Red Hat released Moderate-severity kernel updates for Red Hat Enterprise Linux 9 and 10 to remediate CVE-2024-36357, a transient-execution flaw in certain AMD processors. A local attacker with low privileges could potentially infer data held in the L1D cache, exposing sensitive information across privilege boundaries; Red Hat rates the issue CVSS 5.6.
For RHEL 9, fixes are provided through RHSA-2025:19930 and RHSA-2025:20518; RHEL 10 is addressed by RHSA-2025:20095. RHSA-2025:19930 also fixes CVE-2024-36350 and adds a conditional IBPB mitigation for CVE-2025-40300 (VMSCAPE). Administrators should install the applicable kernel updates and reboot systems for the protections to take effect; RHEL 6, 7, and 8 kernel packages are out of support scope and should be considered affected under Red Hat policy.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:20518 for the RHEL 9 kernel and RHSA-2025:20095 for the RHEL 10 kernel, addressing CVE-2024-36357.
Red Hat published RHSA-2025:19930, a Moderate-severity RHEL 9 kernel update that fixes CVE-2024-36357 alongside CVE-2024-36350 and adds a conditional IBPB mitigation for CVE-2025-40300. Systems must be rebooted after installation for the updated kernel to take effect.
Red Hat released RHBA-2025:15878, fixing CVE-2024-36357 in the Red Hat Enterprise Linux 9 linux-firmware package.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.