Red Hat released Important kernel and real-time kernel updates for selected RHEL 8.2 Telecommunications Update Service channels to remediate CVE-2022-42896, a Bluetooth L2CAP use-after-free vulnerability. An unauthenticated attacker within Bluetooth range could exploit the flaw during L2CAP connection handling to disclose kernel memory or execute arbitrary code; Red Hat rates it CVSS 8.1. Systems not requiring Bluetooth can reduce exposure by disabling Bluetooth, blocking its kernel modules, or disabling the hardware.
The updates also address CVE-2023-4128, use-after-free flaws in the cls_fw, cls_u32, and cls_route network traffic classifiers, alongside a filelayout double-free defect and Hyper-V virtual-machine stability issues. Affected standard RHEL 8.2 update-service deployments should install kernel version 4.18.0-193.116.1.el8_2 under RHSA-2023:5589; RHEL for Real Time and Real Time for NFV Telecommunications Update Service deployments should install 4.18.0-193.116.1.rt13.167.el8_2 under RHSA-2023:5588, then reboot.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:1332, fixing CVE-2022-42896 in RHEL 7 kernel-rt packages.
Red Hat issued RHSA-2024:1323 to remediate CVE-2022-42896 in RHEL 7 kpatch-patch packages.
Red Hat issued RHSA-2024:1249, fixing CVE-2022-42896 in RHEL 7 kernel packages.
Red Hat issued RHSA-2024:0980 to fix CVE-2022-42896 in RHEL 7.6 Advanced Update Support kernel packages.
Red Hat issued RHSA-2023:5580 for kpatch-patch on RHEL 8.2 Update Services for SAP Solutions, fixing CVE-2022-42896 and CVE-2023-4128. The advisory provided live-kernel patch packages for affected x86_64 and Power LE ppc64le systems.
RHSA-2023:5588 provided kernel-rt 4.18.0-193.116.1.rt13.167.el8_2 for RHEL 8.2 Telecommunications Update Service systems, remediating CVE-2022-42896 and CVE-2023-4128.
RHSA-2023:5589 supplied kernel 4.18.0-193.116.1.el8_2 for selected RHEL 8.2 AUS, TUS, and SAP update-service channels, fixing CVE-2022-42896 and CVE-2023-4128.
Red Hat issued RHSA-2023:4517, RHSA-2023:4531, and RHSA-2023:4541 to fix CVE-2022-42896 in RHEL 8 kernel, kpatch-patch, and kernel-rt packages.
Red Hat released RHSA-2023:2458 for the RHEL 9 kernel and RHSA-2023:2148 for kernel-rt, fixing CVE-2022-4128.
Red Hat published the record for CVE-2022-4128, a moderate Linux kernel MPTCP NULL-pointer dereference that a low-privileged local user could use to crash a system.
Red Hat documented CVE-2023-4623, a use-after-free flaw in the Linux kernel HFSC traffic-control queueing discipline that can enable local privilege escalation. Red Hat remediation covered RHEL 7, 8, and 9, including extended-support and specialized update channels, while Fedora fixed the issue in 6.5.3 stable kernel updates.
Red Hat documented CVE-2023-45871, an inadequate receive-buffer sizing issue in the Linux kernel Intel IGB Ethernet driver that can affect frames larger than the physical hardware MTU. The flaw requires an attacker to be adjacent on the physical network and was remediated through Red Hat advisories for RHEL 7, 8, and 9 channels.
Red Hat issued RHSA-2024:1746 to fix CVE-2022-42896 in RHEL 7.7 Advanced Update Support kernel packages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.