Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Red Hat Enterprise Linux Number Of NVD 1711 CRITICAL 141 HIGH 603 MEDIUM 814 LOW 152
URL https://www.redhat.com/technologies/linux-platforms/enterprise-linux
Explanation Full support is 5.5 years from release.
Maintenance support (security updates only) is for 3.5 years.
After that, extended support is available for a fee.
Tag
  • 商用ライセンス有り
  • Linux

Add Information URL
No Type Name URL
1 https://access.redhat.com/ja/articles/16476
2 https://access.redhat.com/support/policy/updates/errata
3 https://access.redhat.com/articles/3078
4 https://access.redhat.com/security
5 https://access.redhat.com/errata/#/?q=&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
371 Red Hat Enterprise Linux 10.2 10.2 May 19, 2026 May 20, 2025 8 24 16 3
372 Red Hat Enterprise Linux 9 9.7 Nov. 11, 2025 May 17, 2022 10 140 183 18
373 Red Hat Enterprise Linux 8 8.10 May 22, 2024 May 7, 2019 May 30, 2029 49 327 454 51
374 Red Hat Enterprise Linux 7 7.9 Sept. 29, 2020 Dec. 11, 2013 Aug. 6, 2020 June 30, 2024 97 283 280 47
375 Red Hat Enterprise Linux 6 6.10 June 19, 2018 Nov. 9, 2010 May 10, 2022 Nov. 30, 2020 June 30, 2024 77 176 212 56
376 Red Hat Enterprise Linux 5 5.11 Sept. 16, 2014 March 15, 2007 March 31, 2017 Nov. 30, 2020 24 59 89 40
377 Red Hat Enterprise Linux 4 4.5 Feb. 29, 2012 March 31, 2017 5 30 29 16
378 Red Hat Enterprise Linux 3 3.0 0 33 44 17
379 Red Hat Enterprise Linux 2 2.1 Update 7 April 28, 2005 0 32 37 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
371 7.5
-
HIGH
Network
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force … CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2021-4213 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 15:37
2022-08-25
Show GitHub Exploit DB Packet Storm
372 6.5
-
MEDIUM
Network
A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of… CWE-476
 NULL Pointer Dereference
CVE-2021-4209 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 15:37
2022-08-25
Show GitHub Exploit DB Packet Storm
373 7.1
-
HIGH
Local
An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or l… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2021-4204 cpe:2.3:o:redhat:enterprise_linux:9.0:* 2024-11-21 15:37
2022-08-25
Show GitHub Exploit DB Packet Storm
374 5.3
-
MEDIUM
Network
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. … CWE-252
 Unchecked Return Value
CVE-2021-4189 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 15:37
2022-08-25
Show GitHub Exploit DB Packet Storm
375 4.4
-
MEDIUM
Local
A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions t… NVD-CWE-Other
CVE-2021-4159 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 15:37
2022-08-25
Show GitHub Exploit DB Packet Storm
376 6.0
-
MEDIUM
Local
A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of … - CVE-2021-4158 cpe:2.3:o:redhat:enterprise_linux:9.0:* 2024-11-21 15:37
2022-08-25
Show GitHub Exploit DB Packet Storm
377 7.8
-
HIGH
Local
A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corr… - CVE-2022-2938 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 16:01
2022-08-24
Show GitHub Exploit DB Packet Storm
378 5.5
-
MEDIUM
Local
A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp. CWE-674
 Uncontrolled Recursion
CVE-2021-3997 cpe:2.3:o:redhat:enterprise_linux:9.0:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*
cpe:2.3:o:redhat:enterprise_linux…
2024-11-21 15:23
2022-08-24
Show GitHub Exploit DB Packet Storm
379 6.5
-
MEDIUM
Network
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. … - CVE-2021-3975 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 15:23
2022-08-24
Show GitHub Exploit DB Packet Storm
380 7.5
-
HIGH
Network
A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any softwa… CWE-125
CWE-787
Out-of-bounds Read
 Out-of-bounds Write
CVE-2021-3839 cpe:2.3:o:redhat:enterprise_linux:9.0:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*
cpe:2.3:o:redhat:enterprise_linux…
2024-11-21 15:22
2022-08-24
Show GitHub Exploit DB Packet Storm