Red Hat released Moderate-severity RHEL 9.0 Extended Update Support kernel updates addressing CVE-2021-33631, an integer-overflow flaw in ext4's ext4_write_inline_data_end(), and CVE-2023-6931, an out-of-bounds write in perf_read_group() caused by perf_event read_size overflow. CVE-2021-33631 also affected openEuler kernel versions 4.19.90 before 4.19.90-2401.3 and 5.10.0-60.18.0 before 5.10.0-183.0.0; the underlying issue was fixed upstream in Linux 6.2.
RHSA-2024:1836 provides kernel 5.14.0-70.97.1.el9_0 for RHEL 9.0 EUS and SAP Update Services on x86_64, s390x, ppc64le, and aarch64. RHSA-2024:1840 supplies the Real Time kernel 5.14.0-70.97.1.rt21.169.el9_0 for x86_64 SAP Solutions 9.0 Update Services. Organizations using the affected EUS or real-time kernel packages should deploy the applicable update and reboot systems to activate the fixes.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2024:1840 for the RHEL 9.0 Extended Update Support Real Time Linux Kernel. The kernel-rt-5.14.0-70.97.1.rt21.169.el9_0 update fixes CVE-2021-33631 and CVE-2023-6931.
Red Hat issued RHSA-2024:1836 for RHEL 9.0 Extended Update Support and associated offerings, providing kernel 5.14.0-70.97.1.el9_0. The update remediates CVE-2021-33631 and CVE-2023-6931 across x86_64, s390x, ppc64le, and aarch64 packages.
The upstream Linux kernel fixed the ext4_write_inline_data_end() integer-overflow issue associated with CVE-2021-33631 in Linux kernel version 6.2, via commit 5c099c4fdc438014d5893629e70a8ba934433ee8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.