Red Hat

Red Hat Enterprise Linux 8 (Upcoming ELS)

Red Hat Enterprise Linux 8 (Upcoming ELS)

Third-party support for the Red Hat Enterprise Linux 8 (Upcoming ELS): 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.

EOSL Date: May 31, 2033
Issue Management

24/7 engineers own your Red Hat Enterprise Linux 8 (Upcoming ELS) incidents end to end.

Vulnerability Remediation

Mitigation and patch-around guidance when the vendor no longer ships fixes.

Compliance Maintenance

Controls evidence and documentation that keep auditors satisfied.

Specifications

product
rhel
release
8
product Label
Red Hat Enterprise Linux
release Label
8 (Upcoming ELS)
codename
lts
latest Version
8.10
release Date
2019-05-07
maintained
true
source Url
https://endoflife.date/rhel

Lifecycle Dates

End of Service Life
May 31, 2033
Last OEM Support
May 31, 2024

Get Third Party Support

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.

OEM vs. 3rd Party Support

See how third-party support compares to the vendor contract for Red Hat Enterprise Linux 8 (Upcoming ELS) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.

FeatureOEM Support3rd Party Support
Post-EOSL Support
Break/Fix Support
Until EOSL
24/7 Monitoring
Vulnerability Scanning & Remediation
Managed Operations
Procedure & Configuration Review
Compliance & Audit Documentation
Limited
Discounted Migration to Other Platforms

Why Choose 3rd Party Support for Red Hat Enterprise Linux 8 (Upcoming ELS)?

Vulnerability Remediation

Scanning, mitigation and patch-around guidance for Red Hat Enterprise Linux 8 (Upcoming ELS) when the vendor no longer ships fixes.

Compliance Maintenance

Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.

24/7 Expert Support

Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.

Red Hat Enterprise Linux 8 (Upcoming ELS) Support: Frequently Asked Questions

Is the Red Hat Enterprise Linux 8 (Upcoming ELS) still supported?

Yes. The Red Hat Enterprise Linux 8 (Upcoming ELS) is currently supported by Red Hat, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.

When is the Red Hat Enterprise Linux 8 (Upcoming ELS) end of service life (EOSL) date?

Red Hat lists the end of service life for the Red Hat Enterprise Linux 8 (Upcoming ELS) as May 31, 2033.

Can I keep using the Red Hat Enterprise Linux 8 (Upcoming ELS) after its EOSL date?

Yes. EOSL means Red Hat stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.

How much does third-party support for the Red Hat Enterprise Linux 8 (Upcoming ELS) cost?

Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.

Known Vulnerabilities Affecting Red Hat Enterprise Linux 8 (Upcoming ELS)

1048 published CVEs affect the Red Hat Enterprise Linux 8 (Upcoming ELS), including 413 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.

CVESeverityCVSSPublishedSummary
CVE-2026-53006CRITICAL9.8Jun 24, 2026In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr when net_dbg_ratelimited() is called in the slow path. - Avoid potential future misuse after pskb_pull() call.
CVE-2026-53002CRITICAL9.8Jun 24, 2026In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflow check. Increase buffer size in mangle_content_len() while at it. BUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5/0x1270 Write of size 1 at addr [..] vsnprintf+0xea5/0x1270 sprintf+0xb1/0xe0 mangle_content_len+0x1ac/0x280 nf_nat_sdp_session+0x1cc/0x240
CVE-2022-30600CRITICAL9.8May 18, 2022A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
CVE-2022-30599CRITICAL9.8May 18, 2022A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
CVE-2021-20325CRITICAL9.8Feb 18, 2022Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstrea
CVE-2021-3773CRITICAL9.8Feb 16, 2022A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.
CVE-2020-36329CRITICAL9.8May 21, 2021A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2020-36328CRITICAL9.8May 21, 2021A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2018-25014CRITICAL9.8May 21, 2021A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
CVE-2018-25011CRITICAL9.8May 21, 2021A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
CVE-2021-3466CRITICAL9.8Mar 25, 2021A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.9.70 is vulnerable.
CVE-2021-20232CRITICAL9.8Mar 12, 2021A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.
CVE-2021-20231CRITICAL9.8Mar 12, 2021A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
CVE-2020-27846CRITICAL9.8Dec 21, 2020A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVE-2019-15606CRITICAL9.8Feb 7, 2020Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
CVE-2019-15605CRITICAL9.8Feb 7, 2020HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
CVE-2019-19334CRITICAL9.8Dec 6, 2019In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.
CVE-2019-19333CRITICAL9.8Dec 6, 2019In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.
CVE-2019-19012CRITICAL9.8Nov 17, 2019An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.
CVE-2019-14813CRITICAL9.8Sep 6, 2019A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

Showing the 20 most severe of 1048 known CVEs.

Get Third Party Support

Related Red Hat Products

All Red Hat products →
Red Hat Enterprise Linux 8 (Upcoming ELS)
Save 40-70% vs OEM
Get Third Party Support