Red Hat released Important kpatch-patch live-kernel updates for RHEL 7, 8, and 9 to remediate multiple Linux kernel vulnerabilities in nftables/nf_tables, netfilter, IPvlan, and traffic-control components. The addressed defects include use-after-free, out-of-bounds read/write, and reference-counter leak conditions; affected CVEs include CVE-2023-31248, CVE-2023-32233, CVE-2023-35001, CVE-2023-3609, CVE-2023-3090, CVE-2023-4004, and CVE-2023-4128.
CVE-2023-31248 is a high-severity use-after-free in nft_chain_lookup_byid() caused by failing to verify that an nftables chain is active. An attacker with CAP_NET_ADMIN in a user or network namespace could use the flaw for local privilege escalation. The live-patch packages apply changes to running kernels after installation, avoiding a conventional reboot, and cover supported x86_64 and IBM Power little-endian deployments across applicable EUS, ELS, AUS, TUS, and SAP service variants.

See real exploitation activity before you spend the cycle.
21 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2024:4073 for RHEL 7 kpatch-patch packages on x86_64 and ppc64le, including Extended Life Cycle Support deployments. The live kernel patch remediates CVE-2024-1086, a use-after-free in the Linux nf_tables nft_verdict_init() function, without a conventional reboot.
Red Hat issued Important advisory RHSA-2024:0089 for the RHEL 8 kpatch-patch package, providing live patches for CVE-2023-4622 and CVE-2023-42753. The update covers x86_64 and little-endian Power systems, including RHEL 8.10 Extended Life Cycle variants, without requiring an immediate reboot.
Red Hat issued Important advisory RHSA-2023:5235 for RHEL 8.1 Update Services for SAP Solutions, updating kpatch-patch for x86_64 and Power LE ppc64le systems. The live patch remediates CVE-2023-3390, CVE-2023-4128, and CVE-2023-35001 without a conventional reboot.
Red Hat issued RHSA-2023:5093, an Important RHEL 9 kpatch-patch security update that remediates CVE-2023-31248 along with six other Linux kernel vulnerabilities. The live-patch module applies the kernel modifications after package installation without a conventional kernel reboot.
Red Hat issued Important advisory RHSA-2023:4967 for RHEL 8.4 Update Services for SAP Solutions and Extended Life Cycle Long Life systems. The kpatch-patch update remediates six Linux kernel flaws, including CVE-2023-1829, CVE-2023-3090, CVE-2023-3390, CVE-2023-4004, CVE-2023-35001, and CVE-2023-35788, on x86_64 and ppc64le.
Red Hat issued Important advisory RHSA-2023:4888 for RHEL 8.6 kpatch-patch channels, providing live-patch remediation for CVE-2022-42896, CVE-2023-1829, CVE-2023-3390, and CVE-2023-35788 on x86_64 and ppc64le systems. The update applies to EUS, ELS/Long Life, AUS, TUS, and SAP-focused services and loads automatically after installation to modify the running kernel.
Red Hat issued Important advisory RHSA-2023:4834 for RHEL 7 kpatch-patch packages on x86_64 and ppc64le, including Extended Life Cycle Support variants. The live kernel patch remediates CVE-2023-35788, an out-of-bounds write in the cls_flower fl_set_geneve_opt() function, and is loaded automatically after installation.
Red Hat issued Important advisory RHSA-2023:4829 for RHEL 8.2 Update Services for SAP Solutions on x86_64 and Power LE ppc64le. The kpatch-patch live update remediates the Linux kernel out-of-bounds write vulnerabilities CVE-2023-3090 in ipvlan and CVE-2023-35788 in cls_flower Geneve-option handling.
Red Hat issued Important advisory RHSA-2023:4699 for RHEL Server AUS 7.4 on x86_64, updating the kernel to version 3.10.0-693.112.1.el7. The update remediates the nf_tables privilege-escalation flaw CVE-2023-32233 and AMD cross-process information-leak flaw CVE-2023-20593; affected systems require a reboot after installation.
