Red Hat released Important-rated kernel and real-time kernel updates for affected RHEL 8.2 Advanced Update Support, Telecommunications Update Service, SAP Solutions, Real Time, and Real Time for NFV deployments. The updates remediate seven Linux kernel flaws, including CVE-2023-4459, a NULL-pointer dereference in the vmxnet3 network driver that can allow a local user to crash a system through an MTU-change error path, and CVE-2023-7192, a Netfilter connection-tracking reference-count leak that a local attacker with CAP_NET_ADMIN can exploit to cause denial of service.
The advisories also address use-after-free, stack-corruption, divide-error, oversized-packet handling, and membarrier resource-exhaustion conditions. Organizations using the affected non-real-time kernel should deploy build 4.18.0-193.133.1.el8_2; affected real-time environments should install the applicable updated kernel-rt packages. Systems must be rebooted after installation for the kernel fixes to take effect.

See real exploitation activity before you spend the cycle.
12 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated advisory RHSA-2024:2008 for RHEL 8.2 Real Time and Real Time for NFV Telecommunications Update Service systems. Kernel-rt version 4.18.0-193.133.1.rt13.184.el8_2 remediated seven flaws, including CVE-2023-4459 and CVE-2023-7192, and required a reboot.
Red Hat issued Important-rated advisory RHSA-2024:2006 for RHEL 8.2 AUS, TUS, and SAP Solutions deployments. Kernel build 4.18.0-193.133.1.el8_2 fixed seven vulnerabilities, including CVE-2023-4459 and CVE-2023-7192; affected systems require a reboot.
Red Hat published an Important kpatch-patch update for RHEL 9.0 Extended Update Support and SAP Solutions systems. The live patch remediated five networking and netfilter vulnerabilities, including CVE-2023-3776, CVE-2023-3812, CVE-2023-4004, CVE-2023-4147, and CVE-2023-42753.
Red Hat issued Important-rated RHSA-2023:7431 for RHEL 8.2 Real Time Telecommunications Update Service and Real Time for NFV Telecommunications Update Service systems. Kernel-rt version 4.18.0-193.119.1.rt13.170.el8_2 fixed CVE-2023-1829, CVE-2023-3609, CVE-2023-3776, and CVE-2023-4004; affected systems require a reboot.
Red Hat issued an Important security and bug-fix update for RHEL 8 kernel-rt packages, including Real Time and Real Time for NFV offerings. It addressed multiple kernel vulnerabilities, including Zenbleed and flaws in Bluetooth, nftables, netfilter, networking schedulers, ipvlan, and cls_flower.
Red Hat issued an Important-rated kernel-rt security and bug-fix update for RHEL 8.4 Advanced Mission Critical, Telecommunications, and SAP update-service offerings. The update remediated eight flaws across traffic control, ipvlan, nftables/netfilter, cls_flower, Bluetooth, and XFS, and required a reboot.
Red Hat issued Important-rated RHSA-2023:4817 for RHEL 8.2 Real Time and Real Time for NFV Telecommunications Update Service deployments. Kernel-rt version 4.18.0-193.113.1.rt13.164.el8_2 fixed CVE-2023-2124, CVE-2023-35788, and CVE-2023-3090; affected systems require a reboot.
CVE-2024-26586 could corrupt the kernel stack and panic systems using mlxsw Spectrum-2 or newer switching ASICs when an ACL group exceeded the 16-ACL PAGT-register capacity. The fix caps ACL-group size at the lower of firmware-reported and hardware-register limits and adds a regression test; fixes were backported to stable kernels and multiple Red Hat Enterprise Linux update streams.
The Linux kernel fixed CVE-2023-7192 in commit ac4893980bbe79ce383daf9a0885666a30fe4c83. A local attacker with CAP_NET_ADMIN could trigger reference-count overflows in ctnetlink_create_conntrack(), resulting in denial of service.
The Linux kernel fixed CVE-2023-4459 in commit edf410cb74dc612fd47ef5be319c5a0bcd6e6ccd. The flaw could allow a local unprivileged attacker to cause denial of service when vmxnet3 receive-queue cleanup dereferences a NULL receive-ring base pointer after DMA allocation failure.
Linux fixed CVE-2023-1829 with commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28. The tcindex_delete flaw failed to deactivate perfect-hash filters before deletion, enabling a double free that a local attacker could use to escalate privileges to root.
Fedora fixed CVE-2023-4004 in its Linux kernel 6.4.7 stable update. The Netfilter nftables pipapo-set flaw is a use-after-free in nft_pipapo_remove() when an element is inserted without NFT_SET_EXT_KEY_END.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.