Red Hat Linux Security Advisories & CVEs
5480 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-64287] Bound used_lrs when flushing the pKVM hyp vCPU
Bound used_lrs when flushing the pKVM hyp vCPU. Red Hat rates this important (CVSS 7). Weakness: CWE-125.
High [CVE-2026-64340] fix use-after-free on disconnect race
fix use-after-free on disconnect race. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364.
High [CVE-2026-64383] fix double-free in SMB2_flush replay
fix double-free in SMB2_flush() replay. Red Hat rates this important (CVSS 7).
High [CVE-2026-64379] mask server-provided mode to 07777 in modefromsid
mask server-provided mode to 07777 in modefromsid. Red Hat rates this moderate (CVSS 7). Weakness: CWE-279.
High [CVE-2026-64525] move policy_bydst RCU sync from per-netns.exit to.pre_exit
move policy_bydst RCU sync from per-netns.exit to.pre_exit. Red Hat rates this moderate (CVSS 7). Weakness: CWE-821.
High [CVE-2026-64312] pcrypt - restore callback for non-parallel fallback
pcrypt - restore callback for non-parallel fallback. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64380] harden POSIX SID length parsing
harden POSIX SID length parsing. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64475] Release the VGA arbiter client on register_device failure
Release the VGA arbiter client on register_device() failure. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64434] Fix UAF in channel timeout by holding conn ref
Fix UAF in channel timeout by holding conn ref. Red Hat rates this important (CVSS 7). Weakness: CWE-364.
High [CVE-2026-64508] Support for hardening against JIT spraying
Support for hardening against JIT spraying. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64305] qat - protect service table iterations with service_lock
qat - protect service table iterations with service_lock. Red Hat rates this moderate (CVSS 7). Weakness: CWE-366.
High [CVE-2026-64422] bound TCP reordering sysctl writes and MTU probe sizes
bound TCP reordering sysctl writes and MTU probe sizes. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64306] drbg - Fix returning success on failure in CTR_DRBG
drbg - Fix returning success on failure in CTR_DRBG. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64410] IPIP tunnel hardware offload is not yet support
IPIP tunnel hardware offload is not yet support. Red Hat rates this moderate (CVSS 7). Weakness: CWE-166.
High [CVE-2026-64375] protect ptrace_may_access with exec_update_lock (FD links)
protect ptrace_may_access() with exec_update_lock (FD links). Red Hat rates this important (CVSS 7). Weakness: CWE-367.
High [CVE-2026-64320] fix pre-auth out-of-bounds heap read in Discovery Get Log Page
fix pre-auth out-of-bounds heap read in Discovery Get Log Page. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.
High [CVE-2026-64527] validate VMBus packet size in receive callback
validate VMBus packet size in receive callback. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805.
High [CVE-2026-64267] avoid 32-bit prune notification count wrap
avoid 32-bit prune notification count wrap. Red Hat rates this moderate (CVSS 7). Weakness: CWE-190.
High [CVE-2026-64471] fix use-after-free on registration failure
fix use-after-free on registration failure. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64473] Remove device debugfs before releasing devres
Remove device debugfs before releasing devres. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911.