Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1440

Browse all 1440 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

Found 323 results / 1440 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-71218 Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated remote memory exhaustion — Red Hat Enterprise Linux 10 CWE-789 5.3 Medium 2026-08-11
CVE-2026-71217 Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabling remote denial of service via resource exhaustion — Red Hat Enterprise Linux 10 CWE-20 7.5 High 2026-08-11
CVE-2026-72693 Kbd: local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login — Red Hat Enterprise Linux 10 CWE-284 7.8 High 2026-08-11
CVE-2026-72694 Mrtg: mrtg daemon symlink-following chown allows local privilege escalation via pid file path manipulation — Red Hat Enterprise Linux 10 CWE-59 7.1 High 2026-08-11
CVE-2026-6426 Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access — Red Hat Enterprise Linux 10 CWE-681 4.4 Medium 2026-08-10
CVE-2026-63623 Libvirt: information disclosure via world-readable storage volume images during clone/convert — Red Hat Enterprise Linux 10 CWE-732 5.5 Medium 2026-08-10
CVE-2026-19389 Gstreamer: gstreamer1-plugins-ugly-free: gstreamer: integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read — Red Hat Enterprise Linux 10 CWE-190 7.1 High 2026-08-10
CVE-2026-19387 Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec ima/dvi adpcm decoder — Red Hat Enterprise Linux 10 CWE-787 7.6 High 2026-08-10
CVE-2026-61477 Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection — Red Hat Enterprise Linux 10 CWE-93 2.3 Low 2026-08-07
CVE-2026-15816 Dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() — Red Hat Enterprise Linux 10 CWE-78 7.5 High 2026-08-07
CVE-2026-18938 P11-kit: integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems — Red Hat Enterprise Linux 10 CWE-122 6.2 Medium 2026-08-07
CVE-2026-18649 Gstreamer1-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders — Red Hat Enterprise Linux 10 CWE-770 7.5 High 2026-08-06
CVE-2026-68743 Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1 — Red Hat Enterprise Linux 10 CWE-125 5.5 Medium 2026-08-04
CVE-2026-68744 Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply — Red Hat Enterprise Linux 10 CWE-908 3.3 Low 2026-08-04
CVE-2026-18477 Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape — Red Hat Enterprise Linux 10 CWE-367 4.4 Medium 2026-08-03
CVE-2026-18508 Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite — Red Hat Enterprise Linux 10 CWE-59 4.4 Medium 2026-08-03
CVE-2026-68742 Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr — Red Hat Enterprise Linux 10 CWE-125 5.5 Medium 2026-08-03
CVE-2026-68563 Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure of postgresql data via insecure backup permissions — Red Hat Enterprise Linux 10 CWE-732 5.5 Medium 2026-07-30
CVE-2026-68562 Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering — Red Hat Enterprise Linux 10 CWE-610 6.2 Medium 2026-07-30
CVE-2026-58216 Samba: kpasswd service: kpasswd packet that contains malformed asn.1 might cause the server to access 6 bytes of unallocated memory leading server to crash — Red Hat Enterprise Linux 10 CWE-125 5.3 Medium 2026-07-30
CVE-2026-58222 Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes — Red Hat Enterprise Linux 10 CWE-90 8.8 High 2026-07-30
CVE-2026-58218 Samba: dns signing dos via tkey name cache exhaustion — Red Hat Enterprise Linux 10 CWE-410 5.3 Medium 2026-07-30
CVE-2026-16531 Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet — Red Hat Enterprise Linux 10 CWE-22 5.3 Medium 2026-07-30
CVE-2026-16530 Pcp: pcp: remote denial of service and information leakage — Red Hat Enterprise Linux 10 CWE-125 6.5 Medium 2026-07-30
CVE-2026-16529 Pcp: pcp: denial of service due to signed integer overflow — Red Hat Enterprise Linux 10 CWE-190 7.5 High 2026-07-30
CVE-2026-16527 Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access rules — Red Hat Enterprise Linux 10 CWE-306 7.3 High 2026-07-30
CVE-2026-16526 Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability — Red Hat Enterprise Linux 10 CWE-403 8.8 High 2026-07-30
CVE-2026-16524 Pcp: pcp linux_sockets pmda: arbitrary command execution via command injection — Red Hat Enterprise Linux 10 CWE-78 7.8 High 2026-07-30
CVE-2026-18220 Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processing — Red Hat Enterprise Linux 10 CWE-787 7.8 High 2026-07-29
CVE-2026-18107 Criu: criu: container escape via rseq critical section hijack during checkpoint/restore — Red Hat Enterprise Linux 10 CWE-269 7.8 High 2026-07-28

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.