Red Hat issued Important advisory RHSA-2023:4696 for RHEL Server AUS 7.6 on x86_64, updating the kernel to version 3.10.0-957.105.1.el7. The update remediates the nf_tables privilege-escalation flaw CVE-2023-32233 and AMD cross-process information-leak flaw CVE-2023-20593; affected systems require a reboot after installation.
Red Hat issued Important advisory RHSA-2023:4516 for RHEL 8.1 Update Services for SAP Solutions on x86_64 and Power LE ppc64le. The kpatch-patch live update remediates CVE-2023-1829, CVE-2023-3090, and CVE-2023-35788 without requiring a conventional reboot.
Red Hat issued Important advisory RHSA-2023:4380 for RHEL 9 kpatch-patch packages on x86_64 and ppc64le. The live-patch update remediates the Linux kernel out-of-bounds write vulnerabilities CVE-2023-3090 in ipvlan and CVE-2023-35788 in cls_flower Geneve-option handling.
Red Hat issued Important advisory RHSA-2023:4262 for RHEL 8.4 Update Services for SAP Solutions and Extended Life Cycle Long Life on x86_64 and ppc64le. The kpatch-patch live update remediates the tcindex use-after-free privilege-escalation flaw CVE-2023-1281 and the nf_tables batch-processing flaw CVE-2023-32233 without a conventional reboot.
Red Hat issued Important advisory RHSA-2023:4145 for RHEL 8.6 kpatch-patch packages on x86_64 and ppc64le across EUS, ELS/Long Life, AUS, TUS, and SAP offerings. The live-patch update remediates the tcindex use-after-free flaw CVE-2023-1281 and the nf_tables batch-processing privilege-escalation flaw CVE-2023-32233 without a conventional reboot.
Tej Rathi reported Red Hat Bug 2220893 for CVE-2023-31248, a high-severity nftables use-after-free in nft_chain_lookup_byid() that can enable local privilege escalation for an attacker with CAP_NET_ADMIN in a user or network namespace.
Red Hat issued Important advisory RHSA-2023:3853 for RHEL 8.1 Update Services for SAP Solutions on x86_64 and Power LE ppc64le. The kpatch-patch live update remediates the tcindex use-after-free flaw CVE-2023-1281 and the nf_tables batch-processing privilege-escalation flaw CVE-2023-32233 without a conventional reboot.
Red Hat issued Important advisory RHSA-2023:3705 for RHEL 9 kpatch-patch packages on x86_64 and ppc64le. The live-patch update remediates CVE-2023-2235 in Performance Events perf_group_detach and the nf_tables privilege-escalation flaw CVE-2023-32233 without a conventional reboot.
Red Hat issued Important advisory RHSA-2023:3490 for the RHEL 9.0 kpatch-patch module on x86_64 and ppc64le EUS and SAP Update Services systems. The live patch remediates CVE-2023-0461, CVE-2023-2008, and the nf_tables privilege-escalation flaw CVE-2023-32233 without a conventional reboot.
Red Hat issued Important advisory RHSA-2023:3351 for RHEL 8 kpatch-patch packages on x86_64 and ppc64le, including ELS, EUS, TUS, and SAP-related offerings. The live kernel patch remediates the nf_tables batch-processing use-after-free and local privilege-escalation flaw CVE-2023-32233 without a conventional reboot.
Red Hat issued Important advisory RHSA-2022:5804 for RHEL 7.6 Update Services kpatch-patch packages on x86_64 and Power LE ppc64le, including SAP Solutions channels. The live patch remediates CVE-2022-32250, a Netfilter use-after-free write flaw that can allow local privilege escalation to root.
Red Hat documented CVE-2023-32233, a use-after-free in Linux Netfilter nf_tables batch-request processing that can allow an unprivileged local user to execute kernel code and escalate privileges. The discussion identified access to user namespaces and CAP_NET_ADMIN in such namespaces as relevant to exploitation, and described disabling nf_tables or restricting unprivileged user namespaces as interim mitigations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
24 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.