| Red Hat Enterprise Linux | Number Of NVD | 1700 | CRITICAL | 140 | HIGH | 597 | MEDIUM | 811 | LOW | 151 |
| URL | https://www.redhat.com/technologies/linux-platforms/enterprise-linux | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Explanation | Full support is 5.5 years from release. Maintenance support (security updates only) is for 3.5 years. After that, extended support is available for a fee. |
||||||||
| Tag | |||||||||
| No | Type | Name | URL |
|---|---|---|---|
| 1 | https://access.redhat.com/ja/articles/16476 | ||
| 2 | https://access.redhat.com/support/policy/updates/errata | ||
| 3 | https://access.redhat.com/articles/3078 | ||
| 4 | https://access.redhat.com/security | ||
| 5 | https://access.redhat.com/errata/#/?q=&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory |
| No | Name | Latest Version | Release date | Initial release | Normal Support | Security Support Service Pack Support |
Extended for a fee |
Critical | High | Medium | Low |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 11 | Red Hat Enterprise Linux 9 | 9.7 | Nov. 11, 2025 | May 17, 2022 | 9 | 134 | 180 | 17 | |||
| 12 | Red Hat Enterprise Linux 8 | 8.10 | May 22, 2024 | May 7, 2019 | May 30, 2029 | 48 | 321 | 451 | 50 | ||
| 13 | Red Hat Enterprise Linux 7 | 7.9 | Sept. 29, 2020 | Dec. 11, 2013 | Aug. 6, 2020 | June 30, 2024 | 96 | 277 | 277 | 46 | |
| 14 | Red Hat Enterprise Linux 6 | 6.10 | June 19, 2018 | Nov. 9, 2010 | May 10, 2022 | Nov. 30, 2020 | June 30, 2024 | 76 | 170 | 210 | 55 |
| 15 | Red Hat Enterprise Linux 5 | 5.11 | Sept. 16, 2014 | March 15, 2007 | March 31, 2017 | Nov. 30, 2020 | 24 | 59 | 89 | 40 | |
| 16 | Red Hat Enterprise Linux 4 | 4.5 | Feb. 29, 2012 | March 31, 2017 | 5 | 30 | 29 | 16 | |||
| 17 | Red Hat Enterprise Linux 3 | 3.0 | 0 | 33 | 44 | 17 | |||||
| 18 | Red Hat Enterprise Linux 2 | 2.1 Update 7 | April 28, 2005 | 0 | 32 | 37 | 6 |
| No | CVSS3 CVSS2 |
Level Attach Vector |
Title | CWE | CVE | cpe23Uri | or higher | or less | more than | less than | Update date Published date |
Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 11 |
7.8 - |
HIGH
Local |
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attack… |
CWE-416
Use After Free |
CVE-2026-50257 |
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux… |
2026-06-9 01:45 2026-06-5 |
Show | GitHub Exploit DB Packet Storm | ||||
| 12 |
7.8 - |
HIGH
Local |
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow… |
CWE-121
Stack-based Buffer Overflow |
CVE-2026-50256 |
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux… |
2026-06-9 01:45 2026-06-5 |
Show | GitHub Exploit DB Packet Storm | ||||
| 13 |
6.5 - |
MEDIUM
Network |
A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to i… |
CWE-280
Improper Handling of Insufficient Permissions or Privileges |
CVE-2026-2340 |
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux… |
2026-05-29 00:33 2026-05-27 |
Show | GitHub Exploit DB Packet Storm | ||||
| 14 |
6.5 - |
MEDIUM
Network |
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem wri… |
CWE-284 NVD-CWE-noinfo Improper Access Control |
CVE-2026-1933 |
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux… |
2026-06-3 05:01 2026-05-27 |
Show | GitHub Exploit DB Packet Storm | ||||
| 15 |
9.8 - |
CRITICAL
Network |
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution charac… |
CWE-78
OS Command |
CVE-2026-4480 |
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux… |
2026-06-2 02:53 2026-05-27 |
Show | GitHub Exploit DB Packet Storm | ||||
| 16 |
9.8 - |
CRITICAL
Network |
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacke… |
CWE-626
Null Byte Interaction Error (Poison Null Byte) |
CVE-2026-42010 |
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux… |
2026-05-13 22:54 2026-05-7 |
Show | GitHub Exploit DB Packet Storm | ||||
| 17 |
9.1 - |
CRITICAL
Network |
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit … |
CWE-805
Buffer Access with Incorrect Length Value |
CVE-2026-34002 |
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux… |
2026-05-7 23:39 2026-05-6 |
Show | GitHub Exploit DB Packet Storm | ||||
| 18 |
9.1 - |
CRITICAL
Network |
A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an at… |
CWE-125
Out-of-bounds Read |
CVE-2026-34000 |
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux… |
2026-05-7 23:35 2026-05-6 |
Show | GitHub Exploit DB Packet Storm | ||||
| 19 |
7.4 - |
HIGH
Network |
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constrai… |
CWE-178
Improper Handling of Case Sensitivity |
CVE-2026-3833 |
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux… |
2026-05-7 11:09 2026-05-1 |
Show | GitHub Exploit DB Packet Storm | ||||
| 20 |
9.1 - |
CRITICAL
Network |
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This… |
CWE-191
Integer Underflow (Wrap or Wraparound) |
CVE-2026-33845 |
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux… |
2026-05-5 12:03 2026-05-1 |
Show | GitHub Exploit DB Packet Storm |