Red Hat released Important-rated Linux kernel updates for RHEL 8 and RHEL 9, including RHEL 8.6 Extended Update Support, addressing numerous memory-safety, privilege-escalation, denial-of-service, and speculative-execution vulnerabilities. The updates cover flaws such as CVE-2024-1086, an nf_tables use-after-free vulnerability; CVE-2023-6546, a GSM multiplexing race condition that can enable privilege escalation; net/sched classifier issues CVE-2023-4128, CVE-2023-4206, CVE-2023-4207, and CVE-2023-4208; and Intel Gather Data Sampling (CVE-2022-40982).
The fixes also address CVE-2023-4155, a KVM double-fetch race affecting multi-vCPU AMD SEV-ES and SEV-SNP guests that could recursively invoke the VMGEXIT handler and exhaust kernel stack space. Red Hat noted that default CONFIG_VMAP_STACK protections mitigate the theoretical guest-to-host escape scenario on RHEL 8 and 9. Separate vmwgfx use-after-free flaws, CVE-2022-38457 and CVE-2022-40133, could allow a local user with DRM-device access to crash affected systems. Organizations should install the applicable kernel packages across supported architectures and reboot hosts to activate the fixes.

See real exploitation activity before you spend the cycle.
41 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2024:6997 for RHEL 9 and supported EUS, AUS, SAP, Extended Life Cycle, and CodeReady Linux Builder variants. The kernel update remediated 21 vulnerabilities, including UIO use-after-free CVE-2023-52439, qla2xxx double-free flaws CVE-2024-26929 and CVE-2024-26930, and KVM MMU overflow CVE-2024-26991; affected systems require a reboot.
Red Hat fixed CVE-2021-46984, a Kyber block I/O scheduler out-of-bounds read caused by CPU and hardware-context mismatches during I/O merging, in RHEL 8 through RHSA-2024:7000 and RHEL 8 kernel-rt through RHSA-2024:7001. The flaw can expose memory contents or cause system crashes; fixes for RHEL 9 and RHEL 9 kernel-rt were deferred.
Red Hat issued Important-rated RHSA-2024:7000 for RHEL 8, providing kernel version 4.18.0-553.22.1.el8_10 for x86_64, aarch64, ppc64le, and s390x, including specified RHEL 8.10 Extended Life Cycle variants. The update remediated numerous flaws, including CVE-2023-6040, CVE-2024-23848, CVE-2024-41040, CVE-2024-41090, and CVE-2024-41091, and requires a reboot.
Red Hat issued Important-rated RHSA-2024:7001 for RHEL 8 Real Time, Real Time for NFV, and RHEL 8.10 x86_64 Extended Life Cycle deployments. The kernel-rt 4.18.0-553.22.1.rt7.363.el8_10 update remediates numerous kernel flaws, including CVE-2023-6040, CVE-2024-26595, and multiple networking, Wi-Fi, filesystem, graphics, and driver vulnerabilities; a reboot is required.
Red Hat issued Moderate-rated RHSA-2024:6753 for RHEL 8.6 Advanced Mission Critical Update Support, SAP Solutions Update Services, and Telecommunications Update Service on x86_64 and ppc64le. The kernel 4.18.0-372.123.1.el8_6 update fixed ten issues affecting ext4, nftables, IPv6 Segment Routing, virtio-net, transparent huge pages, and BPF ring buffers, and requires a reboot.
Red Hat issued RHSA-2024:5101 and RHSA-2024:5102 to fix CVE-2022-48632 in RHEL 8 kernel and kernel-rt packages. The Moderate-severity flaw is a stack overflow in the Mellanox BlueField I2C controller driver's mlxbf_i2c_smbus_start_transaction() function, with practical impact assessed as availability-only.
Red Hat issued Moderate-rated RHSA-2024:4928, updating the RHEL 9 kernel across standard and selected EUS, AUS, SAP, Extended Life Cycle, and CodeReady Linux Builder channels. The update remediated numerous flaws, including CVE-2024-26773, CVE-2024-26737, CVE-2024-26852, CVE-2024-38580, and CVE-2023-52458; affected systems require a reboot.
Red Hat issued Important-rated RHSA-2024:3528 for RHEL Server Advanced Update Support 8.2 on x86_64, providing kernel version 4.18.0-193.135.1.el8_2. The update remediated CVE-2023-2166, CVE-2023-2176, CVE-2024-1086, and CVE-2023-52578; affected systems require a reboot after installation.
Red Hat remediated CVE-2023-6622, an nf_tables nft_dynset_init() NULL-pointer dereference that a local CAP_NET_ADMIN attacker can use to cause denial of service, in RHEL 8 through RHSA-2024:3138 and RHEL 8 kernel-rt through RHSA-2024:2950. Exploitation requires the ability to create user and network namespaces; RHEL 9 had previously received a fix in RHSA-2024:2394.
