CVE Tools

Red Hat Hardened Images

213 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Red Hat Hardened Images, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Hardened Images CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Hardened Images CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-065
2025-075
2025-080
2025-096
2025-101
2025-111
2025-128
2026-0112
2026-025
2026-0324
2026-0431
2026-0513
2026-0627
2026-0719
2026-0820
2026-0936

Severity

How the 213 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical42%
  • High8138%
  • Medium10449%
  • Low2411%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Hardened Images.

  1. CVE-2026-95521Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm7.8
  2. CVE-2026-95519Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows)7.8
  3. CVE-2026-88840Busybox: busybox: tls ssl_server reads one byte out of bounds when parsing truncated clienthello5.3
  4. CVE-2026-88839Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint6.7
  5. CVE-2026-88837Busybox: busybox: httpd misidentifies yescrypt password hashes as plaintext, inverting authentication6.5
  6. CVE-2026-88835Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb packages6.1
  7. CVE-2026-88831Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix lengths5.3
  8. CVE-2026-88832Busybox: busybox: romfs volume id parsing performs unbounded memcpy into fixed-size label buffer, causing heap overflow7.3
  9. CVE-2026-88830Busybox: busybox: tls montgomery reduction allocates bytes instead of digits, causing a pre-auth heap buffer overflow7.5
  10. CVE-2026-96512Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization7.8
  11. CVE-2026-95619Gcc: libstdc++ integer overflow in `new` operator7.7
  12. CVE-2026-93653Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill via unvalidated tiling-pattern repeat count (denial of service)5.5
  13. CVE-2026-76781Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute5.5
  14. CVE-2026-92925Redis: redis: out-of-bounds read via crafted cluster bus packets7.1
  15. CVE-2026-42784Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusion7.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store