Red Hat Enterprise Linux 5 (ELS)
Red Hat Enterprise Linux 5 (ELS)
The Red Hat Enterprise Linux 5 (ELS) reached end of service life on Nov 30, 2020 — Red Hat no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Red Hat Enterprise Linux 5 (ELS) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- rhel
- release
- 5
- product Label
- Red Hat Enterprise Linux
- release Label
- 5 (ELS)
- codename
- lts
- true
- latest Version
- 5.11
- release Date
- 2007-03-15
- maintained
- source Url
- https://endoflife.date/rhel
Lifecycle Dates
- End of Service Life
- Nov 30, 2020
- Last OEM Support
- Jan 8, 2013
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Red Hat Enterprise Linux 5 (ELS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Red Hat Enterprise Linux 5 (ELS)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Red Hat Enterprise Linux 5 (ELS) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Red Hat Enterprise Linux 5 (ELS) Support: Frequently Asked Questions
Is the Red Hat Enterprise Linux 5 (ELS) still supported?
Red Hat ended support for the Red Hat Enterprise Linux 5 (ELS) on Nov 30, 2020 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Red Hat Enterprise Linux 5 (ELS) end of service life (EOSL) date?
Red Hat lists the end of service life for the Red Hat Enterprise Linux 5 (ELS) as Nov 30, 2020.
Can I keep using the Red Hat Enterprise Linux 5 (ELS) after its EOSL date?
Yes. EOSL means Red Hat stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Red Hat Enterprise Linux 5 (ELS) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Red Hat Enterprise Linux 5 (ELS)
216 published CVEs affect the Red Hat Enterprise Linux 5 (ELS), including 84 rated critical or high severity. Red Hat no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2014-4650 | CRITICAL | 9.8 | Feb 20, 2020 | The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator. |
| CVE-2011-2717 | CRITICAL | 9.8 | Nov 27, 2019 | The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message. |
| CVE-2011-2897 | CRITICAL | 9.8 | Nov 12, 2019 | gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw |
| CVE-2015-8980 | CRITICAL | 9.8 | Nov 4, 2019 | The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. |
| CVE-2018-14667 | CRITICAL | 9.8 | Nov 6, 2018 | The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData. |
| CVE-2017-7793 | CRITICAL | 9.8 | Jun 11, 2018 | A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4. |
| CVE-2017-7792 | CRITICAL | 9.8 | Jun 11, 2018 | A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. |
| CVE-2017-7786 | CRITICAL | 9.8 | Jun 11, 2018 | A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. |
| CVE-2017-7785 | CRITICAL | 9.8 | Jun 11, 2018 | A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. |
| CVE-2017-7784 | CRITICAL | 9.8 | Jun 11, 2018 | A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. |
| CVE-2017-5410 | CRITICAL | 9.8 | Jun 11, 2018 | Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is managed for memory cleanup. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8. |
| CVE-2017-5404 | CRITICAL | 9.8 | Jun 11, 2018 | A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8. |
| CVE-2017-5402 | CRITICAL | 9.8 | Jun 11, 2018 | A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8. |
| CVE-2017-5401 | CRITICAL | 9.8 | Jun 11, 2018 | A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8. |
| CVE-2017-5396 | CRITICAL | 9.8 | Jun 11, 2018 | A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. |
| CVE-2017-5390 | CRITICAL | 9.8 | Jun 11, 2018 | The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. |
| CVE-2017-5380 | CRITICAL | 9.8 | Jun 11, 2018 | A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. |
| CVE-2017-5376 | CRITICAL | 9.8 | Jun 11, 2018 | Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. |
| CVE-2016-9899 | CRITICAL | 9.8 | Jun 11, 2018 | Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6. |
| CVE-2016-9898 | CRITICAL | 9.8 | Jun 11, 2018 | Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6. |
Showing the 20 most severe of 216 known CVEs.
Get Third Party SupportRelated Red Hat Products
All Red Hat products →Red Hat Enterprise Linux 9 (Upcoming ELS)
EOSL: May 31, 2036
Red Hat Enterprise Linux 8 (Upcoming ELS)
EOSL: May 31, 2033
Red Hat Enterprise Linux 4
EOSL: Mar 31, 2017
Red Hat Enterprise Linux 10 (Upcoming ELS)
EOSL: May 31, 2039
Red Hat Enterprise Linux 6 (ELS)
EOSL: Jun 30, 2024
Red Hat Enterprise Linux 7 (ELS)
EOSL: May 31, 2029