Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Hardened Images — Vulnerabilities & Security Advisories 35

All 35 CVE vulnerabilities found in Red Hat Hardened Images, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities affecting the Red Hat Hardened Images product line. It aggregates known security weaknesses and configuration flaws identified within these specialized, security-focused container images designed to meet stringent compliance and hardening requirements. The content here collects detailed information on various vulnerability types, including privilege escalation risks, improper access controls, and insecure default configurations that may exist within the hardened image builds. The data covers historical records and recent findings, providing a comprehensive view of the security landscape for this product. This time range allows users to assess long-term trends and immediate risks associated with different versions of the hardened images. By reviewing this aggregation, users can track vendor advisories issued by Red Hat regarding these specific image builds. They can gain a deeper understanding of particular weakness classes and how they manifest in hardened environments. Additionally, users can look up a product's vulnerability history to inform their risk assessments and patch management strategies. This resource serves as a centralized reference for security professionals evaluating the integrity and safety of Red Hat Hardened Images in production deployments.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-72693 Kbd: local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login CWE-284 7.8 High2026-08-11
CVE-2026-19079 Policycoreutils: policycoreutils: toctou race condition in fixfiles allows arbitrary selinux label manipulation CWE-367 4.4 Medium2026-08-07
CVE-2026-44605 Rpm: heap buffer overflow in ndb slot table parsing CWE-190 5.5 Medium2026-08-05
CVE-2026-18477 Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape CWE-367 4.4 Medium2026-08-03
CVE-2026-18508 Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite CWE-59 4.4 Medium2026-08-03
CVE-2026-15003 Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of service CWE-125 5.6 Medium2026-07-27
CVE-2026-16517 Libarchive: libarchive: signed integer overflow in archive_write_zip_header CWE-190 2.9 Low2026-07-21
CVE-2026-59849 Libssh: libssh: denial of service via automatic certificate authentication loop CWE-835 3.1 Low2026-07-21
CVE-2026-59846 Libssh: libssh: information disclosure via proxycommand %r username expansion CWE-78 3.9 Low2026-07-21
CVE-2026-59842 Libssh: libssh: information disclosure via short gssapi curve25519 public key CWE-125 3.7 Low2026-07-21
CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header CWE-805 3.9 Low2026-07-10
CVE-2026-13595 Util-linux: util-linux: heap use-after-free in libblkid nested partition probing CWE-416 6.8 Medium2026-06-29
CVE-2026-4367 Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing CWE-125 5.5 Medium2026-06-16
CVE-2026-11850 Krb5: krb5: integer underflow in berval2tl_data() leads to heap out-of-bounds read CWE-191 5.0 Medium2026-06-11
CVE-2026-44604 Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level directory name in popen() shell command CWE-78 7.0 High2026-05-28
CVE-2026-6732 Libxml2: libxml2: denial of service via crafted xsd-validated document CWE-843 6.5 Medium2026-04-23
CVE-2026-6846 Binutils: binutils: arbitrary code execution via malformed xcoff object file processing CWE-122 7.8 High2026-04-22
CVE-2026-6845 Binutils: binutils: denial of service via crafted elf file CWE-476 5.0 Medium2026-04-22
CVE-2026-1584 Gnutls: gnutls: remote denial of service via crafted clienthello with invalid psk binder CWE-476 7.5 High2026-04-09
CVE-2025-14821 Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows CWE-427 7.8 High2026-04-07
CVE-2026-5745 Libarchive: a null pointer dereference vulnerability exists in the acl parser of libarchive CWE-476 5.5 Medium2026-04-07
CVE-2026-3184 Util-linux: util-linux: access control bypass due to improper hostname canonicalization CWE-289 3.7 Low2026-04-03
CVE-2026-2625 Rust-rpm-sequoia: rust-rpm-sequoia: denial of service via crafted rpm file during signature verification CWE-347 4.0 Medium2026-04-03
CVE-2026-4647 Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library CWE-125 6.1 Medium2026-03-23
CVE-2026-4426 Libarchive: libarchive: denial of service via malformed iso file processing CWE-1335 6.5 Medium2026-03-19
CVE-2026-3441 Binutils: gnu binutils: information disclosure via specially crafted xcoff object file CWE-125 6.1 Medium2026-03-15
CVE-2026-3442 Binutils: gnu binutils: information disclosure or denial of service via out-of-bounds read in bfd linker CWE-125 6.1 Medium2026-03-15
CVE-2026-4105 Systemd: systemd: privilege escalation via improper access control in registermachine d-bus method CWE-284 6.7 Medium2026-03-13
CVE-2026-26158 Busybox: busybox: arbitrary file modification and privilege escalation via unvalidated tar archive entries CWE-73 7.0 High2026-02-11
CVE-2026-26157 Busybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitization CWE-73 7.0 High2026-02-11

All 35 known CVE vulnerabilities affecting Red Hat Hardened Images with full Chinese analysis, references, and POCs where available.