Red Hat issued Important-rated RHSA-2024:2697, providing automatically loaded kpatch-patch packages for affected RHEL 8.8 x86_64 and ppc64le offerings. The live patch remediates the nf_tables use-after-free CVE-2024-1086 and the GSM multiplexing privilege-escalation race CVE-2023-6546 without a conventional kernel reboot.
Zack Miele reported CVE-2024-27020, a medium-severity Linux kernel netfilter nf_tables vulnerability caused by a potential data race in __nft_expr_type_get(). The issue was fixed upstream in Linux 5.15.157, 6.1.88, 6.6.29, 6.8.8, and 6.9-rc5.
Red Hat documented CVE-2023-52578, a Linux network bridge issue involving data races in br_handle_frame_finish(), for which upstream changed the code to use DEV_STATS_INC(). Red Hat remediated the issue in RHEL 9 through RHSA-2024:2394 and across multiple RHEL 8 and extended-support product streams.
Red Hat issued Important-rated RHSA-2024:2394 for RHEL 9, updating Linux kernel packages and requiring a reboot for the changes to take effect. The advisory remediated numerous vulnerabilities, including GSM multiplexing privilege escalation CVE-2023-6546, nf_tables flaws CVE-2024-1085 and CVE-2024-1086, and the CIFS remote-code-execution issue CVE-2024-0565.
Robb Gatica reported Red Hat Bug 2273236 for CVE-2024-26773, a medium-severity flaw in ext4_mb_try_best_found() that could allocate filesystem blocks from a corrupted ext4 block group. The upstream fix prevents allocation from corrupted groups.
Red Hat issued RHSA-2024:1332, a RHEL 7 kernel-rt update addressing the known-exploited nf_tables use-after-free and double-free vulnerability CVE-2024-1086.
Red Hat remediated the vmwgfx NULL-pointer dereference CVE-2022-38096 in RHEL 8.2 kernel variants through RHSA-2024:1268 and RHSA-2024:1269. Additional RHEL 8.4, standard RHEL 8, and kernel-rt fixes followed through RHSA-2024:1367, RHSA-2024:1382, RHSA-2024:1607, and RHSA-2024:1614.
Red Hat issued Important-rated RHSA-2024:1253 for RHEL 9.0 Extended Update Support, supplying automatically loaded kpatch modules for x86_64 and ppc64le systems. The live patches remediate CVE-2023-2163, CVE-2023-3390, CVE-2023-3609, CVE-2023-4622, CVE-2023-6546, and CVE-2024-0646.
Red Hat issued the Important-rated RHSA-2024:1249 update for RHEL 7, providing kernel version 3.10.0-1160.114.2.el7. It remediated six vulnerabilities, including CVE-2022-42896, CVE-2023-4921, CVE-2023-45871, CVE-2023-38409, CVE-2024-1086, and CVE-2024-26602.
Red Hat released the Important-rated RHSA-2024:0930 kernel update for RHEL 8.6 Extended Update Support and associated channels, providing kernel version 4.18.0-372.93.1.el8_6. The update remediated 18 CVEs, including CVE-2022-38457, CVE-2022-40133, CVE-2023-6546, and CVE-2024-1086.
Tej Rathi reported CVE-2023-6040, an out-of-bounds access in nf_tables_newtable() caused by failure to reject invalid or unsupported Netfilter protocol-family values when creating a table. Upstream fixed the issue in commit f1082dd31fe461d482d69da2a8eccfeb7bf07ac2, and Red Hat later addressed it in RHEL 9 and RHEL 8 advisories.
RHSA-2023:6583 addressed CVE-2023-3358 in RHEL 9. The flaw is a potential NULL-pointer dereference in the Intel ISH HID driver's ishtp_cl_get_dma_send_buf() function when kcalloc() fails; it was fixed upstream in commit b3d40c3ec3dc4ad78017de6c3a38979f57aaaab8 and Fedora also fixed it in Linux 6.1.9 stable updates.
Red Hat issued RHSA-2023:6583, an Important security advisory providing an updated RHEL 9 kernel. It remediated numerous flaws, including CVE-2023-4155 and the vmwgfx use-after-free vulnerabilities CVE-2022-38457 and CVE-2022-40133.
Guilherme de Almeida Suckevicz described CVE-2023-2163, in which incorrect eBPF verifier pruning can mark unsafe code paths as safe. Exploitation can enable arbitrary kernel-memory reads and writes, local privilege escalation, and potential container escape.
A patch series for CVE-2023-4155, affecting AMD SEV-ES and SEV-SNP KVM guests with multiple vCPUs, was published. The flaw could recursively invoke the VMGEXIT handler and theoretically cause kernel-stack overflow or guest-to-host escape on configurations without stack guard pages.
