Red Hat released Important security updates for Red Hat Enterprise Linux 8 kernel and Real Time kernel deployments, remediating multiple vulnerabilities including CVE-2023-2163, an eBPF verifier-pruning flaw that can permit arbitrary kernel-memory reads and writes, privilege escalation, and container escape. Other fixes address a use-after-free in NVMe-over-TCP crypto cleanup (CVE-2023-5178), an AMD cross-process information disclosure issue (CVE-2023-20593), a DVB Common Interface driver use-after-free (CVE-2022-45919), network scheduler defects, and an SCTP NULL-pointer dereference.
Affected organizations should deploy the applicable RHEL 8 kernel packages, including kernel-rt-4.18.0-513.9.1.rt7.311.el8_9 for covered Real Time offerings and kernel-4.18.0-372.80.1.el8_6 for RHEL 8.6 extended-support systems, then reboot to activate the fixes. Red Hat also delivered a kpatch update for RHEL 8.2 SAP Solutions that mitigates CVE-2023-3812, an oversized-packet flaw in the TUN driver; its live-patch module loads automatically and does not require a conventional reboot. Red Hat notes that exploiting CVE-2023-2163 on RHEL generally requires CAP_SYS_ADMIN or root because unprivileged eBPF is disabled by default.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued an Important kpatch-patch update for RHEL 8.2 Update Services for SAP Solutions, remediating the oversized TUN packet vulnerability CVE-2023-3812. The live-patch module is automatically loaded after installation and modifies the running kernel without a conventional reboot.
Red Hat issued RHSA-2023:7554 to fix CVE-2023-2163 in the RHEL 8 kpatch-patch package.
Red Hat issued an Important kernel-rt update for RHEL 8.4 extended-life-cycle and telecommunications real-time offerings, fixing the NVMe-over-TCP use-after-free CVE-2023-5178 and AMD information-leak issue CVE-2023-20593. The update provided kernel-rt 4.18.0-305.114.1.rt7.190.el8_4 and required a reboot.
Red Hat issued RHSA-2023:7549 to fix CVE-2023-2163 in the standard RHEL 8 kernel package; the advisory also addressed CVE-2022-45919 for RHEL 8.
Red Hat issued an Important update for RHEL 8 kernel-rt packages, fixing CVE-2023-2163, CVE-2023-3812, CVE-2023-5178, and multiple DVB and SMB2 use-after-free vulnerabilities. The update provided kernel-rt 4.18.0-513.9.1.rt7.311.el8_9 and required affected systems to reboot.
Red Hat issued an Important kernel update for RHEL 8.6 extended-support channels, including fixes for DVB use-after-free flaws CVE-2022-45884, CVE-2022-45886, and CVE-2022-45919. The update supplied kernel version 4.18.0-372.80.1.el8_6 and required a reboot.
Guilherme de Almeida Suckevicz reported CVE-2022-45919, a Linux kernel use-after-free condition in dvb_ca_en50221.c that can occur when a device disconnects after being opened without required synchronization.
Red Hat issued RHSA-2024:0563 to fix CVE-2023-2163 in kernel-rt for RHEL 8.4 Telecommunications Update Service.
Red Hat issued RHSA-2024:0562 to remediate CVE-2023-2163 in the kernel for RHEL 8.4 Advanced Mission Critical Update Support.
Red Hat issued RHSA-2024:0403 to fix CVE-2023-2163 in kernels for RHEL 8.2 Advanced Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
Red Hat issued RHSA-2024:0402 to remediate CVE-2023-2163 in kernel-rt for RHEL 8.2 Telecommunications Update Service.
Red Hat released RHSA-2024:0376 to fix CVE-2023-2163 in kpatch-patch for RHEL 8.2 Update Services for SAP Solutions.
Red Hat addressed CVE-2022-45919 for Red Hat Enterprise Linux 8.8 Extended Update Support through RHSA-2023:7539.
Fedora remediated CVE-2022-45919 in its Linux 6.3.7 stable kernel updates.
Linux committed a fix for an eBPF verifier flaw that could incorrectly prune unsafe program paths and allow out-of-bounds reads or writes relative to a BPF map value. The issue, found through fuzzing by Google researchers, was fixed by propagating register-precision dependencies for register-to-register conditional instructions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.