Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 361

All 361 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Red Hat Enterprise Linux 10. It collects security advisories published by Red Hat covering this specific product version, spanning its entire support lifecycle. Readers can track the vendor's security responses, analyze specific weakness classes such as buffer overflows or privilege escalation, and review the product's complete vulnerability history.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-12912 Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image CWE-122 7.3 High 2026-06-29
CVE-2026-57966 Spice-vdagent: path traversal in file transfer via unsanitized filename CWE-22 4.4 Medium 2026-06-29
CVE-2026-57965 Spice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow CWE-190 5.1 Medium 2026-06-29
CVE-2026-12892 Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parser CWE-125 4.4 Medium 2026-06-23
CVE-2026-12891 Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser CWE-125 4.3 Medium 2026-06-23
CVE-2026-11820 Community.general: community.general nexmo — api credentials exposed in get url query string[security] community.general nexmo — api credentials exposed in get url query string CWE-532 6.5 Medium 2026-06-23
CVE-2026-11819 Community.general: community.general keyring_info — os keyring passphrase returned in plaintext CWE-532 5.5 Medium 2026-06-23
CVE-2026-12969 Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation CWE-125 5.3 Medium 2026-06-23
CVE-2026-55654 Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination CWE-125 3.7 Low 2026-06-23
CVE-2026-55655 Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions CWE-923 5.0 Medium 2026-06-23
CVE-2026-55653 Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service CWE-415 4.3 Medium 2026-06-23
CVE-2026-12549 Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver CWE-805 4.8 Medium 2026-06-22
CVE-2026-12725 Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies CWE-122 5.9 Medium 2026-06-22
CVE-2026-12505 Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall CWE-250 7.8 High 2026-06-18
CVE-2026-10649 Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression CWE-190 8.6 High 2026-06-16
CVE-2026-1767 Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leading to denial of service or information disclosure via malformed mp3 id3 tags CWE-805 5.6 Medium 2026-06-16
CVE-2026-1766 Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and information disclosure via malformed mp3 files. CWE-805 5.6 Medium 2026-06-16
CVE-2026-1765 Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and potential information disclosure via crafted mp3 files CWE-125 5.6 Medium 2026-06-16
CVE-2026-1764 Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leads to denial of service or information disclosure when parsing mp3 files CWE-125 5.6 Medium 2026-06-16
CVE-2026-52718 Gstreamer1-plugins-bad-free: gstreamer: denial of service via av1 tile_list_obu parser byte/bit confusion CWE-617 6.5 Medium 2026-06-15
CVE-2026-52722 Gstreamer1-plugins-bad-free: gstreamer: signed integer overflow in vmnc decoder cursor payload handling CWE-190 7.1 High 2026-06-15
CVE-2026-52720 Gstreamer1-plugins-bad-free: gstreamer: heap buffer overflow via crafted vnc server rectangle in librfb CWE-122 8.8 High 2026-06-15
CVE-2026-53703 Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer audio stream header parser CWE-125 7.1 High 2026-06-15
CVE-2026-53704 Gstreamer1-plugins-ugly-free: gstreamer: out-of-bounds read in realmedia demuxer fileinfo metadata parser CWE-125 7.1 High 2026-06-15
CVE-2026-52721 Gstreamer1-plugins-bad-free: gstreamer: multiple out-of-bounds reads in pcapparse ipv4/tcp header parsing CWE-125 5.3 Medium 2026-06-15
CVE-2026-53705 Gstreamer1-plugins-good: gstreamer: heap buffer overflow in wavpack decoder via integer overflow CWE-190 7.6 High 2026-06-15
CVE-2026-52719 Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds read via jpeg segment length validation in va decoder CWE-125 7.1 High 2026-06-15
CVE-2026-53702 Gstreamer1-plugins-bad-free: gstreamer: stack buffer overflow in h.265 buffering period sei parser CWE-787 6.5 Medium 2026-06-11
CVE-2026-53701 Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps picture partition parser CWE-787 6.5 Medium 2026-06-11
CVE-2026-6893 Dracut: dracut: root code execution via dhcp options command injection CWE-78 7.5 High 2026-06-10

All 361 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.