Red Hat Linux Security Advisories & CVEs
3037 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-68117] clear sock->sk on the failed-insert path in tipc_sk_create
clear sock->sk on the failed-insert path in tipc_sk_create(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68147] Avoid dynamic allocation in fscrypt_get_devices
Avoid dynamic allocation in fscrypt_get_devices(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-68300] verify auth requirement when auth_chunk is NULL
verify auth requirement when auth_chunk is NULL. Red Hat rates this moderate (CVSS 7). Weakness: CWE-303. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68380] Fix use-after-free of mm_struct in job scheduler
Fix use-after-free of mm_struct in job scheduler. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825.
High [CVE-2026-68267] Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1188. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel-rt.
High [CVE-2026-68158] Fix multiplication overflow in decode_new_up_state_weight
Fix multiplication overflow in decode_new_up_state_weight(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68266] Hold a dma-buf reference for imported BOs
Hold a dma-buf reference for imported BOs. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68245] fix lifetime issue of amdgpu_vm_get_task_info_pasid
fix lifetime issue of amdgpu_vm_get_task_info_pasid(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68273] Fix context pstate override handling
Fix context pstate override handling. Red Hat rates this moderate (CVSS 7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-68169] fix use-after-free in get_local_id
fix use-after-free in get_local_id. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68427] Fix use-after-free in host1x_bo_clear_cached_mappings
Fix use-after-free in host1x_bo_clear_cached_mappings. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68103] reject mapping a reserved doorbell to a new queue
reject mapping a reserved doorbell to a new queue. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68123] fix GSO userspace truncation underflow
fix GSO userspace truncation underflow. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
High [CVE-2026-68264] Reset current_op in xe_pt_update_ops_init
Reset current_op in xe_pt_update_ops_init(). Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68391] hold reference for hci_conn in mgmt_pending_cmds
hold reference for hci_conn in mgmt_pending_cmds. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68374] add lock to bos_descriptors_read
add lock to bos_descriptors_read(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68379] fix TIME_WAIT socket reference leak on PSP policy failure
fix TIME_WAIT socket reference leak on PSP policy failure. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.
High [CVE-2026-68181] access mei_device under device_lock on cleanup
access mei_device under device_lock on cleanup. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-48120] Remote Code Execution via malicious backup files
Remote Code Execution via malicious backup files. Red Hat rates this important (CVSS 8.6). Weakness: CWE-94.
High [CVE-2026-11425] Stored cross-site scripting allows administrator account takeover
Stored cross-site scripting allows administrator account takeover. Red Hat rates this important (CVSS 7.7). Weakness: CWE-79.