Red Hat addressed a Linux kernel race condition in UNIX-domain socket handling that can trigger a use-after-free in sk_receive_queue. During garbage collection, an skb can be unlinked and freed while unix_stream_sendpage() still accesses it; the issue is associated with upstream commit 790c2f9d15b594350ae9bca7b236f2b1859de02c and is tracked as BZ#2230094. The flaw is also covered by CVE-2023-4623 in RHEL 9.2 live-patch guidance.
Affected organizations should apply the applicable Red Hat kernel or kernel-rt updates across supported RHEL 8 and RHEL 9 specialized, telecommunications, SAP, and extended-lifecycle channels. RHSA-2024:0403 supplies kernel-4.18.0-193.120.1.el8_2 for eligible RHEL 8.2 systems, while RHSA-2024:0402, RHSA-2024:0134, RHSA-2024:0439, and RHSA-2024:0563 provide related Real Time kernel fixes; systems must be rebooted after kernel installation. RHEL 9.2 customers using live patching can install the updated kpatch-patch packages from RHSA-2024:0381 for the affected vulnerability set.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2024:9943 for the RHEL 9.0 SAP Solutions x86_64 channel. The kernel-rt update remediates CVE-2024-26671, CVE-2022-48796, and CVE-2024-46858; affected systems must be rebooted after installation.
Red Hat issued Important-rated RHSA-2024:5261 for RHEL Server AUS 7.7 x86_64. Kernel version 3.10.0-1062.90.1.el7 remediates CVE-2023-4622 in AF_UNIX unix_stream_sendpage() and CVE-2024-36971, the network route-management use-after-free known as Beaky Buzzard; systems must reboot after applying the update.
Red Hat issued RHSA-2024:1960, an Important advisory, providing updated kpatch-patch live kernel modules for RHEL 7 x86_64 and ppc64le product lines. The live patch remediated CVE-2023-4622 in unix_stream_sendpage and CVE-2023-4623 in sch_hfsc without requiring a conventional kernel reboot.
The Linux kernel CVE team assigned CVE-2024-26671 to an sbitmap wakeup race in the blk-mq block multiqueue subsystem. The race can cause an I/O hang and was resolved upstream by the "blk-mq: fix IO hang from sbitmap wakeup race" patch.
Red Hat issued RHSA-2024:0439 for RHEL 9.2 SAP Solutions and Extended Life Cycle subscriptions. Kernel-rt version 5.14.0-284.48.1.rt14.333.el9_2 addressed the BZ#2230094 Unix-socket race condition, with a reboot required after installation.
Red Hat issued RHSA-2024:0402 and RHSA-2024:0403 for RHEL 8.2 Telecommunications, Advanced Update Support, and SAP-related channels. The kernel and kernel-rt updates addressed BZ#2230094's Unix-socket sk_receive_queue use-after-free race and required affected systems to reboot.
Red Hat marked Bugzilla issue BZ#2230094, involving a Unix-domain socket sk_receive_queue race that could cause a use-after-free, as a duplicate of BZ#2237760.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.