Red Hat

Red Hat Enterprise Linux 6 (ELS)

Red Hat Enterprise Linux 6 (ELS)

The Red Hat Enterprise Linux 6 (ELS) reached end of service life on Jun 30, 2024 — Red Hat no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.

End of Service LifeEOSL Date: Jun 30, 2024
Issue Management

24/7 engineers own your Red Hat Enterprise Linux 6 (ELS) incidents end to end.

Vulnerability Remediation

Mitigation and patch-around guidance when the vendor no longer ships fixes.

Compliance Maintenance

Controls evidence and documentation that keep auditors satisfied.

Specifications

product
rhel
release
6
product Label
Red Hat Enterprise Linux
release Label
6 (ELS)
codename
lts
true
latest Version
6.10
release Date
2010-11-10
maintained
source Url
https://endoflife.date/rhel

Lifecycle Dates

End of Service Life
Jun 30, 2024
Last OEM Support
May 10, 2016

Get Third Party Support

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.

OEM vs. 3rd Party Support

See how third-party support compares to the vendor contract for Red Hat Enterprise Linux 6 (ELS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.

FeatureOEM Support3rd Party Support
Post-EOSL Support
Break/Fix Support
Until EOSL
24/7 Monitoring
Vulnerability Scanning & Remediation
Managed Operations
Procedure & Configuration Review
Compliance & Audit Documentation
Limited
Discounted Migration to Other Platforms

Why Choose 3rd Party Support for Red Hat Enterprise Linux 6 (ELS)?

Vulnerability Remediation

Scanning, mitigation and patch-around guidance for Red Hat Enterprise Linux 6 (ELS) when the vendor no longer ships fixes.

Compliance Maintenance

Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.

24/7 Expert Support

Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.

Red Hat Enterprise Linux 6 (ELS) Support: Frequently Asked Questions

Is the Red Hat Enterprise Linux 6 (ELS) still supported?

Red Hat ended support for the Red Hat Enterprise Linux 6 (ELS) on Jun 30, 2024 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.

When is the Red Hat Enterprise Linux 6 (ELS) end of service life (EOSL) date?

Red Hat lists the end of service life for the Red Hat Enterprise Linux 6 (ELS) as Jun 30, 2024.

Can I keep using the Red Hat Enterprise Linux 6 (ELS) after its EOSL date?

Yes. EOSL means Red Hat stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.

How much does third-party support for the Red Hat Enterprise Linux 6 (ELS) cost?

Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.

Known Vulnerabilities Affecting Red Hat Enterprise Linux 6 (ELS)

602 published CVEs affect the Red Hat Enterprise Linux 6 (ELS), including 258 rated critical or high severity. Red Hat no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.

CVESeverityCVSSPublishedSummary
CVE-2023-34152CRITICAL9.8May 30, 2023A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
CVE-2021-3773CRITICAL9.8Feb 16, 2022A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.
CVE-2021-3466CRITICAL9.8Mar 25, 2021A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.9.70 is vulnerable.
CVE-2014-4650CRITICAL9.8Feb 20, 2020The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.
CVE-2014-8089CRITICAL9.8Feb 17, 2020SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
CVE-2019-14896CRITICAL9.8Nov 27, 2019A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP.
CVE-2014-3585CRITICAL9.8Nov 22, 2019redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
CVE-2013-4409CRITICAL9.8Nov 4, 2019An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
CVE-2018-18314CRITICAL9.8Dec 7, 2018Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CVE-2018-18311CRITICAL9.8Dec 7, 2018Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CVE-2018-18312CRITICAL9.8Dec 5, 2018Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CVE-2018-14667CRITICAL9.8Nov 6, 2018The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
CVE-2018-17456CRITICAL9.8Oct 6, 2018Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.
CVE-2011-2767CRITICAL9.8Aug 26, 2018mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.
CVE-2018-5096CRITICAL9.8Jun 11, 2018A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6.
CVE-2018-5095CRITICAL9.8Jun 11, 2018An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
CVE-2018-5091CRITICAL9.8Jun 11, 2018A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox < 58.
CVE-2017-7809CRITICAL9.8Jun 11, 2018A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
CVE-2017-7802CRITICAL9.8Jun 11, 2018A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially exploitable crash may occur when the freed elements are accessed. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
CVE-2017-7801CRITICAL9.8Jun 11, 2018A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

Showing the 20 most severe of 602 known CVEs.

Get Third Party Support

Related Red Hat Products

All Red Hat products →
Red Hat Enterprise Linux 6 (ELS)
Save 40-70% vs OEM
Get Third Party Support