Red Hat released Important RHEL 9 kernel and real-time kernel updates addressing five Linux kernel vulnerabilities, including CVE-2023-35788, an out-of-bounds write in the Flower traffic-control classifier’s fl_set_geneve_opt() function. Crafted packets containing TCA_FLOWER_KEY_ENC_OPTS_GENEVE can trigger the flaw on affected upstream kernels before 6.3.7, potentially causing denial of service or local privilege escalation. The upstream fix is commit 4d56304e5827c8cc8cc18c75343d283af7c4825c.
The updates also remediate out-of-bounds write CVE-2023-3090, KVM x86/MMU race condition CVE-2022-45869, speculative pointer dereference CVE-2023-0458, and Spectre v2 SMT-mitigation issue CVE-2023-1998. RHSA-2023:4377 applies to RHEL 9 across x86_64, ARM64, IBM Z, and Power architectures; RHSA-2023:4378 delivers kernel-rt-5.14.0-284.25.1.rt14.310.el9_2 for supported x86_64 real-time deployments. Administrators should install the applicable kernel packages and reboot affected systems to activate the fixes.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued an Important advisory for kpatch-patch live-patch modules on RHEL 9.0 EUS and RHEL 9.0 SAP Update Services for x86_64 and ppc64le. The update fixes CVE-2023-4128, CVE-2023-31248, CVE-2023-35001, and CVE-2023-35788 without requiring a running-kernel replacement.
Red Hat issued an Important security advisory for RHEL 8.4 service variants, providing kernel version 4.18.0-305.103.1.el8_4. The update remediated multiple kernel vulnerabilities, including CVE-2023-1829, CVE-2023-3090, CVE-2023-3390, CVE-2023-35001, and CVE-2023-35788, and required affected systems to be rebooted.
Red Hat issued Important-rated advisory RHSA-2023:4815 for selected RHEL 8.2 AUS, TUS, and SAP update-service channels. Kernel version 4.18.0-193.113.1.el8_2 fixes CVE-2023-3090, CVE-2023-35788, and CVE-2023-2124; affected systems must be rebooted after installation.
Red Hat released RHEL 7 kernel, kernel-rt, and kpatch-patch fixes for the cls_flower Geneve option out-of-bounds write vulnerability, CVE-2023-35788, through RHSA-2023:4819, RHSA-2023:4821, and RHSA-2023:4834.
Red Hat issued Important-rated RHSA-2023:4697 for selected RHEL 7.7 AUS, TUS, and SAP Update Services channels. The kernel build 3.10.0-1062.77.1.el7 fixes the cls_flower Geneve option out-of-bounds write vulnerability CVE-2023-35788; affected systems require a reboot after installation.
Red Hat issued Important-rated RHSA-2023:4698 for RHEL 7.7 AUS, TUS, and SAP Update Services channels. The kpatch-patch live-patch update remediates the Linux kernel cls_flower out-of-bounds write vulnerability CVE-2023-35788 for affected x86_64 and ppc64le systems.
Red Hat issued Important-rated advisory RHSA-2023:4515 for RHEL 8.1 Update Services for SAP Solutions on x86_64 and Power LE ppc64le. The kernel update to version 4.18.0-147.87.1.el8_1 remediated CVE-2023-1829, CVE-2023-2124, CVE-2023-3090, and CVE-2023-35788; systems require a reboot after installation.
Red Hat issued an Important security and bug-fix update for the RHEL 9 x86_64 kernel-rt package, version 5.14.0-284.25.1.rt14.310.el9_2. It fixed the same five kernel vulnerabilities, including the cls_flower out-of-bounds write tracked as CVE-2023-35788, and required a system reboot.
Red Hat issued an Important advisory providing updated RHEL 9 kernel packages for multiple architectures and support channels. The update remediated CVE-2023-3090, CVE-2023-35788, CVE-2022-45869, CVE-2023-0458, and CVE-2023-1998; affected systems require a reboot after installation.
Red Hat documented CVE-2023-2002, in which an insufficient HCI socket ioctl permission check can let local unprivileged users obtain trusted Bluetooth sockets and issue management commands. The issue was addressed through multiple RHSA advisories for affected RHEL 7, 8, and 9 product streams.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.