Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Red Hat Enterprise Linux Number Of NVD 1680 CRITICAL 135 HIGH 590 MEDIUM 803 LOW 151
URL https://www.redhat.com/technologies/linux-platforms/enterprise-linux
Explanation Full support is 5.5 years from release.
Maintenance support (security updates only) is for 3.5 years.
After that, extended support is available for a fee.
Tag
  • Linux
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://access.redhat.com/ja/articles/16476
2 https://access.redhat.com/support/policy/updates/errata
3 https://access.redhat.com/articles/3078
4 https://access.redhat.com/security
5 https://access.redhat.com/errata/#/?q=&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
1221 Red Hat Enterprise Linux 9 9.7 Nov. 11, 2025 May 17, 2022 4 127 172 17
1222 Red Hat Enterprise Linux 8 8.10 May 22, 2024 May 7, 2019 May 30, 2029 43 314 444 50
1223 Red Hat Enterprise Linux 7 7.9 Sept. 29, 2020 Dec. 11, 2013 Aug. 6, 2020 June 30, 2024 91 270 270 46
1224 Red Hat Enterprise Linux 6 6.10 June 19, 2018 Nov. 9, 2010 May 10, 2022 Nov. 30, 2020 June 30, 2024 72 169 210 55
1225 Red Hat Enterprise Linux 5 5.11 Sept. 16, 2014 March 15, 2007 March 31, 2017 Nov. 30, 2020 24 59 89 40
1226 Red Hat Enterprise Linux 4 4.5 Feb. 29, 2012 March 31, 2017 5 30 29 16
1227 Red Hat Enterprise Linux 3 3.0 0 33 44 17
1228 Red Hat Enterprise Linux 2 2.1 Update 7 April 28, 2005 0 32 37 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
1221 8.8
9.0
HIGH
Network
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote … - CVE-2017-15103 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 12:14
2017-12-19
Show GitHub Exploit DB Packet Storm
1222 5.5
4.9
MEDIUM
Local
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary. - CVE-2017-15121 cpe:2.3:o:redhat:enterprise_linux:7.0:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*
2024-11-21 12:14
2017-12-7
Show GitHub Exploit DB Packet Storm
1223 5.5
4.9
MEDIUM
Local
The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference). CWE-476
 NULL Pointer Dereference
CVE-2017-15116 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 12:14
2017-12-1
Show GitHub Exploit DB Packet Storm
1224 6.3
6.9
MEDIUM
Physics
The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by… CWE-476
 NULL Pointer Dereference
CVE-2017-15102 cpe:2.3:o:redhat:enterprise_linux:6.0:*
cpe:2.3:o:redhat:enterprise_linux:5.0:*
2024-11-21 12:14
2017-11-16
Show GitHub Exploit DB Packet Storm
1225 7.8
7.2
HIGH
Local
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability w… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-1000253 cpe:2.3:o:redhat:enterprise_linux:7.3:*
cpe:2.3:o:redhat:enterprise_linux:7.2:*
cpe:2.3:o:redhat:enterprise_linux…
2026-04-22 03:00
2017-10-5
Show GitHub Exploit DB Packet Storm
1226 7.8
7.2
HIGH
Local
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety… CWE-787
 Out-of-bounds Write
CVE-2017-1000111 cpe:2.3:o:redhat:enterprise_linux:7.0:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*
cpe:2.3:o:redhat:enterprise_linux…
2024-11-21 12:04
2017-10-5
Show GitHub Exploit DB Packet Storm
1227 5.5
2.1
MEDIUM
Local
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot re… CWE-254
 7PK - Security Features
CVE-2015-7837 cpe:2.3:o:redhat:enterprise_linux:7.3:*
cpe:2.3:o:redhat:enterprise_linux:7.2:*
cpe:2.3:o:redhat:enterprise_linux…
2024-11-21 11:37
2017-09-20
Show GitHub Exploit DB Packet Storm
1228 4.7
4.7
MEDIUM
Local
Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by… CWE-362
Race Condition
CVE-2015-7553 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 11:36
2017-09-15
Show GitHub Exploit DB Packet Storm
1229 7.0
7.6
HIGH
Local
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descript… CWE-416
 Use After Free
CVE-2017-10661 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 12:06
2017-08-20
Show GitHub Exploit DB Packet Storm
1230 8.8
9.3
HIGH
Network
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution. CWE-704
 Incorrect Type Conversion or Cast
CVE-2017-3106 cpe:2.3:o:redhat:enterprise_linux:6.0:* 2024-11-21 12:24
2017-08-12
Show GitHub Exploit DB Packet Storm