Red Hat released Linux kernel security updates for supported RHEL 8 and RHEL 9 streams, addressing dozens of flaws across networking, virtualization, storage, graphics, Bluetooth, filesystems, and device drivers. The updates include CVE-2024-36886, a TIPC message-reassembly use-after-free issue that could permit remote code execution on affected RHEL 8.6 systems, as well as memory-corruption, information-disclosure, race-condition, denial-of-service, and NULL-pointer defects. RHEL 9.2 updates delivered kernel 5.14.0-284.75.1.el9_2, while RHEL 8.8 and 8.6 updates provided 4.18.0-477.64.1.el8_8 and 4.18.0-372.111.1.el8_6, respectively; Real Time kernel users received 5.14.0-284.75.1.rt14.360.el9_2.
The fixes cover, among other issues, CVE-2024-35791, a KVM SVM use-after-free in svm_register_enc_region(), CVE-2024-36952, a race condition in the SCSI lpfc driver's NPIV cleanup sequence, and CVE-2024-27417, an IPv6 reference leak in inet6_rtm_getaddr(). Red Hat shipped remediation through RHSA-2024:4823, RHSA-2024:4831, RHSA-2024:4740, RHSA-2024:4447, RHSA-2024:0113, and RHSA-2024:6567 for affected x86_64, ARM64, IBM Z, and Power offerings, including EUS, SAP, and extended-lifecycle channels. Organizations should apply the applicable kernel packages and reboot systems to activate the fixes.

See real exploitation activity before you spend the cycle.
42 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued the Moderate-rated RHSA-2024:10771 kernel security update for RHEL 9.4, providing kernel version 5.14.0-427.47.1.el9_4 across supported architectures and service channels. The update remediated 36 CVEs affecting kernel subsystems including filesystems, networking, Bluetooth, storage, graphics, BPF, and memory management; affected systems require a reboot.
Red Hat issued Important-rated RHSA-2024:7003 for RHEL 8.4 Real Time offerings, providing kernel-rt-4.18.0-305.141.1.rt7.217.el8_4. The update fixed the TIPC remote-code-execution flaw CVE-2024-36886, the sysfs reference leak CVE-2024-26993, and the mac80211 out-of-bounds flaw CVE-2024-41071; affected systems require a reboot.
Red Hat issued Moderate-rated RHSA-2024:6744 for RHEL 9.2 update streams, delivering kernel version 5.14.0-284.84.1.el9_2. The update remediated 12 CVEs, including Bluetooth, QAT accelerator, TTY line-discipline, CPU-frequency, SCSI, ACPICA, scheduler, memory-management, and SunRPC flaws; affected systems require a reboot.
Red Hat issued a Moderate-rated kernel security update for RHEL 9 across supported architectures and service offerings. The update fixed 27 kernel vulnerabilities, including the KVM SVM use-after-free CVE-2024-35791, and required systems to be rebooted for the fixes to take effect.
Red Hat issued Moderate-rated RHSA-2024:6267 for RHEL 9.2 servicing channels, providing kernel version 5.14.0-284.82.1.el9_2 for supported architectures. The update remediated 14 kernel CVEs, including GFS2, DMA engine, TIPC, BPF sockmap, netfilter, memory-management, and driver flaws; affected systems require a reboot.
Red Hat issued the Important-rated RHSA-2024:6206 kernel security update for RHEL 8.8 EUS and related channels, providing kernel version 4.18.0-477.70.1.el8_8. The update remediated 34 CVEs, including TCP sequence-number disclosure, use-after-free, out-of-bounds, and mlx5_core denial-of-service flaws; affected systems require a reboot.
Red Hat remediated CVE-2024-41071, a Linux kernel mac80211 Wi-Fi scanning flaw caused by accessing req->channels[] before req->n_channels is initialized, resulting in an out-of-bounds array-index calculation. Fixes were issued through RHSA advisories across supported RHEL 6, 7, 8, and 9 service streams, including RHEL 8.8 EUS and RHEL 9.2 EUS.
Red Hat issued Important-rated RHSA-2024:5858 for the kpatch-patch-5_14_0-70_85_1 live kernel patch module on RHEL 9.0 Update Services for SAP Solutions for x86_64 and ppc64le. The update fixed CVE-2024-36886, CVE-2024-36971, and short-frame denial-of-service flaws CVE-2024-41090 and CVE-2024-41091; Red Hat instructed users to apply the package and reboot.
