Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat Hardened Images — Vulnerabilities & Security Advisories 45

All 45 CVE vulnerabilities found in Red Hat Hardened Images, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data specifically for Red Hat Hardened Images, focusing on security weaknesses affecting this product line. The collection covers recent and historical security advisories, detailing various vulnerability classes such as buffer overflows, privilege escalation, and cryptographic flaws across the product's available lifecycle. Readers can use this section to track the vendor's security advisories, understand the characteristics of specific weakness types, and review the complete vulnerability history associated with Red Hat Hardened Images.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-102010 Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in binary heap erase_if CWE-825 7.0 High 2026-09-28
CVE-2026-88840 Busybox: busybox: tls ssl_server reads one byte out of bounds when parsing truncated clienthello CWE-125 5.3 Medium 2026-09-23
CVE-2026-88839 Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint CWE-787 6.7 Medium 2026-09-23
CVE-2026-88837 Busybox: busybox: httpd misidentifies yescrypt password hashes as plaintext, inverting authentication CWE-305 6.5 Medium 2026-09-23
CVE-2026-88835 Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb packages CWE-125 6.1 Medium 2026-09-23
CVE-2026-88831 Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix lengths CWE-636 5.3 Medium 2026-09-23
CVE-2026-88832 Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow CWE-787 7.3 High 2026-09-23
CVE-2026-88830 Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow CWE-131 7.5 High 2026-09-23
CVE-2026-96512 Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization CWE-863 7.8 High 2026-09-23
CVE-2026-95619 Gcc: libstdc++ integer overflow in `new` operator CWE-190 7.7 High 2026-09-22
CVE-2026-76781 Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute CWE-476 5.5 Medium 2026-09-17
CVE-2026-42784 Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion CWE-347 7.4 High 2026-09-16
CVE-2026-85013 Environment-modules: command injection in environment-modules bash completion via malicious module names containing shell metacharacters CWE-78 7.3 High 2026-09-15
CVE-2026-18495 Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough CWE-122 6.1 Medium 2026-09-11
CVE-2026-87876 Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up) CWE-178 3.0 Low 2026-09-09
CVE-2026-87875 Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound CWE-125 4.3 Medium 2026-09-09
CVE-2026-78409 Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks CWE-59 7.0 High 2026-09-02
CVE-2026-78408 Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority CWE-775 7.9 High 2026-09-02
CVE-2026-78410 Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection CWE-367 7.8 High 2026-09-02
CVE-2026-19079 Policycoreutils: policycoreutils: toctou race condition in fixfiles allows arbitrary selinux label manipulation CWE-367 4.4 Medium 2026-08-07
CVE-2026-44605 Rpm: heap buffer overflow in ndb slot table parsing CWE-190 5.5 Medium 2026-08-05
CVE-2026-15003 Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of service CWE-125 5.6 Medium 2026-07-27
CVE-2026-13595 Util-linux: util-linux: heap use-after-free in libblkid nested partition probing CWE-416 6.8 Medium 2026-06-29
CVE-2026-4367 Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing CWE-125 5.5 Medium 2026-06-16
CVE-2026-11850 Krb5: krb5: integer underflow in berval2tl_data() leads to heap out-of-bounds read CWE-191 5.0 Medium 2026-06-11
CVE-2026-44604 Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level directory name in popen() shell command CWE-78 7.0 High 2026-05-28
CVE-2026-6732 Libxml2: libxml2: denial of service via crafted xsd-validated document CWE-843 6.5 Medium 2026-04-23
CVE-2026-6862 Efivar: efivar: denial of service due to stack overflow in device path node parsing CWE-674 5.5 Medium 2026-04-22
CVE-2026-6845 Binutils: binutils: denial of service via crafted elf file CWE-476 5.0 Medium 2026-04-22
CVE-2025-14821 Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows CWE-427 7.8 High 2026-04-07

All 45 known CVE vulnerabilities affecting Red Hat Hardened Images with full Chinese analysis, references, and POCs where available.