Red Hat Enterprise Linux 6 (ELS)
Red Hat Enterprise Linux 6 (ELS)
The Red Hat Enterprise Linux 6 (ELS) reached end of service life on Jun 30, 2024 — Red Hat no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Red Hat Enterprise Linux 6 (ELS) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- rhel
- release
- 6
- product Label
- Red Hat Enterprise Linux
- release Label
- 6 (ELS)
- codename
- lts
- true
- latest Version
- 6.10
- release Date
- 2010-11-10
- maintained
- source Url
- https://endoflife.date/rhel
Lifecycle Dates
- End of Service Life
- Jun 30, 2024
- Last OEM Support
- May 10, 2016
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Red Hat Enterprise Linux 6 (ELS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Red Hat Enterprise Linux 6 (ELS)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Red Hat Enterprise Linux 6 (ELS) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Red Hat Enterprise Linux 6 (ELS) Support: Frequently Asked Questions
Is the Red Hat Enterprise Linux 6 (ELS) still supported?
Red Hat ended support for the Red Hat Enterprise Linux 6 (ELS) on Jun 30, 2024 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Red Hat Enterprise Linux 6 (ELS) end of service life (EOSL) date?
Red Hat lists the end of service life for the Red Hat Enterprise Linux 6 (ELS) as Jun 30, 2024.
Can I keep using the Red Hat Enterprise Linux 6 (ELS) after its EOSL date?
Yes. EOSL means Red Hat stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Red Hat Enterprise Linux 6 (ELS) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Red Hat Enterprise Linux 6 (ELS)
602 published CVEs affect the Red Hat Enterprise Linux 6 (ELS), including 258 rated critical or high severity. Red Hat no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2023-34152 | CRITICAL | 9.8 | May 30, 2023 | A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. |
| CVE-2021-3773 | CRITICAL | 9.8 | Feb 16, 2022 | A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks. |
| CVE-2021-3466 | CRITICAL | 9.8 | Mar 25, 2021 | A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.9.70 is vulnerable. |
| CVE-2014-4650 | CRITICAL | 9.8 | Feb 20, 2020 | The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator. |
| CVE-2014-8089 | CRITICAL | 9.8 | Feb 17, 2020 | SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte. |
| CVE-2019-14896 | CRITICAL | 9.8 | Nov 27, 2019 | A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP. |
| CVE-2014-3585 | CRITICAL | 9.8 | Nov 22, 2019 | redhat-upgrade-tool: Does not check GPG signatures when upgrading versions |
| CVE-2013-4409 | CRITICAL | 9.8 | Nov 4, 2019 | An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests. |
| CVE-2018-18314 | CRITICAL | 9.8 | Dec 7, 2018 | Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |
| CVE-2018-18311 | CRITICAL | 9.8 | Dec 7, 2018 | Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |
| CVE-2018-18312 | CRITICAL | 9.8 | Dec 5, 2018 | Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |
| CVE-2018-14667 | CRITICAL | 9.8 | Nov 6, 2018 | The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData. |
| CVE-2018-17456 | CRITICAL | 9.8 | Oct 6, 2018 | Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character. |
| CVE-2011-2767 | CRITICAL | 9.8 | Aug 26, 2018 | mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes. |
| CVE-2018-5096 | CRITICAL | 9.8 | Jun 11, 2018 | A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6. |
| CVE-2018-5095 | CRITICAL | 9.8 | Jun 11, 2018 | An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58. |
| CVE-2018-5091 | CRITICAL | 9.8 | Jun 11, 2018 | A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox < 58. |
| CVE-2017-7809 | CRITICAL | 9.8 | Jun 11, 2018 | A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. |
| CVE-2017-7802 | CRITICAL | 9.8 | Jun 11, 2018 | A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially exploitable crash may occur when the freed elements are accessed. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. |
| CVE-2017-7801 | CRITICAL | 9.8 | Jun 11, 2018 | A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. |
Showing the 20 most severe of 602 known CVEs.
Get Third Party SupportRelated Red Hat Products
All Red Hat products →Red Hat Enterprise Linux 9 (Upcoming ELS)
EOSL: May 31, 2036
Red Hat Enterprise Linux 8 (Upcoming ELS)
EOSL: May 31, 2033
Red Hat Enterprise Linux 4
EOSL: Mar 31, 2017
Red Hat Enterprise Linux 10 (Upcoming ELS)
EOSL: May 31, 2039
Red Hat Enterprise Linux 5 (ELS)
EOSL: Nov 30, 2020
Red Hat Enterprise Linux 7 (ELS)
EOSL: May 31, 2029