Red Hat released Important-severity kernel updates for RHEL 9.2 support channels, including Extended Update Support, Extended Life Cycle, AUS, SAP, and Real Time Linux offerings. The fixes address ten Linux-kernel vulnerabilities spanning memory corruption, out-of-bounds access, use-after-free conditions, NULL-pointer dereferences, SCTP validation, conntrack, NVMe-over-TCP, kTLS, and USB-storage components.
The updates include CVE-2023-6610, an out-of-bounds read in the SMB client debug path that can be triggered by an unknown SMB frame when CONFIG_CIFS_DEBUG2 is enabled, potentially causing a crash or leaking kernel information. They also remediate CVE-2023-45862, an out-of-bounds memory condition in the ENE UB6250 USB card-reader driver. Organizations using affected RHEL 9.2 systems should install kernel-5.14.0-284.52.1.el9_2 or kernel-rt-5.14.0-284.52.1.rt14.337.el9_2, as applicable, and reboot to activate the patches.

See real exploitation activity before you spend the cycle.
33 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-rated RHSA-2024:8870 for RHEL 8 Real Time, Real Time for NFV, and RHEL 8.10 Extended Life Cycle x86_64 offerings. The update provides kernel-rt 4.18.0-553.27.1.rt7.368.el8_10, remediates 43 Linux kernel vulnerabilities including CVE-2024-40983, and requires a reboot.
Red Hat issued Moderate-rated RHSA-2024:8856 for standard RHEL 8 and RHEL 8.10 Extended Life Cycle kernel packages on x86_64, aarch64, ppc64le, and s390x. The update provides kernel version 4.18.0-553.27.1.el8_10, remediates numerous kernel flaws including CVE-2024-40983, and requires a reboot after installation.
Red Hat issued Important-rated RHSA-2024:5928 for RHEL 9 kernel packages, remediating numerous networking, Netfilter/nftables, driver, storage, wireless, virtualization, memory-management, and cryptographic flaws. The update covers RHEL 9 and associated EUS, ELS, AUS, SAP Solutions, and CodeReady Linux Builder channels across supported architectures; Red Hat required systems to reboot after installation.
Red Hat issued Important-rated RHSA-2024:5672 for RHEL 9.2 Extended Update Support and related channels, providing kernel version 5.14.0-284.80.1.el9_2. The update remediates 11 Linux kernel vulnerabilities affecting efivarfs, BPF sockmap, hugetlb, networking, NFSv4, and Intel network drivers; Red Hat instructed affected systems to reboot after installation.
Red Hat issued Important-rated RHSA-2024:5364 for RHEL 9.2 EUS and associated update streams, delivering kernel version 5.14.0-284.79.1.el9_2. The update remediates 23 CVEs, including network route-management use-after-free CVE-2024-36971 and STM double-free CVE-2024-38627; Red Hat required affected systems to reboot after installation.
Red Hat issued Important-rated RHSA-2024:4108 for RHEL 9.2 Extended Update Support and related channels, providing kernel version 5.14.0-284.71.1.el9_2. The update remediates multiple kernel flaws, including SMB client reconnect-path use-after-free CVE-2024-35870 and Netfilter, Xen netfront, Mellanox, Amazon ENA, HNS3, and OcteonTX2 driver issues; systems require a reboot.
ybuenos reported CVE-2024-36883, a medium-severity Linux kernel networking vulnerability caused by an out-of-bounds access in ops_init. The upstream remediation is titled “net: fix out-of-bounds access in ops_init,” with fixes released across multiple stable kernel branches.
The Linux kernel CVE team assigned CVE-2024-38384 for list corruption in the blk-cgroup subsystem caused by reordering the WRITE-to-lqueued operation. An upstream Linux kernel CVE advisory published in June 2024 reported the issue as resolved upstream; Red Hat later addressed it in RHEL 9.2 and 9.4 EUS advisories.
The Linux kernel CVE team assigned CVE-2024-36000 to a missing hugetlb_lock issue during reservation uncharging in mm/hugetlb. The upstream fix is titled "mm/hugetlb: fix missing hugetlb_lock for resv uncharge."
Robb Gatica recorded CVE-2024-26853, a Linux kernel vulnerability in the Intel igc network driver's XDP_REDIRECT handling that could return a frame twice. The upstream fix prevents the duplicate frame return, and Red Hat later addressed the issue across RHEL 8, RHEL 9, and EUS update streams.
Red Hat issued Important-rated RHSA-2024:1248 for RHEL 9 kernel packages, fixing 11 vulnerabilities including netfilter use-after-free issues, CVE-2023-6610, SMB parsing flaws, and an AMDGPU use-after-free. The update covers RHEL 9 and associated EUS, AUS, SAP, Extended Life Cycle, and CodeReady Linux Builder channels; Red Hat instructed customers to reboot after installation.
Red Hat issued Important-rated RHSA-2024:1019 for RHEL 9.2 extended-support Real Time Linux Kernel offerings on x86_64. The update provides kernel-rt-5.14.0-284.55.1.rt14.340.el9_2, remediates ten kernel vulnerabilities including nf_tables use-after-free flaws, and requires a reboot.
Red Hat issued Important-rated RHSA-2024:1018 for RHEL 9.2 update streams, providing kernel version 5.14.0-284.55.1.el9_2. The update fixes multiple flaws including GSM multiplexing and nf_tables privilege-escalation issues, and requires affected systems to reboot after installation.
Red Hat issued Important-rated RHSA-2024:0725 for the RHEL 9.2 Real Time Linux Kernel, remediating CVE-2023-6610 and CVE-2023-45862 among ten kernel vulnerabilities. The advisory provides kernel-rt-5.14.0-284.52.1.rt14.337.el9_2 and requires a reboot.
