Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

RED HAT — Vulnerabilities & Security Advisories 676

Browse all 676 CVE security advisories affecting RED HAT. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2026-35093 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins — Red Hat Enterprise Linux 10CWE-94 8.8 High2026-04-01
CVE-2026-35092 Corosync: corosync: denial of service via integer overflow in join message validation — Red Hat Enterprise Linux 10CWE-190 7.5 High2026-04-01
CVE-2026-35091 Corosync: corosync: denial of service and information disclosure via crafted udp packet — Red Hat Enterprise Linux 10CWE-253 8.2 High2026-04-01
CVE-2026-5201 Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image — Red Hat Enterprise Linux 10CWE-122 7.5 High2026-03-31
CVE-2026-5165 Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset — Red Hat Enterprise Linux 10CWE-825 6.7 Medium2026-03-30
CVE-2026-5164 Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request — Red Hat Enterprise Linux 10CWE-120 6.7 Medium2026-03-30
CVE-2026-5121 Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing — Red Hat Enterprise Linux 7 Extended Lifecycle SupportCWE-190 7.5 High2026-03-30
CVE-2026-5119 Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment — Red Hat Enterprise Linux 10CWE-319 5.9 Medium2026-03-30
CVE-2026-28369 Undertow: undertow: request smuggling via malformed http request headers — Red Hat build of Apache Camel for Spring Boot 4CWE-444 8.7 High2026-03-27
CVE-2026-28367 Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator — Red Hat build of Apache Camel for Spring Boot 4CWE-444 8.7 High2026-03-27
CVE-2026-28368 Undertow: undertow: request smuggling via inconsistent header parsing — Red Hat build of Apache Camel for Spring Boot 4CWE-444 8.7 High2026-03-27
CVE-2026-4948 Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization — Red Hat Enterprise Linux 10CWE-279 5.5 Medium2026-03-27
CVE-2025-12805 Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy — Red Hat OpenShift AI 2.25CWE-653 8.1 High2026-03-26
CVE-2026-0965 Libssh: libssh: denial of service via improper configuration file handling — Red Hat Enterprise Linux 10CWE-73 5.5 -2026-03-26
CVE-2026-0967 Libssh: libssh: denial of service via inefficient regular expression processing — Red Hat Enterprise Linux 10CWE-1333 7.5 -2026-03-26
CVE-2026-0968 Libssh: libssh: denial of service due to malformed sftp message — Red Hat Enterprise Linux 10CWE-476 3.1 Low2026-03-26
CVE-2026-0964 Libssh: improper sanitation of paths received from scp servers — Red Hat Enterprise Linux 10CWE-22 8.8 -2026-03-26
CVE-2026-0966 Libssh: buffer underflow in ssh_get_hexa() on invalid input — Red Hat Hardened ImagesCWE-124 7.5AIHighAI2026-03-26
CVE-2026-2100 P11-kit: null dereference via c_derivekey with specific null parameters — Red Hat Hardened ImagesCWE-824 5.3 Medium2026-03-26
CVE-2026-2239 Gimp: gimp: application crash (dos) via crafted psd file due to heap-buffer-overflow — Red Hat Enterprise Linux 7CWE-170 2.8 Low2026-03-26
CVE-2026-2272 Gimp: gimp: memory corruption due to integer overflow in ico file handling — Red Hat Enterprise Linux 6CWE-190 4.3 Medium2026-03-26
CVE-2026-2271 Gimp: gimp: denial of service via crafted psp image file — Red Hat Enterprise Linux 6CWE-190 3.3 Low2026-03-26
CVE-2026-2436 Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake — Red Hat Enterprise Linux 10CWE-825 6.5 Medium2026-03-26
CVE-2026-3121 Keycloak: org.keycloak/keycloak-services: keycloak: privilege escalation via manage-clients permission — Red Hat build of Keycloak 26.4CWE-266 6.5 Medium2026-03-26
CVE-2026-3190 Keycloak: keycloak: information disclosure via improper role enforcement in uma 2.0 protection api — Red Hat build of Keycloak 26.4CWE-280 4.3 Medium2026-03-26
CVE-2026-4897 Polkit: polkit: denial of service via unbounded input processing through standard input — Red Hat Enterprise Linux 10CWE-770 5.5 Medium2026-03-26
CVE-2026-1961 Forman: foreman: remote code execution via command injection in websocket proxy — Red Hat Satellite 6.16 for RHEL 8CWE-78 8.0 High2026-03-26
CVE-2026-4887 Gimp: gimp:memory disclosure and denial of service via specially crafted pcx image — Red Hat Enterprise Linux 6CWE-193 6.1 Medium2026-03-26
CVE-2026-4874 Org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: keycloak: server-side request forgery via oidc token endpoint manipulation — Red Hat Build of KeycloakCWE-918 3.1 Low2026-03-26
CVE-2026-4775 Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing — Red Hat Enterprise Linux 10CWE-190 7.8 High2026-03-24

This page lists every published CVE security advisory associated with RED HAT. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.