Red Hat Linux Security Advisories & CVEs
3191 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-68326] bound uAP association event IEs to the event buffer
bound uAP association event IEs to the event buffer. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-68177] Delay module ref count for "enable_event" trigger
Delay module ref count for "enable_event" trigger. Red Hat rates this moderate. Weakness: CWE-825.
Medium [CVE-2026-68197] fix NULL dereference when the AP has HT-cap but no HT-oper
fix NULL dereference when the AP has HT-cap but no HT-oper. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-68414] cancel sched scan results work on unregister
cancel sched scan results work on unregister. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-68168] Fix afs_edit_dir_remove to get, not find, block 0
Fix afs_edit_dir_remove() to get, not find, block 0. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
Medium [CVE-2026-68344] reject descriptors that confuse probe and disconnect
reject descriptors that confuse probe and disconnect. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-68227] fix devres lifetime
fix devres lifetime. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-68139] Use sender devcom for MPV master-up
Use sender devcom for MPV master-up. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-68226] add ioremap return check and cleanup
add ioremap return check and cleanup. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat package: kernel-rt.
Medium [CVE-2026-68212] Fix a possible memory leak in saa7134_video_init1
Fix a possible memory leak in saa7134_video_init1. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: kernel-rt.
Medium [CVE-2026-46405] Denial of Service from unaccessible token accumulation in Kerberos authentication.
Denial of Service from unaccessible token accumulation in Kerberos authentication. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.
Medium [CVE-2026-46358] Authentication material disclosure via incorrect audit log redaction
Authentication material disclosure via incorrect audit log redaction. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-312.
Medium [CVE-2026-71870] Denial of Service via crafted PDF with large /ToUnicode streams
Denial of Service via crafted PDF with large /ToUnicode streams. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770.
Medium [CVE-2026-15970] Authorization bypass via custom public listener
Authorization bypass via custom public listener. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-551. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19017] Sensitive secret exfiltration via partial arbitrary file read
Sensitive secret exfiltration via partial arbitrary file read. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19014] Denial of Service via uncontrolled resource consumption in Connect authorization endpoint
Denial of Service via uncontrolled resource consumption in Connect authorization endpoint. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19012] Authenticated denial of service via configuration entry
Authenticated denial of service via configuration entry. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-15. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19016] Authorization bypass allows arbitrary session deletion via transaction API
Authorization bypass allows arbitrary session deletion via transaction API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-639. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-71852] Denial of Service via crafted PDF with large CID font width ranges
Denial of Service via crafted PDF with large CID font width ranges. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1050.
Medium [CVE-2026-18938] Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems
Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-122.