Red Hat Linux Security Advisories & CVEs
3037 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-68121] Linux kernel: PPPoE memory corruption via stale pointer
Linux kernel: PPPoE memory corruption via stale pointer. Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68118] challenge ACK for non-exact RST in SYN-RECEIVED
challenge ACK for non-exact RST in SYN-RECEIVED. Red Hat rates this moderate (CVSS 7). Weakness: CWE-358. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68108] fix integer overflow in image size
fix integer overflow in image size. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68100] validate num_subauth when copying ACE in set_ntacl_dacl
validate num_subauth when copying ACE in set_ntacl_dacl. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68099] restore DACL size on check_add_overflow to avoid malformed ACL
restore DACL size on check_add_overflow() to avoid malformed ACL. Red Hat rates this important (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68093] Bump asid_generation on CPU online to avoid ASID collision after hotplug
Bump asid_generation on CPU online to avoid ASID collision after hotplug. Red Hat rates this moderate (CVSS 7). Weakness: CWE-821. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-59087] heap buffer overflow in `file-seattle-filmworks` load — `fread` writes attacker-controlled length into undersized allocation
A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several kilobytes of controlled data beyond the intended memory buffer. Such an overflow can result in memory corruption, potentially leading to arbitrary code execution or a denial of service. This flaw is rated as Important because it allows for arbitrary code execution or denial of service within the context of the GIMP application. Exploitation requires a user to open a specially crafted Seattle Filmworks file, which can trigger a heap buffer overflow in the file loader. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-72568] Denial of Service via Out-of-Bounds Read in Cluster Bus
Denial of Service via Out-of-Bounds Read in Cluster Bus. Red Hat rates this a security issue. Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:43236 with package valkey-main-9.0.5-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more. Affected products named by the advisory: Red Hat package: valkey; Red Hat package: redis.
High [CVE-2026-71393] integer overflow via a malicious font file
integer overflow via a malicious font file. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-190.
High [CVE-2026-19389] integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read
integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read. Red Hat rates this important (CVSS 7.1). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:55865 with package gstreamer1-plugins-bad-free-0:1.22.12-7.el9_8.4, gstreamer1-plugins-ugly-free-0:1.22.12-6.el9_8.2, gstreamer1-plugins-ugly-free-0:1.26.7-2.el10_2.2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-19387] heap out-of-bounds write in adpcmdec IMA/DVI ADPCM decoder
heap out-of-bounds write in adpcmdec IMA/DVI ADPCM decoder. Red Hat rates this important (CVSS 7.6). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:55865 with package gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2.7, gstreamer1-plugins-bad-free-0:1.22.12-7.el9_8.4, gstreamer1-plugins-ugly-free-0:1.22.12-6.el9_8.2, gstreamer1-plugins-bad-free-0:1.16.1-9.el8_10.2. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-68388] handle overlapping allocated ranges in fallocate
handle overlapping allocated ranges in fallocate. Red Hat rates this moderate (CVSS 7). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:57251 with package kernel-0:6.12.0-211.49.1.el10_2, kernel-0:5.14.0-687.41.1.el9_8, kernel-rt-0:4.18.0-553.157.1.rt7.498.el8_10, kernel-0:4.18.0-553.157.1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-68315] validate stream count in sctp_process_strreset_inreq
validate stream count in sctp_process_strreset_inreq(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68426] fix stale skb->prev after async crypto steals a GSO segment
fix stale skb->prev after async crypto steals a GSO segment. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68201] drain a slave's callback before its master detaches it
drain a slave's callback before its master detaches it. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68086] write all dirty file folios when collapsing
write all dirty file folios when collapsing. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68236] set new_stream to NULL after release
set new_stream to NULL after release. Red Hat rates this important (CVSS 7). Weakness: CWE-763. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68293] Fix MCIA register buffer overflow on 32 dword reads
Fix MCIA register buffer overflow on 32 dword reads. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68390] hold hdev->lock for hci_conn_params lookups
hold hdev->lock for hci_conn_params lookups. Red Hat rates this moderate (CVSS 7). Weakness: CWE-414. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
High [CVE-2026-68400] Fix Endpoint Memory Access Descriptor offset calculation
Fix Endpoint Memory Access Descriptor offset calculation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.