Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 361

All 361 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Red Hat Enterprise Linux 10. It collects security advisories published by Red Hat covering this specific product version, spanning its entire support lifecycle. Readers can track the vendor's security responses, analyze specific weakness classes such as buffer overflows or privilege escalation, and review the product's complete vulnerability history.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-6843 Nano: nano: format string vulnerability leads to denial of service CWE-134 5.5 Medium 2026-04-22
CVE-2026-6245 Sssd: out-of-bounds read in the sssd CWE-805 5.5 Medium 2026-04-15
CVE-2026-4878 Libcap: libcap: privilege escalation via toctou race condition in cap_set_file() CWE-367 6.7 Medium 2026-04-09
CVE-2026-4631 Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection CWE-78 9.8 Critical 2026-04-07
CVE-2026-5704 Tar: tar: hidden file injection via crafted archives CWE-434 5.0 Medium 2026-04-06
CVE-2026-5673 Libtheora: libtheora: denial of service or information disclosure via malformed avi file processing CWE-125 5.6 Medium 2026-04-06
CVE-2026-35094 Libinput: libinput: information disclosure via dangling pointer in lua plugin handling CWE-825 3.3 Low 2026-04-01
CVE-2026-35093 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins CWE-94 8.8 High 2026-04-01
CVE-2026-35092 Corosync: corosync: denial of service via integer overflow in join message validation CWE-190 7.5 High 2026-04-01
CVE-2026-35091 Corosync: corosync: denial of service and information disclosure via crafted udp packet CWE-253 8.2 High 2026-04-01
CVE-2026-5201 Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image CWE-122 7.5 High 2026-03-31
CVE-2026-5165 Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset CWE-825 6.7 Medium 2026-03-30
CVE-2026-5164 Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request CWE-120 6.7 Medium 2026-03-30
CVE-2026-5119 Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment CWE-319 5.9 Medium 2026-03-30
CVE-2026-4948 Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization CWE-279 5.5 Medium 2026-03-27
CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling CWE-73 5.5 - 2026-03-26
CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing CWE-1333 7.5 - 2026-03-26
CVE-2026-0968 Libssh: libssh: denial of service due to malformed sftp message CWE-476 3.1 Low 2026-03-26
CVE-2026-0964 Libssh: improper sanitation of paths received from scp servers CWE-22 8.8 - 2026-03-26
CVE-2026-0966 Libssh: libssh: denial of service via zero-length input in ssh_get_hexa() CWE-124 7.5AI High AI 2026-03-26
CVE-2026-2436 Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake CWE-825 6.5 Medium 2026-03-26
CVE-2026-4897 Polkit: polkit: denial of service via unbounded input processing through standard input CWE-770 5.5 Medium 2026-03-26
CVE-2026-4775 Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing CWE-190 7.8 High 2026-03-24
CVE-2026-1940 Gstreamer: incomplete fix of cve-2026-1940 5.1 Medium 2026-03-23
CVE-2026-2369 Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources CWE-191 6.5 Medium 2026-03-19
CVE-2026-4424 Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing CWE-125 7.5 High 2026-03-19
CVE-2026-4271 Libsoup: libsoup: denial of service via use-after-free in http/2 server CWE-416 5.3 Medium 2026-03-17
CVE-2026-3632 Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames CWE-1286 3.9 Low 2026-03-17
CVE-2026-3634 Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header CWE-93 3.9 Low 2026-03-17
CVE-2026-3633 Libsoup: libsoup: header and http request injection via crlf injection CWE-93 3.9 Low 2026-03-17

All 361 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.