Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 230

All 230 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with Red Hat Enterprise Linux 10. It aggregates security issues ranging from buffer overflows and injection flaws to permission misconfigurations and logic errors that affect this specific enterprise operating system release. The content compiles known flaws identified in Red Hat Enterprise Linux 10 components, covering security advisories and patch releases issued from the initial launch of the platform through the present day. Readers can use this resource to track Red Hat’s advisory history, understand the prevalence and impact of specific weakness classes within this product line, and examine the vulnerability history of individual packages and services. The data provides a structured overview of how security risks have been identified, categorized, and mitigated over time. This helps administrators assess the current risk posture, compare historical trends, and prioritize remediation efforts based on the severity and exploitability of the listed weaknesses. By centralizing this information, the page supports informed decision-making for system hardening, compliance auditing, and long-term security planning without requiring manual aggregation of disparate vendor bulletins. The scope remains strictly limited to technical vulnerabilities documented by Red Hat for this product version.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-1933 Samba: missing access check on reparse point operations CWE-284 7.1 High 2026-05-27
CVE-2026-2340 Samba: vfs_worm does not block directory modification CWE-280 6.5 Medium 2026-05-27
CVE-2026-3012 Samba: group policy certificate enrollment uses http:// without validation CWE-345 8.0 High 2026-05-27
CVE-2026-48864 Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data CWE-787 7.8 High 2026-05-26
CVE-2026-4480 Samba: samba: remote code execution in printing subsystem via unescaped job description CWE-78 9.0 Critical 2026-05-26
CVE-2026-9149 Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file CWE-122 6.5 Medium 2026-05-20
CVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums CWE-121 6.5 Medium 2026-05-20
CVE-2026-4802 Cockpit: cockpit: arbitrary command execution via crafted links in system logs ui CWE-78 8.0 High 2026-05-11
CVE-2026-6420 Keylime: keylime: security bypass due to hardcoded tpm quote nonce CWE-1241 6.3 Medium 2026-05-06
CVE-2026-33846 Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly CWE-130 7.5 High 2026-05-04
CVE-2026-2708 Libsoup: libsoup: http request smuggling via duplicate content-length headers CWE-444 3.7 Low 2026-04-23
CVE-2026-34003 Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access CWE-125 7.8 High 2026-04-23
CVE-2026-34001 Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption CWE-825 7.8 High 2026-04-23
CVE-2026-33999 Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling CWE-191 7.8 High 2026-04-23
CVE-2026-6862 Efivar: efivar: denial of service due to stack overflow in device path node parsing CWE-674 5.5 Medium 2026-04-22
CVE-2026-6861 Emacs: emacs: memory corruption vulnerability when processing svg css CWE-193 6.1 Medium 2026-04-22
CVE-2026-6844 Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files CWE-400 5.5 Medium 2026-04-22
CVE-2026-6843 Nano: nano: format string vulnerability leads to denial of service CWE-134 5.5 Medium 2026-04-22
CVE-2026-6842 Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions CWE-732 2.5 Low 2026-04-22
CVE-2026-6507 Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing CWE-787 7.5 High 2026-04-17
CVE-2026-6245 Sssd: out-of-bounds read in the sssd CWE-805 5.5 Medium 2026-04-15
CVE-2026-4878 Libcap: libcap: privilege escalation via toctou race condition in cap_set_file() CWE-367 6.7 Medium 2026-04-09
CVE-2026-4631 Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection CWE-78 9.8 Critical 2026-04-07
CVE-2026-5704 Tar: tar: hidden file injection via crafted archives CWE-434 5.0 Medium 2026-04-06
CVE-2026-5673 Libtheora: libtheora: denial of service or information disclosure via malformed avi file processing CWE-125 5.6 Medium 2026-04-06
CVE-2026-35094 Libinput: libinput: information disclosure via dangling pointer in lua plugin handling CWE-825 3.3 Low 2026-04-01
CVE-2026-35093 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins CWE-94 8.8 High 2026-04-01
CVE-2026-35092 Corosync: corosync: denial of service via integer overflow in join message validation CWE-190 7.5 High 2026-04-01
CVE-2026-35091 Corosync: corosync: denial of service and information disclosure via crafted udp packet CWE-253 8.2 High 2026-04-01
CVE-2026-5201 Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image CWE-122 7.5 High 2026-03-31

All 230 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.