Red Hat issued advisories for CVE-2024-36025, an off-by-one flaw in the Linux kernel qla2xxx SCSI driver’s qla_edif_app_getstats() function. Fedora tracking identified affected releases, while Red Hat’s automated assessment rated the issue as potentially valid with an estimated Moderate impact pending manual review. Updates cover supported Red Hat Enterprise Linux 8 and 9 streams, including EUS, SAP, telecommunications, and mission-critical variants.
Red Hat also tracked CVE-2023-52924 as an Important netfilter/nf_tables defect affecting timeout-enabled verdict maps. Expired elements can be skipped during traversal, leaving referenced-chain use counts inconsistent and potentially leaking chain references and nft_chain structures; the issue may also generate warnings during chain removal and erroneous ENOENT responses during flush operations. Red Hat assigned CVSS 7.0 and lists RHEL 7 as affected, with fixes issued across applicable RHEL 8 and 9 streams; RHEL 6 and 10 are not affected.

See real exploitation activity before you spend the cycle.
25 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHBA-2024:9635 to update the integration/camel-k-rhel8-operator container image for RHEL 8-based Middleware Containers used by OpenShift Container Platform 4.11 and 4.12. The image incorporates RHSA-2024:8856 security fixes, including fixes for netfilter CVEs such as CVE-2024-26924, CVE-2024-35898, and CVE-2024-42070, and customers were advised to rebuild dependent images.
Red Hat issued the Important RHSA-2024:5256 advisory for kernel-rt 5.14.0-70.112.1.rt21.184.el9_0 on RHEL 9.0 Update Services for SAP Solutions on x86_64. The update remediates 15 CVEs, including the remotely exploitable TIPC use-after-free flaw CVE-2024-36886 and multiple netfilter/nf_tables issues.
An upstream Linux CVE announcement disclosed CVE-2024-41042, in which obsolete nf_tables loop-detection logic can recurse without bound while validating register stores for a crafted ruleset, potentially hitting a task stack guard page and crashing the kernel. The upstream fix removes nf_tables_check_loops() and relies on nft_chain_validate() and nft_lookup validation callbacks.
CVE-2024-42070 was reported as a medium-severity netfilter/nf_tables vulnerability in which conditional NFT_DATA_VALUE validation during data-register stores could allow leakage of a chain-object pointer. Upstream fixed the issue by deriving register type from the set datatype, and Red Hat issued fixes for RHEL 8, RHEL 9, and RHEL 9.4 EUS.
Red Hat released kernel and kernel-rt updates addressing the CVE-2024-27019 nf_tables __nft_obj_type_get() race condition, beginning with RHEL 9.2 EUS and kernel-rt updates. Subsequent advisories remediated affected RHEL 8, RHEL 9, RHEL 8.6 specialized, and RHEL 8.8 EUS streams.
Red Hat issued RHSA-2024:3138 to address CVE-2023-52924 in Red Hat Enterprise Linux 8.
The Linux kernel CVE team assigned CVE-2024-27011 for a memory leak in the Netfilter nf_tables map abort path. An upstream Linux kernel advisory was published, and Red Hat subsequently issued fixes for RHEL 8, RHEL 9, and RHEL 9.4 EUS.
Zack Miele reported a potential data-race vulnerability in Netfilter's nf_tables __nft_obj_type_get() function. The issue was assigned CVE-2024-27019 and tracked by Red Hat as Bugzilla 2278258 with medium severity and priority.
Red Hat issued RHSA-2024:2394 to remediate CVE-2023-52924 in Red Hat Enterprise Linux 9.
Red Hat issued RHSA-2024:1018 to address CVE-2023-52924 for Red Hat Enterprise Linux 9.2 Extended Update Support.
CVE-2022-48638 was assigned for a Linux kernel cgroup flaw where cgroup_get_from_id() failed to verify that a looked-up kernfs node was a directory. Red Hat addressed it in RHEL 8.8 EUS via RHSA-2024:6993 and in RHEL 8.6 AMQ, SAP Solutions, and Telecommunications service variants via RHSA-2024:6998.
