Red Hat Linux Security Advisories & CVEs
3021 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-71576] Manager trusts self-asserted evt.Source for leaf-hub identity in all status handlers
Manager trusts self-asserted evt. Source() for leaf-hub identity in all status handlers. Red Hat rates this important (CVSS 8.5). Weakness: CWE-345.
High [CVE-2026-59090] arbitrary code execution in psd plugin due to unsigned underflow
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can ultimately result in arbitrary code execution, allowing the attacker to run malicious code on the victim's system. This is an Important severity flaw in the GIMP image manipulation program. This vulnerability primarily affects desktop environments where GIMP is installed and used to process untrusted image files. Red Hat severity: Important — CVSS 8.4 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H). Weakness: CWE-191. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-68415] clear mode callbacks after failed mode setup
clear mode callbacks after failed mode setup. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-68409] Use-after-free vulnerability in mac80211 Wi-Fi driver
Use-after-free vulnerability in mac80211 Wi-Fi driver. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
High [CVE-2026-68404] use wiphy work for socket owner autodisconnect
use wiphy work for socket owner autodisconnect. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68402] Linux kernel: Wi-Fi subsystem out-of-bounds read via crafted frames
Linux kernel: Wi-Fi subsystem out-of-bounds read via crafted frames. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68401] Fix out-of-bound writes in ffa_setup_and_transmit
Fix out-of-bound writes in ffa_setup_and_transmit(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
High [CVE-2026-68399] Fix UAF in sock clone early bailouts
Fix UAF in sock clone early bailouts. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel-rt.
High [CVE-2026-68398] Linux kernel: PPP over L2TP Use-After-Free vulnerability
Linux kernel: PPP over L2TP Use-After-Free vulnerability. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68397] take a reference on the socket found in afiucv_hs_rcv
take a reference on the socket found in afiucv_hs_rcv(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68393] extend conn_hash lookup critical sections
extend conn_hash lookup critical sections. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-68389] Clear memdump state on invalid dump size
Clear memdump state on invalid dump size. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-68381] Use-after-free vulnerability due to race condition in connection handling
Use-after-free vulnerability due to race condition in connection handling. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68377] Linux kernel: Denial of Service due to use-after-free in act_tunnel_key
Linux kernel: Denial of Service due to use-after-free in act_tunnel_key. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68376] Linux kernel SCTP: Out-of-bounds read due to incorrect array size calculation
Linux kernel SCTP: Out-of-bounds read due to incorrect array size calculation. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68373] Linux kernel: Out-of-bounds read in wifi driver due to length underflow
Linux kernel: Out-of-bounds read in wifi driver due to length underflow. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68368] validate datagram bounds in ncm_unwrap_ntb
validate datagram bounds in ncm_unwrap_ntb(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68365] cap received transmit credits
cap received transmit credits. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68363] Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash
Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68351] bound memcpy length in cmd callback to prevent OOB read
bound memcpy length in cmd callback to prevent OOB read. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.