Red Hat 厂商相关 1426 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。
Red Hat 主要提供企业级 Linux 操作系统及中间件解决方案,其开源生态广泛支撑全球关键业务。历史漏洞多集中于远程代码执行、权限提升及信息泄露,部分源于底层组件集成缺陷。值得关注的是,其通过 Red Hat Security Response 团队提供长期安全支持,并集成 SELinux 强制访问控制机制以增强系统隔离性。尽管漏洞数量较多,但官方响应迅速,持续推动补丁更新以保障企业环境稳定性。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-103641 | Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder — Red Hat Enterprise Linux 10 CWE-125 | 5.5 | Medium | 2026-10-01 |
| CVE-2026-103399 | Libsoup HTTP请求走私漏洞 — Red Hat Enterprise Linux 10 CWE-444 | 5.3 | Medium | 2026-09-30 |
| CVE-2026-101295 | Oc-mirror 路径遍历及任意文件写入漏洞 — Assisted Installer for Red Hat OpenShift Container Platform 2 CWE-22 | 7.3 | High | 2026-09-30 |
| CVE-2026-103242 | RPM hex2binv堆溢出漏洞 — Red Hat Enterprise Linux 10 CWE-122 | 7.1 | High | 2026-09-30 |
| CVE-2026-62146 | Cri-o Pod注解污染致运行时套接字暴露漏洞 — Red Hat OpenShift Container Platform 4 CWE-501 | 7.8 | High | 2026-09-30 |
| CVE-2026-102560 | Libsoup 发送缓冲扩展堆溢出漏洞 — Red Hat Enterprise Linux 10 CWE-125 | 8.6 | High | 2026-09-29 |
| CVE-2026-102559 | libsoup websocket掩码堆缓冲区溢出漏洞 — Red Hat Enterprise Linux 10 CWE-125 | 8.6 | High | 2026-09-29 |
| CVE-2026-102558 | Libsoup 接收缓冲区增长堆溢出漏洞 — Red Hat Enterprise Linux 10 CWE-125 | 8.6 | High | 2026-09-29 |
| CVE-2026-102555 | Libsoup 数据URI Base64解码堆溢出 — Red Hat Enterprise Linux 10 CWE-125 | 8.2 | High | 2026-09-29 |
| CVE-2026-102623 | Kubevirt virt-controller 空指针解引用漏洞 — Red Hat OpenShift Virtualization 4 CWE-476 | 6.5 | Medium | 2026-09-29 |
| CVE-2026-102557 | Libsoup WebSocket消息重组堆缓冲区溢出漏洞 — Red Hat Enterprise Linux 10 CWE-125 | 8.6 | High | 2026-09-29 |
| CVE-2026-102556 | Libsoup websocket类型混淆堆溢出漏洞 — Red Hat Enterprise Linux 10 CWE-843 | 8.6 | High | 2026-09-29 |
| CVE-2026-95520 | RPM iterreadarchivenext() 堆溢出漏洞 — Red Hat Enterprise Linux 10 CWE-787 | 7.1 | High | 2026-09-29 |
| CVE-2026-102474 | Dash shell 堆越界写入漏洞(conv_escape) — Red Hat Enterprise Linux 6 CWE-787 | 4.0 | Medium | 2026-09-29 |
| CVE-2026-102473 | Dash pmatch 禁用 libc fnmatch 时存在超多项式回溯漏洞 — Red Hat Enterprise Linux 6 CWE-1333 | 5.5 | Medium | 2026-09-29 |
| CVE-2026-97029 | Flatpak沙盒应用可向同进程组非沙盒进程发送信号 — Red Hat Enterprise Linux 10 CWE-653 | 5.7 | Medium | 2026-09-29 |
| CVE-2026-97024 | Flatpak 通过部署目录路径遍历在根上下文中任意写入漏洞 — Red Hat Enterprise Linux 10 CWE-61 | 7.1 | High | 2026-09-29 |
| CVE-2026-97027 | Flatpak 通过未消毒键导致拒绝服务漏洞 — Red Hat Enterprise Linux 10 CWE-20 | 3.6 | Low | 2026-09-28 |
| CVE-2026-97026 | Flatpak系统辅助缓存路径世界可写临时子仓库 — Red Hat Enterprise Linux 10 CWE-378 | 3.9 | Low | 2026-09-28 |
| CVE-2026-97025 | Flatpak 系统助手缓存路径中OCI认证令牌可读 — Red Hat Enterprise Linux 10 CWE-378 | 3.2 | Low | 2026-09-28 |
| CVE-2026-102010 | gcc-toolset-16 gcc 二进制堆 erase_if 使用-after-free 拒绝服务漏洞 — Red Hat Hardened Images CWE-825 | 7.0 | High | 2026-09-28 |
| CVE-2026-97023 | Flatpak:通过路径遍历实现任意文件删除 — Red Hat Enterprise Linux 10 CWE-61 | 7.1 | High | 2026-09-28 |
| CVE-2026-96740 | Streamshub/console 控制台 operator 通过配置提供者泄露 Sa-Token — StreamsHub Console for Apache Kafka® CWE-470 | 6.5 | Medium | 2026-09-28 |
| CVE-2026-87114 | Kube-compare 容器引用提取漏洞导致提权 — Pen Drive Powered by Red Hat Lightspeed CWE-829 | 7.1 | High | 2026-09-28 |
| CVE-2026-101333 | Keycloak-services 通过 IDP 标签创建无限指标序列漏洞 — Red Hat Build of Keycloak CWE-770 | 3.7 | Low | 2026-09-28 |
| CVE-2026-101292 | Apache ActiveMQ Artemis 联邦消息反序列化存在不安全的反射漏洞 — Red Hat JBoss Enterprise Application Platform 7.4.25 CWE-470 | 8.2 | High | 2026-09-28 |
| CVE-2026-86330 | Noobaa-core 集群API主机名命令注入漏洞 — Red Hat Openshift Data Foundation 4 CWE-78 | 7.2 | High | 2026-09-28 |
| CVE-2026-96284 | Flatpak 系统助手上下文通过 OCI 符号链接跟随实现任意文件读取漏洞 — Red Hat Enterprise Linux 10 CWE-59 | 2.5 | Low | 2026-09-27 |
| CVE-2026-96282 | Flatpak 扩展元数据路径遍历漏洞 — Red Hat Enterprise Linux 10 CWE-59 | 3.1 | Low | 2026-09-27 |
| CVE-2026-96283 | Flatpak系统助手跨用户取消拉取孤儿漏洞 — Red Hat Enterprise Linux 10 CWE-862 | 3.3 | Low | 2026-09-27 |
本页汇总了 Red Hat 厂商截至目前公开的全部 1426 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。