Red Hat released RHSA-2024:0461 for Red Hat Enterprise Linux 9, updating the kernel to remediate 17 security vulnerabilities across networking, storage, graphics, Bluetooth, and virtualization components. The Important-rated advisory affects RHEL 9 and supported update-service variants on x86_64, ARM64, IBM Z, and IBM Power little-endian systems; administrators must reboot after applying the updated kernel.
Among the fixes is CVE-2023-3777, a CVSS 7.8 use-after-free flaw in the Linux nf_tables netfilter component. A local attacker with CAP_NET_ADMIN in a user or network namespace could exploit improper bound-chain validation in nf_tables_delrule() to escalate privileges. Red Hat fixed affected RHEL 9 and selected RHEL 9 Extended Update Support kernel and real-time kernel packages, while RHEL 6, 7, and 8 are not affected; pending patching, organizations can prevent the netfilter module from loading and, where operationally feasible, disable user namespaces on non-containerized systems.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat listed CVE-2023-3777 as fixed for RHEL 9 and RHEL 9.0 and 9.2 Extended Update Support kernel and kernel-rt packages through errata RHSA-2024:0461, RHSA-2024:0431, RHSA-2024:0432, RHSA-2024:0439, and RHSA-2024:0448.
Red Hat issued the Important-rated RHSA-2024:0461 advisory, providing an updated RHEL 9 kernel that remediated 17 vulnerabilities, including CVE-2023-3777. The update required a reboot to take effect.
A use-after-free vulnerability in the Linux kernel netfilter nf_tables component was reported. The flaw can permit local privilege escalation when nf_tables_delrule() flushes rules without confirming that a chain is bound.
Red Hat documented CVE-2023-4015, a Linux kernel netfilter nf_tables use-after-free issue in which nft_immediate_deactivate() can unbind chains and objects during nftables rule-construction error handling before they are later used. The issue was fixed upstream by commit 0a771f7b266b02d262900c75f1e175c7fe76fec2 and addressed for RHEL 9 and RHEL 9.2 EUS through RHSA-2024:0461, RHSA-2024:0439, and RHSA-2024:0448.
The upstream remediation, commit 6eaf41e87a223ae6f8e7a28d6e78384ad7e407f8, was included in Linux kernel 6.5-rc3.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.