Red Hat released RHSA-2023:7418, an Important-security update for the RHEL 9.2 kpatch-patch live-patching module, remediating eight Linux kernel vulnerabilities across supported x86_64 and ppc64le subscription streams. The RPM automatically loads the live patch after installation, updating vulnerable running kernel code without requiring a conventional reboot-based kernel replacement.
The fixes include CVE-2023-3812 (CVSS 7.8), an out-of-bounds write in the TUN/TAP driver that a low-privileged local user can trigger with an oversized IPv6 packet when NAPI fragments are enabled, potentially causing a crash or privilege escalation. They also address CVE-2023-5178 (CVSS 8.8), a use-after-free and double-free flaw in the NVMe/TCP target subsystem that can permit remote code execution or local privilege escalation where NVMe over TCP is enabled, alongside net/sched, netfilter, and other kernel memory-safety defects. Organizations unable to promptly patch CVE-2023-3812 can reduce exposure by preventing the tun kernel module from loading; Red Hat identified no standalone mitigation for CVE-2023-5178.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:7551 and RHSA-2023:7557 to fix the NVMe/TCP use-after-free vulnerability CVE-2023-5178 in RHEL 8.4 Telecommunications Update Service kernel-rt and Advanced Mission Critical Update Support kernel packages.
Red Hat issued RHSA-2023:7548, RHSA-2023:7549, and RHSA-2023:7554 for RHEL 8 kernel-rt, kernel, and kpatch-patch packages, fixing both the TUN/TAP out-of-bounds issue and the NVMe/TCP use-after-free flaw.
Red Hat released RHSA-2023:7418, a kpatch-patch update for supported RHEL 9.2 offerings. It remediated CVE-2023-3812 and CVE-2023-5178 alongside six other Linux kernel vulnerabilities.
Red Hat issued RHSA-2023:6799 and RHSA-2023:6813 to fix the Linux kernel TUN/TAP oversized-packet flaw, CVE-2023-3812, in RHEL 8.1 Update Services for SAP Solutions kpatch-patch and kernel packages.
Red Hat issued RHSA-2024:1961, RHSA-2024:2006, and RHSA-2024:2008 to fix CVE-2023-3812 in RHEL 8.2 Advanced Update Support, Telecommunications Update Service, and SAP Update Services kernel-related packages.
Red Hat issued RHSA-2024:1268, RHSA-2024:1269, and RHSA-2024:1278 to remediate CVE-2023-5178 in RHEL 8.2 Advanced Update Support, Telecommunications Update Service, and SAP Update Services packages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.