead, which bt_to_errno() maps to the -EPROTO (-71) in the log below.

CVE-2026-90087
Linux Kernel
Sep 17, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-90378] Fix memory leak in SDIO TX path

Fix memory leak in SDIO TX path. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.

CVE-2026-90378
Unclassified
Sep 17, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-93102] Free RX data on late probe failure

Free RX data on late probe failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-93102
Linux Kernel
Sep 17, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-93083] Unwind TX receiver mailbox setup failure

Unwind TX receiver mailbox setup failure. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-93083
Linux Kernel
Sep 17, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-90424] Fix VINTF0 leak on the init-failure path

Fix VINTF0 leak on the init-failure path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-90424
Linux Kernel
Sep 17, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-92519] riscv, bpf: Fix memory leak in bpf_jit_free

riscv, bpf: Fix memory leak in bpf_jit_free. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.

CVE-2026-92519
Unclassified
Sep 17, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-93185] always drain jack work on remove

always drain jack work on remove. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-93185
Linux Kernel
Sep 17, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-93059] Fix task_struct reference leak in recover_worker

Fix task_struct reference leak in recover_worker. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.

CVE-2026-93059
Unclassified
Sep 17, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-90188] free global tag_set on init error path

free global tag_set on init error path. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-90188
Linux Kernel
Sep 17, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-90384] release the folio batch on iomap callback failures

release the folio batch on iomap callback failures. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.

CVE-2026-90384
Unclassified
Sep 17, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-93090] Clean up channels on setup failure

Clean up channels on setup failure. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.

CVE-2026-93090
Unclassified
Sep 17, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-93145] tear down per-domain genpds in gdsc_unregister

tear down per-domain genpds in gdsc_unregister(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-93145
Linux Kernel
Sep 17, 2026
Medium6.6Red Hat Updated

Medium [CVE-2026-90255] fix the SCO setup context lifetime

fix the SCO setup context lifetime. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-90255
Linux Kernel
Sep 17, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-90362] Drop dev_pm_opp_set_rate(0)

Drop dev_pm_opp_set_rate(0). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.

CVE-2026-90362
Unclassified
Sep 17, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-90079] fix cn20k mailbox lifetime on repeated rvu_mbox_init

fix cn20k mailbox lifetime on repeated rvu_mbox_init(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-90079
Linux Kernel
Sep 17, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-90219] Free debugfs on registration failure

Free debugfs on registration failure. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-90219
Linux Kernel
Sep 17, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-90273] missing cscfg_csdev_disable_active_config in perf enable

missing cscfg_csdev_disable_active_config() in perf enable. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772.

CVE-2026-90273
Unclassified
Sep 17, 2026
Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-90411] unmap cmd_iu DMA on rsp_iu mapping failure in init_request

unmap cmd_iu DMA on rsp_iu mapping failure in init_request. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-90411
Linux Kernel
Sep 17, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-92504] clean up ODVP on probe failures

clean up ODVP on probe failures. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-92504
Linux Kernel
Sep 17, 2026
Medium5.5Red Hat Updated

Medium [CVE-2026-90108] free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition

free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-90108
Linux Kernel
Sep 17, 2026

← All vendors