Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1444

Browse all 1444 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

Found 320 results / 1444 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-10118 Poppler: integer overflow in poppler splashoutputdev::tilingpatternfill leads to heap buffer overflow via unchecked dimension multiplication — Red Hat Enterprise Linux 10 CWE-190 7.8 High 2026-06-01
CVE-2026-6324 Libsoup: libsoup: http request smuggling via unsigned to signed conversion error — Red Hat Enterprise Linux 10 CWE-444 4.8 Medium 2026-05-29
CVE-2026-10028 Glib-networking: infinite loop in glib-networking gnutls backend allows remote denial of service via circular certificate chain — Red Hat Enterprise Linux 10 CWE-835 4.3 Medium 2026-05-28
CVE-2026-4408 Samba: remote code execution in samr — Red Hat Enterprise Linux 10 CWE-78 9.0 Critical 2026-05-28
CVE-2026-1933 Samba: missing access check on reparse point operations — Red Hat Enterprise Linux 10 CWE-284 7.1 High 2026-05-27
CVE-2026-2340 Samba: vfs_worm does not block directory modification — Red Hat Enterprise Linux 10 CWE-280 6.5 Medium 2026-05-27
CVE-2026-3012 Samba: group policy certificate enrollment uses http:// without validation — Red Hat Enterprise Linux 10 CWE-345 8.0 High 2026-05-27
CVE-2026-48864 Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data — Red Hat Enterprise Linux 10 CWE-787 7.8 High 2026-05-26
CVE-2026-4480 Samba: samba: remote code execution in printing subsystem via unescaped job description — Red Hat Enterprise Linux 10 CWE-78 9.0 Critical 2026-05-26
CVE-2026-9149 Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file — Red Hat Enterprise Linux 10 CWE-122 6.5 Medium 2026-05-20
CVE-2026-9150 Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums — Red Hat Enterprise Linux 10 CWE-121 6.5 Medium 2026-05-20
CVE-2026-4802 Cockpit: cockpit: arbitrary command execution via crafted links in system logs ui — Red Hat Enterprise Linux 10 CWE-78 8.0 High 2026-05-11
CVE-2026-33846 Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly — Red Hat Enterprise Linux 10 CWE-130 7.5 High 2026-05-04
CVE-2026-2708 Libsoup: libsoup: http request smuggling via duplicate content-length headers — Red Hat Enterprise Linux 10 CWE-444 3.7 Low 2026-04-23
CVE-2026-34003 Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory access — Red Hat Enterprise Linux 10 CWE-125 7.8 High 2026-04-23
CVE-2026-34001 Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption — Red Hat Enterprise Linux 10 CWE-825 7.8 High 2026-04-23
CVE-2026-33999 Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map handling — Red Hat Enterprise Linux 10 CWE-191 7.8 High 2026-04-23
CVE-2026-6861 Emacs: emacs: memory corruption vulnerability when processing svg css — Red Hat Enterprise Linux 10 CWE-193 6.1 Medium 2026-04-22
CVE-2026-6844 Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files — Red Hat Enterprise Linux 10 CWE-400 5.5 Medium 2026-04-22
CVE-2026-6843 Nano: nano: format string vulnerability leads to denial of service — Red Hat Enterprise Linux 10 CWE-134 5.5 Medium 2026-04-22
CVE-2026-6245 Sssd: out-of-bounds read in the sssd — Red Hat Enterprise Linux 10 CWE-805 5.5 Medium 2026-04-15
CVE-2026-4878 Libcap: libcap: privilege escalation via toctou race condition in cap_set_file() — Red Hat Enterprise Linux 10 CWE-367 6.7 Medium 2026-04-09
CVE-2026-4631 Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection — Red Hat Enterprise Linux 10 CWE-78 9.8 Critical 2026-04-07
CVE-2026-5704 Tar: tar: hidden file injection via crafted archives — Red Hat Enterprise Linux 10 CWE-434 5.0 Medium 2026-04-06
CVE-2026-5673 Libtheora: libtheora: denial of service or information disclosure via malformed avi file processing — Red Hat Enterprise Linux 10 CWE-125 5.6 Medium 2026-04-06
CVE-2026-35094 Libinput: libinput: information disclosure via dangling pointer in lua plugin handling — Red Hat Enterprise Linux 10 CWE-825 3.3 Low 2026-04-01
CVE-2026-35093 Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins — Red Hat Enterprise Linux 10 CWE-94 8.8 High 2026-04-01
CVE-2026-35092 Corosync: corosync: denial of service via integer overflow in join message validation — Red Hat Enterprise Linux 10 CWE-190 7.5 High 2026-04-01
CVE-2026-35091 Corosync: corosync: denial of service and information disclosure via crafted udp packet — Red Hat Enterprise Linux 10 CWE-253 8.2 High 2026-04-01
CVE-2026-5201 Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image — Red Hat Enterprise Linux 10 CWE-122 7.5 High 2026-03-31

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.