The Linux kernel CVE team assigned CVE-2024-27012 for an nf_tables flaw in which set elements were not restored after deletion of a set failed. Red Hat addressed the issue in RHEL 9 through RHSA-2024:9315 and RHEL 9.4 Extended Update Support through RHSA-2025:1658; Fedora tracked it as bug 2278276.
The Linux kernel CVE team assigned CVE-2024-26924 for a netfilter nft_set_pipapo flaw in which a live element could be freed. Red Hat addressed the issue in RHEL 8, RHEL 9, and RHEL 9.4 EUS through RHSA-2024:8856, RHSA-2024:8870, RHSA-2024:9315, and RHSA-2025:1658.
The Linux kernel CVE team assigned CVE-2024-35848 for a memory-corruption race condition in the EEPROM at24 driver. Red Hat resolved the issue for RHEL 9 through RHSA-2024:5363; Fedora tracked affected builds as fedora-all.
The Linux kernel CVE team assigned CVE-2024-35898 for a potential data race in Netfilter nf_tables' __nft_flowtable_type_get() function. Red Hat issued fixes across affected RHEL 8 and 9 streams, including EUS, SAP, telecommunications, and mission-critical variants.
The Linux kernel CVE team assigned CVE-2024-27397 for an nf_tables issue resolved by using timestamps when checking set-element timeouts. Red Hat issued errata for affected RHEL 8 and 9 streams, including EUS, SAP, telecommunications, and mission-critical offerings; Fedora tracked the issue as bug 2280435.
The Linux kernel CVE team assigned CVE-2024-35900 for an nf_tables issue that allowed creation of a new base chain after a table flag update; the upstream fix rejects such chains. Red Hat issued fixes for RHEL 8, RHEL 9, and RHEL 9.4 EUS, while Fedora tracked the issue as bug 2281665.
The Linux kernel CVE team assigned CVE-2024-36005 for an nf_tables issue in which the table dormant flag was not honored from the netdev release-event path. Red Hat remediated the resolved issue across supported RHEL 8 and 9 streams, including EUS and specialized support offerings.
CVE-2024-26925 was assigned for an nf_tables abort-path flaw that fails to release a mutex after nft_gc_seq_end. Red Hat addressed it in RHEL 8, RHEL 9, and RHEL 9.2 EUS through RHSA-2024:4823, 4831, 5101, 5102, and 5928; Fedora also tracked the issue as affecting fedora-all.
Red Hat addressed CVE-2024-36025 across supported RHEL 8 and 9 streams, including EUS, SAP, telecommunications, and mission-critical variants, through advisories including RHSA-2024:4823, 4831, 4902, 5101, 5102, 5928, and 8107.
The Linux kernel CVE announcement detailed an off-by-one bounds-check error in qla_edif_app_getstats() that could cause memory corruption. The issue was fixed in stable kernel versions 5.15.156, 6.1.87, 6.6.28, 6.8.7, and 6.9, with users advised to update to a current stable release rather than cherry-pick individual commits.
The Linux kernel CVE team assigned CVE-2024-36025 to an off-by-one vulnerability in the qla2xxx SCSI driver's qla_edif_app_getstats() function. Fedora tracked the issue as affecting fedora-all.
Red Hat issued RHSA-2024:4447 to fix CVE-2023-52924 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
Red Hat issued RHSA-2024:3421 to address CVE-2023-52924 for Red Hat Enterprise Linux 9.0 Extended Update Support.
CVE-2023-52924 was identified as a Linux kernel netfilter/nf_tables flaw in timeout-enabled verdict maps that can leak chain references and cause warnings or erroneous ENOENT flush errors. Red Hat classified the issue as Important and assigned a CVSS v3.1 score of 7.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
21 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.