Red Hat Linux Security Advisories & CVEs
3035 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-68320] fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68316] Fix element size accounting for cmd stream validation
Fix element size accounting for cmd stream validation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-131.
High [CVE-2026-68299] fix BUG_ON in vmxnet3_get_hdr_len for Geneve packets
fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets. Red Hat rates this moderate (CVSS 7). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68294] restrict socket creation to the initial network namespace
restrict socket creation to the initial network namespace. Red Hat rates this important (CVSS 7.3). Weakness: CWE-653. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68290] Use-after-free vulnerability in RDS TCP can lead to system instability
Use-after-free vulnerability in RDS TCP can lead to system instability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68289] fix integer overflow in tipc_recvmsg and tipc_recvstream
fix integer overflow in tipc_recvmsg() and tipc_recvstream(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68278] fix buffer overflows in sideband chunk accumulation
fix buffer overflows in sideband chunk accumulation. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68276] fix cleaner shader IB buffer overflow
fix cleaner shader IB buffer overflow. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
High [CVE-2026-68274] Fix buffer overflow in steered register list allocation
Fix buffer overflow in steered register list allocation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787.
High [CVE-2026-68263] Linux kernel: drm/imagination use-after-free vulnerability
Linux kernel: drm/imagination use-after-free vulnerability. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
High [CVE-2026-68257] fix 32-bit overflow in CWSR total size calculation
fix 32-bit overflow in CWSR total size calculation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68253] check streams bounds before overflow
check streams[] bounds before overflow. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68202] close a re-opened queue timer in the destructor
close a re-opened queue timer in the destructor. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68200] Linux kernel: ALSA timer use-after-free vulnerability allows privilege escalation
Linux kernel: ALSA timer use-after-free vulnerability allows privilege escalation. Red Hat rates this important (CVSS 7.8). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
High [CVE-2026-68198] Linux kernel: Use-after-free in ath6kl Wi-Fi driver leading to denial of service
Linux kernel: Use-after-free in ath6kl Wi-Fi driver leading to denial of service. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68188] Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios
Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68171] Linux kernel (arm64): Security bypass due to stale syscall argument in ptrace and seccomp
Linux kernel (arm64): Security bypass due to stale syscall argument in ptrace and seccomp. Red Hat rates this moderate (CVSS 7). Weakness: CWE-807. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68166] Linux kernel: Arbitrary code execution via userfaultfd shadow stack manipulation
Linux kernel: Arbitrary code execution via userfaultfd shadow stack manipulation. Red Hat rates this important (CVSS 7.3). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
High [CVE-2026-68162] avoid auth_enable sysctl UAF during netns teardown
avoid auth_enable sysctl UAF during netns teardown. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68161] close UDP tunnel sockets during netns teardown
close UDP tunnel sockets during netns teardown. Red Hat rates this moderate (CVSS 7). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.