Red Hat addressed CVE-2022-36879, a moderate-severity Linux kernel flaw in the XFRM packet-transformation framework. Faulty policy resolution in xfrm_bundle_lookup/xfrm_expand_policies can decrement a reference count twice, creating a memory-lifecycle error that a local, low-privileged attacker could use to crash the kernel and cause denial of service. Red Hat rates the issue CVSS 5.5, with high availability impact and no confidentiality or integrity impact.
The defect affects upstream kernels through version 5.18.14; Fedora incorporated the correction in kernel 5.18.15, while upstream Linux includes it in version 5.19. Red Hat shipped fixes for supported RHEL 8 and RHEL 9 releases, including specified kernel-rt and Extended Update Support variants, as well as Red Hat Virtualization 4 for RHEL 8. Organizations should install the applicable supported kernel update and reboot where required; RHEL 6 and RHEL 7 are outside Red Hat's supported scope for this issue.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2024:0432, an Important RHEL 9.0 Extended Update Support kernel update to version 5.14.0-70.85.1.el9_0 that fixes CVE-2022-36879 and other vulnerabilities. Systems require a reboot after installation for the updated kernel to take effect.
Red Hat released fixes for RHEL 8 kernel packages in RHSA-2023:2951 and RHEL 8 kernel-rt packages in RHSA-2023:2736.
Red Hat shipped fixes for RHEL 9 kernel packages through RHSA-2023:2458 and for kernel-rt packages through RHSA-2023:2148.
Guilherme de Almeida Suckevicz reported the xfrm_expand_policies() reference-count issue, affecting Linux kernels through version 5.18.14.
CVE-2022-36879 was publicly listed for a Linux kernel XFRM policy-handling flaw that could drop a reference count twice and cause a kernel denial of service.
Red Hat addressed CVE-2022-36879 in RHEL 9.0 Extended Update Support kernel-rt packages through RHSA-2024:0431.
RHSA-2023:5627 delivered the CVE-2022-36879 fix for RHEL 8.6 Extended Update Support kernel packages and Red Hat Virtualization 4 for RHEL 8 kernel packages.
Fedora fixed the issue in its 5.18.15 stable kernel updates, while the upstream Linux kernel fix was included in version 5.19.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.