Red Hat Linux Security Advisories & CVEs
3038 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-64551] validate STALE_COOKIE cause length before reading staleness
validate STALE_COOKIE cause length before reading staleness. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64554] fix stale prevhdr pointer in br_ip6_fragment
fix stale prevhdr pointer in br_ip6_fragment(). Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64543] fix use-after-free of the discoverer in tipc_disc_rcv
fix use-after-free of the discoverer in tipc_disc_rcv(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64539] Fix stack OOB write when prepending the Flags AD
Fix stack OOB write when prepending the Flags AD. Red Hat rates this moderate (CVSS 7).
High [CVE-2026-64548] bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data
bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-787.
High [CVE-2026-64530] Handle TC_ACT_CONSUMED in tcf_qevent_handle
A flaw was found in the Linux kernel's traffic control (TC) classifier application programming interface (API). The `tcf_qevent_handle` function does not properly handle a consumed socket buffer (`skb`) when it is processed by the defragmentation engine. This can lead to a Use-After-Free (UAF) vulnerability, where the system attempts to use memory that has already been freed. An attacker could potentially exploit this to cause system instability or execute arbitrary code. This Important flaw in the Linux kernel's networking scheduler can lead to a use-after-free vulnerability. Exploitation requires a local attacker to configure specific `tc qdisc` and `tc filter` rules involving RED qdisc with early drop events and connection tracking on fragmented network traffic. This non-default configuration limits the attack surface, but successful exploitation could lead to privilege escalation or a denial of service. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-431. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.
High [CVE-2024-14040] Increase weight to u16
Increase weight to u16. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-190.
High [CVE-2026-66373] Remote Code Execution via specially crafted RESTORE payload
Remote Code Execution via specially crafted RESTORE payload. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1341. Red Hat lists fixing advisory RHSA-2026:43236 with package valkey-main-9.0.5-0.1.hum1.
High [CVE-2026-64456] clamp device-reported used.len at copy_data
clamp device-reported used.len at copy_data(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.
High [CVE-2026-64342] fix use-after-free on disconnect
fix use-after-free on disconnect. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64377] Fix possible double free
Fix possible double free. Red Hat rates this moderate (CVSS 7). Weakness: CWE-763.
High [CVE-2026-64490] Validate control metadata from the device
Validate control metadata from the device. Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-64418] fix shrinker_info teardown race with expansion
fix shrinker_info teardown race with expansion. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364.
High [CVE-2026-64384] fix change notify replay double-free
fix change notify replay double-free. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1341.
High [CVE-2026-64277] synaptics-rmi4 - bound the F3A keymap to the GPIO count
synaptics-rmi4 - bound the F3A keymap to the GPIO count. Red Hat rates this important (CVSS 7). Weakness: CWE-125.
High [CVE-2026-64515] fix MLE defragmentation
fix MLE defragmentation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-823.
High [CVE-2026-64378] fix race between cgroup_writeback_umount and inode_switch_wbs
fix race between cgroup_writeback_umount() and inode_switch_wbs(). Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64321] fix ndev refcount leak on queue connect
fix ndev refcount leak on queue connect. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911.
High [CVE-2026-64276] synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count. Red Hat rates this important (CVSS 7). Weakness: CWE-125.
High [CVE-2026-64355] Reject fragmented frames in devmap
Reject fragmented frames in devmap. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.