Red Hat released updated OpenShift Dev Spaces 3 container images through the Red Hat Container Registry, incorporating backported security fixes from RHSA-2023:7077. The updated dashboard, plugin-registry, and UDI images are available for x86_64, ppc64le, and s390x; organizations should upgrade the images and rebuild dependent container images.
The remediation covers numerous Linux kernel issues, including CVE-2022-3594, which can let a remote attacker force excessive logging through the Realtek r8152 USB Ethernet driver, and local denial-of-service flaws in the VMware graphics driver: CVE-2022-40133 and CVE-2022-38457. It also includes CVE-2022-45869, a KVM race condition that can allow a low-privileged nested-virtualization guest user to crash or corrupt host memory. Where updates cannot be applied immediately, Red Hat recommends blacklisting unneeded r8152 or vmwgfx kernel modules and disabling nested virtualization for the KVM issue.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHBA-2023:7328, updating OpenShift Dev Spaces 3 container images with backported security fixes from RHSA-2023:7077, including fixes for numerous Linux kernel vulnerabilities. Users were advised to upgrade the images and rebuild dependent images.
Red Hat released RHSA-2023:6901 and RHSA-2023:7077, fixing CVE-2022-3594, CVE-2022-40133, CVE-2022-38457, and CVE-2022-45869 in applicable RHEL 8 kernel and kernel-rt packages.
RHSA-2023:6583 fixed CVE-2022-3594 and the vmwgfx use-after-free vulnerabilities CVE-2022-40133 and CVE-2022-38457 in the RHEL 9 kernel.
Red Hat released RHSA-2023:4377 and RHSA-2023:4378 to fix CVE-2022-45869 in the RHEL 9 kernel and kernel-rt packages. The KVM direct_page_fault() race can let a low-privileged guest user crash or corrupt memory on a host when nested virtualization and the TDP MMU are enabled.
Rohit Keshri reported CVE-2022-3594, a remotely triggerable excessive-logging flaw in the Realtek r8152 USB network driver's intr_callback function.
CVE-2022-38457, a use-after-free flaw in the Linux vmwgfx driver's vmw_cmd_res_check function that can allow a local attacker to crash a system, was made public.
Red Hat released RHSA-2024:4823 and RHSA-2024:4831 to fix CVE-2022-40133 and CVE-2022-38457 in the RHEL 9.2 EUS kernel and kernel-rt packages.
RHSA-2024:1404 fixed CVE-2022-3594, both vmwgfx use-after-free flaws CVE-2022-40133 and CVE-2022-38457, and the KVM race CVE-2022-45869 in the RHEL 8.8 EUS kernel.
RHSA-2024:1188 fixed CVE-2022-45869 in the RHEL 8.6 EUS kernel and Red Hat Virtualization 4 for RHEL 8.
RHSA-2024:0930 fixed CVE-2022-40133 and CVE-2022-38457, two vmwgfx driver use-after-free vulnerabilities, in the RHEL 8.6 EUS kernel and Red Hat Virtualization 4 for RHEL 8.
RHSA-2024:0724 fixed the excessive-logging r8152 driver vulnerability CVE-2022-3594 in the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 for RHEL 8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.