Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 230

All 230 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with Red Hat Enterprise Linux 10. It aggregates security issues ranging from buffer overflows and injection flaws to permission misconfigurations and logic errors that affect this specific enterprise operating system release. The content compiles known flaws identified in Red Hat Enterprise Linux 10 components, covering security advisories and patch releases issued from the initial launch of the platform through the present day. Readers can use this resource to track Red Hat’s advisory history, understand the prevalence and impact of specific weakness classes within this product line, and examine the vulnerability history of individual packages and services. The data provides a structured overview of how security risks have been identified, categorized, and mitigated over time. This helps administrators assess the current risk posture, compare historical trends, and prioritize remediation efforts based on the severity and exploitability of the listed weaknesses. By centralizing this information, the page supports informed decision-making for system hardening, compliance auditing, and long-term security planning without requiring manual aggregation of disparate vendor bulletins. The scope remains strictly limited to technical vulnerabilities documented by Red Hat for this product version.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-15709 Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service CWE-409 7.5 High 2026-07-14
CVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption CWE-125 5.9 Medium 2026-07-14
CVE-2026-12478 Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path) CWE-125 4.8 Medium 2026-07-14
CVE-2026-59692 Gstreamer: gstreamer: dtls certificate subject dn stack buffer overflow in openssl_verify_callback CWE-121 7.5 High 2026-07-09
CVE-2026-59691 Gstreamer: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16bpp framebuffer CWE-787 7.1 High 2026-07-09
CVE-2026-14935 Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check CWE-670 3.7 Low 2026-07-07
CVE-2026-14476 Sssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows kerberos authentication bypass CWE-23 8.0 High 2026-07-07
CVE-2026-14474 Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalation CWE-1188 8.8 High 2026-07-07
CVE-2026-14612 Freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorization CWE-787 4.2 Medium 2026-07-03
CVE-2026-14330 Pipewire: pulse server alloca stack overflow CWE-770 5.5 Medium 2026-07-01
CVE-2026-14324 Pipewire: raop rtsp null deref CWE-476 6.5 Medium 2026-07-01
CVE-2026-14258 Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling CWE-835 6.5 Medium 2026-07-01
CVE-2026-12610 Sssd: use-after-free crash in sssd' 'sssd_pam' process CWE-825 6.4 Medium 2026-06-30
CVE-2026-14164 Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack() CWE-415 7.5 High 2026-06-30
CVE-2026-13757 P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing CWE-674 6.2 Medium 2026-06-29
CVE-2026-12912 Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image CWE-122 7.3 High 2026-06-29
CVE-2026-57966 Spice-vdagent: path traversal in file transfer via unsanitized filename CWE-22 4.4 Medium 2026-06-29
CVE-2026-57965 Spice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow CWE-190 5.1 Medium 2026-06-29
CVE-2026-12892 Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parser CWE-125 4.4 Medium 2026-06-23
CVE-2026-12891 Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser CWE-125 4.3 Medium 2026-06-23
CVE-2026-11820 Community.general: community.general nexmo — api credentials exposed in get url query string[security] community.general nexmo — api credentials exposed in get url query string CWE-532 6.5 Medium 2026-06-23
CVE-2026-11819 Community.general: community.general keyring_info — os keyring passphrase returned in plaintext CWE-532 5.5 Medium 2026-06-23
CVE-2026-12969 Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation CWE-125 5.3 Medium 2026-06-23
CVE-2026-55654 Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination CWE-125 3.7 Low 2026-06-23
CVE-2026-55655 Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions CWE-923 5.0 Medium 2026-06-23
CVE-2026-55653 Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service CWE-415 4.3 Medium 2026-06-23
CVE-2026-12549 Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver CWE-805 4.8 Medium 2026-06-22
CVE-2026-12725 Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies CWE-122 5.9 Medium 2026-06-22
CVE-2026-12505 Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall CWE-250 7.8 High 2026-06-18
CVE-2026-10649 Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression CWE-190 8.6 High 2026-06-16

All 230 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.