AlmaLinux OS 10
AlmaLinux OS 10
Third-party support for the AlmaLinux OS 10: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.
24/7 engineers own your AlmaLinux OS 10 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- almalinux
- release
- 10
- product Label
- AlmaLinux OS
- release Label
- AlmaLinux OS 10
- codename
- lts
- latest Version
- 10.2
- release Date
- 2025-05-27
- maintained
- true
- source Url
- https://endoflife.date/almalinux
Lifecycle Dates
- End of Service Life
- May 31, 2035
- Last OEM Support
- May 31, 2030
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for AlmaLinux OS 10 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for AlmaLinux OS 10?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for AlmaLinux OS 10 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
AlmaLinux OS 10 Support: Frequently Asked Questions
Is the AlmaLinux OS 10 still supported?
Yes. The AlmaLinux OS 10 is currently supported by AlmaLinux, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.
When is the AlmaLinux OS 10 end of service life (EOSL) date?
AlmaLinux lists the end of service life for the AlmaLinux OS 10 as May 31, 2035.
Can I keep using the AlmaLinux OS 10 after its EOSL date?
Yes. EOSL means AlmaLinux stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the AlmaLinux OS 10 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting AlmaLinux OS 10
5 published CVEs affect the AlmaLinux OS 10, including 2 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2024-12084 | CRITICAL | 9.8 | Jan 15, 2025 | A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer. |
| CVE-2024-12085 | HIGH | 7.5 | Jan 14, 2025 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time. |
| CVE-2024-12088 | MEDIUM | 6.5 | Jan 14, 2025 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory. |
| CVE-2024-12087 | MEDIUM | 6.5 | Jan 14, 2025 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server c |
| CVE-2024-12086 | MEDIUM | 6.1 | Jan 14, 2025 | A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byt |