Red Hat released RHEL 8 and RHEL 9 kernel updates to remediate a use-after-free race condition in the Linux kernel Qualcomm EMAC Gigabit Ethernet Controller driver's emac_remove path. Removing a Qualcomm EMAC device before driver cleanup can leave freed memory accessible, potentially causing a system crash or other undefined behavior. The upstream fix, “net: qcom/emac: fix UAF in emac_remove,” is present in kernel versions 4.9.277, 4.14.241, 4.19.199, 5.4.135, 5.10.53, 5.13.5, and later.
Red Hat tracks the issue as CVE-2023-33203 with a CVSS v3.1 score of 6.4 and as CVE-2021-47311 in its kernel bug record. Exploitation requires physical access and high attack complexity, limiting remote exposure, but organizations using systems with Qualcomm EMAC hardware should apply the relevant RHEL 8, RHEL 8.6/8.8 extended-support, and RHEL 9 kernel advisories. RHEL 6 and RHEL 7 are unaffected because they do not include Qualcomm EMAC support; RHEL 9 kernel-rt was listed as affected without a corresponding erratum.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
A Red Hat security bug for CVE-2021-47311, a use-after-free flaw in the Qualcomm EMAC driver's emac_remove path, was reported. The issue had an upstream fix titled "net: qcom/emac: fix UAF in emac_remove."
Red Hat addressed CVE-2021-47311 for RHEL 8 and supported extended-support variants through RHSA-2024:4211, RHSA-2024:4352, RHSA-2024:4740, and RHSA-2024:5281. The latter also covered RHEL 8.6 Update Services for SAP Solutions and Telecommunications Update Service.
Red Hat released RHSA-2023:6901 for the RHEL 8 kernel-rt package and RHSA-2023:7077 for the RHEL 8 kernel package, addressing CVE-2023-33203.
Red Hat released RHSA-2023:6583 to fix the Qualcomm EMAC emac_remove use-after-free issue in the RHEL 9 kernel package.
Red Hat released RHSA-2024:0575 to fix CVE-2023-33203 in RHEL 8.8 Extended Update Support.
RHSA-2024:0412 addressed CVE-2023-33203 for RHEL 8.6 Extended Update Support and Red Hat Virtualization 4 for RHEL 8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.