Red Hat Enterprise Linux AI是美国红帽(Red Hat)公司的一个为生成式 AI 打造的 Linux 发行版。 Red Hat Enterprise Linux AI存在路径遍历漏洞,该漏洞源于聊天会话处理程序存在路径遍历,本地攻击者可通过操纵logs_dir参数在系统任意位置创建目录和写入文件,可能导致未经授权的数据修改或泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6859 | 8.8 HIGH | Instructlab: instructlab: arbitrary code execution due to hardcoded `trust_remote_code=tru |
| CVE-2026-6861 | 6.1 MEDIUM | Emacs: emacs: memory corruption vulnerability when processing svg css |
| CVE-2026-6862 | 5.5 MEDIUM | Efivar: efivar: denial of service due to stack overflow in device path node parsing |
| CVE-2026-6844 | 5.5 MEDIUM | Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files |
| CVE-2026-6843 | 5.5 MEDIUM | Nano: nano: format string vulnerability leads to denial of service |
| CVE-2026-6848 | 5.4 MEDIUM | Quay: red hat quay: authentication bypass allows privileged actions without valid credenti |
| CVE-2026-6845 | 5.0 MEDIUM | Binutils: binutils: denial of service via crafted elf file |
No comments yet