Red Hat issued bug-fix advisory RHBA-2024:5866 updating the integration/camel-k-rhel8-operator-bundle image for RHEL 8-based Middleware Containers, including OpenShift Container Platform 4.11 and 4.12. The image incorporated security updates including fixes for CVE-2024-36886 and CVE-2024-2201; users were advised to upgrade and rebuild dependent container images.
Red Hat issued Important-rated RHSA-2024:5256 for the kernel-rt package on RHEL 9.0 Update Services for SAP Solutions x86_64, providing version 5.14.0-70.112.1.rt21.184.el9_0. The update remediated 15 CVEs, including the TIPC use-after-free RCE flaw CVE-2024-36886, netfilter issues CVE-2024-26808 and CVE-2024-35897, and the route-management use-after-free CVE-2024-36971.
Red Hat issued Important-rated RHSA-2024:5257 for RHEL 9.0 Update Services for SAP Solutions, providing kernel 5.14.0-70.112.1.el9_0 for supported architectures. The update remediated 17 CVEs, including the TIPC use-after-free RCE flaw CVE-2024-36886 and network route-management use-after-free CVE-2024-36971; affected systems require a reboot.
Red Hat issued Bug Fix Advisory RHBA-2024:5208 updating the rhpam-7/rhpam-kogito-builder-rhel8 image for RHEL 8-based Middleware Containers. The image incorporated backported security fixes including CVE-2024-36886 and CVE-2024-2201; users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued Bug Fix Advisory RHBA-2024:5207 updating the RHEL 8 el8/flatpak-sdk container image with backported security patches, including fixes for CVE-2024-36886 and CVE-2024-2201. Users were advised to update image references and rebuild dependent container images.
Red Hat issued bug-fix advisory RHBA-2024:5117 updating OpenShift Dev Spaces 3 container images for x86_64, ppc64le, and s390x. The images incorporated backported kernel security fixes, including CVE-2024-36886, CVE-2024-2201, and CVE-2024-21823; users were advised to upgrade images and rebuild dependent containers.
Red Hat fixed CVE-2021-47018, a low-severity Linux kernel PPC64 invalid-fixmap-area flaw, in the RHEL 8 kernel through RHSA-2024:5101. Exploitation required local access and high privileges; RHEL 6, 7, 8 kernel-rt, 9, and 9 kernel-rt were listed as not affected.
Red Hat issued Moderate-rated RHSA-2024:5066 for RHEL 9.2 extended-support offerings, providing kernel version 5.14.0-284.77.1.el9_2. The update remediated 22 CVEs across block I/O, ext4, BPF, networking, Netfilter, SCSI, graphics, virtual-terminal, and cgroup components; affected systems require a reboot.
Red Hat issued an Important-rated kernel-rt update for affected x86_64 RHEL 9.2 SAP Update Services and Extended Life Cycle offerings, providing version 5.14.0-284.75.1.rt14.360.el9_2. The Real Time Linux Kernel update fixed 46 vulnerabilities, including CVE-2024-1151 and the KVM SVM, IPv6, and lpfc SCSI issues tracked as CVE-2024-35791, CVE-2024-27417, and CVE-2024-36952.
Red Hat issued an Important-rated RHEL 9.2 servicing-stream kernel update, version 5.14.0-284.75.1.el9_2. It remediated vulnerabilities including the Open vSwitch denial-of-service flaw CVE-2024-1151, vmwgfx issues, and KVM, IPv6, and SCSI flaws including CVE-2024-35791, CVE-2024-27417, and CVE-2024-36952; a reboot was required.
Red Hat issued a Moderate-rated RHEL 8.8 Extended Update Support kernel update, version 4.18.0-477.64.1.el8_8. It remediated 17 CVEs across Bluetooth, KVM, Wi-Fi, networking, netfilter, graphics, and Ethernet components, and required a system reboot.
Red Hat issued Bug Fix Advisory RHBA-2024:4691 updating the RHEL 9 el9/flatpak-sdk container image across supported architectures. The image incorporated RHSA-2024:4583 kernel fixes, including CVE-2024-36886, and Red Hat advised users to pull the updated image and rebuild dependent container images.
