Red Hat released RHSA-2023:7423 for Red Hat Enterprise Linux 7, updating the kernel to 3.10.0-1160.105.1.el7 across x86_64, s390x, ppc64, and ppc64le systems. The advisory remediates multiple use-after-free vulnerabilities in Linux traffic-control classifiers—including cls_fw, cls_u32, and cls_route—that could allow a local attacker to escalate privileges, as well as flaws in the sch_qfq scheduler component.
The update also mitigates CVE-2022-40982 (Downfall/Gather Data Sampling), a moderate-severity Intel transient-execution side channel through which a low-privileged local attacker could infer stale data from vector registers on the same physical CPU core. Red Hat recommends installing the updated kernel and applicable microcode updates, including microcode_ctl-20230808; affected RHEL 7 systems must be rebooted for the kernel fixes to take effect.

See real exploitation activity before you spend the cycle.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2024:1831 for RHEL 6 Extended Lifecycle Support, providing kernel 2.6.32-754.53.1.el6. The update remediates CVE-2023-31436, CVE-2023-3611, CVE-2023-3776, and CVE-2023-4921 in Linux traffic-control and network-scheduling components; affected systems require a reboot.
Red Hat issued Important advisory RHSA-2023:7423 and RHSA-2023:7424 for RHEL 7, updating the kernel and kernel-rt packages. RHSA-2023:7423 supplied kernel version 3.10.0-1160.105.1.el7 and remediated CVE-2022-40982 plus net/sched flaws including CVE-2023-4128 and CVE-2023-4206 through CVE-2023-4208; systems require a reboot after installation.
Red Hat issued RHSA-2023:6901 and RHSA-2023:7077 for RHEL 8, providing kernel-rt and kernel fixes for CVE-2022-40982, respectively. These advisories are also listed as addressing the overlapping net/sched use-after-free vulnerabilities.
Red Hat issued RHSA-2023:5221, RHSA-2023:5244, and RHSA-2023:5255 for RHEL 8 kernel-rt, kpatch-patch, and kernel packages to remediate the CVE-2023-3776 cls_fw use-after-free vulnerability.
Red Hat released RHSA-2022:7444 for the RHEL 8 kernel-rt package and RHSA-2022:7683 for the RHEL 8 kernel package to remediate CVE-2022-29581, a use-after-free flaw in the cls_u32 network classifier's u32_change function.
Guilherme de Almeida Suckevicz reported CVE-2022-29581, a use-after-free in the Linux net/sched cls_u32 u32_change function caused by incorrect reference-count updates. The flaw could allow a local attacker to crash a system and potentially escalate privileges or leak kernel information.
Red Hat documents CVE-2023-4128 as rejected as a duplicate of the related Linux kernel classifier vulnerability. It also advises blacklisting the cls_u32 module to prevent automatic module loading as a mitigation for the related use-after-free flaws.
A use-after-free vulnerability in the Linux net/sched sch_qfq traffic-control scheduler can allow local privilege escalation when an attacker configures sch_plug as a QFQ class and sends network packets. Red Hat remediated CVE-2023-4921 through advisories covering RHEL 6, 7, and 8 support streams, while Fedora fixed it in Linux 6.5.4 stable-kernel updates.
Red Hat issued errata for the net/sched classifier use-after-free flaws across RHEL 7, 8, and 9 and specialized EUS, SAP, telecommunications, and advanced-support streams. Listed advisories include RHSA-2023:5235, RHSA-2023:5238, RHSA-2023:5548, RHSA-2023:5575, RHSA-2023:5580, RHSA-2023:5588, RHSA-2023:5589, RHSA-2023:5603, RHSA-2023:5604, RHSA-2023:5627, RHSA-2023:5628, RHSA-2023:5775, RHSA-2023:5794, RHSA-2023:7418, RHSA-2023:7419, RHSA-2023:7539, RHSA-2023:7558, RHSA-2024:0261, and RHSA-2024:0262.
Red Hat issued additional microcode- and kernel-related advisories for CVE-2022-40982 across RHEL 7, 8, and 9, including Extended Update Support, Advanced Update Support, Telecommunications Update Service, and SAP Solutions offerings. The listed advisories include RHSA-2023:6583, RHSA-2023:7370, RHSA-2023:7379, RHSA-2023:7539, RHSA-2024:0412, RHSA-2024:0562, RHSA-2024:0563, RHSA-2024:1250, RHSA-2024:1268, RHSA-2024:1269, and RHSA-2024:1306.
Red Hat issued RHSA-2024:3319 to fix CVE-2022-40982 in the RHEL 7.7 Advanced Update Support kernel.
A use-after-free flaw in the Linux net/sched cls_fw component can permit local privilege escalation when tcf_change_indev() fails during fw_set_parms() processing after tcf_bind_filter() changes a reference count. An attacker able to control that counter can reduce it to zero and free an object that remains referenced; upstream fixed the issue in commit 0323bce598eea038714f941ce2b22541c46d488f.
CVE-2023-4128 was identified in the Linux net/sched cls_fw, cls_u32, and cls_route classifiers, where incorrect filter handling can cause a use-after-free condition and local privilege escalation. Red Hat's CVE overlaps with CVE-2023-4206, CVE-2023-4207, and CVE-2023-4208, which Google assigned concurrently for the same patch set.
CVE-2022-40982 (Gather Data Sampling) was identified as a transient-execution side-channel flaw in certain Intel processors. A local low-privileged attacker can use gather instructions to infer limited stale vector-register data from the same physical CPU core; Intel TDX-capable processors are not affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
19 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourcegit.kernel.org
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.