Red Hat released updated Linux kernel packages for Red Hat Enterprise Linux 8.6 extended-support channels and RHEL 8.8 supported update channels, remediating CVE-2022-3640, a Bluetooth L2CAP use-after-free flaw in l2cap_conn_del. The vulnerability can allow compromise of confidentiality, integrity, and availability from an adjacent network under specific conditions; Red Hat rates it Moderate (CVSS 7.1), while NVD rates it 8.8. RHEL 7, 8, 9, and Red Hat Virtualization 4 product streams received fixes, while RHEL 6 is not affected.
RHSA-2024:1877 covers RHEL 8.6 EUS and associated ELL, AUS, TUS, SAP, virtualization-host, and CodeReady Linux Builder channels, while RHSA-2024:2621 supplies kernel 4.18.0-477.55.1.el8_8 for RHEL 8.8 on x86_64, s390x, ppc64le, and aarch64. The advisories also address other kernel defects, including AMD CPU, ext4, x86 emulation, veth/GRO, GSM multiplexing, virtual-machine-monitor, and information-disclosure issues. Red Hat reports no generally deployable mitigation for the affected Bluetooth flaw; organizations should install the applicable errata and reboot systems to load the updated kernel.

See real exploitation activity before you spend the cycle.
18 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:22910 and RHSA-2025:22914, fixing CVE-2022-3640 in RHEL 7 Extended Lifecycle Support kernel and kernel-rt packages.
Red Hat issued Important advisory RHSA-2024:6993 for RHEL 8.8 extended-support and related channels, supplying kernel version 4.18.0-477.74.1.el8_8. The update remediated 38 vulnerabilities, including UIO, SMB, netfilter, Bluetooth L2CAP, networking, and filesystem flaws; Red Hat required systems to reboot after installation.
Red Hat issued Important advisory RHSA-2024:2621, providing kernel 4.18.0-477.55.1.el8_8 for RHEL 8.8 supported update channels. The advisory fixed CVE-2022-3640 and CVE-2021-33631, as well as Bluetooth information-disclosure, GSM multiplexing, and int80 syscall-handling flaws.
Red Hat issued Moderate-severity advisory RHSA-2024:1877, delivering kernel 4.18.0-372.100.1.el8_6 for RHEL 8.6 extended-support channels and fixing CVE-2022-3640 alongside five other vulnerabilities. The update also covered Red Hat Virtualization Host 4 and required affected systems to reboot after installation.
Red Hat issued RHSA-2024:1607 and RHSA-2024:1614 to fix CVE-2021-33631 in RHEL 8 kernel and kernel-rt packages.
Red Hat issued RHSA-2023:7077 and RHSA-2023:6901, providing fixes for CVE-2022-3640 in RHEL 8 kernel and kernel-rt packages, respectively.
Red Hat issued Important advisory RHSA-2023:4789 for RHEL 8.6 servicing channels, providing kernel 4.18.0-372.70.1.el8_6. The update fixed the Bluetooth L2CAP use-after-free CVE-2022-42896 and multiple additional kernel vulnerabilities; Red Hat required systems to reboot after installation.
Red Hat issued Important advisory RHSA-2023:4517 for RHEL 8, supplying kernel 4.18.0-477.21.1.el8_8. The update fixed the distinct Bluetooth L2CAP use-after-free CVE-2022-42896, along with multiple tcindex, performance-event, XFS, and driver vulnerabilities.
Red Hat released RHSA-2023:2736 and RHSA-2023:2951 for RHEL 8, fixing CVE-2021-33656, an out-of-bounds kernel memory write reachable through malicious font data supplied to the PIO_FONT ioctl.
Red Hat issued RHSA-2023:2148 to fix CVE-2022-3640 and CVE-2021-33631 in RHEL 9 kernel-rt packages.
Red Hat issued RHSA-2023:2458 to update RHEL 9 kernel packages, fixing the Bluetooth L2CAP use-after-free flaw CVE-2022-3640 and the openEuler filesystem integer-overflow flaw CVE-2021-33631.
Marian Rehak reported CVE-2023-28466, a race condition in the Linux kernel's do_tls_getsockopt TLS socket-option path caused by a missing lock_sock call. The flaw could result in a use-after-free or NULL-pointer dereference and was later fixed upstream in Linux 6.3-rc2.
Linux kernel commit 42cf46dea905a80f6de218e837ba4d4cc33d6979 fixed a Bluetooth L2CAP use-after-free in l2cap_conn_del() by retaining an additional reference after creating an A2MP channel. The flaw could be triggered during hci_error_reset-driven Bluetooth teardown, causing l2cap_chan_unlock() to access a freed channel.
CVE-2024-26698 was assigned for a race condition between netvsc_probe and netvsc_remove in the Linux kernel's hv_netvsc Hyper-V network driver. Red Hat addressed the issue through advisories for RHEL 9.2 EUS and several RHEL 8 streams, including RHSA-2024:4823, RHSA-2024:4831, RHSA-2024:5101, RHSA-2024:6297, and RHSA-2024:6993.
Red Hat addressed CVE-2023-52522, a Linux kernel neighbor-table periodic-worker flaw involving possible store tearing in neigh_periodic_work(), through advisories for RHEL 9 and multiple RHEL 8 variants. The listed advisories include RHSA-2024:2394, RHSA-2024:7000, RHSA-2024:7001, RHSA-2024:6993, RHSA-2024:6998, RHSA-2024:9497, and RHSA-2024:9498.
Red Hat issued RHSA-2024:2093 to fix CVE-2021-33631 in the RHOL-5.7-RHEL-8 openshift-logging/cluster-logging-operator-bundle component.
Red Hat issued RHSA-2024:1836 and RHSA-2024:1840 to fix CVE-2021-33631 in RHEL 9.0 Extended Update Support kernel and kernel-rt packages.
Red Hat issued RHSA-2024:1653, fixing CVE-2021-33631 in RHEL 8.6 Extended Update Support kernel packages and Red Hat Virtualization 4 for RHEL 8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.