Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 227

All 227 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with Red Hat Enterprise Linux 10. It aggregates security issues ranging from buffer overflows and injection flaws to permission misconfigurations and logic errors that affect this specific enterprise operating system release. The content compiles known flaws identified in Red Hat Enterprise Linux 10 components, covering security advisories and patch releases issued from the initial launch of the platform through the present day. Readers can use this resource to track Red Hat’s advisory history, understand the prevalence and impact of specific weakness classes within this product line, and examine the vulnerability history of individual packages and services. The data provides a structured overview of how security risks have been identified, categorized, and mitigated over time. This helps administrators assess the current risk posture, compare historical trends, and prioritize remediation efforts based on the severity and exploitability of the listed weaknesses. By centralizing this information, the page supports informed decision-making for system hardening, compliance auditing, and long-term security planning without requiring manual aggregation of disparate vendor bulletins. The scope remains strictly limited to technical vulnerabilities documented by Red Hat for this product version.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-59844 Libssh: libssh: denial of service via oversized sftp read length CWE-789 6.5 Medium2026-07-21
CVE-2026-59845 Libssh: libssh: denial of service via unchecked proxycommand fork() failure CWE-390 5.3 Medium2026-07-21
CVE-2026-59843 Libssh: libssh: denial of service via zero advertised channel packet size CWE-835 6.5 Medium2026-07-21
CVE-2026-15370 Libssh: libssh: stack buffer overflow in sftp server longname construction CWE-121 6.7 Medium2026-07-21
CVE-2026-15811 Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes CWE-212 5.8 Medium2026-07-21
CVE-2026-15812 Kronosnet: kronosnet: access control list bypass via link id spoofing on unencrypted dynamic links CWE-290 4.8 Medium2026-07-21
CVE-2026-64612 Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malformed png CWE-248 7.5 High2026-07-20
CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() CWE-121 6.5 Medium2026-07-20
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys CWE-61 7.3 High2026-07-20
CVE-2026-15813 Kronosnet: kronosnet: memory corruption and out-of-bounds access via malformed network packet defragmentation CWE-787 6.5 Medium2026-07-20
CVE-2026-5674 Pipewire: pipewire: sandbox escape and arbitrary code execution via malicious library loading CWE-427 8.8 High2026-07-16
CVE-2026-15779 Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validation CWE-732 6.1 Medium2026-07-15
CVE-2026-15714 Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string CWE-125 6.5 Medium2026-07-14
CVE-2026-15713 Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak CWE-772 5.9 Medium2026-07-14
CVE-2026-15711 Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation CWE-770 7.5 High2026-07-14
CVE-2026-15709 Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service CWE-409 7.5 High2026-07-14
CVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption CWE-125 5.9 Medium2026-07-14
CVE-2026-12478 Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path) CWE-125 4.8 Medium2026-07-14
CVE-2026-59692 Gstreamer: gstreamer: dtls certificate subject dn stack buffer overflow in openssl_verify_callback CWE-121 7.5 High2026-07-09
CVE-2026-59691 Gstreamer: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16bpp framebuffer CWE-787 7.1 High2026-07-09
CVE-2026-14935 Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check CWE-670 3.7 Low2026-07-07
CVE-2026-14476 Sssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows kerberos authentication bypass CWE-23 8.0 High2026-07-07
CVE-2026-14474 Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalation CWE-1188 8.8 High2026-07-07
CVE-2026-14612 Freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorization CWE-787 4.2 Medium2026-07-03
CVE-2026-14544 Hplip: incomplete fix for cve-2026-8631 CWE-190 9.8 Critical2026-07-03
CVE-2026-14330 Pipewire: pulse server alloca stack overflow CWE-770 5.5 Medium2026-07-01
CVE-2026-14324 Pipewire: raop rtsp null deref CWE-476 6.5 Medium2026-07-01
CVE-2026-14258 Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling CWE-835 6.5 Medium2026-07-01
CVE-2026-12610 Sssd: use-after-free crash in sssd' 'sssd_pam' process CWE-825 6.4 Medium2026-06-30
CVE-2026-14164 Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack() CWE-415 7.5 High2026-06-30

All 227 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.