Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Red Hat Enterprise Linux Number Of NVD 1680 CRITICAL 135 HIGH 590 MEDIUM 803 LOW 151
URL https://www.redhat.com/technologies/linux-platforms/enterprise-linux
Explanation Full support is 5.5 years from release.
Maintenance support (security updates only) is for 3.5 years.
After that, extended support is available for a fee.
Tag
  • Linux
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://access.redhat.com/ja/articles/16476
2 https://access.redhat.com/support/policy/updates/errata
3 https://access.redhat.com/articles/3078
4 https://access.redhat.com/security
5 https://access.redhat.com/errata/#/?q=&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
171 Red Hat Enterprise Linux 9 9.7 Nov. 11, 2025 May 17, 2022 4 127 172 17
172 Red Hat Enterprise Linux 8 8.10 May 22, 2024 May 7, 2019 May 30, 2029 43 314 444 50
173 Red Hat Enterprise Linux 7 7.9 Sept. 29, 2020 Dec. 11, 2013 Aug. 6, 2020 June 30, 2024 91 270 270 46
174 Red Hat Enterprise Linux 6 6.10 June 19, 2018 Nov. 9, 2010 May 10, 2022 Nov. 30, 2020 June 30, 2024 72 169 210 55
175 Red Hat Enterprise Linux 5 5.11 Sept. 16, 2014 March 15, 2007 March 31, 2017 Nov. 30, 2020 24 59 89 40
176 Red Hat Enterprise Linux 4 4.5 Feb. 29, 2012 March 31, 2017 5 30 29 16
177 Red Hat Enterprise Linux 3 3.0 0 33 44 17
178 Red Hat Enterprise Linux 2 2.1 Update 7 April 28, 2005 0 32 37 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
171 5.5
-
MEDIUM
Local
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2023-5366 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 17:41
2023-10-7
Show GitHub Exploit DB Packet Storm
172 5.5
-
MEDIUM
Local
A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) was assumed to be associated with a device before calling __ip_options_compile, which is not always t… CWE-476
 NULL Pointer Dereference
CVE-2023-42754 cpe:2.3:o:redhat:enterprise_linux:9.0:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*
2024-11-21 17:23
2023-10-6
Show GitHub Exploit DB Packet Storm
173 5.5
-
MEDIUM
Local
A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyond the linear part of the skb, leading to an out-of-bounds read in the `r… CWE-125
Out-of-bounds Read
CVE-2023-42755 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 17:23
2023-10-6
Show GitHub Exploit DB Packet Storm
174 6.5
-
MEDIUM
Network
A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code vi… CWE-122
Heap-based Buffer Overflow
CVE-2023-41175 cpe:2.3:o:redhat:enterprise_linux:9.0:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*
2024-11-24 21:15
2023-10-6
Show GitHub Exploit DB Packet Storm
175 6.5
-
MEDIUM
Network
LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which … CWE-190
 Integer Overflow or Wraparound
CVE-2023-40745 cpe:2.3:o:redhat:enterprise_linux:9.0:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*
2024-11-21 17:20
2023-10-6
Show GitHub Exploit DB Packet Storm
176 5.5
-
MEDIUM
Local
A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, … CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2023-3576 cpe:2.3:o:redhat:enterprise_linux:9.0:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*
2024-11-21 17:17
2023-10-5
Show GitHub Exploit DB Packet Storm
177 8.2
-
HIGH
Local
An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior… NVD-CWE-noinfo
CVE-2023-39191 cpe:2.3:o:redhat:enterprise_linux:9.0:* 2024-11-21 17:14
2023-10-5
Show GitHub Exploit DB Packet Storm
178 5.9
-
MEDIUM
Network
A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page). CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2022-4132 cpe:2.3:o:redhat:enterprise_linux:9.0:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*
2024-11-21 16:34
2023-10-4
Show GitHub Exploit DB Packet Storm
179 7.8
-
HIGH
Local
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously craft… CWE-787
 Out-of-bounds Write
CVE-2023-4911 cpe:2.3:o:redhat:enterprise_linux:9.0:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*
2024-11-21 17:36
2023-10-4
Show GitHub Exploit DB Packet Storm
180 4.7
-
MEDIUM
Local
A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker with a local user privilege may cause a denial of service problem due to a BUG… CWE-362
Race Condition
CVE-2023-4732 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 17:35
2023-10-4
Show GitHub Exploit DB Packet Storm