Decision Guide — RHEL 7 & 8

Red Hat Patches Stop on a Schedule:
Upgrade, Buy ELS, or Go Third-Party?

Updated July 21, 2026 · endoflife.ai · Decision Guide · Linux / Infrastructure

Current Status

Where each RHEL version stands right now (dates from our vendor-checked RHEL lifecycle table):

VersionPhaseWhat that means
RHEL 7 Past EOLMaintenance ended June 30, 2024No patches on a standard subscription. Red Hat ELS (paid add-on) runs to May 2029.
RHEL 8 MaintenanceFull support ended May 31, 2024Security fixes continue to May 31, 2029 — plan the exit now, not in 2029.
RHEL 9 Full supportFull support to May 31, 2027Maintenance then runs to May 2032. Safe today; the natural upgrade target.
RHEL 10 CurrentReleased May 2025Full support to 2030, maintenance to 2035. The long-runway target for new builds.

If you searched "Red Hat support" because a RHEL 7 box stopped getting patches: that's not a subscription glitch — the standard support window closed in June 2024, and every CVE since then is unpatched on your system unless you have ELS or third-party coverage.

Running RHEL 7 or 8 past its window?
Extended support for EOL RHEL exists — from Red Hat and from third parties, at very different price points. endoflife.ai helps you find the EOL support you need, the moment you need it: tell us your situation and we'll match you with the right option.
Free · no obligation · we match you with the right provider
Get Matched With a Provider →

The Decision Flow

Most RHEL 7 and 8 teams land on one of three paths. Work through it in order:

Q1: Can you upgrade in place (Leapp to RHEL 8/9) within your risk window?
Yes
Upgrade PathRun Red Hat's Leapp in-place upgrade on a controlled timeline — RHEL 7 → 8 → 9. Your subscription already covers it; the cost is engineering time and app re-validation, not new licensing.
No
Q2: Is the workload compliance-critical or internet-facing?
Yes
Extended Support NowThe exposure is too high to leave unpatched. Two routes: Red Hat ELS (official, priciest, critical-fix scope) or a third-party extended-support vendor (independent patching, often cheaper). Coverage first, migration planning in parallel.
No
Planned UpgradeLower exposure buys planning room — but set a hard deadline and put the 2029 RHEL 8 maintenance cutoff on the roadmap now. "Internal-only" workloads have a way of becoming internet-facing without ceremony.

Upgrade vs Red Hat ELS vs Third-Party vs Do Nothing

Factor Upgrade (Leapp) Red Hat ELS Third-Party Support Do Nothing
Cost profile Engineering time; no new licensing Highest recurring — add-on on top of subscription Recurring fee, typically below ELS No spend; risk accrues silently
Time-to-safe Weeks–months per fleet Days — coverage from contract signing Days — coverage from contract signing Never
Patch scope Full patch stream on the new version Critical/important security errata only Varies by vendor — check CVE scope None
Compliance posture Clean — current vendor-supported platform Defensible — official vendor coverage Defensible — documented active coverage Open audit finding

What Teams in Your Position Typically Weigh

RHEL estates skew large and old. The single-app shop with a handful of RHEL 7 hosts usually finds Leapp upgrades cheaper than a year of any extended support — the work is scoping app compatibility, not the OS mechanics. The 500-host estate with vendor-certified appliances, custom kernel modules, or software the vendor never re-validated past RHEL 7 is a different story: there, a support bridge (ELS or third-party) is often the only honest way to stay patched while a multi-quarter migration runs.

The ELS-vs-third-party question usually comes down to three things: budget (ELS carries a premium), scope (ELS covers critical/important errata; some third parties cover more, some less — read the CVE policy), and procurement comfort (some compliance regimes and vendor relationships favor the official Red Hat route; many accept any documented active coverage).

One pattern worth naming honestly: extended support is frequently treated as a permanent fix once it's in place. It works best explicitly scoped as a bridge with an end date attached to an upgrade plan — RHEL 7 ELS itself ends in May 2029, so even the bridge has a hard far bank.

Not sure which path fits your RHEL footprint?

The support you need, the moment you need it — tell us your RHEL version count and constraints and we'll match you with a provider suited to it, upgrade help or extended-support coverage.

Free · no obligation · we match you with the right provider
Get Matched →

Frequently Asked Questions

Does Red Hat still support RHEL 7?

Standard support ended June 30, 2024 — no more security patches on a regular subscription. Red Hat's Extended Life-cycle Support (ELS) add-on continues critical security fixes (currently tracked to May 2029). Without ELS or third-party coverage, every CVE since June 2024 is unpatched on your system.

What is Red Hat Extended Life-cycle Support (ELS)?

Red Hat's official paid add-on that extends critical-severity patching after a version's maintenance phase ends. It buys migration time, at a premium price and a narrower scope: critical and important security errata only — no bug fixes, no new features.

How long will RHEL 8 keep getting security patches?

RHEL 8 is in maintenance: security fixes continue until May 31, 2029, with ELS projected through 2033. Not an emergency — but a roadmap item, and upgrade projects at fleet scale routinely take longer than teams expect.

Do I have to buy ELS from Red Hat, or are there alternatives?

Alternatives exist: third-party extended-support vendors patch EOL Enterprise Linux independently of Red Hat, often at lower cost — and an in-place Leapp upgrade to RHEL 8/9 avoids the question entirely. The right answer depends on host count, compliance posture, and how real your migration timeline is.

Ready to get RHEL patched again — or bridge it safely while you upgrade?

We track the dates so you find the support you need the moment you need it — matched to your situation, not a sales list.

Free · no obligation · we match you with the right provider
Get Matched → View RHEL lifecycle data

The Monthly EOL Digest™

Once a month — critical end-of-life dates, CVE blind spots, and lifecycle changes worth knowing about.