Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

RED HAT — Vulnerabilities & Security Advisories 676

Browse all 676 CVE security advisories affecting RED HAT. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2026-5265 Ovn: ovn: heap over-read in icmp error response generation - security issue — Fast Datapath for RHEL 7CWE-130 6.5 Medium2026-04-24
CVE-2026-5367 Ovn: ovn: information disclosure via crafted dhcpv6 packets — Fast Datapath for RHEL 7CWE-130 8.6 High2026-04-24
CVE-2026-6732 Libxml2: libxml2: denial of service via crafted xsd-validated document — Red Hat Enterprise Linux 10CWE-843 6.5 Medium2026-04-23
CVE-2026-2708 Libsoup: libsoup: http request smuggling via duplicate content-length headers — Red Hat Enterprise Linux 10CWE-444 3.7 Low2026-04-23
CVE-2026-34003 Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access — Red Hat Enterprise Linux 10CWE-125 7.8 High2026-04-23
CVE-2026-34001 Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption — Red Hat Enterprise Linux 10CWE-825 7.8 High2026-04-23
CVE-2026-33999 Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling — Red Hat Enterprise Linux 10CWE-191 7.8 High2026-04-23
CVE-2025-66286 Webkitgtk: authorization bypass through webpage::send-request signal handler — Red Hat Enterprise Linux 6CWE-639 4.7 Medium2026-04-23
CVE-2026-6862 Efivar: efivar: denial of service due to stack overflow in device path node parsing — Red Hat Enterprise Linux 10CWE-674 5.5 Medium2026-04-22
CVE-2026-6861 Emacs: emacs: memory corruption vulnerability when processing svg css — Red Hat Enterprise Linux 10CWE-193 6.1 Medium2026-04-22
CVE-2026-6859 Instructlab: instructlab: arbitrary code execution due to hardcoded `trust_remote_code=true` — Red Hat Enterprise Linux AI (RHEL AI) 3CWE-829 8.8 High2026-04-22
CVE-2026-6857 Camel-infinispan: camel-infinispan: remote code execution via unsafe deserialization — Red Hat build of Apache Camel 4 for Quarkus 3CWE-502 7.5 High2026-04-22
CVE-2026-6855 Instructlab: instructlab: path traversal allows arbitrary directory creation and file write — Red Hat Enterprise Linux AI (RHEL AI) 3CWE-22 7.1 High2026-04-22
CVE-2026-6848 Quay: red hat quay: authentication bypass allows privileged actions without valid credentials — Red Hat Quay 3CWE-613 5.4 Medium2026-04-22
CVE-2026-6846 Binutils: binutils: arbitrary code execution via malformed xcoff object file processing — Red Hat Enterprise Linux 10CWE-122 7.8 High2026-04-22
CVE-2026-6844 Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files — Red Hat Enterprise Linux 10CWE-400 5.5 Medium2026-04-22
CVE-2026-6843 Nano: nano: format string vulnerability leads to denial of service — Red Hat Enterprise Linux 10CWE-134 5.5 Medium2026-04-22
CVE-2026-6845 Binutils: binutils: denial of service via crafted elf file — Red Hat Enterprise Linux 10CWE-476 5.0 Medium2026-04-22
CVE-2026-6842 Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions — Red Hat Enterprise Linux 10CWE-732 2.5 Low2026-04-22
CVE-2026-6507 Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing — Red Hat Enterprise Linux 10CWE-787 7.5 High2026-04-17
CVE-2026-6494 Aap-mcp-server: aap mcp server: log injection allows social engineering attacks via unsanitized input — Red Hat Ansible Automation Platform 2CWE-117 5.3 Medium2026-04-17
CVE-2026-6388 Argocd-image-updater: argocd image updater: cross-namespace privilege escalation via insufficient namespace validation — Red Hat OpenShift GitOpsCWE-1220 9.1 Critical2026-04-15
CVE-2026-6385 Ffmpeg: ffmpeg: denial of service and potential arbitrary code execution via signed integer overflow in dvd subtitle parser — Lightspeed CoreCWE-190 6.5 Medium2026-04-15
CVE-2026-6384 Gimp: gimp: arbitrary code execution or denial of service via buffer overflow in gif image processing — Red Hat Enterprise Linux 6CWE-120 7.3 High2026-04-15
CVE-2026-40919 Gimp: gimp: denial of service via specially crafted seattle filmworks file — Red Hat Enterprise Linux 6CWE-787 6.1 Medium2026-04-15
CVE-2026-40918 Gimp: gimp: denial of service via crafted pvr image file — Red Hat Enterprise Linux 6CWE-131 5.5 Medium2026-04-15
CVE-2026-40917 Gimp: gimp: application crashes or information disclosure via crafted icns image files — Red Hat Enterprise Linux 6CWE-125 5.0 Medium2026-04-15
CVE-2026-40916 Gimp: gimp: denial of service due to stack buffer overflow in tim image loader — Red Hat Enterprise Linux 6CWE-787 5.0 Medium2026-04-15
CVE-2026-40915 Gimp: gimp: heap buffer overflow due to integer overflow in fits image loader — Red Hat Enterprise Linux 6CWE-190 5.5 Medium2026-04-15
CVE-2026-6245 Sssd: out-of-bounds read in the sssd — Red Hat Enterprise Linux 10CWE-805 5.5 Medium2026-04-15

This page lists every published CVE security advisory associated with RED HAT. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.