Red Hat Linux Security Advisories & CVEs
3067 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-63993] do not reuse cached ip_hdr value after skb_tunnel_check_pmtu
do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu(). Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64025] bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
bpf, skmsg: fix verdict sk_data_ready racing with ktls rx. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364.
High [CVE-2026-63979] hand off the pinned file reference to accept_doit
hand off the pinned file reference to accept_doit. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64015] fix missed RCU read section on lookup
fix missed RCU read section on lookup. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-63978] Drain pending requests at net namespace exit
Drain pending requests at net namespace exit. Red Hat rates this moderate (CVSS 7). Weakness: CWE-821.
High [CVE-2026-64034] Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367.
High [CVE-2026-63984] fix hdrlen overflow in ipv6_rpl_srh_decompress
fix hdrlen overflow in ipv6_rpl_srh_decompress(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-190.
High [CVE-2026-64001] Fix setup list UAF on proc write error
Fix setup list UAF on proc write error. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64009] Check for underflow in xfrm_state_mtu
Check for underflow in xfrm_state_mtu. Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-63987] cap profile updates at NET_DIM_PARAMS_NUM_PROFILES
cap profile updates at NET_DIM_PARAMS_NUM_PROFILES. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787.
High [CVE-2026-63970] bind uarg before filling zerocopy skb
bind uarg before filling zerocopy skb. Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-63981] Fix blockcast recursion bypass leading to stack overflow
Fix blockcast recursion bypass leading to stack overflow. Red Hat rates this moderate (CVSS 7). Weakness: CWE-770.
High [CVE-2026-63996] require exact CDB reply length
require exact CDB reply length. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787.
High [CVE-2026-9323] Predictable session IDs lead to remote code execution and information disclosure
Predictable session IDs lead to remote code execution and information disclosure. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1241.
High [CVE-2026-50274] Datadog dd-trace-go: Denial of Service via malicious baggage headers
Datadog dd-trace-go: Denial of Service via malicious baggage headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-53727] Arbitrary local file disclosure via Server-Side Request Forgery
Arbitrary local file disclosure via Server-Side Request Forgery. Red Hat rates this important (CVSS 8.6). Weakness: CWE-918.
High [CVE-2026-44891] Denial of Service vulnerability in STOMP decoder
Denial of Service vulnerability in STOMP decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-54465] Denial of Service via unbounded memory consumption
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client, a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. This issue is fixed in version 0.8.1. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Red Hat lists Red Hat Hardened Images as not affected.
High [CVE-2026-54463] Denial of Service via unbounded memory consumption in WebSocket length header
websocket-driver is a WebSocket protocol handler with pluggable I/O. This can make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. This issue is fixed in version 0.8.1. A remote attacker could exploit a vulnerability in how draft versions of the WebSocket protocol handle length headers. By sending an indefinite sequence of specially crafted bytes, an attacker can cause the affected component to consume an unbounded amount of memory. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Red Hat lists Red Hat Hardened Images as not affected.
High [CVE-2026-16118] heap-based buffer overflow in _xdg_mime_magic_parse_magic_line in xdgmimemagic.c
heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-122.