Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 361

All 361 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Red Hat Enterprise Linux 10. It collects security advisories published by Red Hat covering this specific product version, spanning its entire support lifecycle. Readers can track the vendor's security responses, analyze specific weakness classes such as buffer overflows or privilege escalation, and review the product's complete vulnerability history.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-93653 Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill via unvalidated tiling-pattern repeat count (denial of service) CWE-606 5.5 Medium 2026-09-18
CVE-2026-81627 Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram CWE-787 8.2 High 2026-09-18
CVE-2026-86320 Flatpak-builder: host code execution via `git am` hook execution in patch source extraction (`use-git-am`) CWE-94 7.8 High 2026-09-17
CVE-2026-91786 Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size CWE-125 6.1 Medium 2026-09-15
CVE-2026-90996 Sssd: sssd: denial of service in nss responder via crafted zero-length requests CWE-191 4.0 Medium 2026-09-14
CVE-2026-90995 Sssd: sssd: local denial of service due to null pointer dereference in pam responder CWE-476 5.5 Medium 2026-09-14
CVE-2026-90994 Sssd: sssd: denial of service via malformed pam v1 requests CWE-125 4.0 Medium 2026-09-14
CVE-2026-90463 Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`) CWE-125 4.0 Medium 2026-09-14
CVE-2026-89329 Device-mapper-multipath: local denial of service via blocking ipc send operations CWE-1322 6.2 Medium 2026-09-11
CVE-2026-77159 Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file ownership change via symlink CWE-61 5.5 Medium 2026-09-11
CVE-2026-88914 Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser CWE-190 4.4 Medium 2026-09-11
CVE-2026-84828 Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token CWE-732 6.5 Medium 2026-09-10
CVE-2026-84042 Crun: crun: rootful krun with passt executes container payload as host root CWE-269 7.8 High 2026-09-10
CVE-2026-18147 Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url CWE-79 8.1 High 2026-09-09
CVE-2026-87853 Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation CWE-187 7.5 High 2026-09-09
CVE-2026-87766 Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup CWE-59 8.8 High 2026-09-09
CVE-2026-18090 Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block CWE-125 6.1 Medium 2026-09-08
CVE-2026-74860 Libxml2: double-free/uaf in libxml2 python bindings CWE-763 8.5 High 2026-09-08
CVE-2026-76561 Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint) CWE-78 7.2 High 2026-09-08
CVE-2026-86469 Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path CWE-59 5.3 Medium 2026-09-07
CVE-2026-79678 Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service CWE-95 8.1 High 2026-09-07
CVE-2026-76578 Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci CWE-306 9.8 Critical 2026-09-07
CVE-2026-76925 Flatpak: flatpak: toctou race condition allows symlink redirection CWE-367 5.8 Medium 2026-09-04
CVE-2026-85769 Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize CWE-125 6.5 Medium 2026-09-04
CVE-2026-85534 Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read CWE-617 5.9 Medium 2026-09-04
CVE-2026-81666 Corosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems CWE-190 6.5 Medium 2026-09-04
CVE-2026-81665 Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly CWE-122 7.5 High 2026-09-04
CVE-2026-85197 Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload CWE-416 7.6 High 2026-09-04
CVE-2026-85150 Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted digest authorization/www-authenticate header CWE-476 7.5 High 2026-09-03
CVE-2026-84838 Rpm: command injection in rpmuncompress via unescaped filenames passed to popen() CWE-78 7.8 High 2026-09-02

All 361 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.