Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 233

All 233 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with Red Hat Enterprise Linux 10. It aggregates security issues ranging from buffer overflows and injection flaws to permission misconfigurations and logic errors that affect this specific enterprise operating system release. The content compiles known flaws identified in Red Hat Enterprise Linux 10 components, covering security advisories and patch releases issued from the initial launch of the platform through the present day. Readers can use this resource to track Red Hat’s advisory history, understand the prevalence and impact of specific weakness classes within this product line, and examine the vulnerability history of individual packages and services. The data provides a structured overview of how security risks have been identified, categorized, and mitigated over time. This helps administrators assess the current risk posture, compare historical trends, and prioritize remediation efforts based on the severity and exploitability of the listed weaknesses. By centralizing this information, the page supports informed decision-making for system hardening, compliance auditing, and long-term security planning without requiring manual aggregation of disparate vendor bulletins. The scope remains strictly limited to technical vulnerabilities documented by Red Hat for this product version.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-1709 Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication CWE-322 9.4 Critical2026-02-06
CVE-2026-1801 Libsoup: libsoup: http request smuggling via malformed chunk headers CWE-444 5.3 Medium2026-02-03
CVE-2026-1760 Libsoup: soupserver: denial of service via http request smuggling CWE-444 5.3 Medium2026-02-02
CVE-2026-1761 Libsoup: stack-based buffer overflow in libsoup multipart response parsingmultipart http response CWE-121 8.6 High2026-02-02
CVE-2026-1539 Libsoup: libsoup: credential leakage via http redirects CWE-201 5.8 Medium2026-01-28
CVE-2026-1536 Libsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition header CWE-93 5.8 Medium2026-01-28
CVE-2026-1489 Glib: glib: memory corruption via integer overflow in unicode case conversion CWE-787 5.4 Medium2026-01-27
CVE-2026-1485 Glib: glib: local denial of service via buffer underflow in content type parsing CWE-124 2.8 Low2026-01-27
CVE-2026-1484 Glib: integer overflow leading to buffer underflow and out-of-bounds write in glib g_base64_encode() CWE-787 4.2 Medium2026-01-27
CVE-2026-1467 Libsoup: libsoup: http header injection via specially crafted urls when an http proxy is configured CWE-93 5.8 Medium2026-01-27
CVE-2025-9820 Gnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() function CWE-121 4.0 Medium2026-01-26
CVE-2025-9615 Networkmanager: networkmanager file access CWE-281 8.1AIHighAI2026-01-26
CVE-2025-14242 Vsftpd: vsftpd: denial of service via integer overflow in ls command parameter parsing CWE-190 6.5 Medium2026-01-14
CVE-2026-0716 Libsoup: out-of-bounds read in libsoup websocket frame processing CWE-805 4.8 Medium2026-01-13
CVE-2026-0719 Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication CWE-121 8.6 High2026-01-08
CVE-2025-14523 Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins) CWE-444 8.2 High2025-12-11
CVE-2025-7493 Freeipa: idm: privilege escalation from host to domain admin in freeipa CWE-1220 9.1 Critical2025-09-30
CVE-2025-5962 Rhel-lightspeed: improper access control in lightspeed history management allows local privilege manipulation CWE-284 7.7 High2025-09-22
CVE-2025-9901 Libsoup: improper handling of http vary header in libsoup caching CWE-524 5.9 Medium2025-09-03
CVE-2025-7039 Glib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file() CWE-22 3.7 Low2025-09-03
CVE-2025-6052 Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring CWE-190 3.7 Low2025-06-13
CVE-2025-5024 Gnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdus CWE-400 7.4 High2025-05-22
CVE-2025-4035 Libsoup: cookie domain validation bypass via uppercase characters in libsoup CWE-178 4.3 Medium2025-04-29

All 233 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.