Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 232

All 232 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with Red Hat Enterprise Linux 10. It aggregates security issues ranging from buffer overflows and injection flaws to permission misconfigurations and logic errors that affect this specific enterprise operating system release. The content compiles known flaws identified in Red Hat Enterprise Linux 10 components, covering security advisories and patch releases issued from the initial launch of the platform through the present day. Readers can use this resource to track Red Hat’s advisory history, understand the prevalence and impact of specific weakness classes within this product line, and examine the vulnerability history of individual packages and services. The data provides a structured overview of how security risks have been identified, categorized, and mitigated over time. This helps administrators assess the current risk posture, compare historical trends, and prioritize remediation efforts based on the severity and exploitability of the listed weaknesses. By centralizing this information, the page supports informed decision-making for system hardening, compliance auditing, and long-term security planning without requiring manual aggregation of disparate vendor bulletins. The scope remains strictly limited to technical vulnerabilities documented by Red Hat for this product version.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-76235 Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie in send_login_html CWE-401 7.5 High2026-08-19
CVE-2026-75900 Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs sizeof(struct) mismatch CWE-125 6.1 Medium2026-08-19
CVE-2026-75032 Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder CWE-125 6.3 Medium2026-08-18
CVE-2026-13002 Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing CWE-835 4.4 Medium2026-08-14
CVE-2026-58224 Samba: ctdb fails to do integrity checking of received packets CWE-353 6.5 Medium2026-08-14
CVE-2026-19617 Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser CWE-770 5.5 Medium2026-08-14
CVE-2026-73584 Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling CWE-377 6.3 Medium2026-08-13
CVE-2026-73583 Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr CWE-125 6.6 Medium2026-08-13
CVE-2026-73585 Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack CWE-377 6.3 Medium2026-08-13
CVE-2026-18728 Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing CWE-191 6.5 Medium2026-08-13
CVE-2026-18727 Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing CWE-191 6.5 Medium2026-08-12
CVE-2026-18726 Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing CWE-835 6.5 Medium2026-08-12
CVE-2026-19654 Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd CWE-125 7.5 High2026-08-12
CVE-2026-19548 Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing CWE-416 5.5 Medium2026-08-12
CVE-2026-19550 Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes CWE-863 4.3 Medium2026-08-11
CVE-2026-19546 Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via caller-influenced profile attribute CWE-94 8.8 High2026-08-11
CVE-2026-71218 Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated remote memory exhaustion CWE-789 5.3 Medium2026-08-11
CVE-2026-71217 Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabling remote denial of service via resource exhaustion CWE-20 7.5 High2026-08-11
CVE-2026-72694 Mrtg: mrtg daemon symlink-following chown allows local privilege escalation via pid file path manipulation CWE-59 7.1 High2026-08-11
CVE-2026-6426 Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access CWE-681 4.4 Medium2026-08-10
CVE-2026-63622 Libvirt: swtpm privilege escalation via symlink following CWE-59 7.8 High2026-08-10
CVE-2026-63623 Libvirt: information disclosure via world-readable storage volume images during clone/convert CWE-732 5.5 Medium2026-08-10
CVE-2026-19389 Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read CWE-190 7.1 High2026-08-10
CVE-2026-19387 Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec ima/dvi adpcm decoder CWE-787 7.6 High2026-08-10
CVE-2026-61477 Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection CWE-93 2.3 Low2026-08-07
CVE-2026-15816 Dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() CWE-78 7.5 High2026-08-07
CVE-2026-18938 P11-kit: integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems CWE-122 6.2 Medium2026-08-07
CVE-2026-7867 Udisks2: udisks2: local privilege escalation via as-user option spoofing CWE-863 7.8 High2026-08-06
CVE-2026-18649 Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders CWE-770 7.5 High2026-08-06
CVE-2026-68743 Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1 CWE-125 5.5 Medium2026-08-04

All 232 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.