Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Red Hat Enterprise Linux 10 — Vulnerabilities & Security Advisories 200

All 200 CVE vulnerabilities found in Red Hat Enterprise Linux 10, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities associated with Red Hat Enterprise Linux 10 under the Common Weakness Enumeration framework. It serves as a comprehensive resource for tracking security flaws identified in this specific enterprise operating system release, providing a structured view of potential risks. The content herein aggregates vulnerability data covering a broad historical timeline, capturing incidents from initial discovery through to resolution. It includes details on software flaws, configuration errors, and design weaknesses that have been reported against Red Hat Enterprise Linux 10 components. The data reflects the evolving threat landscape and the cumulative security posture of the product over time, ensuring that administrators and security analysts have access to a complete record of past and present issues. Users can utilize this resource to track vendor advisories issued by Red Hat, gaining insight into how specific weakness classes are addressed in enterprise environments. It enables security teams to understand the prevalence and impact of particular vulnerability types within this OS version. Additionally, the page allows for the lookup of a product’s vulnerability history, supporting risk assessment, patch prioritization, and long-term security planning. By consolidating this information, the page facilitates a deeper understanding of the security context surrounding Red Hat Enterprise Linux 10, helping stakeholders make informed decisions regarding system hardening and maintenance schedules without relying on fragmented data sources.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2026-61477 Libvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection CWE-93 2.3 Low2026-08-07
CVE-2026-15816 Dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() CWE-78 7.5 High2026-08-07
CVE-2026-18938 P11-kit: integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems CWE-122 6.2 Medium2026-08-07
CVE-2026-7867 Udisks2: udisks2: local privilege escalation via as-user option spoofing CWE-863 7.8 High2026-08-06
CVE-2026-18649 Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders CWE-770 7.5 High2026-08-06
CVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return CWE-835 5.1 Medium2026-08-05
CVE-2026-71226 Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path CWE-416 7.3 High2026-08-05
CVE-2026-71225 Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries CWE-330 6.5 Medium2026-08-05
CVE-2026-68743 Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol v1 CWE-125 5.5 Medium2026-08-04
CVE-2026-68744 Sssd: sssd: nss responder uninitialized heap disclosure in initgroups reply CWE-908 3.3 Low2026-08-04
CVE-2026-68742 Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr CWE-125 5.5 Medium2026-08-03
CVE-2026-68563 Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure of postgresql data via insecure backup permissions CWE-732 5.5 Medium2026-07-30
CVE-2026-68562 Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering CWE-610 6.2 Medium2026-07-30
CVE-2026-58216 Samba: kpasswd service: kpasswd packet that contains malformed asn.1 might cause the server to access 6 bytes of unallocated memory leading server to crash CWE-125 5.3 Medium2026-07-30
CVE-2026-58222 Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes CWE-90 8.8 High2026-07-30
CVE-2026-58218 Samba: dns signing dos via tkey name cache exhaustion CWE-410 5.3 Medium2026-07-30
CVE-2026-16531 Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet CWE-22 5.3 Medium2026-07-30
CVE-2026-16530 Pcp: pcp: remote denial of service and information leakage CWE-125 6.5 Medium2026-07-30
CVE-2026-16529 Pcp: pcp: denial of service due to signed integer overflow CWE-190 7.5 High2026-07-30
CVE-2026-16527 Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access rules CWE-306 7.3 High2026-07-30
CVE-2026-16526 Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability CWE-403 8.8 High2026-07-30
CVE-2026-16524 Pcp: pcp linux_sockets pmda: arbitrary command execution via command injection CWE-78 7.8 High2026-07-30
CVE-2026-18220 Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processing CWE-787 7.8 High2026-07-29
CVE-2026-18107 Criu: criu: container escape via rseq critical section hijack during checkpoint/restore CWE-269 7.8 High2026-07-28
CVE-2026-16313 Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export CWE-93 7.6 High2026-07-28
CVE-2026-17072 Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_flac_stream_headers when parsing flac codec data in matroska containers CWE-125 3.3 Low2026-07-28
CVE-2026-17523 Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges CWE-825 7.8 High2026-07-27
CVE-2026-66338 Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked() CWE-444 5.4 Medium2026-07-24
CVE-2026-66337 Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until() CWE-125 6.5 Medium2026-07-24
CVE-2026-66339 Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels CWE-201 6.5 Medium2026-07-24

All 200 known CVE vulnerabilities affecting Red Hat Enterprise Linux 10 with full Chinese analysis, references, and POCs where available.