Red Hat issued Important-rated kernel security advisory RHSA-2024:4583 for RHEL 9, remediating 17 vulnerabilities across networking, memory management, storage, drivers, console, and block-cgroup components. The update included the TIPC message-reassembly use-after-free RCE flaw CVE-2024-36886 and required affected systems to be rebooted.
Red Hat issued Important-rated RHSA-2024:4554 for the Real Time Linux Kernel on RHEL 9.2 x86_64 Update Services for SAP Solutions and Extended Life Cycle systems. The update delivered kernel-rt 5.14.0-284.73.1.rt14.358.el9_2, remediating CVE-2024-36886 and other kernel flaws; affected systems must reboot after installation.
Red Hat issued Important-rated kernel security advisory RHSA-2024:4533 for RHEL 9.2 update channels, delivering kernel version 5.14.0-284.73.1.el9_2. The update remediated 16 CVEs, including the TIPC message-reassembly use-after-free RCE flaw CVE-2024-36886, and required affected systems to be rebooted.
Red Hat issued an Important-rated kernel update for supported RHEL 8.6 service variants, providing kernel 4.18.0-372.111.1.el8_6. The update fixed CVE-2024-36886, a TIPC message-reassembly use-after-free flaw that could permit remote code execution, along with other kernel vulnerabilities including CVE-2024-36952; affected systems required a reboot.
Red Hat recorded CVE-2024-26974 as Bug 2278354, a medium-severity race condition in the Linux kernel QAT crypto driver's Advanced Error Reporting recovery path. The issue was reported by Zack Miele and was resolved upstream in multiple kernel versions beginning with 4.19.312.
Red Hat issued an Important-rated RHEL 8 kernel update, version 4.18.0-513.11.1.el8_9. It remediated use-after-free, out-of-bounds, and information-disclosure issues including CVE-2023-4622, CVE-2023-5633, CVE-2023-42753, CVE-2023-2162, and CVE-2023-20569; a reboot was required.
Red Hat remediated CVE-2023-28746, a medium-severity local information-disclosure flaw affecting some Intel Atom processors that exposes information through microarchitectural state following transient execution. Fixes were issued for RHEL 8, RHEL 9, and RHEL 9.2 EUS through RHSA-2024:5101, RHSA-2024:8157, RHSA-2024:8158, RHSA-2024:8162, and RHSA-2024:9401.
Red Hat remediated CVE-2024-36899, a use-after-free vulnerability in the Linux kernel GPIO character-device subsystem's gpiolib cdev lineinfo_changed_notify function. Fixes were delivered for RHEL 9 and RHEL 9.2 Extended Update Support through RHSA-2024:6997, RHSA-2024:7004, and RHSA-2024:7005.
Red Hat delivered fixes for CVE-2022-48627, a Linux kernel virtual-terminal flaw involving overlapping memory operations when deleting characters from a buffer. Fixes were issued for RHEL 8, RHEL 9, RHEL 9.2 EUS, and RHEL 8.8 EUS through RHSA-2024:3618, RHSA-2024:3627, RHSA-2024:4533, RHSA-2024:4554, RHSA-2024:4583, and RHSA-2024:5255.
Red Hat remediated CVE-2024-41091, a TUN-side mlx5_core short-frame denial-of-service flaw in which a virtio-net KVM guest could crash its host by sending an Ethernet frame shorter than ETH_HLEN. Fixes were issued across RHEL 8 and 9 support streams, including RHEL 9.0 SAP Solutions, RHEL 9.2 EUS, RHEL 8.2, 8.4, 8.6, and 8.8 EUS, through advisories including RHSA-2024:5256, RHSA-2024:5257, RHSA-2024:5858, RHSA-2024:6206, and RHSA-2024:7429.
Red Hat addressed the Linux kernel network route-management use-after-free flaw CVE-2024-36971 across RHEL 7, 8, and 9 support streams and OpenShift Container Platform 4.12 through 4.16. The flaw is a race condition in the network-stack function __dst_negative_advice().
Red Hat Bugzilla tracked CVE-2024-26808, a Linux kernel netfilter nft_chain_filter issue concerning handling of NETDEV_UNREGISTER for inet/ingress basechains.
Red Hat remediated CVE-2024-42228, an AMDGPU DRM driver flaw in which the size value could be used uninitialized when calling amdgpu_vce_cs_reloc. Fixes were issued for RHEL 8, RHEL 9, and RHEL 9.4 EUS through RHSA-2024:7000, RHSA-2024:7001, RHSA-2024:9315, and RHSA-2024:10771, alongside related bug-fix advisories.
