Red Hat released kernel security updates for RHEL 8, RHEL 8 Real Time, and RHEL 9 that address Linux-kernel vulnerabilities ranging from memory-safety defects and denial of service to local privilege escalation and potential remote code execution. Notable issues include the CIFS-client RCE flaw, a GSM multiplexing privilege-escalation race, and use-after-free defects in nf_tables/nftables and AMDGPU. CVE-2023-4244 arises from a race between nftables set garbage collection and transactions, allowing a local attacker to crash a host and potentially disclose kernel information.
The updates also remediate CVE-2023-52434, in which insufficient validation of SMB2 create-context offsets and lengths in smb2_parse_contexts() lets a malicious or malformed SMB server trigger an out-of-bounds access and kernel page fault on an SMB/CIFS client. Red Hat shipped affected fixes through advisories including RHSA-2024:1248, RHSA-2024:1607/1614, RHSA-2024:2950, and RHSA-2024:3138, covering supported x86_64, s390x, ppc64le, and aarch64 streams as applicable; organizations should install the relevant kernel packages, reboot hosts, and rebuild dependent rhel9/support-tools and el9/flatpak-sdk container images.

See real exploitation activity before you spend the cycle.
24 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:4211, an Important RHEL 8 kernel security and bug-fix update providing kernel version 4.18.0-553.8.1.el8_10. The update remediates numerous flaws across Bluetooth, KVM, TLS, networking, Wi-Fi, storage, cryptography, USB, and drivers; affected systems require a reboot.
Red Hat released Moderate-severity advisory RHSA-2024:3138, updating RHEL 8 kernel packages to 4.18.0-553.el8_10. The update fixed a broad set of kernel vulnerabilities, including CVE-2023-4244 and CVE-2023-52434, and requires a reboot.
Red Hat issued a Moderate-severity kernel-rt update for RHEL 8, version 4.18.0-553.rt7.342.el8_10, addressing numerous memory-safety, race-condition, denial-of-service, and privilege-escalation vulnerabilities. Affected real-time systems must be rebooted after installation.
Red Hat addressed CVE-2023-52581 in RHEL 9 through RHSA-2024:2394. The Netfilter nf_tables flaw could leak memory when more than 255 elements expired.
Red Hat released an Important kernel-rt update for RHEL 8 Real Time and Real Time for NFV, providing version 4.18.0-513.24.1.rt7.326.el8_9. The update remediated seven issues, including CIFS remote code execution and a GSM multiplexing privilege-escalation flaw.
Red Hat issued an Important RHEL 8 kernel update, version 4.18.0-513.24.1.el8_9, addressing seven flaws including CIFS remote code execution, GSM privilege escalation, and nf_tables and AMDGPU use-after-free issues. A reboot is required for the updated kernel to take effect.
Red Hat issued Moderate-security advisory RHSA-2024:1533 for RHEL 9.2 Extended Update Support kernel-rt packages, providing version 5.14.0-284.59.1.rt14.344.el9_2. The update fixes CVE-2024-0565 in the CIFS client and CVE-2024-26602 in sched/membarrier; affected systems require a reboot.
Red Hat issued Moderate-security advisory RHSA-2024:1532 for RHEL 9.2 support channels, updating the kernel to 5.14.0-284.59.1.el9_2. The update fixes CVE-2024-0565, a CIFS encrypted receive-path input-validation flaw with potential remote code execution impact, and CVE-2024-26602; affected systems require a reboot.
RHBA-2024:1379 updated the rhel9/support-tools container image with the kernel security fixes referenced in RHSA-2024:1248. Red Hat advised users to upgrade the image and rebuild dependent container images.
Red Hat released RHBA-2024:1336 for the el9/flatpak-sdk container image, incorporating backported fixes from RHSA-2024:1248. Users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued an Important-security-impact RHEL 9 kernel update fixing 11 vulnerabilities, including netfilter use-after-free flaws, SMB parsing issues, and an AMDGPU use-after-free. Systems require a reboot after applying the updated packages.
CVE-2023-52580 was reported as a medium-severity Linux kernel net/core flaw in which processing ETH_P_1588 traffic could crash the kernel. The upstream fix corrected ETH_P_1588 flow dissection; Red Hat later shipped fixes in existing RHEL 8 and RHEL 9 security advisories.
Red Hat remediated CVE-2023-4244 in RHEL 9.2 Extended Update Support kernel and kernel-rt packages through RHSA-2024:1018 and RHSA-2024:1019.
Patrick Del Bello reported CVE-2024-1085, a Linux kernel Netfilter nf_tables use-after-free flaw in nft_setelem_catchall_deactivate() that can enable local privilege escalation. A generation-state mismatch can allow a catch-all set element to be freed multiple times, resulting in a double-free condition.
Dhananjay Arunesh reported CVE-2020-26555, a Linux kernel Bluetooth BR/EDR PIN-pairing vulnerability that permits impersonation when an attacker connects using the victim device's Bluetooth address and reflects an encrypted nonce. Red Hat later remediated the issue in RHEL 9 and RHEL 8 security advisories.
Red Hat documented that CVE-2024-0565 affects the CIFS client’s handling of the server-controlled SMB NextCommand field, enabling an out-of-bounds read and a memcpy-length integer underflow that can produce an unsafe memory copy. Red Hat listed fixes for RHEL 8.6 and 8.8 Extended Update Support, RHEL 9.2 Extended Update Support, and standard RHEL 8 and 9 channels.
CVE-2023-52581 was documented as an nftables use-after-free caused by a race between set garbage collection and transaction handling. A local attacker with CAP_NET_ADMIN in a user or network namespace could crash an affected system; Red Hat advised preventing nftables module loading as a temporary mitigation and listed RHEL 9 kernel-rt as still affected.
CVE-2023-42756 was documented as a Linux kernel Netfilter IPSet race between IPSET_CMD_ADD and IPSET_CMD_SWAP. A lock is not held during cond_resched(), allowing a concurrent set swap that can cause local denial of service; RHEL 9 addressed it through RHSA-2024:2394.
CVE-2023-6622 was documented as an nftables flaw in nft_dynset_init() where set->exprs[i] can be NULL when its ops field is dereferenced, allowing a kernel crash. Upstream fixed the denial-of-service issue in commit 3701cd390fd731ee7ae8b8006246c8db82c72bea; Red Hat remediated it through RHEL 9 RHSA-2024:2394 and RHEL 8 RHSA-2024:2950 and RHSA-2024:3138.
Red Hat published RHBA-2024:2686 as a Bug Fix Advisory. The supplied reference provides no further details about affected products or fixes.
Red Hat published RHBA-2024:2650 as a Bug Fix Advisory. The supplied reference contains no further details on the affected products or fixes.
Red Hat published RHBA-2024:2634 as a Bug Fix Advisory. The supplied reference contains no further details on the affected products or fixes.
CVE-2023-52434 was documented in the Linux SMB/CIFS client's smb2_parse_contexts() function, where insufficient validation of create-context offsets and lengths could cause an out-of-bounds access and kernel crash. The remediation validates the offsets and lengths before dereferencing them.
A race between nftables set garbage collection and transactions was documented as CVE-2023-4244; a missing nft_set_elem_mark_busy call could lead to double deactivation of an element. A local attacker could crash an affected system and potentially disclose kernel information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
24 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.