Red Hat issued Important-rated RHSA-2024:0723 for RHEL 9.2 kernel packages, including fixes for CVE-2023-6610 and CVE-2023-45862. The update provides kernel version 5.14.0-284.52.1.el9_2 and requires a reboot.
Red Hat issued Important-rated RHSA-2024:0439 for the RHEL 9.2 Real Time Linux Kernel in x86_64 SAP Solutions and Extended Life Cycle channels. The update provides kernel-rt-5.14.0-284.48.1.rt14.333.el9_2, fixes numerous flaws including CVE-2023-46813, CVE-2023-20569, and CVE-2023-1192, and requires a reboot.
Red Hat issued Important-rated RHSA-2024:0448 for RHEL 9.2 Extended Update Support and associated update-service channels. The update provides kernel version 5.14.0-284.48.1.el9_2, fixes numerous kernel vulnerabilities including CVE-2023-1192, and requires a reboot.
Fedora stated that CONFIG_CIFS_DEBUG2 is not enabled in its builds, preventing the vulnerable SMB debugging path for CVE-2023-6610 from being enabled by default.
Red Hat issued Important-rated RHSA-2023:7749 for RHEL 9 kernel packages, fixing CVE-2023-1192, CVE-2023-5345, CVE-2023-45871, and CVE-2023-20569 across supported architectures and product variants. Red Hat instructed customers to reboot after applying the update.
Rohit Keshri described the Linux kernel SMB client out-of-bounds read in smb2_dump_detail, tracked as Linux kernel Bugzilla issue 218219. A malicious SMB2 Command value can index beyond the has_smb2_data_area array when the CIFS debugging path is enabled.
Robb Gatica reported Red Hat's tracking bug for CVE-2023-45862, an out-of-bounds memory condition in the Linux kernel ENE UB6250 USB card-reader driver.
Red Hat issued Important-rated RHSA-2023:5091 for RHEL 9 Real Time Linux Kernel packages. The update delivered kernel-rt-5.14.0-284.30.1.rt14.315.el9_2 for x86_64 and fixed ten vulnerabilities, including multiple nf_tables use-after-free flaws; Red Hat required a reboot after installation.
A stack out-of-bounds read/write vulnerability in the Linux kernel nftables nft_byteorder expression was described. Improper handling of virtual-machine register contents can be exploited by a process with CAP_NET_ADMIN in any user or network namespace.
Red Hat documented CVE-2024-40905, a race in the Linux kernel IPv6 function __fib6_drop_pcpu_from() where repeated reads of a per-CPU route pointer could lead to a NULL-pointer dereference and general-protection fault. The upstream fix uses READ_ONCE() and RCU read-side locking; Red Hat remediated the issue for RHEL 9 in RHSA-2024:5928.
A logic error in the Linux kernel's __efi_rt_asm_wrapper function can bypass shadow-stack protection and potentially permit local privilege escalation without additional execution privileges. Red Hat addressed the flaw for RHEL 9 through RHSA-2023:5091 and RHSA-2023:5069.
Red Hat documented CVE-2024-40961, in which in6_dev_get() can return NULL during IPv6 route validation and propagate to fib6_nh_init(), causing a kernel general-protection fault. syzbot reproduced the crash through IPv6 route-add ioctl handling; Red Hat remediated it in RHEL 9 through RHSA-2024:5363 and in RHEL 8 through RHSA-2024:8856 and RHSA-2024:8870.
Red Hat documented CVE-2024-40983, in which asynchronous TIPC decryption work can outlive the RCU-protected region without retaining a reference to the skb destination entry, potentially causing a kernel crash. The remediation calls skb_dst_force() before decryption; Red Hat addressed the issue through advisories for RHEL 9, RHEL 9.2 EUS, and RHEL 8.
Red Hat documented CVE-2024-42110, in which ntb_netdev called __netif_rx() from an idxd/DSA DMA-engine threaded interrupt completion context, potentially triggering a kernel BUG warning for smp_processor_id() in preemptible code. The upstream fix changes ntb_netdev_rx_handler() to use netif_rx(), and Red Hat remediated the issue for RHEL 9 in RHSA-2024:5928.
Red Hat documented CVE-2024-40939 in the Linux kernel WWAN iOSM driver, where a failed ipc_devlink_create_region() call could cause cleanup to delete regions through a tainted pointer holding an error value. The fix decrements the region index before cleanup; Red Hat remediated the issue for RHEL 9 in RHSA-2024:5928.
Red Hat tracked CVE-2023-6931, in which perf_event_validate_size() mishandles mixed read_format values in performance-event groups, allowing a perf_event read_size overflow and an out-of-bounds write in perf_read_group(). The upstream issue was fixed by commit a723968c0ed3 ("perf: Fix u16 overflows").
Red Hat tracked CVE-2023-6817, a Linux kernel nf_tables use-after-free that can enable local privilege escalation. The flaw occurs because nft_pipapo_walk does not skip inactive elements, permitting double deactivation of PIPAPO elements; the upstream fix is commit 317eb9685095678f2c9f5a8189de698c5354316a.
Red Hat documented CVE-2023-1192 as a use-after-free in the Linux kernel CIFS/SMB client, where smb2_is_status_io_timeout() can dereference a response buffer freed during response processing or decryption. The upstream fix changes the timeout-status check to use bufs[0], and Red Hat assessed the issue as not apparently exploitable; CVE-2023-52572 was marked as a duplicate.
The upstream Linux kernel fix for CVE-2023-45862 was included in Linux 6.2.5, and Fedora incorporated the fix through 6.2.5 stable kernel updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
31 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.