Red Hat released Important security updates for Real Time Linux Kernel packages in Red Hat Enterprise Linux (RHEL) 8.4 and RHEL 9.0 support channels. The updates address multiple kernel memory-safety and logic flaws, including use-after-free vulnerability CVE-2022-3545 in the Netronome NFP driver, NULL-pointer dereference CVE-2023-2166 in the CAN protocol implementation, and an out-of-bounds read/possible privilege-escalation issue, CVE-2023-2176, in the RDMA Connection Manager. They also remediate CVE-2022-38096, a vmwgfx driver NULL-pointer dereference that a local user with access to DRM device nodes could use to crash a host.
Affected deployments include RHEL 9.0 Extended Update Support for SAP Solutions using kernel-rt-5.14.0-70.85.1.rt21.156.el9_0, and RHEL 8.4 Real Time variants using kernel-rt-4.18.0-305.125.1.rt7.201.el8_4, including long-life, telecommunications, and NFV support offerings. The advisories collectively fix additional use-after-free, reference-counting, memory-boundary, networking, netfilter, and local privilege-escalation defects; organizations should apply the applicable kernel-rt update and reboot affected systems to activate the fixes.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important advisory RHSA-2024:1382 for RHEL 8.4 Real Time offerings, providing kernel-rt 4.18.0-305.125.1.rt7.201.el8_4. The advisory fixed CVE-2022-3545, CVE-2022-38096, CVE-2023-2166, CVE-2023-2176, and other kernel defects; affected systems required a reboot.
Red Hat issued Important advisory RHSA-2024:0563 for specialized RHEL 8.4 Real Time services, providing kernel-rt version 4.18.0-305.120.1.rt7.196.el8_4. The update fixed 11 vulnerabilities, including eBPF verifier, use-after-free, netfilter, Intel GDS, and networking-driver flaws; systems required a reboot after installation.
Red Hat issued Important advisory RHSA-2024:0431 for RHEL 9.0 Extended Update Support kernel-rt packages, delivering version 5.14.0-70.85.1.rt21.156.el9_0. The update remediated ten listed kernel vulnerabilities and required a reboot to take effect.
Red Hat addressed CVE-2022-38096 through 2024 advisories for RHEL 8 and 9, including Extended Update Support, Advanced Update Support, Telecommunications Update Service, and SAP Solutions channels.
Red Hat addressed CVE-2023-2176 across RHEL 8 and 9 product streams, including Extended Update Support and specialized support variants. The flaw can corrupt the CMA ID tree and cause an out-of-bounds condition in compare_netdev_and_ip.
Red Hat issued fixes for CVE-2023-2166 across multiple RHEL 8 and 9 support streams, including Extended Update Support and specialized support variants.
Red Hat addressed CVE-2022-3545 in multiple RHEL 8 and 9 support streams, including standard, Extended Update Support, Advanced Update Support, Telecommunications Update Service, SAP Solutions, and Mission Critical Update Support channels.
Rohit Keshri was identified in documentation for CVE-2023-2166, a NULL-pointer dereference in the Linux CAN receive path. The uninitialized ml_priv member could allow a local user to crash the system.
The use-after-free issue later tracked as CVE-2022-3545 was referenced in ipsec-next commit 02e1a114fdb71e59ee6770294166c30d437bf86a. The flaw affects area_cache_get in the Netronome NFP driver.
Mauro Matteo Cascella documented CVE-2022-38096, a NULL-pointer dereference in the Linux kernel vmwgfx driver's vmw_cmd_dx_define_query function. A local unprivileged user with access to the applicable DRM device could potentially crash an affected system.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.