Red Hat released RHSA-2023:7417, an Important security advisory supplying updated kpatch-patch live-kernel modules for Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions on x86_64 and IBM Power LE (ppc64le). The packages cover kernel streams 4.18.0-193.109.1, 4.18.0-193.113.1, and 4.18.0-193.116.1, enabling affected systems to receive the fixes without a kernel reboot.
The update remediates four Linux-kernel vulnerabilities: CVE-2023-1829, CVE-2023-3609, CVE-2023-3776, and CVE-2023-4004. CVE-2023-1829 is a use-after-free and potential double-free issue in the traffic-control tcindex filter that may let a local attacker obtain root privileges; CVE-2023-4004 is an Important-severity use-after-free in Netfilter nftables nft_pipapo_remove() that a low-privileged local user could trigger to crash a system or escalate privileges. Red Hat rated CVE-2023-4004 CVSS 7.8 and noted that blocking the affected Netfilter module from loading can mitigate exposure where patching is not immediately possible.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:5221, RHSA-2023:5244, and RHSA-2023:5255 for RHEL 8 kpatch-patch, kernel, and kernel-rt packages, respectively, remediating CVE-2023-4004.
Red Hat released RHSA-2023:4961 and RHSA-2023:4962 for RHEL 8.4 Telecommunications Update Service, addressing CVE-2023-4004. These advisories also addressed the Linux tcindex use-after-free flaw CVE-2023-1829 for applicable RHEL 8.4 update-service channels.
Red Hat published the CVE-2023-4004 record for an Important-severity Linux kernel Netfilter use-after-free vulnerability in nft_pipapo_remove(). A low-privileged local user could trigger a crash or potentially escalate privileges by removing an element without NFT_SET_EXT_KEY_END.
Red Hat published RHSA-2023:7417, providing kpatch-patch live kernel patch modules for RHEL 8.2 Update Services for SAP Solutions. The update remediated CVE-2023-1829 and CVE-2023-4004, along with CVE-2023-3609 and CVE-2023-3776.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.