Red Hat Linux Security Advisories & CVEs
5472 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-63920] validate extension header length before copying to cmsg
validate extension header length before copying to cmsg. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.
High [CVE-2026-63938] Check PSC request indices against the actual size of the buffer
Check PSC request indices against the actual size of the buffer. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1285.
High [CVE-2026-63914] route MIGRATE notifications to caller's netns
route MIGRATE notifications to caller's netns. Red Hat rates this moderate (CVSS 7). Weakness: CWE-653.
High [CVE-2026-63894] serialize DMABUF cancel against request completion
serialize DMABUF cancel against request completion. Red Hat rates this moderate (CVSS 7). Weakness: CWE-366.
High [CVE-2026-63883] fix kfifo underflow when flush precedes DMA completion IRQ
fix kfifo underflow when flush precedes DMA completion IRQ. Red Hat rates this moderate (CVSS 7). Weakness: CWE-124.
High [CVE-2026-63939] Compute the correct max length of the in-GHCB scratch area
Compute the correct max length of the in-GHCB scratch area. Red Hat rates this important (CVSS 7). Weakness: CWE-131.
High [CVE-2026-63885] fix race between change_handle and handle_delete
fix race between change_handle and handle_delete. Red Hat rates this moderate (CVSS 7). Weakness: CWE-366.
High [CVE-2026-63921] Use ip6_tnl.net in vti6_siocdevprivate
Use ip6_tnl.net in vti6_siocdevprivate(). Red Hat rates this important (CVSS 7). Weakness: CWE-653.
High [CVE-2026-63957] fix memory corruption with small endpoint
fix memory corruption with small endpoint. Red Hat rates this moderate (CVSS 7). Weakness: CWE-131.
High [CVE-2026-63956] fix memory corruption with small endpoint
fix memory corruption with small endpoint. Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-63940] Ignore Port I/O requests of length '0'
Ignore Port I/O requests of length '0'. Red Hat rates this moderate (CVSS 7). Weakness: CWE-130.
High [CVE-2026-63918] use refcount_inc_not_zero in l2tp_session_get_by_ifname
use refcount_inc_not_zero in l2tp_session_get_by_ifname. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911.
High [CVE-2026-63947] fix missing length checks in hidp_input_report
fix missing length checks in hidp_input_report(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.
High [CVE-2026-63950] initialize nr_pages to 1 at loop start in try_to_unmap_one
initialize nr_pages to 1 at loop start in try_to_unmap_one. Red Hat rates this important (CVSS 7). Weakness: CWE-911.
High [CVE-2026-63925] fix replay protection at XPN lower-PN wrap
fix replay protection at XPN lower-PN wrap. Red Hat rates this moderate (CVSS 7). Weakness: CWE-294.
High [CVE-2026-63919] hold netns during deferred transport reinjection
hold netns during deferred transport reinjection. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911.
High [CVE-2026-63944] fix UAF in hci_le_create_cis_sync
fix UAF in hci_le_create_cis_sync. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364.
High [CVE-2026-63912] restore combined single-frag length gate
restore combined single-frag length gate. Red Hat rates this moderate (CVSS 7). Weakness: CWE-770.
High [CVE-2026-63923] validate body pcifunc in rvu_mbox_handler_rep_event_notify
validate body pcifunc in rvu_mbox_handler_rep_event_notify. Red Hat rates this important (CVSS 7). Weakness: CWE-787.
High [CVE-2026-64018] validate rx_req_idx to prevent out-of-bounds array access
validate rx_req_idx to prevent out-of-bounds array access. Red Hat rates this important (CVSS 7). Weakness: CWE-787.