Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 361

All 361 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Red Hat Enterprise Linux 10. It collects security advisories published by Red Hat covering this specific product version, spanning its entire support lifecycle. Readers can track the vendor's security responses, analyze specific weakness classes such as buffer overflows or privilege escalation, and review the product's complete vulnerability history.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-84837 Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path CWE-78 7.8 High 2026-09-02
CVE-2026-53683 Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html CWE-601 4.3 Medium 2026-09-02
CVE-2026-13732 Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf CWE-787 7.0 High 2026-08-31
CVE-2026-82327 Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist data CWE-129 5.5 Medium 2026-08-28
CVE-2026-81893 Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery CWE-787 4.7 Medium 2026-08-27
CVE-2026-78002 Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function CWE-131 7.5 High 2026-08-27
CVE-2026-80186 Bluez: stack overflow in name2utf8 causes dos and potential code execution CWE-120 7.6 High 2026-08-25
CVE-2026-80185 Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary code execution as root CWE-843 5.7 Medium 2026-08-25
CVE-2026-77680 Libsoup3: libsoup: quadratic cpu denial of service in http range coalescing after cve-2025-32907 fix CWE-407 5.3 Medium 2026-08-25
CVE-2026-79992 Emacs: emacs: command injection via crafted filenames in tramp CWE-78 7.8 High 2026-08-25
CVE-2026-79655 Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write CWE-59 7.8 High 2026-08-25
CVE-2026-78701 389-ds-base: 389-ds-base: cve-2026-11610 incomplete fix may introduce a connection-stall dos CWE-787 6.5 Medium 2026-08-25
CVE-2026-19685 Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615) CWE-863 7.1 High 2026-08-24
CVE-2026-78367 Rpm: rpmbuild gettarspec() crafted tar member name → macro injection CWE-94 7.0 High 2026-08-24
CVE-2026-73199 Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value CWE-476 6.5 Medium 2026-08-20
CVE-2026-11861 Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships CWE-266 9.6 Critical 2026-08-20
CVE-2026-73198 Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read CWE-770 7.5 High 2026-08-20
CVE-2026-13097 Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore CWE-706 8.7 High 2026-08-20
CVE-2026-73196 Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding CWE-770 4.3 Medium 2026-08-20
CVE-2026-73197 Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body read CWE-770 7.5 High 2026-08-20
CVE-2026-18917 Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow CWE-190 7.8 High 2026-08-20
CVE-2026-77014 Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of http range responses CWE-197 5.3 Medium 2026-08-20
CVE-2026-76235 Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie in send_login_html CWE-401 7.5 High 2026-08-19
CVE-2026-75900 Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs sizeof(struct) mismatch CWE-125 6.1 Medium 2026-08-19
CVE-2026-75032 Bluez: bluez: out-of-bounds read in avrcp parse_media_element and parse_media_folder CWE-125 6.3 Medium 2026-08-18
CVE-2026-13002 Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing CWE-835 4.4 Medium 2026-08-14
CVE-2026-58224 Samba: ctdb fails to do integrity checking of received packets CWE-353 6.5 Medium 2026-08-14
CVE-2026-19730 Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives CWE-459 4.2 Medium 2026-08-13
CVE-2026-73584 Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling CWE-377 6.3 Medium 2026-08-13
CVE-2026-73583 Sblim-sfcb: unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr CWE-125 6.6 Medium 2026-08-13

All 361 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.