Red Hat released an Important security update for Red Hat Enterprise Linux Server AUS 7.6 that fixes CVE-2023-4623, a CVSS 7.8 use-after-free flaw in the Linux kernel's net/sched Hierarchical Fair Service Curve (HFSC) traffic-control component. A local low-privileged attacker could exploit the dangling-pointer condition to escalate privileges when HFSC handles classes using link-sharing curves under a parent without one.
RHSA-2024:1747 provides kernel build 3.10.0-957.112.1.el7 and associated packages for affected x86_64 RHEL 7.6 AUS systems; fixes were also issued for affected RHEL 7 and 8 kernel, real-time kernel, and kpatch packages. Administrators should install applicable prior errata and reboot to activate the updated kernel. Until patching is complete, Red Hat recommends blacklisting the sch_hfsc module to prevent its automatic loading.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released fixes for affected RHEL 7 kernel, kernel-rt, and kpatch-patch packages through RHSA-2024:2004, RHSA-2024:2003, and RHSA-2024:1960.
Red Hat published Important advisory RHSA-2024:1747 for RHEL Server AUS 7.6 on x86_64, supplying kernel build 3.10.0-957.112.1.el7 to remediate the HFSC use-after-free flaw. The advisory instructed administrators to reboot after applying the update.
Red Hat issued kernel and kernel-rt fixes for affected RHEL 8.2 Advanced Update Support and 8.2 Telecommunications Update Service packages through RHSA-2024:1268 and RHSA-2024:1269.
Red Hat released fixes for CVE-2023-4623 in Red Hat Enterprise Linux 8 kernel, kernel-rt, and kpatch-patch packages through RHSA-2024:0897, RHSA-2024:0881, and RHSA-2024:0876.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.