Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 234

All 234 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with Red Hat Enterprise Linux 10. It aggregates security issues ranging from buffer overflows and injection flaws to permission misconfigurations and logic errors that affect this specific enterprise operating system release. The content compiles known flaws identified in Red Hat Enterprise Linux 10 components, covering security advisories and patch releases issued from the initial launch of the platform through the present day. Readers can use this resource to track Red Hat’s advisory history, understand the prevalence and impact of specific weakness classes within this product line, and examine the vulnerability history of individual packages and services. The data provides a structured overview of how security risks have been identified, categorized, and mitigated over time. This helps administrators assess the current risk posture, compare historical trends, and prioritize remediation efforts based on the severity and exploitability of the listed weaknesses. By centralizing this information, the page supports informed decision-making for system hardening, compliance auditing, and long-term security planning without requiring manual aggregation of disparate vendor bulletins. The scope remains strictly limited to technical vulnerabilities documented by Red Hat for this product version.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-52720 Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfb CWE-122 8.8 High2026-06-15
CVE-2026-53703 Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer audio stream header parser CWE-125 7.1 High2026-06-15
CVE-2026-52721 Gstreamer1-plugins-bad-free: gstreamer: multiple out-of-bounds reads in pcapparse ipv4/tcp header parsing CWE-125 5.3 Medium2026-06-15
CVE-2026-53705 Gstreamer1-plugins-good: gstreamer: heap buffer overflow in wavpack decoder via integer overflow CWE-190 7.6 High2026-06-15
CVE-2026-52719 Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds read via jpeg segment length validation in va decoder CWE-125 7.1 High2026-06-15
CVE-2026-53702 Gstreamer1-plugins-bad-free: gstreamer: stack buffer overflow in h.265 buffering period sei parser CWE-787 6.5 Medium2026-06-11
CVE-2026-53701 Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps picture partition parser CWE-787 6.5 Medium2026-06-11
CVE-2026-6893 Dracut: dracut: root code execution via dhcp options command injection CWE-78 7.5 High2026-06-10
CVE-2026-11837 Ansible-collection-ansible-posix: ansible.posix authorized_key: local privilege escalation via symlink-following chown CWE-59 7.3 High2026-06-10
CVE-2026-3238 Samba: denial of service against ad dc wins server CWE-476 7.5 High2026-06-08
CVE-2026-50263 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow() CWE-416 5.5 Medium2026-06-05
CVE-2026-50262 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes CWE-125 5.5 Medium2026-06-05
CVE-2026-50264 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds heap write in dri2 drigetbuffers/drigetbufferswithformat CWE-787 7.8 High2026-06-05
CVE-2026-50261 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter() CWE-416 7.8 High2026-06-05
CVE-2026-50260 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter() CWE-416 7.8 High2026-06-05
CVE-2026-50259 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing CWE-121 7.8 High2026-06-05
CVE-2026-50258 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels CWE-121 7.8 High2026-06-05
CVE-2026-50256 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch CWE-121 7.8 High2026-06-05
CVE-2026-50257 Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence() CWE-416 7.8 High2026-06-05
CVE-2026-5419 Gnutls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal CWE-208 3.7 Low2026-06-01
CVE-2026-43958 Rrdtool: rrdtool: stack buffer overflow allows local code execution or denial of service CWE-121 7.8 High2026-06-01
CVE-2026-10118 Poppler: integer overflow in poppler splashoutputdev::tilingpatternfill leads to heap buffer overflow via unchecked dimension multiplication CWE-190 7.8 High2026-06-01
CVE-2026-6324 Libsoup: libsoup: http request smuggling via unsigned to signed conversion error CWE-444 4.8 Medium2026-05-29
CVE-2026-10028 Glib-networking: infinite loop in glib-networking gnutls backend allows remote denial of service via circular certificate chain CWE-835 4.3 Medium2026-05-28
CVE-2026-4408 Samba: remote code execution in samr CWE-78 9.0 Critical2026-05-28
CVE-2026-1933 Samba: missing access check on reparse point operations CWE-284 7.1 High2026-05-27
CVE-2026-2340 Samba: vfs_worm does not block directory modification CWE-280 6.5 Medium2026-05-27
CVE-2026-3012 Samba: group policy certificate enrollment uses http:// without validation CWE-345 8.0 High2026-05-27
CVE-2026-42015 Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling CWE-193 5.3 Medium2026-05-26
CVE-2026-42013 Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name CWE-295 8.2 High2026-05-26

All 234 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.