Red Hat released Important RHEL 8 kernel updates addressing CVE-2023-1281, a use-after-free flaw in the Linux traffic-control tcindex filter. A local attacker could exploit a race involving updates to the imperfect hash area while packets traverse it, causing a freed tcf_ext object to be used by tcf_exts_exec() and potentially escalating privileges to root. Linux kernel versions from 4.14 through the upstream fix commit ee059170b1f7e94e55fa6cadee544e176a6e59c2 are affected.
The RHEL 8.2 AUS, TUS, SAP Solutions Update Services, and Telecommunications Update Service updates also remediate CVE-2023-0461, CVE-2023-1390, and CVE-2023-32233, including additional local use-after-free issues and a remotely triggerable TIPC denial of service. Organizations should install the applicable kernel packages—such as 4.18.0-193.109.1.el8_2 or the real-time 4.18.0-193.109.1.rt13.160.el8_2 release—and reboot; SAP Update Services deployments can use the supplied kpatch live-patch packages, which load automatically after installation on supported x86_64 and ppc64le systems.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2023:4256 for specified RHEL 8.4 service variants, providing kernel version 4.18.0-305.97.1.el8_4 for x86_64 and ppc64le offerings. The update fixes CVE-2023-1281 and CVE-2023-32233, among other bugs, and requires a system reboot to take effect.
Red Hat issued Important advisory RHSA-2023:4255 for kernel-rt packages on specified RHEL 8.4 real-time offerings, including Extended Life Cycle Long Life and Telecommunications/NFV Telecommunications Update Services. Kernel-rt version 4.18.0-305.97.1.rt7.172.el8_4 remediates CVE-2023-1281 and CVE-2023-32233; affected systems require a reboot after installation.
Red Hat issued Important advisory RHSA-2023:4130 for RHEL 8.6 Extended Update Support and related product channels, providing kernel build 4.18.0-372.64.1.el8_6. The update fixes CVE-2023-1281, CVE-2023-32233, CVE-2022-50396, and CVE-2022-50493; affected systems must reboot after installation.
Red Hat issued Important advisory RHSA-2023:4146, supplying kpatch live-patch packages for RHEL 8.2 Update Services for SAP Solutions on x86_64 and ppc64le. The live patch remediates CVE-2023-1281 and three additional kernel flaws, and is automatically loaded following RPM installation.
Red Hat issued Important advisory RHSA-2023:4126 for kernel-rt packages on RHEL for Real Time Telecommunications Update Service 8.2, including NFV deployments. The update, version 4.18.0-193.109.1.rt13.160.el8_2, fixes CVE-2023-1281 and three other kernel vulnerabilities; affected systems must reboot after installation.
Red Hat issued Important advisory RHSA-2023:4125, providing kernel version 4.18.0-193.109.1.el8_2 for affected RHEL 8.2 AUS, TUS, and SAP Update Services deployments. The update remediates CVE-2023-1281 along with CVE-2023-0461, CVE-2023-1390, and CVE-2023-32233; a reboot is required for the kernel fixes to take effect.
Red Hat issued Important advisory RHSA-2023:3852 for RHEL 8.1 Update Services for SAP Solutions on x86_64 and ppc64le. Kernel version 4.18.0-147.85.1.el8_1 fixes CVE-2023-1281 and CVE-2023-32233; affected systems must be rebooted after installation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.