VulnSea

Red Hat has 1,285 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1043 in the last 90 days against 120 in the 90 before. The busiest recent month was September 2026 with 638. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1043 prev 120

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1285
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1285 CVEsRSS

CVE-2026-81012Medium· 5.5⚖ disputed
2w ago

kernel: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (CVE-2026-81012)

A flaw was found in the Linux kernel's hp-bioscfg component. The `hp_get_string_from_buffer()` function contains an off-by-one write vulnerability. This occurs because the NUL terminator can be written one byte beyond the allocated buffer,…

▾ SunlitRed Hat · LinuxEPSS 0.20%via CSAF
CVE-2026-89551High· 7.0⚖ disputed
2w ago

kernel: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow (CVE-2026-89551)

A flaw was found in the Linux kernel's SUNRPC subsystem, specifically within the `xdr_buf_trim()` function. This vulnerability occurs when `xdr_buf_trim()` attempts to reduce the size of an XDR buffer. If the buffer's length is smaller tha…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89548High· 7.0
2w ago

kernel: SUNRPC: always drain cache_cleaner before destroying a cache_detail (CVE-2026-89548)

A flaw was found in the Linux kernel's SUNRPC component. When `sunrpc_destroy_cache_detail()` is called, it may not properly drain the `cache_cleaner` before freeing a `cache_detail` object. This oversight can lead to a use-after-free vuln…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89547High· 7.0
2w ago

kernel: SUNRPC: Check svc pool percpu counter allocation (CVE-2026-89547)

A flaw was found in the Linux kernel's SUNRPC component. A local administrator, under specific conditions of memory pressure or fault injection during RPC server startup, can trigger a failure in per-CPU counter allocation. This failure le…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.57%via CSAF
CVE-2026-89541High· 7.0⚖ disputed
2w ago

kernel: SUNRPC: harden gss_unwrap_resp_priv length checks (CVE-2026-89541)

A flaw was found in the Linux kernel. Specifically, an integer overflow vulnerability exists in the `gss_unwrap_resp_priv()` function within the SUNRPC component. This flaw occurs when validating the length of RPCSEC_GSS opaque data. A mal…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89540High· 7.0
2w ago

kernel: sunrpc: init gssp_lock before publishing proc entry (CVE-2026-89540)

A flaw was found in the Linux kernel's sunrpc component. A race condition exists where the `gssp_lock` mutex is not initialized before its associated `/proc/net/rpc/use-gss-proxy` entry is published. This allows a local attacker to trigger…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89538High· 7.0⚖ disputed
2w ago

kernel: SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field (CVE-2026-89538)

A flaw was found in the Linux kernel's Server Unix Remote Procedure Call (SUNRPC) component. A remote attacker, with a valid Generic Security Service (GSS) context, could send a specially crafted Kerberos v2 wrap token with an oversized "e…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89533High· 7.0⚖ disputed
2w ago

kernel: svcrdma: Fix offset arithmetic in read_chunk_range (CVE-2026-89533)

A flaw was found in the `svcrdma` component of the Linux kernel. Incorrect offset arithmetic in the `svc_rdma_read_chunk_range()` function can lead to a `u32` underflow. This underflow can cause the system to attempt to allocate a large am…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.74%via CSAF
CVE-2026-89532High· 7.0⚖ disputed
2w ago

kernel: svcrdma: Fix pcl_for_each_segment for empty chunks (CVE-2026-89532)

A flaw was found in the Linux kernel's svcrdma component. A remote attacker could send a specially crafted network packet that causes an integer underflow in the `pcl_for_each_segment` function when processing a chunk with zero segments. T…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.72%via CSAF
CVE-2026-89525Medium· 5.5
2w ago

kernel: udf: reject VAT indexes equal to the entry count (CVE-2026-89525)

A flaw was found in the Linux kernel. A local attacker could craft a malicious Universal Disk Format (UDF) image to trigger an out-of-bounds read vulnerability in the `udf_get_pblock_virt15()` function. This occurs when the system attempts…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-89524Medium· 5.5⚖ disputed
2w ago

kernel: wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (CVE-2026-89524)

A flaw was found in the ath6kl Wi-Fi driver of the Linux kernel. An integer underflow vulnerability occurs when processing Wi-Fi association requests or responses that are shorter than expected. This can cause the system to read beyond the…

▾ SunlitRed Hat · LinuxEPSS 0.42%via CSAF
CVE-2026-89515Medium· 5.5
2w ago

kernel: scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() (CVE-2026-89515)

A flaw was found in the Linux kernel's SCSI core component. When processing data transfers using scatter-gather lists, the system does not properly initialize padding bytes for unaligned data elements. This can result in the exposure of un…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.22%via CSAF
CVE-2026-89512Medium· 5.5
2w ago

kernel: remoteproc: scp: Fix device reference leak on failed lookup (CVE-2026-89512)

A flaw was found in the Linux kernel's remoteproc SCP component. This vulnerability involves a device reference leak, where the system fails to properly release a reference to a device during a driver data lookup. This occurs specifically …

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-89511Medium· 5.5⚖ disputed
2w ago

kernel: qede: Fix NULL pointer dereference in TPA fragment processing (CVE-2026-89511)

A flaw was found in the qede driver in the Linux kernel. Under specific memory pressure conditions, the driver can encounter a NULL pointer dereference when processing network traffic using TPA (TCP Segmentation Offload) continuation fragm…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.72%via CSAF
CVE-2026-89510High· 7.0
2w ago

kernel: RDMA/cxgb4: Cancel reg_work before freeing device on remove (CVE-2026-89510)