Guilherme de Almeida Suckevicz reported CVE-2022-3565, a medium-severity use-after-free flaw in Linux kernel ISDN-over-IP (l1oip) timer handlers. Manipulation of timer handling involving del_timer in l1oip_core.c can trigger the condition.
Red Hat documented CVE-2024-26665, a Moderate Linux kernel flaw in handling non-linear socket buffers while calculating checksums for ICMPv6 Path MTU error messages. The out-of-bounds read can expose memory or crash a system; RHEL 8 kernel and kernel-rt fixes were delivered in RHSA-2024:7000 and RHSA-2024:7001, while the standard RHEL 9 kernel was already fixed in 9.4.0.
Red Hat documented CVE-2023-52439, in which a race between uio_unregister_device() and uio_open() can leave uio_open() using a freed idev object and potentially cause a later double free. The fix atomically retrieves idev and increments its device reference while holding minor_lock; Red Hat issued fixes across multiple RHEL 8 and RHEL 9 product streams.
Red Hat documented CVE-2024-26880, a Linux kernel device-mapper vulnerability resolved by ensuring the resume method is called during internal suspend operations. Red Hat addressed it in RHEL 9.2 EUS, RHEL 9, and RHEL 8 advisories including RHSA-2024:4823, RHSA-2024:4831, RHSA-2024:4928, RHSA-2024:7000, and RHSA-2024:7001.
Red Hat addressed the nf_tables verdict-parameter flaw tracked as CVE-2024-1086 in RHEL 8 through RHSA-2024:2950 and RHSA-2024:3138. CVE-2024-26609, initially assigned for the same QUEUE/DROP verdict-parameter issue, was rejected upstream as a duplicate.
Red Hat documented CVE-2023-3390, a use-after-free in nf_tables_api.c that occurs when a set is both named and marked anonymous during an nftables batch transaction. The issue was fixed upstream in commit 1240eb93f0616b21c675416516ff3d74798fdc97; CVE-2023-3117 was classified as a duplicate assignment.
Red Hat documented CVE-2023-3773, in which the Linux XFRM xfrma_policy omitted an NLA_U32 validation entry for XFRMA_MTIMER_THRESH. A local attacker with CAP_NET_ADMIN can submit an empty attribute to trigger a four-byte out-of-bounds read and potentially leak heap data; RHEL 9 was fixed through RHSA-2023:6583 and Fedora through Linux 6.4.12 stable updates.
Red Hat addressed CVE-2022-38457 and CVE-2022-40133 for RHEL 8.8 Extended Update Support through RHSA-2024:1404 and for RHEL 9.2 Extended Update Support through RHSA-2024:4823 and RHSA-2024:4831.
Red Hat addressed CVE-2023-4155 for RHEL 8.8 Extended Update Support through RHSA-2024:4740.
Red Hat addressed CVE-2023-4155 for RHEL 8.6 Advanced Mission Critical Update Support, SAP Solutions Update Services, and Telecommunications Update Service through RHSA-2024:3859.
CVE-2024-26602 affects the Linux kernel scheduler membarrier subsystem and was resolved by reducing the ability to repeatedly hammer the sys_membarrier interface. Fedora fixed it in Linux kernel 6.7.6, while Red Hat issued fixes across RHEL 7, 8, and 9, including EUS, telecommunications, SAP, and mission-critical support channels.
Red Hat released RHSA-2024:3318 and RHSA-2024:3319 for RHEL 7.6 and RHEL 7.7 Advanced Update Support, respectively, remediating the known-exploited nf_tables privilege-escalation vulnerability CVE-2024-1086.
Red Hat documented CVE-2024-1086, a Linux netfilter nf_tables use-after-free that can enable local privilege escalation. Positive drop-error values accepted by nft_verdict_init() can let a crafted NF_DROP verdict cause nf_hook_slow() to double-free memory; the upstream fix is commit f342de4e2f33e0e39165d8639387aa6c19dff660.
Red Hat addressed CVE-2023-4155 for RHEL 8 through RHSA-2023:6901 and RHSA-2023:7077. These advisories also addressed the referenced vmwgfx use-after-free flaws in RHEL 8.
Red Hat documented CVE-2022-3523, in which Linux kernel drivers handling device-private ZONE_DEVICE pages can mishandle page reference counts and access removed or freed struct pages. RHEL 9 was affected and Red Hat remediated it through RHSA-2023:6583, incorporating upstream commit 16ce101db85db694a91380aa4c89b25530871d33.
Fedora remediated CVE-2022-38457 and CVE-2022-40133 through its stable Linux kernel 6.1.7 update.
Red Hat addressed CVE-2022-23960, the Branch History Injection (Spectre-BHB) speculative-execution vulnerability, in RHEL 8 through RHSA-2022:7683. The flaw lets malicious code manipulate shared branch-history-buffer data to induce victim-context branch mispredictions and infer otherwise inaccessible information through cache effects.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
40 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.