Red Hat 厂商相关 1428 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。
Red Hat 主要提供企业级 Linux 操作系统及中间件解决方案,其开源生态广泛支撑全球关键业务。历史漏洞多集中于远程代码执行、权限提升及信息泄露,部分源于底层组件集成缺陷。值得关注的是,其通过 Red Hat Security Response 团队提供长期安全支持,并集成 SELinux 强制访问控制机制以增强系统隔离性。尽管漏洞数量较多,但官方响应迅速,持续推动补丁更新以保障企业环境稳定性。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-84714 | Automation Controller Jinja模板注入漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-184 | 7.1 | High | 2026-09-23 |
| CVE-2026-84706 | Ansible Automation Controller 凭据类型环境变量注入器绕过漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-184 | 7.6 | High | 2026-09-23 |
| CVE-2026-75884 | Awx OpenShift命名空间权限提升漏洞 — Red Hat Ansible Automation Platform 2.4 for RHEL 8 CWE-184 | 9.1 | Critical | 2026-09-23 |
| CVE-2026-84691 | Automation-controller 格式化字符串注入漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-134 | 8.7 | High | 2026-09-23 |
| CVE-2026-84683 | Automation-controller 存储型 XSS 漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-79 | 8.7 | High | 2026-09-23 |
| CVE-2026-84499 | 自动化控制器明文泄露密码漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-209 | 7.7 | High | 2026-09-23 |
| CVE-2026-84502 | Ansible Automation Controller scm_url 参数注入远程代码执行漏洞 — Red Hat Ansible Automation Platform 2.4 for RHEL 8 CWE-88 | 9.9 | Critical | 2026-09-23 |
| CVE-2026-84474 | Ansible AWX view_jobtemplate 权限提升漏洞 — Red Hat Ansible Automation Platform 2.4 for RHEL 8 CWE-807 | 9.9 | Critical | 2026-09-23 |
| CVE-2026-84486 | Automation Controller 调试接口未授权拒绝服务漏洞 — Red Hat Ansible Automation Platform 2.6 for RHEL 9 CWE-489 | 8.2 | High | 2026-09-23 |
| CVE-2026-96546 | Gimp DDS加载器堆越界读取漏洞 — Red Hat Enterprise Linux 10 CWE-125 | 2.5 | Low | 2026-09-23 |
| CVE-2026-71465 | Ansible Automation Controller 命令行参数注入漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 | 3.1 | Low | 2026-09-23 |
| CVE-2026-71464 | 自动化控制器 Git参数前导破折号防护绕过漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-88 | 3.1 | Low | 2026-09-23 |
| CVE-2026-71463 | Automation-controller Jinja模板白名单绕过 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-209 | 2.7 | Low | 2026-09-23 |
| CVE-2026-96545 | GIMP 4bpp TIM图像加载器越界堆读取漏洞 — Red Hat Enterprise Linux 10 CWE-125 | 4.4 | Medium | 2026-09-23 |
| CVE-2026-71462 | Automation-controller 容器自定义路径存在性漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-204 | 4.1 | Medium | 2026-09-23 |
| CVE-2026-71461 | Automation-controller 异常披露漏洞 — Red Hat Ansible Automation Platform 2.7 CWE-209 | 4.3 | Medium | 2026-09-23 |
| CVE-2026-71460 | Red Hat 自动化控制器认证用户读取订阅详情漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 | 4.3 | Medium | 2026-09-23 |
| CVE-2026-76648 | Ansible Automation Controller 敏感信息恢复漏洞 — Red Hat Ansible Automation Platform 2.7 CWE-862 | 8.5 | High | 2026-09-23 |
| CVE-2026-96541 | GNOME-Remote-Desktop RDP未认证握手超时漏洞 — Red Hat Enterprise Linux 10 CWE-400 | 7.5 | High | 2026-09-23 |
| CVE-2026-71459 | Automation-controller 跨租户作业事件树 RBAC 绕过漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-862 | 5.0 | Medium | 2026-09-23 |
| CVE-2026-71458 | Automation Controller named-url租户资源枚举漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 CWE-204 | 5.0 | Medium | 2026-09-23 |
| CVE-2026-88840 | Busybox TLS SSL服务端越界读取漏洞 — Red Hat Hardened Images CWE-125 | 5.3 | Medium | 2026-09-23 |
| CVE-2026-88839 | Busybox passwd/group解析器堆溢出漏洞 — Red Hat Hardened Images CWE-787 | 6.7 | Medium | 2026-09-23 |
| CVE-2026-88837 | Busybox httpd yescrypt哈希误判致认证反转 — Red Hat Hardened Images CWE-305 | 6.5 | Medium | 2026-09-23 |
| CVE-2026-88835 | Busybox 处理恶意.deb包越界读取漏洞 — Red Hat Hardened Images CWE-125 | 6.1 | Medium | 2026-09-23 |
| CVE-2026-88831 | Busybox HTTPD CIDR前缀处理逻辑错误 — Red Hat Hardened Images CWE-636 | 5.3 | Medium | 2026-09-23 |
| CVE-2026-88832 | BusyBox romfs 卷 ID 解析堆溢出漏洞 — Red Hat Hardened Images CWE-787 | 7.3 | High | 2026-09-23 |
| CVE-2026-88830 | BusyBox TLS Montgomery归约堆溢出漏洞 — Red Hat Hardened Images CWE-131 | 7.5 | High | 2026-09-23 |
| CVE-2026-96276 | Flatpak build-init任意写漏洞 — Red Hat Enterprise Linux 10 CWE-22 | 6.5 | Medium | 2026-09-23 |
| CVE-2026-96275 | Flatpak 额外数据提取导致的 root 任意写漏洞 — Red Hat Enterprise Linux 10 CWE-22 | 8.8 | High | 2026-09-23 |
本页汇总了 Red Hat 厂商截至目前公开的全部 1428 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。