Red Hat released RHSA-2024:0461, an Important RHEL 9 kernel update that remediates 17 vulnerabilities across networking, storage, graphics, Bluetooth, and virtualization components. The flaws include use-after-free, out-of-bounds access, integer-overflow, and NULL-pointer-dereference issues, including CVE-2022-36402 in the vmwgfx graphics driver, which could let a local user with DRM-device access crash a host, and CVE-2023-6679 in the DPLL subsystem, which can cause denial of service. The update applies to supported RHEL 9 variants on x86_64, ARM64, IBM Z, and Power little-endian systems; affected hosts require a reboot after installation.
Red Hat also refreshed RHEL 9 container images through RHBA-2024:0611 and Red Hat OpenStack Platform 17.1 container images through RHBA-2024:0688, incorporating the kernel security fixes and related remediation from RHSA-2024:0448. The container updates cover multiple RHEL 9 image variants, including EUS, AUS, SAP, extended-lifecycle, and four-year update offerings, and address issues such as eBPF-verification flaws and an AMD SEV-ES local privilege-escalation vulnerability. Organizations should pull the updated images, update base-image references in Dockerfiles and build automation, rebuild dependent images, and deploy the refreshed artifacts.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHBA-2024:0688 for Red Hat OpenStack Platform 17.1 RHEL 9 x86_64 container images, incorporating security fixes covered by RHSA-2024:0448. The company provided updated Nova Compute, Nova Compute Ironic, and Nova Libvirt image digests and advised rebuilding dependent images.
Red Hat issued RHBA-2024:0610 updating the RHEL 9 rhel9/gcc-toolset-12-toolchain container image for four architectures. The image incorporates security fixes from RHSA-2024:0461, and Red Hat advised users to upgrade and rebuild dependent container images.
Red Hat published RHBA-2024:0611, updating RHEL 9 container images for x86_64, s390x, ppc64le, and aarch64 with backported fixes from RHSA-2024:0461. Red Hat advised users to pull the updated images and rebuild dependent container images.
Red Hat issued Important-rated RHSA-2024:0461 with an updated RHEL 9 kernel addressing 17 flaws, including vmwgfx integer overflow, multiple use-after-free issues, and an AMD SEV-ES local privilege-escalation vulnerability. The update applies across supported RHEL 9 architectures and variants and requires a reboot after installation.
The upstream Linux kernel remediated CVE-2022-36402, an integer-overflow flaw in the vmwgfx graphics driver that could allow a local user with DRM-device access to cause denial of service, in kernel version 6.5.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.