Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1444

Browse all 1444 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

Found 50 results / 1444 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-95512 Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader — Red Hat Hardened Images CWE-400 5.5 Medium 2026-10-02
CVE-2026-102010 Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in binary heap erase_if — Red Hat Hardened Images CWE-825 7.0 High 2026-09-28
CVE-2026-88840 Busybox: busybox: tls ssl_server reads one byte out of bounds when parsing truncated clienthello — Red Hat Hardened Images CWE-125 5.3 Medium 2026-09-23
CVE-2026-88839 Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint — Red Hat Hardened Images CWE-787 6.7 Medium 2026-09-23
CVE-2026-88837 Busybox: busybox: httpd misidentifies yescrypt password hashes as plaintext, inverting authentication — Red Hat Hardened Images CWE-305 6.5 Medium 2026-09-23
CVE-2026-88835 Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb packages — Red Hat Hardened Images CWE-125 6.1 Medium 2026-09-23
CVE-2026-88831 Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix lengths — Red Hat Hardened Images CWE-636 5.3 Medium 2026-09-23
CVE-2026-88832 Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow — Red Hat Hardened Images CWE-787 7.3 High 2026-09-23
CVE-2026-88830 Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow — Red Hat Hardened Images CWE-131 7.5 High 2026-09-23
CVE-2026-96512 Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization — Red Hat Hardened Images CWE-863 7.8 High 2026-09-23
CVE-2026-95619 Gcc: libstdc++ integer overflow in `new` operator — Red Hat Hardened Images CWE-190 7.7 High 2026-09-22
CVE-2026-76781 Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute — Red Hat Hardened Images CWE-476 5.5 Medium 2026-09-17
CVE-2026-42784 Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion — Red Hat Hardened Images CWE-347 7.4 High 2026-09-16
CVE-2026-79705 Podman: buildah: buildah/copier: directory escape via crafted tar symlinks when used outside buildah by non-root callers — Red Hat Hardened Images CWE-22 4.5 Medium 2026-09-15
CVE-2026-85013 Environment-modules: command injection in environment-modules bash completion via malicious module names containing shell metacharacters — Red Hat Hardened Images CWE-78 7.3 High 2026-09-15
CVE-2026-18495 Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough — Red Hat Hardened Images CWE-122 6.1 Medium 2026-09-11
CVE-2026-88265 Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and chown — Red Hat Hardened Images CWE-59 5.6 Medium 2026-09-10
CVE-2026-87876 Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up) — Red Hat Hardened Images CWE-178 3.0 Low 2026-09-09
CVE-2026-87875 Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound — Red Hat Hardened Images CWE-125 4.3 Medium 2026-09-09
CVE-2026-78409 Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks — Red Hat Hardened Images CWE-59 7.0 High 2026-09-02
CVE-2026-78408 Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority — Red Hat Hardened Images CWE-775 7.9 High 2026-09-02
CVE-2026-78410 Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection — Red Hat Hardened Images CWE-367 7.8 High 2026-09-02
CVE-2026-84233 Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames — Red Hat Hardened Images CWE-78 7.0 High 2026-09-01
CVE-2026-19617 Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser — Red Hat Hardened Images CWE-770 5.5 Medium 2026-08-14
CVE-2026-19079 Policycoreutils: policycoreutils: toctou race condition in fixfiles allows arbitrary selinux label manipulation — Red Hat Hardened Images CWE-367 4.4 Medium 2026-08-07
CVE-2026-44605 Rpm: heap buffer overflow in ndb slot table parsing — Red Hat Hardened Images CWE-190 5.5 Medium 2026-08-05
CVE-2026-15003 Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of service — Red Hat Hardened Images CWE-125 5.6 Medium 2026-07-27
CVE-2026-13595 Util-linux: util-linux: heap use-after-free in libblkid nested partition probing — Red Hat Hardened Images CWE-416 6.8 Medium 2026-06-29
CVE-2026-4367 Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing — Red Hat Hardened Images CWE-125 5.5 Medium 2026-06-16
CVE-2026-11850 Krb5: krb5: integer underflow in berval2tl_data() leads to heap out-of-bounds read — Red Hat Hardened Images CWE-191 5.0 Medium 2026-06-11

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.