Red Hat Linux Security Advisories & CVEs
3037 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-68162] avoid auth_enable sysctl UAF during netns teardown
avoid auth_enable sysctl UAF during netns teardown. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68161] close UDP tunnel sockets during netns teardown
close UDP tunnel sockets during netns teardown. Red Hat rates this moderate (CVSS 7). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68160] fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps
fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps(). Red Hat rates this important (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68159] Linux kernel: libceph stack out-of-bounds write via crafted OSDMap
Linux kernel: libceph stack out-of-bounds write via crafted OSDMap. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68157] Linux kernel: libceph null pointer dereference leads to denial of service
Linux kernel: libceph null pointer dereference leads to denial of service. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68156] refresh auth->authorizer_buf{,_len} after authorizer update
refresh auth->authorizer_buf{,_len} after authorizer update. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68155] Linux kernel (libceph): Denial of Service due to malformed monitor maps
Linux kernel (libceph): Denial of Service due to malformed monitor maps. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68154] reject zero bucket types in crush_decode
reject zero bucket types in crush_decode. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68149] preserve ACL_DONT_CACHE state in forget_cached_acl
preserve ACL_DONT_CACHE state in forget_cached_acl(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-524.
High [CVE-2026-68148] Add missing superblock check in find_or_insert_direct_key
Add missing superblock check in find_or_insert_direct_key(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-772.
High [CVE-2026-68145] fix out-of-bounds bitmap_set with zero-length range
fix out-of-bounds bitmap_set() with zero-length range. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
High [CVE-2026-68144] Linux kernel Phonet: Memory corruption vulnerability in pep_get_sb function
Linux kernel Phonet: Memory corruption vulnerability in pep_get_sb() function. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68143] Linux kernel SLIP: Out-of-bounds write due to race condition during MTU change
Linux kernel SLIP: Out-of-bounds write due to race condition during MTU change. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68142] require CAP_NET_ADMIN in the device netns for changelink
require CAP_NET_ADMIN in the device netns for changelink. Red Hat rates this moderate (CVSS 7). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68140] fix use-after-free of a severed iucv_path
fix use-after-free of a severed iucv_path. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68138] serialize qdisc_rtab_list against concurrent get/put
serialize qdisc_rtab_list against concurrent get/put. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel-rt.
High [CVE-2026-68136] fix double aggregation of flush-marked skbs
fix double aggregation of flush-marked skbs. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel-rt.
High [CVE-2026-68131] Reset positive result codes to zero in object map update path
Reset positive result codes to zero in object map update path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68128] Linux kernel (ice): Denial of Service via out-of-range ptype in VIRTCHNL
Linux kernel (ice): Denial of Service via out-of-range ptype in VIRTCHNL. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
High [CVE-2026-68125] reject frames shorter than the authentication tag
reject frames shorter than the authentication tag. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.