Funny; our RHEL systems were a nightmare for compliance actually. Most of the tools the auditor/pentester type people use only search for, (completely fake example) libfoo 1.x.2 having a security hole, and redhat's libfoo 1.x.2-wibble13 even though it has a backported fix, is flagged as vulnerable.
For each one of these packages, it's a crazy process to prove that the CVE they reported isn't actually there, and it delays our accreditation to the point where it was easier for us to change distro than go thorough hundreds of these..