Red Hat released Important kernel security updates for RHEL 8, RHEL 8 Real Time, and RHEL 9 Extended Update Support/SAP channels, remediating 19 to 21 Linux-kernel vulnerabilities. The affected packages include standard RHEL 8 kernel 4.18.0-513.18.1.el8_9, RHEL 8 Real Time kernel 4.18.0-513.18.1.rt7.320.el8_9, and RHEL 9.0 EUS kernel 5.14.0-70.93.2.el9_0 across x86_64, aarch64, s390x, and ppc64le systems.
The fixes include CVE-2023-5717, a heap out-of-bounds write in the Performance Events perf_read_group() path that can enable local privilege escalation, and CVE-2023-46813, in which faulty SEV-ES MMIO access validation and a race condition can give a local user arbitrary kernel-memory write capability. The advisories also address use-after-free, NULL-pointer dereference, out-of-bounds access, resource-exhaustion, and side-channel flaws in networking, storage, Bluetooth, HID, SMB, virtualization, and performance-monitoring components. Organizations should deploy the applicable kernel packages and reboot affected hosts to activate the fixes.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:1250 for RHEL 9.0 Extended Update Support and applicable SAP, CodeReady Linux Builder EUS, and four-year update channels. Kernel 5.14.0-70.93.2.el9_0 fixed 21 CVEs, including the perf_read_group out-of-bounds write CVE-2023-5717, and required affected systems to be rebooted.
Red Hat issued Moderate-severity advisory RHSA-2024:1188 for RHEL 8.6 Extended Update Support and associated offerings, providing kernel 4.18.0-372.95.1.el8_6. The update remediated 14 CVEs, including SMB/CIFS out-of-bounds read CVE-2023-6606 and CIFS client RCE CVE-2024-0565; affected systems require a reboot.
Red Hat issued RHSA-2024:0897, providing kernel 4.18.0-513.18.1.el8_9 for RHEL 8 and RHEL 8.10 Extended Life Cycle across x86_64, aarch64, ppc64le, and s390x. The update fixed 19 flaws, including CVE-2023-5717 and the SEV-ES privilege-escalation vulnerability CVE-2023-46813, and required a reboot.
Red Hat issued RHSA-2024:0881 for RHEL 8 Real Time, Real Time for NFV, and x86_64 RHEL 8.10 Extended Life Cycle deployments. Kernel-rt 4.18.0-513.18.1.rt7.320.el8_9 remediated 19 vulnerabilities, including CVE-2023-5717 and CVE-2023-46813; a reboot was required.
Rohit Keshri reported CVE-2023-6606, an out-of-bounds read in the Linux SMB/CIFS client's smbCalcSize function. An attacker-controlled SMB WordCount could make the calculated Byte Count pointer fall outside the received SMB frame, potentially crashing the system or disclosing kernel information.
CVE-2023-2162 was described in the Linux SCSI mailing list as a use-after-free flaw in iscsi_sw_tcp_session_create in the kernel iSCSI TCP implementation. Exploitation could leak internal kernel information.
CVE-2023-6546 was identified in the Linux kernel GSM 07.10 TTY multiplexor, where concurrent GSMIOC_SETCONF calls can trigger a use-after-free of struct gsm_dlci during multiplexer restart. The flaw can allow a local unprivileged user to escalate privileges; upstream fixed it in commit 3c4f8333b582487a2d1e02171f1465531cde53e3, with Fedora and multiple RHEL streams receiving fixes.
Upstream commit 32671e3799ca2e4590773fd0e63aaa4229e50c06 fixed CVE-2023-5717 in the Linux perf component, where perf_read_group() could write beyond an allocated buffer and permit local privilege escalation. Fedora shipped the remediation in stable Linux 6.5.9 kernel updates.
Upstream Linux kernel 6.5.9 fixed CVE-2023-46813, in which flawed SEV-ES MMIO access checks, instruction emulation, and a race condition could give a local attacker arbitrary kernel-memory write access and enable privilege escalation. Fedora also incorporated the fix through its 6.5.9 stable kernel updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.