Red Hat remediated CVE-2024-41093, a medium-severity DRM AMDGPU flaw caused by potentially dereferencing a null framebuffer object. Fixes were delivered for RHEL 8, 8.8 EUS, 9, 9.2 EUS, and 9.4 EUS through RHSA-2024:6993, RHSA-2024:8856, RHSA-2024:8870, RHSA-2024:9315, RHSA-2024:10772, RHSA-2024:10773, and RHSA-2024:10771.
Red Hat remediated CVE-2023-52463, an efivarfs flaw that could let a local authorized user crash the kernel on UEFI systems without SetVariable support by remounting efivarfs read-write and updating an EFI variable. Fixes were issued for RHEL 8, RHEL 9.2 EUS, and RHEL 9 through RHSA-2024:5101, RHSA-2024:5102, RHSA-2024:5672, RHSA-2024:5673, and RHSA-2024:6567.
Red Hat remediated CVE-2024-26583, a Linux kernel TLS asynchronous-crypto race that could allow code to access freed data after an async handler completes while a recvmsg/sendmsg thread exits. Fixes were issued for RHEL 8 and 9, including RHEL 8.6 specialized services, RHEL 9.2 EUS, and RHEL 8.8 EUS, through advisories including RHSA-2024:2394, RHSA-2024:4211, RHSA-2024:4352, RHSA-2024:4447, RHSA-2024:4533, and RHSA-2024:5255.
Red Hat remediated CVE-2024-26584, a Linux kernel TLS asynchronous crypto-request handling flaw in which valid backlogged requests can return -EBUSY and invoke callbacks twice. Fixes were issued for RHEL 8 and 9 streams, including RHEL 9.2 EUS, RHEL 8.6 specialized services, and RHEL 8.8 EUS, through advisories including RHSA-2024:1881, RHSA-2024:1882, RHSA-2024:2394, RHSA-2024:4211, RHSA-2024:4352, RHSA-2024:4447, and RHSA-2024:5255.
Red Hat remediated CVE-2023-52448, a Linux kernel GFS2 flaw that could trigger a NULL-pointer dereference in gfs2_rgrp_dump(). Fixes were delivered through RHSA-2024:2394, RHSA-2024:2950, RHSA-2024:3138, RHSA-2024:5255, RHSA-2024:5281, RHSA-2024:5364, and RHSA-2024:5365 for RHEL 8, RHEL 9, and supported specialized channels.
Red Hat remediated the Linux kernel TIPC message-reassembly use-after-free vulnerability CVE-2024-36886 across additional RHEL 8 and 9 support streams. The fixes included RHEL 9.2 EUS, RHEL 9 SAP offerings, RHEL 8.8 EUS, and RHEL 8.4 specialized support offerings through advisories including RHSA-2024:4533, RHSA-2024:4583, RHSA-2024:5255, RHSA-2024:7002, and RHSA-2024:7427.
Red Hat remediated the Linux kernel MPTCP initialization flaw CVE-2024-36889, which could leave snd_nxt improperly initialized during connection establishment. Fixes were issued for RHEL 8 and 9, including RHEL 8.6 specialized support editions, RHEL 8.8 EUS, and RHEL 9.2 EUS, through advisories including RHSA-2024:5101, RHSA-2024:6998, RHSA-2024:8162, RHSA-2024:8613, RHSA-2024:8614, and RHSA-2024:10262.
Red Hat remediated the Linux kernel netfilter/nf_tables flaw CVE-2024-35897 in RHEL 8, RHEL 9.0 Update Services for SAP Solutions, and RHEL 9 through RHSA-2024:5101, RHSA-2024:5102, RHSA-2024:5256, RHSA-2024:5257, and RHSA-2024:5928. The flaw involves a table-flag update while deletion of a basechain is pending.
Red Hat remediated CVE-2024-41090, a TAP/virtio-net short-frame flaw that could allow a KVM guest to crash an mlx5-equipped host kernel by transmitting an undersized Ethernet packet. Fixes were issued across RHEL 8 and 9 support streams, including RHEL 8.2, 8.4, 8.6, 8.8 EUS, RHEL 9, RHEL 9.0 SAP Solutions, and RHEL 9.2 EUS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.