CVE-2026-16529 – Red Hat Enterprise Linux 10
“A collection of High severity flaws across core system components can create multiple paths to compromise if left unpatched.”
This update addresses multiple vulnerabilities affecting Red Hat Enterprise Linux 10. CVE-2026-16526 and CVE-2026-58222 each have a CVSS score of 8.8, which is High severity. CVE-2026-16524, CVE-2026-17523, CVE-2026-18107, and CVE-2026-18220 each have a CVSS score of 7.8, High severity. CVE-2026-16313 has a CVSS score of 7.6, High severity. CVE-2026-16529 has a CVSS score of 7.5, High severity, and CVE-2026-16527 has a CVSS score of 7.3, High severity. No verified real-world exploitation has been reported for any of these vulnerabilities.
The update resolves vulnerabilities across several components, including Performance Co-Pilot (PCP), the Linux kernel, CRIU, GNU binutils, Samba Active Directory Domain Controller, and sg3_utils. The issues include command injection, insecure internal connections, access control bypass, integer overflow, kernel privilege escalation, checkpoint and restore privilege escalation, memory corruption, LDAP filter injection, and improper handling of device data. Successful exploitation could lead to arbitrary command execution, disclosure of sensitive information, denial of service, privilege escalation, unauthorized access to Active Directory data, or system compromise under specific conditions. Based on the supplied assessment, CVE-2026-16524, CVE-2026-16529, and CVE-2026-18220 have Remote Code Execution (RCE) characteristics, while CVE-2026-18107 and CVE-2026-18220 have Elevation of Privilege (EoP) characteristics.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-190