Red Hat released kernel and live-patch updates across supported RHEL 8 and RHEL 9 service streams to remediate CVE-2023-3609, a use-after-free flaw in the Linux net/sched cls_u32 traffic-control classifier. A local attacker able to manipulate a filter reference count could trigger an error path in u32_set_parms(), free an object, and subsequently use it, potentially achieving local privilege escalation. The upstream correction is associated with commit 04c55383fa5689357bcdd2c8036725a55ed632bc.
Affected offerings include RHEL 8.2, 8.4, 8.6, and 8.8 update-service variants, plus RHEL 9.0 and 9.2—including Real Time, SAP, AUS, TUS, EUS, and extended-lifecycle channels. Relevant fixed builds include RHEL 9.2 kernel 5.14.0-284.40.1.el9_2, RHEL 8.8 kernel 4.18.0-477.36.1.el8_8, and RHEL 8.6 kernel 4.18.0-372.75.1.el8_6; Red Hat also supplied kpatch-patch live updates for certain RHEL 8.6 and 8.8 deployments. Administrators should install the applicable errata and reboot systems unless deploying the supported live-patch package.

See affected versions and whether adversaries are exploiting it.
21 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:1306 for the RHEL 9.0 Extended Update Support Real Time kernel, providing kernel-rt 5.14.0-70.93.1.rt21.165.el9_0 for affected x86_64 systems. The update remediated CVE-2023-3609 alongside numerous memory-safety, privilege-escalation, and side-channel vulnerabilities.
Marco Benatto reported CVE-2023-6536, a medium-severity NULL-pointer dereference in the Linux NVMe driver's __nvmet_req_complete function. Crafted NVMe-over-Fabrics TCP packets can trigger the flaw and remotely cause a denial of service; Red Hat tracked it as Bug 2254052.
Marco Benatto reported CVE-2023-6535, a medium-severity NULL-pointer dereference in the Linux NVMe-over-Fabrics TCP target path's nvmet_tcp_execute_request function. Crafted NVMe-oF/TCP packets can trigger remote denial of service; Fedora tracking bug 2254056 was created for the issue.
Marco Benatto reported CVE-2023-6356, a medium-severity NULL-pointer dereference in the Linux kernel's nvmet_tcp_build_iovec function. Crafted TCP packets can trigger the flaw in vulnerable NVMe-over-TCP target deployments, causing remote denial of service.
Red Hat issued RHSA-2023:7539, delivering kernel 4.18.0-477.36.1.el8_8 for RHEL 8.8 Extended Update Support and related service variants. The update fixed CVE-2023-3609 and multiple additional kernel use-after-free, out-of-bounds, race-condition, and side-channel flaws.
Red Hat issued RHSA-2023:7379 for RHEL 9.2 Real Time kernel deployments, supplying kernel-rt 5.14.0-284.40.1.rt14.325.el9_2. The advisory remediated CVE-2023-3609 along with nine other vulnerabilities and required a reboot.
Red Hat issued RHSA-2023:7370 for RHEL 9.2 service streams, providing kernel version 5.14.0-284.40.1.el9_2. The update remediated CVE-2023-3609 and other traffic-control, TUN/TAP, NVMe/TCP, Netfilter, and processor side-channel issues.
Red Hat issued RHSA-2023:7410 for RHEL 8.6 Extended Update Support and associated x86_64 and ppc64le service channels. The kpatch-patch update remediated CVE-2023-3609 and CVE-2023-3776 through live kernel patch modules automatically loaded after installation.
Red Hat issued RHSA-2023:7434 for RHEL 8.2 AUS, Telecommunications Update Service, and SAP Solutions update-service channels, supplying kernel version 4.18.0-193.119.1.el8_2. The Important update remediated CVE-2023-3609 alongside CVE-2023-1829, CVE-2023-3776, and CVE-2023-4004, and required systems to reboot.
Red Hat issued RHSA-2023:7294 for RHEL Server 7.6 Advanced Update Support on x86_64, providing kernel 3.10.0-957.108.1.el7 and associated packages. The Important update remediated CVE-2023-3609 and CVE-2023-3776; affected systems must reboot after installation.
Red Hat issued RHSA-2023:6799 for RHEL 8.1 Update Services for SAP Solutions, providing kpatch-patch live kernel modules for x86_64 and Power LE systems. The update remediated CVE-2023-3609, CVE-2023-3776, and CVE-2023-3812 and automatically loaded the patch module after RPM installation without requiring a conventional reboot.
Red Hat issued RHSA-2023:6813 for RHEL 8.1 Update Services for SAP Solutions, delivering kernel version 4.18.0-147.94.1.el8_1 for x86_64 and Power LE systems. The Important update remediated CVE-2023-3609 alongside CVE-2023-1095, CVE-2023-3776, and CVE-2023-3812, and required affected systems to reboot.
Red Hat issued RHSA-2023:5775 for RHEL 8.4 Update Services for SAP Solutions and x86_64 Extended Life Cycle Long Life deployments. The kpatch-patch update remediated CVE-2023-3609, CVE-2023-3776, and CVE-2023-4128 on x86_64 and ppc64le systems without a conventional reboot.
Red Hat issued RHSA-2023:5794 for RHEL 8.4 Real Time Extended Life Cycle Long Life, Telecommunications Update Service, and NFV Telecommunications Update Service deployments on x86_64. The update supplied kernel-rt 4.18.0-305.108.1.rt7.183.el8_4, fixing CVE-2023-3609 and three other kernel vulnerabilities; affected systems require a reboot.
Red Hat issued RHSA-2023:5621 for RHEL 7 kernel-rt, RHSA-2023:5574 for RHEL 7 kpatch-patch, and RHSA-2023:5622 for the RHEL 7 kernel. The advisories remediated CVE-2023-3609 for the respective RHEL 7 packages.
Red Hat issued RHSA-2023:5628 for supported RHEL 8.4 service variants, supplying kernel version 4.18.0-305.108.1.el8_4. The Important update remediated CVE-2023-3609 alongside four other kernel vulnerabilities and required affected systems to reboot.
Red Hat issued RHSA-2023:5244 for RHEL 8, delivering kernel version 4.18.0-477.27.1.el8_8 for supported architectures and channels. The Important update fixed multiple kernel flaws affecting networking, nftables/netfilter, Bluetooth, and AMD hardware, including out-of-bounds and use-after-free vulnerabilities.
Red Hat tracked CVE-2023-1095, a Linux kernel netfilter vulnerability involving a NULL-pointer dereference in nf_tables caused by a zeroed list head.
A race-condition use-after-free flaw was identified in Linux kernels using OverlayFS on Ext4 during asynchronous direct I/O reads. OverlayFS can free an aio_req and its embedded I/O control block before Ext4 accesses iocb->ki_filp; systems lacking upstream patch 9a2544037600 are affected.
A reference-counter handling flaw was identified in the Linux kernel net/sched cls_u32 classifier when tcf_change_indev() fails in u32_set_parms(). An attacker able to control the counter could free a referenced object and trigger a use-after-free condition enabling local privilege escalation; the upstream fix is commit 04c55383fa5689357bcdd2c8036725a55ed632bc.
An upstream Linux kernel patch reworked cls_u32 key destruction by adding __u32_destroy_key() and limiting tcf_exts_put_net() to the normal destruction path. The u32_change() error paths were changed to use the internal cleanup routine after failed key initialization or hardware replacement, avoiding network-reference cleanup for incompletely initialized keys.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
34 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcegit.kernel.org
Open sourcegit.kernel.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.