Red Hat released RHSA-2024:2004 for standard Red Hat Enterprise Linux 7 kernels and RHSA-2024:2003 for RHEL for Real Time 7, addressing five vulnerabilities: CVE-2020-36558, CVE-2023-2002, CVE-2023-25775, CVE-2023-4622, and CVE-2023-4623. The flaws include use-after-free conditions in unix_stream_sendpage and sch_hfsc, unauthorized Bluetooth management-command execution, improper access control in irdma, and a race in the VT_RESIZEX ioctl handler that can trigger a NULL-pointer dereference and crash a system.
The standard RHEL 7 advisory provides kernel version 3.10.0-1160.118.1.el7; the Real Time advisory affects RHEL for Real Time, Real Time for NFV, and eligible x86_64 Extended Life Cycle Support deployments. Red Hat previously tracked the VT console issue as CVE-2020-36558, affecting kernels before 5.5.7, and had also issued RHEL 8 fixes through earlier kernel updates. Administrators should apply applicable prerequisite errata and updated kernel packages, then reboot systems for the mitigations to take effect.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHBA-2024:2615 to update the rhscl/devtoolset-12-perftools-rhel7 container image for RHEL 7. The image update addresses the kernel security issues covered by RHSA-2024:2004, including CVE-2020-36558, and users were advised to rebuild dependent container images.
Red Hat issued Important-security advisory RHSA-2024:2004 for RHEL 7, providing kernel version 3.10.0-1160.118.1.el7 and fixing CVE-2020-36558 plus four additional vulnerabilities. The update covers supported RHEL 7 variants and requires a reboot for the new kernel to take effect.
Red Hat issued Important-security advisory RHSA-2024:2003 for RHEL 7 Real Time kernel packages, updating them to 3.10.0-1160.118.1.rt56.1269.el7 and fixing CVE-2020-36558 and four other vulnerabilities. The update applies to RHEL for Real Time, Real Time for NFV, and the x86_64 Extended Life Cycle Support offering.
Red Hat provided a fix for CVE-2020-36558 in the RHEL 8.6 Extended Update Support channel through RHSA-2023:5627.
Red Hat closed its tracking issue, Bug 2112693, for the VT_RESIZEX ioctl race condition identified as CVE-2020-36558.
Red Hat issued RHSA-2022:7444 for the RHEL 8 kernel-rt package, remediating CVE-2020-36558 in the RHEL 8 Real Time kernel channel.
Red Hat issued Moderate-security advisory RHSA-2022:7683 for RHEL 8, delivering kernel version 4.18.0-425.3.1.el8 and remediating CVE-2020-36558 along with numerous other kernel vulnerabilities.
Red Hat tracked Fedora as affected by CVE-2020-36558 under Bug 2274389.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.