CVE-2026-5674 – Red Hat Enterprise Linux 10
“These flaws can break sandbox boundaries, crash exposed services, and corrupt critical system memory.”
Red Hat has released updates for five High-severity vulnerabilities affecting Red Hat Enterprise Linux 10. The fixes address a PipeWire sandbox escape, two remotely triggered libsoup denial-of-service flaws, an xdgmime heap buffer overflow, and a QEMU out-of-bounds write. Potential impacts include code execution outside a sandbox, service disruption, memory corruption, information disclosure, and privilege escalation.
CVE-2026-5674 has a CVSS score of 8.8, High severity. CVE-2026-15709 has a CVSS score of 7.5, High severity. CVE-2026-15711 has a CVSS score of 7.5, High severity. CVE-2026-16118 has a CVSS score of 7.1, High severity. CVE-2026-3842 has a CVSS score of 7.8, High severity. Public proof-of-concept code is identified for the two libsoup WebSocket denial-of-service vulnerabilities.
Key Details
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-427