Red Hat released Moderate-severity advisory RHSA-2024:9500 for Red Hat Enterprise Linux 8.6, updating the kernel to 4.18.0-372.129.1.el8_6. The update remediates three use-after-free flaws: CVE-2022-48695 in the mpt3sas SCSI driver, CVE-2024-26656 in the AMDGPU DRM driver, and CVE-2024-46858 in MPTCP path-manager timer handling.
CVE-2022-48695 arises from incorrect refcount_t handling during mpt3sas controller resets and can allow a low-privileged local attacker to cause a denial of service without user interaction. Affected RHEL 8.6 Extended Life Cycle Long Life, AUS, TUS, and SAP Solutions offerings should install the applicable kernel package and reboot to activate the fixes; Red Hat rates the issue 5.5 CVSS v3.1 based on availability impact, while NVD and cve.org assign 7.8 scores.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:2951 for the RHEL 8 kernel and RHSA-2023:2736 for the RHEL 8 kernel-rt package to remediate CVE-2022-48695.
Red Hat released RHSA-2023:2458 for the RHEL 9 kernel and RHSA-2023:2148 for the RHEL 9 kernel-rt package, fixing the mpt3sas use-after-free vulnerability CVE-2022-48695.
The Linux kernel CVE team documented CVE-2022-48695 as a use-after-free issue in the mpt3sas SCSI driver during controller reset, affecting drivers/scsi/mpt3sas/mpt3sas_scsih.c. It identified fixes in stable kernel releases from 4.9.328 through 6.0 and recommended updating to a current stable release rather than cherry-picking individual commits.
Red Hat published Moderate-severity advisory RHSA-2024:9500, providing kernel version 4.18.0-372.129.1.el8_6 for supported RHEL 8.6 extended-support offerings. The update fixes CVE-2022-48695 along with CVE-2024-26656 and CVE-2024-46858; affected systems require a reboot after installation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.