Red Hat released Important kernel and real-time kernel updates for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, delivering kernel version 5.14.0-70.105.1.el9_0 for x86_64, ppc64le, aarch64, and s390x, and kernel-rt version 5.14.0-70.105.1.rt21.177.el9_0 for x86_64. The updates remediate CVE-2024-0193, a Netfilter use-after-free vulnerability in which local unprivileged users could potentially escalate privileges by triggering double deactivation during pipapo-set removal and catchall-element garbage collection.
The advisories also address CVE-2023-52434, an SMB client out-of-bounds flaw caused by inadequate validation of SMB2 create-context offsets and lengths; Red Hat rates it 5.9 CVSS and considers adjacent-network denial of service the most likely impact. The standard kernel update additionally fixes a KVM use-after-free issue and a Netfilter protocol-number sanitization weakness, while the real-time update includes the latter Netfilter flaw. Administrators should apply the applicable packages and reboot affected systems for the fixes to take effect; preventing the cifs module from loading can mitigate the SMB issue until patching is complete.

Get the actors, campaigns, and ATT&CK mapping behind it.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2024:6991 for RHEL 9.0 Update Services for SAP Solutions, delivering kernel version 5.14.0-70.117.1.el9_0. The update fixes 12 CVEs, including CVE-2023-52489, CVE-2024-40995, CVE-2024-41055, and CVE-2024-41071, and requires affected systems to be rebooted.
Red Hat issued an Important kernel update for RHEL 9.0 Update Services for SAP Solutions, providing kernel version 5.14.0-70.105.1.el9_0. The update remediates CVE-2024-0193, CVE-2023-52434, CVE-2024-26598, and CVE-2024-26673, and requires a reboot to take effect.
Red Hat issued an Important kernel-rt update for RHEL 9.0 Update Services for SAP Solutions on x86_64. Version 5.14.0-70.105.1.rt21.177.el9_0 fixes CVE-2024-0193, CVE-2023-52434, and CVE-2024-26673; systems require a reboot after installation.
Red Hat released RHSA-2024:2950 for RHEL 8 kernel-rt and RHSA-2024:3138 for the RHEL 8 kernel, remediating CVE-2023-52434.
Red Hat released RHSA-2024:2394 to fix CVE-2023-52434, an out-of-bounds condition in the Linux SMB client's smb2_parse_contexts() function, for Red Hat Enterprise Linux 9.
Mauro Matteo Cascella reported the Linux kernel Netfilter flaw later tracked as CVE-2024-0193. The bug can double-deactivate a catchall element during pipapo set removal, causing use-after-free and possible local privilege escalation.
Red Hat released RHSA-2024:6993 to fix CVE-2023-52434 in the RHEL 8.8 Extended Update Support kernel stream.
RHSA-2024:5692 remediated CVE-2023-52434 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
An upstream Netfilter fix was made available in commit 7315dc1e122c85ffdfc8defffbb8f8b616c2eb1a, and Fedora fixed CVE-2024-0193 in Linux 6.6.10 stable kernel updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.