Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 242

All 242 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with Red Hat Enterprise Linux 10. It aggregates security issues ranging from buffer overflows and injection flaws to permission misconfigurations and logic errors that affect this specific enterprise operating system release. The content compiles known flaws identified in Red Hat Enterprise Linux 10 components, covering security advisories and patch releases issued from the initial launch of the platform through the present day. Readers can use this resource to track Red Hat’s advisory history, understand the prevalence and impact of specific weakness classes within this product line, and examine the vulnerability history of individual packages and services. The data provides a structured overview of how security risks have been identified, categorized, and mitigated over time. This helps administrators assess the current risk posture, compare historical trends, and prioritize remediation efforts based on the severity and exploitability of the listed weaknesses. By centralizing this information, the page supports informed decision-making for system hardening, compliance auditing, and long-term security planning without requiring manual aggregation of disparate vendor bulletins. The scope remains strictly limited to technical vulnerabilities documented by Red Hat for this product version.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-6324 Libsoup: libsoup: http request smuggling via unsigned to signed conversion error CWE-444 4.8 Medium2026-05-29
CVE-2026-10028 Glib-networking: infinite loop in glib-networking gnutls backend allows remote denial of service via circular certificate chain CWE-835 4.3 Medium2026-05-28
CVE-2026-4408 Samba: remote code execution in samr CWE-78 9.0 Critical2026-05-28
CVE-2026-1933 Samba: missing access check on reparse point operations CWE-284 7.1 High2026-05-27
CVE-2026-2340 Samba: vfs_worm does not block directory modification CWE-280 6.5 Medium2026-05-27
CVE-2026-3012 Samba: group policy certificate enrollment uses http:// without validation CWE-345 8.0 High2026-05-27
CVE-2026-42015 Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling CWE-193 5.3 Medium2026-05-26
CVE-2026-42013 Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name CWE-295 8.2 High2026-05-26
CVE-2026-42012 Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans CWE-295 7.1 High2026-05-26
CVE-2026-5260 Gnutls: gnutls: information disclosure via heap overread in rsa key exchange CWE-126 8.2 High2026-05-26
CVE-2026-48864 Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data CWE-787 7.8 High2026-05-26
CVE-2026-4480 Samba: samba: remote code execution in printing subsystem via unescaped job description CWE-78 9.0 Critical2026-05-26
CVE-2026-9149 Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file CWE-122 6.5 Medium2026-05-20
CVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums CWE-121 6.5 Medium2026-05-20
CVE-2026-42009 Gnutls: gnutls: denial of service via dtls packet reordering vulnerability CWE-475 7.5 High2026-05-18
CVE-2026-4802 Cockpit: cockpit: arbitrary command execution via crafted links in system logs ui CWE-78 8.0 High2026-05-11
CVE-2026-42011 Gnutls: gnutls: security bypass due to incorrect name constraint handling CWE-295 7.4 High2026-05-07
CVE-2026-42010 Gnutls: gnutls: authentication bypass via nul character in username CWE-170 7.1 High2026-05-07
CVE-2026-6420 Keylime: keylime: security bypass due to hardcoded tpm quote nonce CWE-1241 6.3 Medium2026-05-06
CVE-2026-33846 Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly CWE-130 7.5 High2026-05-04
CVE-2026-2708 Libsoup: libsoup: http request smuggling via duplicate content-length headers CWE-444 3.7 Low2026-04-23
CVE-2026-34003 Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access CWE-125 7.8 High2026-04-23
CVE-2026-34001 Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption CWE-825 7.8 High2026-04-23
CVE-2026-33999 Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling CWE-191 7.8 High2026-04-23
CVE-2026-6862 Efivar: efivar: denial of service due to stack overflow in device path node parsing CWE-674 5.5 Medium2026-04-22
CVE-2026-6861 Emacs: emacs: memory corruption vulnerability when processing svg css CWE-193 6.1 Medium2026-04-22
CVE-2026-6844 Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files CWE-400 5.5 Medium2026-04-22
CVE-2026-6843 Nano: nano: format string vulnerability leads to denial of service CWE-134 5.5 Medium2026-04-22
CVE-2026-6842 Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions CWE-732 2.5 Low2026-04-22
CVE-2026-6507 Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing CWE-787 7.5 High2026-04-17

All 242 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.