Red Hat released Important-rated kernel security updates for Red Hat Enterprise Linux 8 and 9 streams, including RHEL 9.0 Extended Update Support and associated SAP and CodeReady Linux Builder repositories. The RHEL 9.0 EUS update delivers kernel version 5.14.0-70.101.1.el9_0 for x86_64, s390x, ppc64le, and aarch64 systems.
The updates remediate multiple Linux kernel concurrency flaws, including CVE-2024-26585, a TLS asynchronous-cryptography race between transmit-work scheduling and socket closure; CVE-2024-26810, involving VFIO PCI external INTx masking operations; and CVE-2024-26686, affecting procfs thread and child-statistics collection. Administrators should apply the relevant Red Hat kernel packages across standard, EUS, SAP, telecommunications, and mission-critical support deployments, then reboot systems to activate the fixes.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated advisory RHSA-2024:3421 for RHEL 9.0 Extended Update Support, providing kernel version 5.14.0-70.101.1.el9_0. The update addressed multiple kernel flaws, including CVE-2023-6240, CVE-2024-1086, CVE-2024-26586, CVE-2024-25742, and CVE-2024-25743; affected systems require a reboot after installation.
Red Hat addressed CVE-2023-52639, a race condition during shadow creation in the Linux kernel KVM s390 VSIE component, through RHSA-2024:3855 for RHEL 9.2 EUS, RHSA-2024:4740 for RHEL 8.8 EUS, and RHSA-2024:5257 for RHEL 9.0 Update Services for SAP Solutions.
Red Hat addressed CVE-2024-36003 for Red Hat Enterprise Linux 9 through RHSA-2024:5928. The resolved Linux kernel issue involves a lock-dependency problem between LAG handling and VF operations in the Intel Ethernet Controller (ice) driver's ice_reset_vf() function.
CVE-2021-47353 affects the Linux kernel UDF filesystem's udf_symlink function, where a NULL-pointer dereference could cause a kernel crash or denial of service. Red Hat addressed the resolved upstream issue for RHEL 8 through RHSA-2024:4211 and RHSA-2024:4352.
CVE-2021-46909 affects ARM Footbridge PCI interrupt mapping: IRQ-mapping functions marked __init could be invoked after initialization when PCI drivers are loaded or bound, causing a kernel oops. Red Hat addressed the issue for RHEL 8 through RHSA-2024:4211 and RHSA-2024:4352.
Red Hat addressed CVE-2024-26686 through advisories for RHEL 8 and 9, including RHEL 8.8 and RHEL 9.2/9.4 EUS as well as specialized mission-critical, SAP, and telecommunications offerings.
CVE-2024-26686 was assigned for a Linux kernel fs/proc do_task_stat issue affecting the collection of thread and child statistics. The remediation uses sig->stats_lock while gathering the statistics.
Red Hat addressed CVE-2024-26810 in advisories covering RHEL 8 and 9, including EUS, SAP, telecommunications, and mission-critical support variants.
CVE-2024-26810 was assigned for a Linux kernel VFIO PCI subsystem issue involving external INTx masking operations. The upstream remediation locks those operations to address a potential concurrency condition.
Red Hat addressed CVE-2024-26585 through advisories for RHEL 8 and 9, including RHSA-2024:2394, RHSA-2024:4211, RHSA-2024:4352, and specialized EUS, SAP, telecommunications, and mission-critical offerings.
CVE-2024-26585 was identified as an ordering race in Linux kernel TLS asynchronous cryptographic request handling, where a submitting recvmsg/sendmsg thread can exit after completion is signaled. The upstream fix schedules work before invoking complete().
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.