Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 232

All 232 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with Red Hat Enterprise Linux 10. It aggregates security issues ranging from buffer overflows and injection flaws to permission misconfigurations and logic errors that affect this specific enterprise operating system release. The content compiles known flaws identified in Red Hat Enterprise Linux 10 components, covering security advisories and patch releases issued from the initial launch of the platform through the present day. Readers can use this resource to track Red Hat’s advisory history, understand the prevalence and impact of specific weakness classes within this product line, and examine the vulnerability history of individual packages and services. The data provides a structured overview of how security risks have been identified, categorized, and mitigated over time. This helps administrators assess the current risk posture, compare historical trends, and prioritize remediation efforts based on the severity and exploitability of the listed weaknesses. By centralizing this information, the page supports informed decision-making for system hardening, compliance auditing, and long-term security planning without requiring manual aggregation of disparate vendor bulletins. The scope remains strictly limited to technical vulnerabilities documented by Red Hat for this product version.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-68744 Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply CWE-908 3.3 Low2026-08-04
CVE-2026-68742 Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr CWE-125 5.5 Medium2026-08-03
CVE-2026-68563 Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure of postgresql data via insecure backup permissions CWE-732 5.5 Medium2026-07-30
CVE-2026-68562 Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering CWE-610 6.2 Medium2026-07-30
CVE-2026-58216 Samba: kpasswd service: kpasswd packet that contains malformed asn.1 might cause the server to access 6 bytes of unallocated memory leading server to crash CWE-125 5.3 Medium2026-07-30
CVE-2026-58222 Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes CWE-90 8.8 High2026-07-30
CVE-2026-58218 Samba: dns signing dos via tkey name cache exhaustion CWE-410 5.3 Medium2026-07-30
CVE-2026-16531 Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet CWE-22 5.3 Medium2026-07-30
CVE-2026-16530 Pcp: pcp: remote denial of service and information leakage CWE-125 6.5 Medium2026-07-30
CVE-2026-16529 Pcp: pcp: denial of service due to signed integer overflow CWE-190 7.5 High2026-07-30
CVE-2026-16527 Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access rules CWE-306 7.3 High2026-07-30
CVE-2026-16526 Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability CWE-403 8.8 High2026-07-30
CVE-2026-16524 Pcp: pcp linux_sockets pmda: arbitrary command execution via command injection CWE-78 7.8 High2026-07-30
CVE-2026-18220 Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processing CWE-787 7.8 High2026-07-29
CVE-2026-18107 Criu: criu: container escape via rseq critical section hijack during checkpoint/restore CWE-269 7.8 High2026-07-28
CVE-2026-16313 Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export CWE-93 7.6 High2026-07-28
CVE-2026-17072 Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_flac_stream_headers when parsing flac codec data in matroska containers CWE-125 3.3 Low2026-07-28
CVE-2026-66338 Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked() CWE-444 5.4 Medium2026-07-24
CVE-2026-66337 Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until() CWE-125 6.5 Medium2026-07-24
CVE-2026-66339 Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels CWE-201 6.5 Medium2026-07-24
CVE-2026-16743 Accountsservice: accountsservice: arbitrary file read via seticonfile for systemd-homed users CWE-269 5.5 Medium2026-07-24
CVE-2026-16730 Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup CWE-755 5.5 Medium2026-07-24
CVE-2026-64611 Libcupsfilters: cups-filters: libcupsfilters: cpu exhaustion via infinite loop in cfieee1284normalizemakemodel() CWE-835 7.5 High2026-07-23
CVE-2026-6390 Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling. CWE-134 6.8 Medium2026-07-23
CVE-2026-16473 Sbc: sbc: heap out-of-bounds read via crafted sbc audio frame CWE-125 4.3 Medium2026-07-22
CVE-2026-12548 Libsoup: heap out-of-bounds read in libsoup due to integer truncation CWE-125 4.2 Medium2026-07-21
CVE-2026-12547 Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch CWE-201 3.4 Low2026-07-21
CVE-2026-59851 Libssh: libssh: authentication bypass via missing gssapi principal check CWE-863 8.8 High2026-07-21
CVE-2026-59850 Libssh: libssh: use-after-free via data callbacks on closed channels CWE-416 4.3 Medium2026-07-21
CVE-2026-59849 Libssh: libssh: denial of service via automatic certificate authentication loop CWE-835 3.1 Low2026-07-21

All 232 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.