Red Hat released updated Linux kernels for RHEL 8 Extended Update Support deployments that remediate CVE-2022-41674, a medium-severity cfg80211_update_notlisted_nontrans() flaw. An attacker-controlled MBSSID length can trigger an 8-bit integer overflow, causing memcpy() to write up to 256 bytes beyond an allocated buffer. The fixes were delivered for RHEL 8.6 EUS in RHSA-2024:1188, which provides kernel 4.18.0-372.95.1.el8_6 across x86_64, s390x, ppc64le, and aarch64 systems.
The RHEL 8 EUS kernel advisories also address CVE-2021-4204, an eBPF input-validation defect that permits out-of-bounds kernel memory access. A locally privileged attacker could use the issue to crash a host or disclose internal kernel data. Red Hat’s RHEL 8.8 EUS advisory, RHSA-2024:10262, provides kernel 4.18.0-477.81.1.el8_8 and fixes 22 kernel CVEs, including eBPF memory-safety, privilege-escalation, race, and buffer-corruption issues. Administrators should install the applicable kernel packages and reboot systems for the mitigations to take effect.

See real exploitation activity before you spend the cycle.
12 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Moderate-severity advisory RHSA-2024:10262 with kernel 4.18.0-477.81.1.el8_8 for RHEL 8.8 Extended Update Support, addressing CVE-2021-4204 and 21 other kernel CVEs. The updated kernel requires a reboot for fixes to take effect.
Red Hat addressed CVE-2021-4204 for RHEL 8.6 Extended Update Support in RHSA-2024:0724 and for RHEL 8 in RHSA-2024:2950 and RHSA-2024:3138.
Red Hat addressed CVE-2022-41674 for Red Hat Enterprise Linux 8 through RHSA-2023:2736 and RHSA-2023:2951.
Red Hat addressed CVE-2022-41674 for Red Hat Enterprise Linux 9 through RHSA-2023:2148 and RHSA-2023:2458.
Red Hat issued Moderate-severity advisory RHSA-2022:7444 for RHEL 8 Real Time kernel-rt packages, providing kernel-rt 4.18.0-425.3.1.rt7.213.el8. The update fixes numerous kernel vulnerabilities across Real Time, Real Time for NFV, and specified Telecommunications Update Service and Extended Life Cycle offerings; Red Hat said affected systems require a reboot after installation.
Rohit Keshri reported Red Hat Bug 2134377 for CVE-2022-41674, a u8 length-calculation overflow in cfg80211_update_notlisted_nontrans() that can lead to an oversized memcpy().
Red Hat received a tracking report for CVE-2022-2938, a medium-severity Linux kernel PSI use-after-free flaw that occurs when a PSI trigger is destroyed while being polled. The issue affects systems only when PSI is enabled at boot with the psi=1 parameter.
Marian Rehak reported Red Hat Bug 2039178 for CVE-2021-4204, an improper-input-validation flaw in the Linux kernel eBPF subsystem that can cause out-of-bounds memory access.
A Linux Kernel Mailing List patch was referenced for CVE-2021-3640, a use-after-free flaw caused by locking behavior in the Bluetooth SCO sco_sock_sendmsg() function. The issue could allow an attacker to inject a malicious payload.
Red Hat published Moderate-severity advisory RHSA-2024:1188, delivering kernel 4.18.0-372.95.1.el8_6 for RHEL 8.6 Extended Update Support and fixing CVE-2022-41674 among 14 CVEs. Systems must be rebooted after installing the updated kernel packages.
Red Hat closed Bug 2134377, its tracking record for the Linux kernel MBSSID length-overflow vulnerability.
Red Hat closed Bug 2037386, its tracking record for CVE-2022-0168, a Linux kernel CIFS/SMB2 zero-length output-buffer flaw that could lead to an invalid-buffer memcpy.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.