CVE Tools

Red Hat Enterprise Linux 7 Extended Lifecycle Support

142 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Red Hat Enterprise Linux 7 Extended Lifecycle Support, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Enterprise Linux 7 Extended Lifecycle Support CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Enterprise Linux 7 Extended Lifecycle Support CVEs per month
MonthCVEs
2024-103
2024-111
2024-120
2025-012
2025-0210
2025-030
2025-046
2025-054
2025-0612
2025-072
2025-082
2025-093
2025-104
2025-115
2025-124
2026-011
2026-022
2026-036
2026-047
2026-0512
2026-0631
2026-079
2026-087
2026-095

Severity

How the 142 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical96%
  • High10574%
  • Medium2719%
  • Low11%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Enterprise Linux 7 Extended Lifecycle Support.

  1. CVE-2026-18922389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property9.8
  2. CVE-2026-18453389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results and use_one_backend control in op_shared_search7.5
  3. CVE-2026-18355389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound underflow in sasl_io_start_packet()7.5
  4. CVE-2026-76560389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empty bind dn7.5
  5. CVE-2026-81665Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly7.5
  6. CVE-2026-18917Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow7.8
  7. CVE-2026-73433Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd parsing leading to out-of-bounds read/write6.6
  8. CVE-2026-73434Gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing6.1
  9. CVE-2026-63622Libvirt: swtpm privilege escalation via symlink following7.8
  10. CVE-2026-19387Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec ima/dvi adpcm decoder7.6
  11. CVE-2026-15816Dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die()7.5
  12. CVE-2026-18649Gstreamer1-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders7.5
  13. CVE-2026-11770389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check7.5
  14. CVE-2026-15722389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing7.5
  15. CVE-2026-16313Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export7.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store