Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 361

All 361 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Red Hat Enterprise Linux 10. It collects security advisories published by Red Hat covering this specific product version, spanning its entire support lifecycle. Readers can track the vendor's security responses, analyze specific weakness classes such as buffer overflows or privilege escalation, and review the product's complete vulnerability history.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-73585 Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack CWE-377 6.3 Medium 2026-08-13
CVE-2026-18728 Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing CWE-191 6.5 Medium 2026-08-13
CVE-2026-18727 Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing CWE-191 6.5 Medium 2026-08-12
CVE-2026-18726 Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing CWE-835 6.5 Medium 2026-08-12
CVE-2026-19654 Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd CWE-125 7.5 High 2026-08-12
CVE-2026-19548 Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing CWE-416 5.5 Medium 2026-08-12
CVE-2026-19550 Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes CWE-863 8.2 High 2026-08-11
CVE-2026-19546 Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via caller-influenced profile attribute CWE-94 8.8 High 2026-08-11
CVE-2026-71218 Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated remote memory exhaustion CWE-789 5.3 Medium 2026-08-11
CVE-2026-71217 Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabling remote denial of service via resource exhaustion CWE-20 7.5 High 2026-08-11
CVE-2026-72693 Kbd: local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login CWE-284 7.8 High 2026-08-11
CVE-2026-72694 Mrtg: mrtg daemon symlink-following chown allows local privilege escalation via pid file path manipulation CWE-59 7.1 High 2026-08-11
CVE-2026-6426 Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access CWE-681 4.4 Medium 2026-08-10
CVE-2026-63622 Libvirt: swtpm privilege escalation via symlink following CWE-59 7.8 High 2026-08-10
CVE-2026-63623 Libvirt: information disclosure via world-readable storage volume images during clone/convert CWE-732 5.5 Medium 2026-08-10
CVE-2026-19389 Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read CWE-190 7.1 High 2026-08-10
CVE-2026-19387 Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec ima/dvi adpcm decoder CWE-787 7.6 High 2026-08-10
CVE-2026-61477 Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection CWE-93 2.3 Low 2026-08-07
CVE-2026-15816 Dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() CWE-78 7.5 High 2026-08-07
CVE-2026-18938 P11-kit: integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems CWE-122 6.2 Medium 2026-08-07
CVE-2026-18649 Gstreamer1-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders CWE-770 7.5 High 2026-08-06
CVE-2026-68743 Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1 CWE-125 5.5 Medium 2026-08-04
CVE-2026-68744 Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply CWE-908 3.3 Low 2026-08-04
CVE-2026-18477 Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape CWE-367 4.4 Medium 2026-08-03
CVE-2026-18508 Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite CWE-59 4.4 Medium 2026-08-03
CVE-2026-68742 Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr CWE-125 5.5 Medium 2026-08-03
CVE-2026-68563 Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure of postgresql data via insecure backup permissions CWE-732 5.5 Medium 2026-07-30
CVE-2026-68562 Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering CWE-610 6.2 Medium 2026-07-30
CVE-2026-58216 Samba: kpasswd service: kpasswd packet that contains malformed asn.1 might cause the server to access 6 bytes of unallocated memory leading server to crash CWE-125 5.3 Medium 2026-07-30
CVE-2026-58222 Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes CWE-90 8.8 High 2026-07-30

All 361 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.