Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 232

All 232 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with Red Hat Enterprise Linux 10. It aggregates security issues ranging from buffer overflows and injection flaws to permission misconfigurations and logic errors that affect this specific enterprise operating system release. The content compiles known flaws identified in Red Hat Enterprise Linux 10 components, covering security advisories and patch releases issued from the initial launch of the platform through the present day. Readers can use this resource to track Red Hat’s advisory history, understand the prevalence and impact of specific weakness classes within this product line, and examine the vulnerability history of individual packages and services. The data provides a structured overview of how security risks have been identified, categorized, and mitigated over time. This helps administrators assess the current risk posture, compare historical trends, and prioritize remediation efforts based on the severity and exploitability of the listed weaknesses. By centralizing this information, the page supports informed decision-making for system hardening, compliance auditing, and long-term security planning without requiring manual aggregation of disparate vendor bulletins. The scope remains strictly limited to technical vulnerabilities documented by Red Hat for this product version.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-5201 Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image CWE-122 7.5 High2026-03-31
CVE-2026-5165 Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset CWE-825 6.7 Medium2026-03-30
CVE-2026-5164 Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request CWE-120 6.7 Medium2026-03-30
CVE-2026-5119 Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment CWE-319 5.9 Medium2026-03-30
CVE-2026-4948 Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization CWE-279 5.5 Medium2026-03-27
CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling CWE-73 5.5 -2026-03-26
CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing CWE-1333 7.5 -2026-03-26
CVE-2026-0968 Libssh: libssh: denial of service due to malformed sftp message CWE-476 3.1 Low2026-03-26
CVE-2026-0964 Libssh: improper sanitation of paths received from scp servers CWE-22 8.8 -2026-03-26
CVE-2026-0966 Libssh: libssh: denial of service via zero-length input in ssh_get_hexa() CWE-124 7.5AIHighAI2026-03-26
CVE-2026-2436 Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake CWE-825 6.5 Medium2026-03-26
CVE-2026-4897 Polkit: polkit: denial of service via unbounded input processing through standard input CWE-770 5.5 Medium2026-03-26
CVE-2026-4775 Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing CWE-190 7.8 High2026-03-24
CVE-2026-1940 Gstreamer: incomplete fix of cve-2026-1940 5.1 Medium2026-03-23
CVE-2026-2369 Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources CWE-191 6.5 Medium2026-03-19
CVE-2026-4424 Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing CWE-125 7.5 High2026-03-19
CVE-2026-4271 Libsoup: libsoup: denial of service via use-after-free in http/2 server CWE-416 5.3 Medium2026-03-17
CVE-2026-3632 Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames CWE-1286 3.9 Low2026-03-17
CVE-2026-3634 Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header CWE-93 3.9 Low2026-03-17
CVE-2026-3633 Libsoup: libsoup: header and http request injection via crlf injection CWE-93 3.9 Low2026-03-17
CVE-2026-4111 Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive CWE-835 7.5 High2026-03-13
CVE-2026-3099 Libsoup: libsoup: authentication bypass via digest authentication replay attack CWE-323 5.8 Medium2026-03-12
CVE-2026-3234 Mod_proxy_cluster: mod_proxy_cluster: response body corruption via crlf injection CWE-93 4.3 Medium2026-03-12
CVE-2025-12801 Nfs-utils: rpc.mountd in the nfs-utils privilege escalation CWE-279 6.5 Medium2026-03-04
CVE-2026-28295 Gvfs: gvfs ftp backend: information disclosure via untrusted pasv responses CWE-918 4.3 Medium2026-02-26
CVE-2026-28296 Gvfs: ftp gvfs backend: arbitrary ftp command injection via crlf sequences in file paths CWE-93 4.3 Medium2026-02-26
CVE-2026-26104 Udisks: missing authorization check allows unprivileged users to back up luks headers via udisks d-bus api CWE-862 5.5 Medium2026-02-25
CVE-2026-26103 Udisks: missing authorization check allows unprivileged users to restore luks headers via udisks d-bus api CWE-862 7.1 High2026-02-25
CVE-2026-2443 Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure CWE-125 5.3 Medium2026-02-13
CVE-2026-1709 Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication CWE-322 9.4 Critical2026-02-06

All 232 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.