Red Hat released RHSA-2023:4801, an Important security and bug-fix update for Red Hat Enterprise Linux 9.0 Extended Update Support and selected SAP Update Services channels. The 5.14.0-70.70.1.el9_0 kernel packages remediate five disclosed flaws, including an ipvlan out-of-bounds write, a PF_KEY information leak, a TLS use-after-free or NULL-pointer dereference, and the stale-TLB race tracked as CVE-2022-39188. That flaw can let a device driver free a page while stale TLB entries remain during a race between unmap_mapping_range() and munmap() on VM_PFNMAP memory areas.
The update also fixes CVE-2023-0458, a speculative pointer-dereference issue in do_prlimit() that a locally authenticated low-privilege attacker could potentially use to leak kernel memory by controlling resource-related pointer arithmetic. Red Hat rated both issues moderate severity at CVSS 4.7 and did not identify a qualifying standalone mitigation; affected organizations should install the relevant kernel errata and reboot systems to load the patched kernel.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHEL 8 kernel and kernel-rt updates addressing CVE-2023-0458 through RHSA-2023:7077 and RHSA-2023:6901.
Red Hat published RHSA-2023:4814 for the RHEL 9.0 EUS Real Time Linux Kernel on x86_64 SAP Solutions systems. The kernel-rt update fixed CVE-2023-0458, CVE-2022-39188, and three other kernel vulnerabilities; affected systems require a reboot after installation.
Red Hat addressed the do_prlimit() speculative pointer-dereference vulnerability in RHEL 9 kernel and kernel-rt packages through RHSA-2023:4377 and RHSA-2023:4378.
Guilherme de Almeida Suckevicz documented a heap out-of-bounds write in the Linux kernel ipvlan driver caused by uninitialized skb->cb. The flaw is reachable with CONFIG_IPVLAN enabled and can permit local privilege escalation.
Red Hat issued fixes for CVE-2022-39188 in RHEL 8 kernel-rt and kernel packages through RHSA-2023:2736 and RHSA-2023:2951.
Red Hat released RHEL 9 kernel and kernel-rt fixes for the stale-TLB use-after-free vulnerability through RHSA-2023:2458 and RHSA-2023:2148.
Guilherme de Almeida Suckevicz reported the speculative pointer-dereference vulnerability in the Linux kernel's do_prlimit() function. The flaw could allow a low-privileged local attacker to potentially leak memory contents.
RHSA-2024:0724 fixed CVE-2023-0458 for the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 for RHEL 8.
RHSA-2024:0575 addressed CVE-2023-0458 for the RHEL 8.8 Extended Update Support kernel.
Red Hat published RHSA-2023:4801, providing kernel version 5.14.0-70.70.1.el9_0 for RHEL 9.0 EUS and selected SAP channels. The update addressed CVE-2022-39188, CVE-2023-0458, and other disclosed kernel vulnerabilities; Red Hat instructed affected organizations to reboot after installation.
RHSA-2023:3388 fixed the stale-TLB race vulnerability for the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 for RHEL 8.
Red Hat closed its CVE-2022-1353 bug after issuing fixes for affected RHEL 8, RHEL 8 EUS, RHEL 9, and RHEL 9.0 EUS releases. The Linux kernel pfkey_register flaw could allow an unprivileged local user to access kernel memory, crash the system, or disclose internal information.
Linux kernel 5.19 included upstream commit b67fbebd4cf980aecbcc750e1462128bffe8ae15, fixing a race between munmap() and unmap_mapping_range() that could leave stale TLB entries for VM_PFNMAP mappings and permit access to freed pages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugs.chromium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.