Red Hat Enterprise Linux
Red Hat Enterprise Linux provides a flexible and stable foundation to support hybrid cloud innovation. Deploy applications and critical workloads faster with a consistent experience across physical, virtual, private, public cloud, and edge deployments.
browse_doc
10.2 Release NotesRelease Notes
Interactively installing RHEL from installation mediaInstalling RHEL
Upgrading from RHEL 9 to RHEL 10Upgrading and converting to RHEL
Composing a customized RHEL system imageComposing RHEL images using image builder
Automating system administration by using RHEL system rolesSystem administration
Security hardeningSecurity
Configuring and managing networkingNetworking
latest_security
| severity | advisory_cve | synopsis | date |
|---|---|---|---|
| severity Moderate | advisory_cveCVE-2026-68424 | synopsis A flaw was found in the Linux kernel's `mtd_virt_concat` module. This use-after-free vulnerability occurs when the `mtd_concat_destroy()` function frees memory before it is no longer referenced by `mtd_virt_concat_put_mtd_devices()`. An attacker could potentially exploit this flaw to cause memory corruption, which may lead to a denial of service or other impacts on system stability. | date |
| severity Moderate | advisory_cveCVE-2026-68421 | synopsis A flaw was found in the Linux kernel's `sched_ext` component. The `put_prev_task_scx()` function incorrectly issues a warning when a runnable task transitions to an idle state due to core scheduling. This occurs because the core scheduling mechanism bypasses certain checks, leading to a misleading warning. | date |
| severity Moderate | advisory_cveCVE-2026-68423 | synopsis A flaw was found in the Linux kernel's `mtd: virt_concat` subsystem. The `mtd_virt_concat_destroy()` function incorrectly calls `mtd_virt_concat_put_mtd_devices()` after `mtd_concat_destroy()` has already freed the associated memory. This use-after-free vulnerability can lead to system instability or potentially enable a local attacker to achieve privilege escalation or arbitrary code execution. | date |
| severity Moderate | advisory_cveCVE-2026-68417 | synopsis A flaw was found in the Linux kernel's RDMA/siw component. The `siw_create_qp()` function prematurely publishes a Queue Pair (QP) before its complete initialization. This allows a Queue Pair Number (QPN) lookup to access a QP that is still under construction, potentially leading to unexpected behavior or system instability. | date |
| severity Important | advisory_cveCVE-2026-69244 | synopsis A flaw was found in AIOHTTP, an asynchronous HTTP client/server framework. This vulnerability involves an out-of-bounds heap read in the C response parser when processing malformed HTTP responses. An attacker operating a malicious server, or even an accidental malformed response, could exploit this to trigger a Denial of Service (DoS) in the client application, making it unavailable. | date |
top_resources
Upgrade best practices
Describes the best practices and recommendations in order to plan and upgrade RHEL using Leapp.
Red Hat Enterprise Linux Upgrade Helper
Upgrade from Red Hat Enterprise Linux 8 to Red Hat Enterprise Linux 9.
Knowledgebase
Access articles and solutions to find answers to your questions.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.