目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

Red Hat 厂商漏洞列表 / CVE 中文分析 1426

Red Hat 厂商相关 1426 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

Red Hat 主要提供企业级 Linux 操作系统及中间件解决方案,其开源生态广泛支撑全球关键业务。历史漏洞多集中于远程代码执行、权限提升及信息泄露,部分源于底层组件集成缺陷。值得关注的是,其通过 Red Hat Security Response 团队提供长期安全支持,并集成 SELinux 强制访问控制机制以增强系统隔离性。尽管漏洞数量较多,但官方响应迅速,持续推动补丁更新以保障企业环境稳定性。

CVE ID 标题 CVSS 风险等级 Published
CVE-2026-96281 Flatpak 未授权用户绕过系统应用/运行时降版本检查漏洞 — Red Hat Enterprise Linux 10 CWE-284 6.2 Medium 2026-09-27
CVE-2026-96280 Flatpak 32位系统 OCI delta 路径缓冲区溢出漏洞 — Red Hat Enterprise Linux 10 CWE-197 7.5 High 2026-09-27
CVE-2026-96279 Flatpak OCI归档提取路径穿越漏洞 — Red Hat Enterprise Linux 10 CWE-59 6.5 Medium 2026-09-27
CVE-2026-93834 Qemu-kvm 9pfs use-after-free漏洞导致VM逃逸 — Red Hat Enterprise Linux 10 CWE-416 8.8 High 2026-09-25
CVE-2026-96448 Keycloak-services fgap v2 组合盲角色映射权限提升漏洞 — Red Hat Build of Keycloak CWE-285 6.6 Medium 2026-09-25
CVE-2026-97846 Keycloak keycloak-services mtls持有密钥绑定绕过漏洞 — Red Hat Build of Keycloak CWE-287 6.8 Medium 2026-09-25
CVE-2026-90959 Pulpcore 文件上传任意文件读取及密钥泄露漏洞 — Red Hat Ansible Automation Platform 2 CWE-22 8.1 High 2026-09-24
CVE-2026-95521 RPM 源码RPM安装时通过宏展开源/规格文件名注入Shell命令漏洞 — Red Hat Enterprise Linux 10 CWE-78 7.8 High 2026-09-24
CVE-2026-95519 RPM rpmgi 宏展开代码执行漏洞 — Red Hat Enterprise Linux 10 CWE-78 7.8 High 2026-09-24
CVE-2026-94416 aap-gateway 通过伪造工作负载身份令牌绕过授权漏洞 — Red Hat Ansible Automation Platform 2 CWE-290 6.8 Medium 2026-09-24
CVE-2026-97311 Keycloak-services 管理API角色组接口未授权泄露群组信息漏洞 — Red Hat Build of Keycloak CWE-862 4.3 Medium 2026-09-24
CVE-2026-97185 GIMP 外置写入漏洞 — Red Hat Enterprise Linux 10 CWE-787 7.8 High 2026-09-24
CVE-2026-97177 Keycloak services 通用用户更新绕过重置密码权限限制漏洞 — Red Hat Build of Keycloak CWE-862 6.6 Medium 2026-09-24
CVE-2026-97176 Keycloak 重要身份验证级别要求通过Cookie身份验证器被绕过 — Red Hat Build of Keycloak CWE-862 4.2 Medium 2026-09-24
CVE-2026-75887 OpenShift Console 国际化语言处理程序未授权路径遍历漏洞 — Red Hat OpenShift Container Platform 4.19 CWE-22 7.5 High 2026-09-23
CVE-2026-75886 OpenShift Console 未认证反向代理漏洞 — Red Hat OpenShift Container Platform 4.19 CWE-441 7.2 High 2026-09-23
CVE-2026-84724 Automation-controller systemjob额外参数注入控制平面 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 6.6 Medium 2026-09-23
CVE-2026-84721 Automation-controller 邮件通知后端 SSRF 漏洞 — Red Hat Ansible Automation Platform 2.7 CWE-918 6.4 Medium 2026-09-23
CVE-2026-84720 Automation Controller 祖先工件缺少防止搜索,通过ORM遍历暴露no_log设置的统计信息 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-639 6.5 Medium 2026-09-23
CVE-2026-84718 Automation-controller IP欺骗致日志伪造漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-348 4.3 Medium 2026-09-23
CVE-2026-84717 Automation Controller Bitbucket数据中台Webhook接收器未授权枚举漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-204 5.3 Medium 2026-09-23
CVE-2026-84716 Automation-controller 证书颁发漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-266 6.6 Medium 2026-09-23
CVE-2026-84713 自动化控制器通知收件人密钥泄露漏洞 — Red Hat Ansible Automation Platform 2.7 CWE-639 6.5 Medium 2026-09-23
CVE-2026-84712 Automation-controller 未授权 API 漏洞暴露实例拓扑与成员信息 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-497 5.3 Medium 2026-09-23
CVE-2026-96889 Librsvg xml包含重复实体时出现Use-After-Free漏洞 — Red Hat Enterprise Linux 10 CWE-416 7.8 High 2026-09-23
CVE-2026-85475 Ansible Automation Controller rsyslog注入导致远程代码执行漏洞 — Red Hat Ansible Automation Platform 2.7 CWE-96 7.2 High 2026-09-23
CVE-2026-84719 Automation Controller workflow模板副本越权漏洞 — Red Hat Ansible Automation Platform 2.4 for RHEL 8 CWE-862 9.9 Critical 2026-09-23
CVE-2026-84714 Automation Controller Jinja模板注入漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-184 7.1 High 2026-09-23
CVE-2026-84706 Ansible Automation Controller 凭据类型环境变量注入器绕过漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-184 7.6 High 2026-09-23
CVE-2026-75884 Awx OpenShift命名空间权限提升漏洞 — Red Hat Ansible Automation Platform 2.4 for RHEL 8 CWE-184 9.1 Critical 2026-09-23

本页汇总了 Red Hat 厂商截至目前公开的全部 1426 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。