Red Hat released moderate-severity updates for the standard Linux kernel and Real Time Linux Kernel in RHEL 9, delivering kernel-rt-5.14.0-162.6.1.rt21.168.el9_1 for x86_64 and corresponding kernel packages across x86_64, ARM64, IBM Z, and Power. The updates remediate numerous vulnerabilities, including memory-safety defects that could enable local privilege escalation, information disclosure, denial of service, out-of-bounds writes, TCP session injection or termination, and AMD and Intel speculative-execution issues including RetBleed-related weaknesses.
Among the fixed flaws is CVE-2022-1016, a Netfilter/nf_tables defect in nft_do_chain() in which uninitialized stack registers could leak kernel pointers to userspace. The upstream fix initializes those registers; Red Hat shipped remediations for RHEL 8 and 9 through multiple advisories. Organizations running affected RHEL 9 standard or real-time kernels should apply the relevant updates and reboot systems, as the kernel fixes do not take effect until restart.

See real exploitation activity before you spend the cycle.
12 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2023:3708 for RHEL 9 x86_64 Real Time Linux Kernel version 5.14.0-284.18.1.rt14.303.el9_2. The update fixed six kernel vulnerabilities, including CVE-2023-32233 in netfilter nf_tables, and required affected systems to be rebooted.
Red Hat issued Moderate-severity advisory RHSA-2022:8267 for the standard RHEL 9 kernel across x86_64, ARM64, IBM Z, and Power offerings. It fixed CVE-2022-1016 and other memory-safety, network, denial-of-service, and CPU speculative-execution vulnerabilities, with a reboot required after installation.
Red Hat issued Moderate-severity advisory RHSA-2022:7933 for RHEL 9 kernel-rt, delivering version 5.14.0-162.6.1.rt21.168.el9_1 for x86_64. The update remediated numerous kernel flaws, including CVE-2022-1016 and speculative-execution issues; affected systems require rebooting.
Red Hat remediated CVE-2022-20572, a dm-verity missing-permission-check flaw that can permit modification of read-only files and local privilege escalation, through RHSA-2022:7444 for RHEL 8 kernel-rt and RHSA-2022:7683 for the standard RHEL 8 kernel. Red Hat rated the issue Moderate, with a CVSS v3.1 score of 6.7.
Red Hat issued RHSA-2022:7683 for RHEL 8 kernel packages and RHSA-2022:7444 for RHEL 8 kernel-rt packages, remediating CVE-2022-1016. The flaw involves uninitialized stack registers in nft_do_chain() that can expose kernel pointers to a local low-privileged attacker.
Marian Rehak reported Red Hat's tracking bug for CVE-2022-1852, a medium-severity KVM x86 instruction-emulation flaw that can cause a NULL-pointer dereference and denial of service when an Intel-hosted guest executes an illegal instruction.
Marian Rehak reported that the Linux kernel ALSA subsystem's snd_pcm_hw_free function may unlock too early, creating a race condition that can lead to a use-after-free vulnerability. Fedora was tracked as affected.
Marian Rehak described CVE-2022-1016, a Netfilter/nf_tables flaw in which uninitialized stack registers in nft_do_chain() could leak kernel pointers.
Marian Rehak reported Red Hat's tracking bug for CVE-2022-24448, a low-severity Linux kernel NFS flaw where nfs_atomic_open() may return uninitialized file-descriptor data instead of ENOTDIR when O_DIRECTORY is used on a regular file.
CVE-2022-1184 was documented as a use-after-free in ext4 directory-index insertion, where crafted filesystem images and rename operations can trigger invalid reads in dx_insert_block(). The issue was reported reproducible on kernels 4.14, 5.16, and upstream 5.17.15, and Red Hat remediated it through RHEL 8, RHEL 9, and RHEL 8.6 EUS advisories.
Red Hat closed its Bugzilla record tracking CVE-2022-1016 after fixes had been made available for affected RHEL releases.
Upstream fixed CVE-2022-1016 with commit 4c905f6740a365464e91467aa50916555b28213d, which initializes nft_do_chain() registers. Fedora incorporated the correction in 5.16.18 stable kernel updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.