Red Hat Linux Security Advisories & CVEs
3025 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-68368] validate datagram bounds in ncm_unwrap_ntb
validate datagram bounds in ncm_unwrap_ntb(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68365] cap received transmit credits
cap received transmit credits. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68363] Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash
Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68351] bound memcpy length in cmd callback to prevent OOB read
bound memcpy length in cmd callback to prevent OOB read. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68349] fix buffer overflow in rx_stream failover path
fix buffer overflow in rx_stream failover path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68343] validate DFS referral PathConsumed
validate DFS referral PathConsumed. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:57252 with package kernel-0:5.14.0-687.41.1.el9_8. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-68335] Linux kernel RDS: Use-after-free due to cross-network namespace message delivery
Linux kernel RDS: Use-after-free due to cross-network namespace message delivery. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68329] Wait for completion instead of returning early in iommu_completion_wait
Wait for completion instead of returning early in iommu_completion_wait(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68325] Bound the early ACPI HID map
Bound the early ACPI HID map. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68323] serialize udp bearer replicast list updates
serialize udp bearer replicast list updates. Red Hat rates this moderate (CVSS 7). Weakness: CWE-820. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68320] fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68316] Fix element size accounting for cmd stream validation
Fix element size accounting for cmd stream validation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-131.
High [CVE-2026-68299] fix BUG_ON in vmxnet3_get_hdr_len for Geneve packets
fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets. Red Hat rates this moderate (CVSS 7). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68294] restrict socket creation to the initial network namespace
restrict socket creation to the initial network namespace. Red Hat rates this important (CVSS 7.3). Weakness: CWE-653. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68290] Use-after-free vulnerability in RDS TCP can lead to system instability
Use-after-free vulnerability in RDS TCP can lead to system instability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68289] fix integer overflow in tipc_recvmsg and tipc_recvstream
fix integer overflow in tipc_recvmsg() and tipc_recvstream(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68278] fix buffer overflows in sideband chunk accumulation
fix buffer overflows in sideband chunk accumulation. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68276] fix cleaner shader IB buffer overflow
fix cleaner shader IB buffer overflow. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
High [CVE-2026-68274] Fix buffer overflow in steered register list allocation
Fix buffer overflow in steered register list allocation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787.
High [CVE-2026-68263] Linux kernel: drm/imagination use-after-free vulnerability
Linux kernel: drm/imagination use-after-free vulnerability. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.