Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1444

Browse all 1444 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

Found 320 results / 1444 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-15714 Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string — Red Hat Enterprise Linux 10 CWE-125 6.5 Medium 2026-07-14
CVE-2026-15713 Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak — Red Hat Enterprise Linux 10 CWE-772 5.9 Medium 2026-07-14
CVE-2026-15711 Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation — Red Hat Enterprise Linux 10 CWE-770 7.5 High 2026-07-14
CVE-2026-15709 Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service — Red Hat Enterprise Linux 10 CWE-409 7.5 High 2026-07-14
CVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption — Red Hat Enterprise Linux 10 CWE-125 5.9 Medium 2026-07-14
CVE-2026-12478 Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame processing (unmasked path) — Red Hat Enterprise Linux 10 CWE-125 4.8 Medium 2026-07-14
CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header — Red Hat Enterprise Linux 10 CWE-805 3.9 Low 2026-07-10
CVE-2026-59692 Gstreamer1-plugins-bad-free: gstreamer: dtls certificate subject dn stack buffer overflow in openssl_verify_callback — Red Hat Enterprise Linux 10 CWE-121 7.5 High 2026-07-09
CVE-2026-59691 Gstreamer1-plugins-bad-free: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16bpp framebuffer — Red Hat Enterprise Linux 10 CWE-787 7.1 High 2026-07-09
CVE-2026-14935 Gstreamer1-plugins-bad-free: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check — Red Hat Enterprise Linux 10 CWE-670 3.7 Low 2026-07-07
CVE-2026-14476 Sssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows kerberos authentication bypass — Red Hat Enterprise Linux 10 CWE-23 8.0 High 2026-07-07
CVE-2026-14474 Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalation — Red Hat Enterprise Linux 10 CWE-1188 8.8 High 2026-07-07
CVE-2026-14612 Freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorization — Red Hat Enterprise Linux 10 CWE-787 4.2 Medium 2026-07-03
CVE-2026-14324 Pipewire: raop rtsp null deref — Red Hat Enterprise Linux 10 CWE-476 6.5 Medium 2026-07-01
CVE-2026-14258 Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling — Red Hat Enterprise Linux 10 CWE-835 6.5 Medium 2026-07-01
CVE-2026-12610 Sssd: use-after-free crash in sssd' 'sssd_pam' process — Red Hat Enterprise Linux 10 CWE-825 6.4 Medium 2026-06-30
CVE-2026-14164 Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack() — Red Hat Enterprise Linux 10 CWE-415 7.5 High 2026-06-30
CVE-2026-13757 P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing — Red Hat Enterprise Linux 10 CWE-674 6.2 Medium 2026-06-29
CVE-2026-12912 Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image — Red Hat Enterprise Linux 10 CWE-122 7.3 High 2026-06-29
CVE-2026-57966 Spice-vdagent: path traversal in file transfer via unsanitized filename — Red Hat Enterprise Linux 10 CWE-22 4.4 Medium 2026-06-29
CVE-2026-57965 Spice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow — Red Hat Enterprise Linux 10 CWE-190 5.1 Medium 2026-06-29
CVE-2026-12892 Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parser — Red Hat Enterprise Linux 10 CWE-125 4.4 Medium 2026-06-23
CVE-2026-12891 Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser — Red Hat Enterprise Linux 10 CWE-125 4.3 Medium 2026-06-23
CVE-2026-11820 Community.general: community.general nexmo — api credentials exposed in get url query string[security] community.general nexmo — api credentials exposed in get url query string — Red Hat Enterprise Linux 10 CWE-532 6.5 Medium 2026-06-23
CVE-2026-11819 Community.general: community.general keyring_info — os keyring passphrase returned in plaintext — Red Hat Enterprise Linux 10 CWE-532 5.5 Medium 2026-06-23
CVE-2026-12969 Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation — Red Hat Enterprise Linux 10 CWE-125 5.3 Medium 2026-06-23
CVE-2026-55654 Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination — Red Hat Enterprise Linux 10 CWE-125 3.7 Low 2026-06-23
CVE-2026-55655 Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions — Red Hat Enterprise Linux 10 CWE-923 5.0 Medium 2026-06-23
CVE-2026-55653 Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service — Red Hat Enterprise Linux 10 CWE-415 4.3 Medium 2026-06-23
CVE-2026-12549 Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver — Red Hat Enterprise Linux 10 CWE-805 4.8 Medium 2026-06-22

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.