Red Hat Linux Security Advisories & CVEs
3063 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-63958] validate connector number in ucsi_connector_change
validate connector number in ucsi_connector_change(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-787.
High [CVE-2026-63889] Widen FPIN pname walker counter to u32
Widen FPIN pname walker counter to u32. Red Hat rates this moderate (CVSS 7). Weakness: CWE-190.
High [CVE-2026-63884] Fix potential UAF in TTM object purge
Fix potential UAF in TTM object purge. Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-63899] fix memory corruption with small endpoint
fix memory corruption with small endpoint. Red Hat rates this important (CVSS 7). Weakness: CWE-120.
High [CVE-2026-63924] refresh nh pointer after ipv6_hop_jumbo
refresh nh pointer after ipv6_hop_jumbo(). Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-63922] refresh nh after handling HAO option
refresh nh after handling HAO option. Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-63886] Validate CHAP_R length before base64 decode
Validate CHAP_R length before base64 decode. Red Hat rates this important (CVSS 7). Weakness: CWE-805.
High [CVE-2026-63920] validate extension header length before copying to cmsg
validate extension header length before copying to cmsg. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.
High [CVE-2026-63938] Check PSC request indices against the actual size of the buffer
Check PSC request indices against the actual size of the buffer. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1285.
High [CVE-2026-63914] route MIGRATE notifications to caller's netns
route MIGRATE notifications to caller's netns. Red Hat rates this moderate (CVSS 7). Weakness: CWE-653.
High [CVE-2026-63894] serialize DMABUF cancel against request completion
serialize DMABUF cancel against request completion. Red Hat rates this moderate (CVSS 7). Weakness: CWE-366.
High [CVE-2026-63883] fix kfifo underflow when flush precedes DMA completion IRQ
fix kfifo underflow when flush precedes DMA completion IRQ. Red Hat rates this moderate (CVSS 7). Weakness: CWE-124.
High [CVE-2026-63939] Compute the correct max length of the in-GHCB scratch area
Compute the correct max length of the in-GHCB scratch area. Red Hat rates this important (CVSS 7). Weakness: CWE-131.
High [CVE-2026-63885] fix race between change_handle and handle_delete
fix race between change_handle and handle_delete. Red Hat rates this moderate (CVSS 7). Weakness: CWE-366.
High [CVE-2026-63921] Use ip6_tnl.net in vti6_siocdevprivate
Use ip6_tnl.net in vti6_siocdevprivate(). Red Hat rates this important (CVSS 7). Weakness: CWE-653.
High [CVE-2026-63957] fix memory corruption with small endpoint
fix memory corruption with small endpoint. Red Hat rates this moderate (CVSS 7). Weakness: CWE-131.
High [CVE-2026-63956] fix memory corruption with small endpoint
fix memory corruption with small endpoint. Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-63940] Ignore Port I/O requests of length '0'
Ignore Port I/O requests of length '0'. Red Hat rates this moderate (CVSS 7). Weakness: CWE-130.
High [CVE-2026-63918] use refcount_inc_not_zero in l2tp_session_get_by_ifname
use refcount_inc_not_zero in l2tp_session_get_by_ifname. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911.
High [CVE-2026-63947] fix missing length checks in hidp_input_report
fix missing length checks in hidp_input_report(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.