Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 361

All 361 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Red Hat Enterprise Linux 10. It collects security advisories published by Red Hat covering this specific product version, spanning its entire support lifecycle. Readers can track the vendor's security responses, analyze specific weakness classes such as buffer overflows or privilege escalation, and review the product's complete vulnerability history.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-4111 Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive CWE-835 7.5 High 2026-03-13
CVE-2026-3099 Libsoup: libsoup: authentication bypass via digest authentication replay attack CWE-323 5.8 Medium 2026-03-12
CVE-2026-3234 Mod_proxy_cluster: mod_proxy_cluster: response body corruption via crlf injection CWE-93 4.3 Medium 2026-03-12
CVE-2025-12801 Nfs-utils: rpc.mountd in the nfs-utils privilege escalation CWE-279 6.5 Medium 2026-03-04
CVE-2026-28295 Gvfs: gvfs ftp backend: information disclosure via untrusted pasv responses CWE-918 4.3 Medium 2026-02-26
CVE-2026-28296 Gvfs: ftp gvfs backend: arbitrary ftp command injection via crlf sequences in file paths CWE-93 4.3 Medium 2026-02-26
CVE-2026-26104 Udisks: missing authorization check allows unprivileged users to back up luks headers via udisks d-bus api CWE-862 5.5 Medium 2026-02-25
CVE-2026-26103 Udisks: missing authorization check allows unprivileged users to restore luks headers via udisks d-bus api CWE-862 7.1 High 2026-02-25
CVE-2026-2443 Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure CWE-125 5.3 Medium 2026-02-13
CVE-2026-1709 Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication CWE-322 9.4 Critical 2026-02-06
CVE-2026-1801 Libsoup: libsoup: http request smuggling via malformed chunk headers CWE-444 5.3 Medium 2026-02-03
CVE-2026-1760 Libsoup: soupserver: denial of service via http request smuggling CWE-444 5.3 Medium 2026-02-02
CVE-2026-1761 Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http response CWE-121 8.6 High 2026-02-02
CVE-2026-1539 Libsoup: libsoup: credential leakage via http redirects CWE-201 5.8 Medium 2026-01-28
CVE-2026-1536 Libsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition header CWE-93 5.8 Medium 2026-01-28
CVE-2026-1489 Glib: glib: memory corruption via integer overflow in unicode case conversion CWE-787 5.4 Medium 2026-01-27
CVE-2026-1485 Glib: glib: local denial of service via buffer underflow in content type parsing CWE-124 2.8 Low 2026-01-27
CVE-2026-1484 Glib: integer overflow leading to buffer underflow and out-of-bounds write in glib g_base64_encode() CWE-787 4.2 Medium 2026-01-27
CVE-2026-1467 Libsoup: libsoup: http header injection via specially crafted urls when an http proxy is configured CWE-93 5.8 Medium 2026-01-27
CVE-2025-9615 Networkmanager: networkmanager file access CWE-281 8.1AI High AI 2026-01-26
CVE-2025-14242 Vsftpd: vsftpd: denial of service via integer overflow in ls command parameter parsing CWE-190 6.5 Medium 2026-01-14
CVE-2026-0716 Libsoup: out-of-bounds read in libsoup websocket frame processing CWE-805 4.8 Medium 2026-01-13
CVE-2026-0719 Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication CWE-121 8.6 High 2026-01-08
CVE-2025-14523 Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins) CWE-444 8.2 High 2025-12-11
CVE-2025-7493 Freeipa: idm: privilege escalation from host to domain admin in freeipa CWE-1220 9.1 Critical 2025-09-30
CVE-2025-5962 Rhel-lightspeed: improper access control in lightspeed history management allows local privilege manipulation CWE-284 7.7 High 2025-09-22
CVE-2025-9901 Libsoup: improper handling of http vary header in libsoup caching CWE-524 5.9 Medium 2025-09-03
CVE-2025-7039 Glib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file() CWE-22 3.7 Low 2025-09-03
CVE-2025-6052 Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring CWE-190 3.7 Low 2025-06-13
CVE-2025-5024 Gnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdus CWE-400 7.4 High 2025-05-22

All 361 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.