Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Red Hat Enterprise Linux Number Of NVD 1681 CRITICAL 136 HIGH 590 MEDIUM 803 LOW 151
URL https://www.redhat.com/technologies/linux-platforms/enterprise-linux
Explanation Full support is 5.5 years from release.
Maintenance support (security updates only) is for 3.5 years.
After that, extended support is available for a fee.
Tag
  • 商用ライセンス有り
  • Linux

Add Information URL
No Type Name URL
1 https://access.redhat.com/ja/articles/16476
2 https://access.redhat.com/support/policy/updates/errata
3 https://access.redhat.com/articles/3078
4 https://access.redhat.com/security
5 https://access.redhat.com/errata/#/?q=&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
981 Red Hat Enterprise Linux 9 9.7 Nov. 11, 2025 May 17, 2022 5 127 172 17
982 Red Hat Enterprise Linux 8 8.10 May 22, 2024 May 7, 2019 May 30, 2029 44 314 444 50
983 Red Hat Enterprise Linux 7 7.9 Sept. 29, 2020 Dec. 11, 2013 Aug. 6, 2020 June 30, 2024 92 270 270 46
984 Red Hat Enterprise Linux 6 6.10 June 19, 2018 Nov. 9, 2010 May 10, 2022 Nov. 30, 2020 June 30, 2024 73 169 210 55
985 Red Hat Enterprise Linux 5 5.11 Sept. 16, 2014 March 15, 2007 March 31, 2017 Nov. 30, 2020 24 59 89 40
986 Red Hat Enterprise Linux 4 4.5 Feb. 29, 2012 March 31, 2017 5 30 29 16
987 Red Hat Enterprise Linux 3 3.0 0 33 44 17
988 Red Hat Enterprise Linux 2 2.1 Update 7 April 28, 2005 0 32 37 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
981 6.5
3.3
MEDIUM
Adjacent
A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1. CWE-125
Out-of-bounds Read
CVE-2019-3459 cpe:2.3:o:redhat:enterprise_linux:8.0:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*
cpe:2.3:o:redhat:enterprise_linux…
2024-11-21 13:42
2019-04-12
Show GitHub Exploit DB Packet Storm
982 6.1
4.9
MEDIUM
Local
It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded userspace application calling recvmsg() for the same n… CWE-362
CWE-401
Race Condition
 Missing Release of Memory after Effective Lifetime
CVE-2019-3837 cpe:2.3:o:redhat:enterprise_linux:6.0:* 2024-11-21 13:42
2019-04-12
Show GitHub Exploit DB Packet Storm
983 7.0
4.4
HIGH
Local
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular config… CWE-863
 Incorrect Authorization
CVE-2019-3842 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 13:42
2019-04-10
Show GitHub Exploit DB Packet Storm
984 5.4
5.5
MEDIUM
Network
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they… CWE-22
Path Traversal
CVE-2019-3880 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 13:42
2019-04-10
Show GitHub Exploit DB Packet Storm
985 5.6
4.7
MEDIUM
Local
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via … - CVE-2019-3887 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:42
2019-04-10
Show GitHub Exploit DB Packet Storm
986 6.5
4.0
MEDIUM
Network
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tam… NVD-CWE-noinfo
CVE-2019-0757 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:17
2019-04-9
Show GitHub Exploit DB Packet Storm
987 7.8
7.2
HIGH
Local
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scrip… CWE-416
 Use After Free
CVE-2019-0211 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:16
2019-04-9
Show GitHub Exploit DB Packet Storm
988 7.5
6.0
HIGH
Network
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another usern… CWE-362
Race Condition
CVE-2019-0217 cpe:2.3:o:redhat:enterprise_linux:-:* 2024-11-21 13:16
2019-04-9
Show GitHub Exploit DB Packet Storm
989 9.8
7.5
CRITICAL
Network
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access. CWE-787
 Out-of-bounds Write
CVE-2019-0160 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:16
2019-03-28
Show GitHub Exploit DB Packet Storm
990 6.1
4.3
MEDIUM
Network
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the brows… CWE-601
Open Redirect
CVE-2019-3877 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 13:42
2019-03-27
Show GitHub Exploit DB Packet Storm