Red Hat released Important kernel and Real Time kernel updates for Red Hat Enterprise Linux 9.0 Extended Update Support, remediating six Linux kernel vulnerabilities. The flaws include multiple use-after-free conditions, an out-of-bounds access in XFS, a kernel-pointer information disclosure issue in nftables processing, and unauthorized execution of Bluetooth management commands. Affected packages include kernel-5.14.0-70.64.1.el9_0 for x86_64, s390x, ppc64le, and aarch64 deployments, and kernel-rt-5.14.0-70.64.1.rt21.135.el9_0 for supported x86_64 SAP Solutions systems.
One fixed issue, CVE-2023-2235, is a use-after-free vulnerability in the Performance Events subsystem that may allow a local attacker to escalate privileges. The defect in perf_group_detach() could leave a dangling pointer when remove_on_exec invokes list_del_event() before group detachment; upstream corrected it in commit fd0815f632c24878e325821943edccc7fde947a2. Organizations using affected RHEL 9.0 EUS systems should install the applicable updated kernel packages and reboot hosts to activate the fixes.

See real exploitation activity before you spend the cycle.
12 events from the most recent confirmed update back to the earliest known activity.
Red Hat released CVE-2023-2124 fixes for RHEL 8 kernel and kernel-rt streams in RHSA-2023:4517 and RHSA-2023:4541 on August 8, 2023, with additional supported-stream errata issued through September 5. The fixes address an XFS recovery-path out-of-bounds access associated upstream with commit 22ed903eee23a5b174e240f1cdfa9acf393a5210.
Red Hat issued Important-rated advisory RHSA-2023:4138 for the RHEL 9.0 Extended Update Support Real Time Linux Kernel. The kernel-rt 5.14.0-70.64.1.rt21.135.el9_0 update fixed CVE-2023-2235 and five additional kernel vulnerabilities for affected x86_64 SAP Solutions systems.
Red Hat issued Important-rated advisory RHSA-2023:4137 for the RHEL 9.0 Extended Update Support kernel. Kernel version 5.14.0-70.64.1.el9_0 fixed CVE-2023-2235 and five other kernel vulnerabilities across supported architectures and offerings.
Red Hat issued Important-rated advisory RHSA-2023:3465 for RHEL 9.0 Extended Update Support. Kernel version 5.14.0-70.58.1.el9_0 fixed CVE-2023-0461, CVE-2023-2008, and CVE-2023-32233 across supported architectures and update-service channels.
Red Hat issued Important-rated advisory RHSA-2023:1203 for the RHEL 9.0 EUS real-time kernel for x86_64 SAP Solutions Update Services. The kernel-rt 5.14.0-70.49.1.rt21.120.el9_0 update fixed six vulnerabilities, including remote DoS flaw CVE-2022-4379 in NFSv4.2 server-side copy handling.
Red Hat logged Bug 2152807 for CVE-2022-4379, a high-severity use-after-free in the Linux NFS __nfs42_ssc_open() path that could allow a remote attacker to cause denial of service. The flaw affected kernel versions through v6.1-rc8 and was also tracked as affecting Fedora.
A flaw in the Linux kernel XFS filesystem could cause an out-of-bounds memory access when a user mounts a specially crafted XFS disk image. Red Hat ultimately rated the issue Moderate after initially assessing it as High, and tracked it in Fedora bug 2187963.
Red Hat listed fixes for CVE-2023-2235 in RHEL 9 advisories RHSA-2023:3705, RHSA-2023:3708, and RHSA-2023:3723; RHEL 8 advisories RHSA-2023:4517 and RHSA-2023:4541; and RHEL 8.6 EUS advisory RHSA-2023:5627.
Red Hat closed its record for CVE-2022-4269, a Linux kernel networking denial-of-service flaw where an unprivileged local user can trigger a CPU soft lockup through an ABBA deadlock involving TC mirred egress-to-ingress redirection and TCP or SCTP retransmissions. The issue was fixed upstream in commit ca22da2fbd69 and was addressed in Fedora 6.2.9 and multiple RHEL 8 and 9 advisories.
Fedora addressed CVE-2023-2235 in its stable kernel version 6.2.8 updates.
The upstream Linux kernel corrected CVE-2023-2235 in commit fd0815f632c24878e325821943edccc7fde947a2.
A use-after-free vulnerability was identified in the Linux kernel Performance Events subsystem that could permit local privilege escalation. The flaw involved perf_group_detach() failing to validate sibling events' attach_state, potentially leaving a dangling pointer after remove_on_exec processing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.