Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Red Hat Enterprise Linux Number Of NVD 1680 CRITICAL 135 HIGH 590 MEDIUM 803 LOW 151
URL https://www.redhat.com/technologies/linux-platforms/enterprise-linux
Explanation Full support is 5.5 years from release.
Maintenance support (security updates only) is for 3.5 years.
After that, extended support is available for a fee.
Tag
  • 商用ライセンス有り
  • Linux

Add Information URL
No Type Name URL
1 https://access.redhat.com/ja/articles/16476
2 https://access.redhat.com/support/policy/updates/errata
3 https://access.redhat.com/articles/3078
4 https://access.redhat.com/security
5 https://access.redhat.com/errata/#/?q=&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
421 Red Hat Enterprise Linux 9 9.7 Nov. 11, 2025 May 17, 2022 4 127 172 17
422 Red Hat Enterprise Linux 8 8.10 May 22, 2024 May 7, 2019 May 30, 2029 43 314 444 50
423 Red Hat Enterprise Linux 7 7.9 Sept. 29, 2020 Dec. 11, 2013 Aug. 6, 2020 June 30, 2024 91 270 270 46
424 Red Hat Enterprise Linux 6 6.10 June 19, 2018 Nov. 9, 2010 May 10, 2022 Nov. 30, 2020 June 30, 2024 72 169 210 55
425 Red Hat Enterprise Linux 5 5.11 Sept. 16, 2014 March 15, 2007 March 31, 2017 Nov. 30, 2020 24 59 89 40
426 Red Hat Enterprise Linux 4 4.5 Feb. 29, 2012 March 31, 2017 5 30 29 16
427 Red Hat Enterprise Linux 3 3.0 0 33 44 17
428 Red Hat Enterprise Linux 2 2.1 Update 7 April 28, 2005 0 32 37 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
421 6.5
4.0
MEDIUM
Network
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression D… CWE-400
 Uncontrolled Resource Consumption
CVE-2021-3733 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 15:22
2022-03-11
Show GitHub Exploit DB Packet Storm
422 7.5
7.1
HIGH
Network
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinit… CWE-400
CWE-835
 Uncontrolled Resource Consumption
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-3737 cpe:2.3:o:redhat:enterprise_linux:8.0:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*
cpe:2.3:o:redhat:enterprise_linux…
2024-11-21 15:22
2022-03-5
Show GitHub Exploit DB Packet Storm
423 8.8
7.2
HIGH
Local
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a ne… CWE-862
 Missing Authorization
CVE-2021-3656 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 15:22
2022-03-5
Show GitHub Exploit DB Packet Storm
424 7.8
6.8
HIGH
Local
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permission… - CVE-2021-3575 cpe:2.3:o:redhat:enterprise_linux:8.0:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*
cpe:2.3:o:redhat:enterprise_linux…
2024-11-21 15:21
2022-03-5
Show GitHub Exploit DB Packet Storm
425 8.1
5.1
HIGH
Network
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection … - CVE-2021-23214 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 14:51
2022-03-5
Show GitHub Exploit DB Packet Storm
426 7.8
6.9
HIGH
Local
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_… CWE-862
 Missing Authorization
CVE-2022-0492 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 15:38
2022-03-4
Show GitHub Exploit DB Packet Storm
427 5.5
2.1
MEDIUM
Local
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest th… - CVE-2021-3620 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 15:22
2022-03-4
Show GitHub Exploit DB Packet Storm
428 5.5
1.9
MEDIUM
Local
An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment varia… CWE-212
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2021-3602 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 15:21
2022-03-4
Show GitHub Exploit DB Packet Storm
429 3.1
3.5
LOW
Network
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY bef… NVD-CWE-Other
CVE-2021-3716 cpe:2.3:o:redhat:enterprise_linux:8.0:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*
2024-11-21 15:22
2022-03-3
Show GitHub Exploit DB Packet Storm
430 6.5
5.8
MEDIUM
Network
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used a… - CVE-2021-3772 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 15:22
2022-03-3
Show GitHub Exploit DB Packet Storm