Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 361

All 361 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Red Hat Enterprise Linux 10. It collects security advisories published by Red Hat covering this specific product version, spanning its entire support lifecycle. Readers can track the vendor's security responses, analyze specific weakness classes such as buffer overflows or privilege escalation, and review the product's complete vulnerability history.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-104038 Sssd: sssd: denial of service via missing sid extension in certificate mapping CWE-476 5.9 Medium 2026-10-06
CVE-2026-104037 Sssd: sssd: denial of service via packet length underflow in autofs responder CWE-125 5.5 Medium 2026-10-06
CVE-2026-92821 Sssd: sssd: access control bypass via premature ldap access rule evaluation CWE-393 6.8 Medium 2026-10-06
CVE-2026-104036 Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin CWE-787 5.8 Medium 2026-10-06
CVE-2026-104035 Sssd: sssd: denial of service via memory exhaustion in kcm responder CWE-772 5.5 Medium 2026-10-06
CVE-2026-104034 Sssd: sssd: denial of service via use-after-free in kcm ticket renewal CWE-825 4.7 Medium 2026-10-06
CVE-2026-104033 Sssd: sssd: access control bypass via improper ldap shadow expiration check CWE-193 5.4 Medium 2026-10-06
CVE-2026-104032 Sssd: sssd: denial of service via unprivileged autofs cache invalidation CWE-408 5.5 Medium 2026-10-06
CVE-2026-104031 Sssd: sssd: denial of service via memory exhaustion in autofs responder CWE-772 5.5 Medium 2026-10-06
CVE-2026-104029 Sssd: sssd: denial of service via out-of-bounds read in autofs responder CWE-125 3.3 Low 2026-10-05
CVE-2026-104030 Sssd: sssd: denial of service via out-of-bounds read during passkey parsing CWE-125 5.5 Medium 2026-10-05
CVE-2026-103641 Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder CWE-125 5.5 Medium 2026-10-01
CVE-2026-103399 Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body CWE-444 5.3 Medium 2026-09-30
CVE-2026-103242 Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag CWE-122 7.1 High 2026-09-30
CVE-2026-102560 Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth CWE-125 8.6 High 2026-09-29
CVE-2026-102559 Libsoup: libsoup: heap buffer overflow during websocket client-frame masking CWE-125 8.6 High 2026-09-29
CVE-2026-102558 Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth CWE-125 8.6 High 2026-09-29
CVE-2026-102555 Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding CWE-125 8.2 High 2026-09-29
CVE-2026-102557 Libsoup: libsoup: heap buffer overflow during websocket message reassembly CWE-125 8.6 High 2026-09-29
CVE-2026-102556 Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion CWE-843 8.6 High 2026-09-29
CVE-2026-95520 Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages CWE-787 7.1 High 2026-09-29
CVE-2026-97029 Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group CWE-653 5.7 Medium 2026-09-29
CVE-2026-97024 Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc CWE-61 7.1 High 2026-09-29
CVE-2026-97027 Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus service files CWE-20 3.6 Low 2026-09-28
CVE-2026-97026 Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path CWE-378 3.9 Low 2026-09-28
CVE-2026-97025 Flatpak: flatpak: world-readable oci authentication token in system-helper cache path CWE-378 3.2 Low 2026-09-28
CVE-2026-97023 Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy directory export/bin CWE-61 7.1 High 2026-09-28
CVE-2026-96284 Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following CWE-59 2.5 Low 2026-09-27
CVE-2026-96282 Flatpak: flatpak: extension metadata path traversal file existence oracle CWE-59 3.1 Low 2026-09-27
CVE-2026-96283 Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pull CWE-862 3.3 Low 2026-09-27

All 361 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.