Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Hardened Images — Vulnerabilities & Security Advisories 44

All 44 CVE vulnerabilities found in Red Hat Hardened Images, with AI-generated Chinese analysis, references, and POCs.

This page catalogs common weakness types associated with the Red Hat Hardened Images product, categorized under vendor-specific security tags. It aggregates a comprehensive collection of vulnerabilities that affect this specialized operating system variant, covering security incidents reported and published from 2010 through the present day. By centralizing this data, the resource allows security professionals to efficiently track Red Hat’s official advisories and patch cycles for hardened environments. Users can also gain a deeper understanding of prevalent weakness classes, such as privilege escalation or information exposure, as they specifically manifest within the context of Red Hat’s security-focused distributions. Furthermore, the page facilitates the lookup of a product’s historical vulnerability trajectory, enabling analysts to assess the long-term security posture and remediation trends of Red Hat Hardened Images over time. This aggregation serves as a vital reference for compliance officers and system administrators who need to verify the security status of their hardened infrastructure against known threats. The information presented is derived from official vendor notifications and trusted security databases, ensuring accuracy and reliability for operational decision-making. By reviewing these entries, stakeholders can identify potential gaps in their current configurations and prioritize updates based on severity and impact. This structured approach to vulnerability data helps streamline the process of maintaining a secure and compliant environment using Red Hat’s hardened solutions, providing clarity on which issues have been addressed and which may still require attention.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-72693 Kbd: local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login CWE-284 7.8 High2026-08-11
CVE-2026-19079 Policycoreutils: policycoreutils: toctou race condition in fixfiles allows arbitrary selinux label manipulation CWE-367 4.4 Medium2026-08-07
CVE-2026-44605 Rpm: heap buffer overflow in ndb slot table parsing CWE-190 5.5 Medium2026-08-05
CVE-2026-18477 Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape CWE-367 4.4 Medium2026-08-03
CVE-2026-18508 Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite CWE-59 4.4 Medium2026-08-03
CVE-2026-15003 Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of service CWE-125 5.6 Medium2026-07-27
CVE-2026-16517 Libarchive: libarchive: signed integer overflow in archive_write_zip_header CWE-190 2.9 Low2026-07-21
CVE-2026-59851 Libssh: libssh: authentication bypass via missing gssapi principal check CWE-863 8.8 High2026-07-21
CVE-2026-59850 Libssh: libssh: use-after-free via data callbacks on closed channels CWE-416 4.3 Medium2026-07-21
CVE-2026-59849 Libssh: libssh: denial of service via automatic certificate authentication loop CWE-835 3.1 Low2026-07-21
CVE-2026-59848 Libssh: libssh: denial of service via sftp responses with unknown request ids CWE-770 5.3 Medium2026-07-21
CVE-2026-59847 Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification CWE-253 5.9 Medium2026-07-21
CVE-2026-59846 Libssh: libssh: information disclosure via proxycommand %r username expansion CWE-78 3.9 Low2026-07-21
CVE-2026-59844 Libssh: libssh: denial of service via oversized sftp read length CWE-789 6.5 Medium2026-07-21
CVE-2026-59845 Libssh: libssh: denial of service via unchecked proxycommand fork() failure CWE-390 5.3 Medium2026-07-21
CVE-2026-59843 Libssh: libssh: denial of service via zero advertised channel packet size CWE-835 6.5 Medium2026-07-21
CVE-2026-59842 Libssh: libssh: information disclosure via short gssapi curve25519 public key CWE-125 3.7 Low2026-07-21
CVE-2026-15370 Libssh: libssh: stack buffer overflow in sftp server longname construction CWE-121 6.7 Medium2026-07-21
CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering CWE-770 5.3 Medium2026-07-20
CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header CWE-805 3.9 Low2026-07-10
CVE-2026-13595 Util-linux: util-linux: heap use-after-free in libblkid nested partition probing CWE-416 6.8 Medium2026-06-29
CVE-2026-4367 Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing CWE-125 5.5 Medium2026-06-16
CVE-2026-11850 Krb5: krb5: integer underflow in berval2tl_data() leads to heap out-of-bounds read CWE-191 5.0 Medium2026-06-11
CVE-2026-44604 Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level directory name in popen() shell command CWE-78 7.0 High2026-05-28
CVE-2026-6732 Libxml2: libxml2: denial of service via crafted xsd-validated document CWE-843 6.5 Medium2026-04-23
CVE-2026-6846 Binutils: binutils: arbitrary code execution via malformed xcoff object file processing CWE-122 7.8 High2026-04-22
CVE-2026-6845 Binutils: binutils: denial of service via crafted elf file CWE-476 5.0 Medium2026-04-22
CVE-2026-1584 Gnutls: gnutls: remote denial of service via crafted clienthello with invalid psk binder CWE-476 7.5 High2026-04-09
CVE-2025-14821 Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows CWE-427 7.8 High2026-04-07
CVE-2026-5745 Libarchive: a null pointer dereference vulnerability exists in the acl parser of libarchive CWE-476 5.5 Medium2026-04-07

All 44 known CVE vulnerabilities affecting Red Hat Hardened Images with full Chinese analysis, references, and POCs where available.