Red Hat Linux Security Advisories & CVEs
5469 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
High [CVE-2026-63992] do not assume transport header in iptunnel_pmtud_check_icmp
do not assume transport header in iptunnel_pmtud_check_icmp(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-805.
High [CVE-2026-64000] fix potential OOB access in supervision frame handling
fix potential OOB access in supervision frame handling. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805.
High [CVE-2026-63917] Use ip6_tnl.net in vti6_changelink
Use ip6_tnl.net in vti6_changelink(). Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64026] Fix DATA decrypt vs splice by copying data to buffer in recvmsg
Fix DATA decrypt vs splice() by copying data to buffer in recvmsg. Red Hat rates this important (CVSS 7). Weakness: CWE-366.
High [CVE-2026-63913] do not force CLOSE on invalid-seq RST without direction check
do not force CLOSE on invalid-seq RST without direction check. Red Hat rates this moderate (CVSS 7). Weakness: CWE-358.
High [CVE-2026-63910] fix UAF in dma_buf_fd tracepoint
fix UAF in dma_buf_fd() tracepoint. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367.
High [CVE-2026-63888] Fix CRC overread and double-free in iscsit_handle_text_cmd
Fix CRC overread and double-free in iscsit_handle_text_cmd(). Red Hat rates this important (CVSS 7). Weakness: CWE-125.
High [CVE-2026-63994] load network headers after skb_cow in iptunnel_pmtud_build_icmp[v6]
load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6](). Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-63946] fix UAF in iso_recv_frame
fix UAF in iso_recv_frame. Red Hat rates this moderate (CVSS 7). Weakness: CWE-366.
High [CVE-2026-63887] Bound iscsi_encode_text_output appends to rsp_buf
Bound iscsi_encode_text_output() appends to rsp_buf. Red Hat rates this important (CVSS 7). Weakness: CWE-120.
High [CVE-2026-63891] Cap recursion depth in __tb_property_parse_dir
Cap recursion depth in __tb_property_parse_dir(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-606.
High [CVE-2026-64017] pop cached request if it is usable
pop cached request if it is usable. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:47040 with package kernel-0:5.14.0-687.31.1.el9_8. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-64008] fix UAF via dangling GEM handle in create_bo
fix UAF via dangling GEM handle in create_bo. Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64030] bounds-check link_id in ieee80211_ml_epcs
bounds-check link_id in ieee80211_ml_epcs. Red Hat rates this important (CVSS 7). Weakness: CWE-476.
High [CVE-2026-63879] fix amdgpu_hmm_range_get_pages
fix amdgpu_hmm_range_get_pages. Red Hat rates this important (CVSS 7). Weakness: CWE-824.
High [CVE-2026-63896] fix integer underflow in WebUSB GET_URL handling
fix integer underflow in WebUSB GET_URL handling. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787.
High [CVE-2026-63971] fix race between sctp_wait_for_connect and peeloff
fix race between sctp_wait_for_connect and peeloff. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367.
High [CVE-2026-64032] Fix a possible use-after-free when removing a bridge port
Fix a possible use-after-free when removing a bridge port. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.
High [CVE-2026-64024] fix stale per-CPU tcp_tw_isn leak enabling ISN prediction
fix stale per-CPU tcp_tw_isn leak enabling ISN prediction. Red Hat rates this moderate (CVSS 7). Weakness: CWE-342.
High [CVE-2026-64027] rework the VALID marking (again)
rework the VALID marking (again). Red Hat rates this moderate (CVSS 7). Weakness: CWE-367.