Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1428

Browse all 1428 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

Found 323 results / 1428 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-103641 Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder — Red Hat Enterprise Linux 10 CWE-125 5.5 Medium 2026-10-01
CVE-2026-103399 Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body — Red Hat Enterprise Linux 10 CWE-444 5.3 Medium 2026-09-30
CVE-2026-103242 Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag — Red Hat Enterprise Linux 10 CWE-122 7.1 High 2026-09-30
CVE-2026-102560 Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth — Red Hat Enterprise Linux 10 CWE-125 8.6 High 2026-09-29
CVE-2026-102559 Libsoup: libsoup: heap buffer overflow during websocket client-frame masking — Red Hat Enterprise Linux 10 CWE-125 8.6 High 2026-09-29
CVE-2026-102558 Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth — Red Hat Enterprise Linux 10 CWE-125 8.6 High 2026-09-29
CVE-2026-102555 Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding — Red Hat Enterprise Linux 10 CWE-125 8.2 High 2026-09-29
CVE-2026-102557 Libsoup: libsoup: heap buffer overflow during websocket message reassembly — Red Hat Enterprise Linux 10 CWE-125 8.6 High 2026-09-29
CVE-2026-102556 Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion — Red Hat Enterprise Linux 10 CWE-843 8.6 High 2026-09-29
CVE-2026-95520 Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages — Red Hat Enterprise Linux 10 CWE-787 7.1 High 2026-09-29
CVE-2026-97029 Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group — Red Hat Enterprise Linux 10 CWE-653 5.7 Medium 2026-09-29
CVE-2026-97024 Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc — Red Hat Enterprise Linux 10 CWE-61 7.1 High 2026-09-29
CVE-2026-97027 Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus service files — Red Hat Enterprise Linux 10 CWE-20 3.6 Low 2026-09-28
CVE-2026-97026 Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path — Red Hat Enterprise Linux 10 CWE-378 3.9 Low 2026-09-28
CVE-2026-97025 Flatpak: flatpak: world-readable oci authentication token in system-helper cache path — Red Hat Enterprise Linux 10 CWE-378 3.2 Low 2026-09-28
CVE-2026-97023 Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy directory export/bin — Red Hat Enterprise Linux 10 CWE-61 7.1 High 2026-09-28
CVE-2026-96284 Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following — Red Hat Enterprise Linux 10 CWE-59 2.5 Low 2026-09-27
CVE-2026-96282 Flatpak: flatpak: extension metadata path traversal file existence oracle — Red Hat Enterprise Linux 10 CWE-59 3.1 Low 2026-09-27
CVE-2026-96283 Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pull — Red Hat Enterprise Linux 10 CWE-862 3.3 Low 2026-09-27
CVE-2026-96281 Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes — Red Hat Enterprise Linux 10 CWE-284 6.2 Medium 2026-09-27
CVE-2026-96280 Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems — Red Hat Enterprise Linux 10 CWE-197 7.5 High 2026-09-27
CVE-2026-96279 Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks — Red Hat Enterprise Linux 10 CWE-59 6.5 Medium 2026-09-27
CVE-2026-93834 Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape — Red Hat Enterprise Linux 10 CWE-416 8.8 High 2026-09-25
CVE-2026-95521 Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm — Red Hat Enterprise Linux 10 CWE-78 7.8 High 2026-09-24
CVE-2026-95519 Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows) — Red Hat Enterprise Linux 10 CWE-78 7.8 High 2026-09-24
CVE-2026-97185 Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file — Red Hat Enterprise Linux 10 CWE-787 7.8 High 2026-09-24
CVE-2026-96889 Librsvg: use-after-free when xml includes have duplicated entities — Red Hat Enterprise Linux 10 CWE-416 7.8 High 2026-09-23
CVE-2026-96546 Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader — Red Hat Enterprise Linux 10 CWE-125 2.5 Low 2026-09-23
CVE-2026-96545 Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader — Red Hat Enterprise Linux 10 CWE-125 4.4 Medium 2026-09-23
CVE-2026-96541 Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline — Red Hat Enterprise Linux 10 CWE-400 7.5 High 2026-09-23

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.