Red Hat issued Important-rated kernel security updates for multiple Red Hat Enterprise Linux (RHEL) 7 and RHEL 8 support channels. RHSA-2024:1249 updates RHEL 7 to kernel 3.10.0-1160.114.2.el7, addressing six vulnerabilities including use-after-free flaws in Bluetooth L2CAP, sch_qfq, and nf_tables; an Intel IGB driver buffer flaw; the fbcon console issue tracked as CVE-2023-38409; and a sched/membarrier flaw. CVE-2023-38409 could leave framebuffer-console mappings pointing to obsolete fb_info objects; upstream fixed it in kernel 6.2.12.
Additional advisories deliver fixes to specialized RHEL channels: RHSA-2024:0980 updates RHEL 7.6 AUS for Bluetooth, scheduler, and IGB flaws; RHSA-2024:3319 updates RHEL 7.7 AUS for CVE-2024-1086 in nf_tables and Intel Gather Data Sampling (CVE-2022-40982); and RHSA-2024:1278 provides a live kpatch-patch update for RHEL 8.2 SAP Solutions covering nine kernel vulnerabilities across networking, NVMe, kTLS, and IGB components. Administrators should apply the applicable packages and reboot systems where required; live-patch deployments should follow Red Hat’s kpatch update procedure.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2024:3319 for RHEL Server AUS 7.7 on x86_64, supplying kernel version 3.10.0-1062.88.1.el7. The update fixed the nf_tables use-after-free CVE-2024-1086 and Intel Gather Data Sampling vulnerability CVE-2022-40982; installation required a reboot.
Red Hat issued Important-rated RHSA-2024:1368 for RHEL 8.8 supported update channels on x86_64 and ppc64le. The kpatch-patch update remediated CVE-2023-4921 in the sch_qfq scheduler and CVE-2024-0646 in kTLS, supplying patches for kernel builds 4.18.0-477.27.1, 4.18.0-477.36.1, and 4.18.0-477.43.1.
Red Hat issued Important-rated RHSA-2024:1249 for RHEL 7, providing kernel-3.10.0-1160.114.2.el7 for supported architectures and product variants. The update remediated CVE-2023-38409 along with five other kernel vulnerabilities, and required affected systems to reboot.
Red Hat issued Important-rated RHSA-2024:1278 for the RHEL 8.2 SAP Solutions kpatch-patch module on x86_64 and ppc64le. The live-patch update addressed nine kernel vulnerabilities affecting kTLS, networking schedulers, nftables, NVMe, and the Intel IGB driver.
Red Hat issued RHSA-2024:0980 for RHEL 7.6 Advanced Update Support on x86_64, updating the kernel to 3.10.0-957.111.1.el7. The update remediated CVE-2022-42896, CVE-2023-4921, and CVE-2023-45871 and required a reboot.
Red Hat issued Important-rated RHSA-2024:0876 for RHEL 8 kpatch-patch modules on x86_64 and ppc64le, including specified RHEL 8.10 Extended Life Cycle offerings. The live-patch update remediated CVE-2023-4623, CVE-2023-4921, CVE-2023-45871, and CVE-2024-0646.
Red Hat issued Important-rated RHSA-2024:0851 for RHEL 8.6 support channels, providing kpatch-patch live kernel modules for x86_64 and ppc64le. The update remediated CVE-2023-4921 and CVE-2024-0646, including a kTLS flaw that can overwrite read-only memory pages during splice operations.
The upstream Linux kernel corrected an fbcon flaw in set_con2fb_map that could desynchronize fbcon arrays and leave con2fb_map referencing an obsolete fb_info structure. The fix was made in commit fffb0b52d5258554c645c966c6cbef7de50b851d.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.