CVE Tools

Red Hat Enterprise Linux 8.4 Extended Update Support Long-life Add-on

130 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Red Hat Enterprise Linux 8.4 Extended Update Support Long-life Add-on, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Red Hat Enterprise Linux 8.4 Extended Update Support Long-life Add-on CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat Enterprise Linux 8.4 Extended Update Support Long-life Add-on CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-011
2025-021
2025-031
2025-041
2025-053
2025-0610
2025-073
2025-082
2025-094
2025-105
2025-115
2025-125
2026-012
2026-023
2026-036
2026-047
2026-0514
2026-0633
2026-0712
2026-087
2026-095

Severity

How the 130 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical65%
  • High8968%
  • Medium3426%
  • Low11%

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat Enterprise Linux 8.4 Extended Update Support Long-life Add-on.

  1. CVE-2026-18922389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property9.8
  2. CVE-2026-18453389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results and use_one_backend control in op_shared_search7.5
  3. CVE-2026-18355389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound underflow in sasl_io_start_packet()7.5
  4. CVE-2026-76560389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empty bind dn7.5
  5. CVE-2026-81665Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly7.5
  6. CVE-2026-18917Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow7.8
  7. CVE-2026-73433Gstreamer1-plugins-good: gstreamer: unsigned integer underflow in avidemux fujifilm strd parsing leading to out-of-bounds read/write6.6
  8. CVE-2026-73434Gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing6.1
  9. CVE-2026-63622Libvirt: swtpm privilege escalation via symlink following7.8
  10. CVE-2026-19387Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec ima/dvi adpcm decoder7.6
  11. CVE-2026-15816Dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die()7.5
  12. CVE-2026-18649Gstreamer1-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders7.5
  13. CVE-2026-11770389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check7.5
  14. CVE-2026-15722389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing7.5
  15. CVE-2026-16313Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export7.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store