A flaw was found in the Linux kernel's RDMA/cxgb4 component. This vulnerability occurs when the `c4iw_remove()` function frees a device while its registration work (`reg_work`) is still pending or actively running. This timing issue can le…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89508Medium· 5.5⚖ disputed
2w ago

kernel: RDMA/ucma: Lock the handler in ucma_set_ib_path() (CVE-2026-89508)

A flaw was found in the Linux kernel's RDMA/ucma component. A race condition exists in the `ucma_set_ib_path()` function when handling events concurrently with `ucma_migrate_id()`. This can allow a local attacker with access to an RDMA dev…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89504Medium· 5.5⚖ disputed
2w ago

kernel: regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (CVE-2026-89504)

A flaw was found in the Linux kernel's regulator subsystem. This vulnerability arises from a programming error where a device tree node pointer is released too early, creating a "dangling pointer"—a reference to memory that is no longer va…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.20%via CSAF
CVE-2026-89498Medium· 5.5
2w ago

kernel: orangefs: fix double-free of trailer_buf on readdir copy failure (CVE-2026-89498)

A flaw was found in OrangeFS within the Linux kernel. A local client, by sending a specially crafted readdir downcall with a declared trailer_size exceeding the actual supplied bytes, can trigger a double-free vulnerability. This memory co…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.22%via CSAF
CVE-2026-89496Medium· 5.5
2w ago

kernel: ocfs2: always run deallocs on copy-on-write completion (CVE-2026-89496)

A flaw was found in ocfs2, the Oracle Cluster File System, within the Linux kernel. A local user could exploit this vulnerability by performing a `copy_file_range()` operation within the same filesystem. This can lead to a memory leak, pot…

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-89495Medium· 5.5⚖ disputed
2w ago

kernel: ocfs2: bound namelen in dlm_migrate_request_handler (CVE-2026-89495)

A flaw was found in ocfs2 in the Linux kernel. A malicious or compromised node within a Distributed Lock Manager (DLM) cluster can send specially crafted messages with unchecked length fields. This can lead to a heap out-of-bounds write, p…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.76%via CSAF
CVE-2026-89493Medium· 5.5⚖ disputed
2w ago

kernel: ocfs2: validate rl_used against rl_count in refcount block validator (CVE-2026-89493)

A flaw was found in the Linux kernel's ocfs2 component. A local attacker with CAP_SYS_ADMIN privileges could exploit this by mounting a crafted or corrupted ocfs2 image, or by performing a raw write to the block device backing an already-m…

▾ SunlitRed Hat · LinuxEPSS 0.68%via CSAF
CVE-2026-89491Medium· 5.5
2w ago

kernel: ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() (CVE-2026-89491)

A flaw was found in the Linux kernel's ocfs2 cluster module. This vulnerability allows a local attacker to trigger a denial of service. The issue arises when a sleeping function is called while a spinlock is held within the o2hb_region_pin…

▾ SunlitRed Hat · LinuxEPSS 0.22%via CSAF
CVE-2026-89489Medium· 5.5⚖ disputed
2w ago

kernel: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall (CVE-2026-89489)

A flaw was found in the Linux kernel. The `sys_or1k_atomic()` syscall, specific to the openrisc architecture, does not adequately validate user-provided pointers. An unprivileged process can exploit this by supplying kernel addresses to th…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.18%via CSAF
CVE-2026-89488High· 7.0
2w ago

kernel: openvswitch: Fix CT limit teardown use-after-free (CVE-2026-89488)

A flaw was found in the Linux kernel's Open vSwitch (OVS) component. An unprivileged user, operating from a user and network namespace, can trigger a use-after-free vulnerability during network namespace teardown. This occurs because packe…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-89487High· 7.0
2w ago

kernel: openvswitch: only skb_tx_error() a packet we are about to drop (CVE-2026-89487)

A flaw was found in openvswitch in the Linux kernel. This vulnerability occurs when the `queue_userspace_packet()` function incorrectly modifies a shared network packet buffer by stripping a critical flag. This action can lead to an unpriv…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89485High· 7.0⚖ disputed
2w ago

kernel: lockd: pin next file across nlm_inspect_file lock-drop (CVE-2026-89485)

A flaw was found in the `lockd` component of the Linux kernel. This use-after-free vulnerability occurs in the `nlm_traverse_files()` function when a file's memory is prematurely released while an iterator still holds a pointer to it. A re…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.76%via CSAF
CVE-2026-89483Medium· 5.5⚖ disputed
2w ago

kernel: nvme: zero the discard fallback page (CVE-2026-89483)

A flaw was found in the Linux kernel's Non-Volatile Memory Express (NVMe) subsystem. Under specific memory pressure conditions, a local user could trigger a scenario where uninitialized kernel memory is used and potentially exposed. This c…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.58%via CSAF
CVE-2026-89607High· 7.0
2w ago

kernel: ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet (CVE-2026-89607)

A flaw was found in ecryptfs in the Linux kernel. The parse_tag_3_packet() function does not properly validate the size of the encrypted key, allowing an oversized key to be processed. This improper validation leads to out-of-bounds writes…

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.18%via CSAF
CVE-2026-89606High· 7.0
2w ago

kernel: ecryptfs: reject too-small tag 70 packets (CVE-2026-89606)

A flaw was found in ecryptfs, a component of the Linux kernel. This vulnerability allows a remote attacker to send a specially crafted tag 70 packet with a body smaller than expected. This can lead to an integer underflow during size calcu…

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.18%via CSAF
CVE-2026-89605Medium· 5.5⚖ disputed
2w ago

kernel: ecryptfs: release message context on send failure (CVE-2026-89605)

A flaw was found in the `ecryptfs` component of the Linux kernel. When the `ecryptfs_send_miscdev()` function fails to send a message to the userspace daemon, the associated message context is not properly released. This oversight leaves t…

▾ SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.18%via CSAF
Red Hat vulnerabilities (CVEs) — page 14 · VulnSea