Red Hat released the Moderate-severity RHSA-2024:1653 kernel update for RHEL 8.6 Update Services for SAP Solutions and other applicable RHEL 8.6 variants. The update fixes CVE-2023-1118, a use-after-free race condition in the Linux ENE integrated infrared receiver/transceiver driver (drivers/media/rc/ene_ir.c) that could allow a local low-privileged attacker to crash a system or potentially escalate privileges when an RC device is detached.
Affected administrators should deploy kernel version 4.18.0-372.98.1.el8_6 on supported x86_64, s390x, ppc64le, and aarch64 systems, apply prerequisite errata, and reboot to activate the new kernel. The advisory also addresses CVE-2021-33631 in ext4 and CVE-2024-26602 affecting sys_membarrier; RHEL 9 is not affected by the ENE issue because the CONFIG_IR_ENE driver is not built.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:6901 for RHEL 8 kernel-rt and RHSA-2023:7077 for the RHEL 8 kernel, remediating the ENE infrared-driver use-after-free vulnerability CVE-2023-1118.
Linux commit 29b0589 fixed use-after-free races in the ENE infrared remote-control driver during device removal. The patch unregisters the RC device and synchronously cancels the transmit simulation timer before releasing IRQ, I/O, and device-memory resources.
Red Hat released RHSA-2024:3810 to fix CVE-2023-1118 in the Red Hat Enterprise Linux 8.8 Extended Update Support kernel.
Red Hat published RHSA-2024:1653, a Moderate-severity kernel update for RHEL 8.6 update-service variants. The update, containing kernel version 4.18.0-372.98.1.el8_6, fixes CVE-2023-1118 along with CVE-2021-33631 and CVE-2024-26602.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.