Red Hat remediated CVE-2024-53241, a moderate-severity Linux kernel flaw in the x86 Xen paravirtualized iret hypercall path. The Xen hypercall page could be unsafe under speculative execution, potentially allowing a low-privileged attacker to disclose sensitive information; Red Hat scored the issue 5.7 CVSS v3.1, while NVD scored it 5.5. The fix encodes the required iret sequence directly in xen-asm.S rather than jumping through the Xen hypercall page.
RHEL 8 received fixes in April 2025, including kernel-rt build 4.18.0-553.50.1.rt7.391.el8_10 through RHSA-2025:3894; affected systems require a reboot. A related RHEL 8 kernel build, 4.18.0-553.50.1.el8_10, caused early-boot invalid-opcode panics in some Xen HVM guests on XenServer, IBM Cloud Classic, and legacy-BIOS AWS t2.xlarge instances, but 4.18.0-553.51.1.el8_10 resolved the boot issue. Red Hat later released fixes for RHEL 9 and RHEL 10 kernels, while RHEL 9 kernel-rt and OpenShift Container Platform 4 RHCOS were designated will-not-fix.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:20518 for the RHEL 9 kernel and RHSA-2025:20095 for the RHEL 10 kernel to address CVE-2024-53241.
Red Hat released RHSA-2025:3893 for the RHEL 8 kernel and RHSA-2025:3894 for RHEL 8 kernel-rt, addressing CVE-2024-53241. RHSA-2025:3894 supplied kernel-rt version 4.18.0-553.50.1.rt7.391.el8_10 and required a reboot for the update to take effect.
Red Hat publicly listed CVE-2024-53241, a Linux kernel Xen paravirtualized iret-hypercall vulnerability associated with Xen Security Advisory XSA-466.
RHEL 8 kernel 4.18.0-553.51.1.el8_10 was reported to restore booting on affected Xen HVM guests after version 4.18.0-553.50.1.el8_10 caused invalid-opcode panics in xen_time_init.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.