Red Hat released kernel and container-image updates to remediate a broad set of Linux kernel vulnerabilities across RHEL 8 and RHEL 9. The flaws include memory-safety defects, use-after-free and out-of-bounds conditions, NULL-pointer dereferences, race conditions, deadlocks, information disclosure, and denial-of-service risks across subsystems such as USB, HID, RDMA, networking, BPF, Bluetooth, filesystems, storage, graphics, and virtualization. Examples include CVE-2024-26933, a USB-core deadlock, CVE-2024-26717, a NULL dereference in the HID I2C driver, and CVE-2024-26743, an RDMA/qedr error-flow flaw.
The fixes were delivered through RHEL kernel advisories including RHSA-2024:9315 for RHEL 9, and through refreshed RHEL 8 base and middleware container images tied to RHSA-2024:7000, including Flatpak SDK, Go Toolset, Support Tools, Camel K Operator, and RHPAM Kogito Builder images. Organizations should apply the updated RHEL kernel packages and reboot affected hosts; for containers, pull the revised images, update Dockerfiles or build scripts to use current tags, and rebuild and redeploy all downstream images. Red Hat later corrected RHSA-2024:9315 to remove CVE-2023-52490, which had been incorrectly listed as fixed, without changing the packages.

See real exploitation activity before you spend the cycle.
72 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2025:4341 for RHEL 9 kernel packages, fixing CVE-2024-42292, CVE-2024-42322, CVE-2024-44990, CVE-2024-46826, and CVE-2025-21927. The update covers supported RHEL 9 architectures and multiple EUS, ELS, SAP, AUS, and CodeReady Linux Builder offerings; systems require a reboot after installation.
Red Hat issued Important-rated RHSA-2025:3215 for RHEL 9.4 channels, providing kernel 5.14.0-427.61.1.el9_4 and fixes for 11 Linux kernel CVEs, including CVE-2024-24857 and CVE-2025-21785. The update applies across x86_64, aarch64, ppc64le, and s390x RHEL 9.4 offerings; systems must be rebooted after installation.
Red Hat revised RHSA-2024:9315 to remove CVE-2023-52490 after determining it had been incorrectly listed as fixed. Red Hat said the correction did not change the distributed kernel packages.
Red Hat issued RHBA-2024:9811 to update the integration/camel-k-rhel8-operator-bundle image for RHEL 8-based Middleware Containers with kernel security fixes referenced in RHBA-2024:9635. The update affects OpenShift Container Platform 4.11 and 4.12 on RHEL 8 x86_64; Red Hat advised users to upgrade the image and rebuild dependent images.
Red Hat issued moderate-severity RHSA-2024:9315 for the RHEL 9 Linux kernel across supported architectures and variants. The update fixed a broad set of kernel flaws, including CVE-2024-26717, CVE-2024-26743, and CVE-2024-26933; affected systems require a reboot after installation.
Red Hat issued RHBA-2024:9014 to update the RHEL 9 el9/flatpak-sdk container image with backported Linux kernel security fixes from RHSA-2024:8617, including CVE-2024-2201 and numerous networking, filesystem, USB, wireless, and SCSI flaws. Red Hat advised users to upgrade the image and rebuild dependent container images across supported RHEL 9 architectures and variants.
Red Hat released RHBA-2024:8227 for the rhpam-7/rhpam-kogito-builder-rhel8 image, incorporating RHSA-2024:7000 kernel security content. The advisory covered affected RHEL 8 OpenShift Container Platform 4.10, 4.11, and 4.12 deployments and called for dependent images to be rebuilt.
RHBA-2024:7637 updated the rhel8/support-tools container image with backported RHSA-2024:7000 kernel security fixes, including fixes for use-after-free, out-of-bounds, deadlock, and denial-of-service flaws. Red Hat advised customers to update the image and rebuild dependent containers.
Red Hat issued RHBA-2024:7198 for rhel8/go-toolset container images, incorporating backported RHSA-2024:7000 kernel fixes for memory-safety, bounds-checking, NULL-pointer, race, and denial-of-service issues. Red Hat instructed users to pull the new image, update Dockerfiles or scripts, and rebuild dependent images.
Red Hat released RHBA-2024:7236, refreshing the RHEL 8 el8/flatpak-sdk image with backported Linux kernel security fixes from RHSA-2024:7000. Users were advised to upgrade the image and rebuild downstream containers.
Red Hat issued RHBA-2024:7235 to update the RHEL 9 el9/flatpak-sdk container image with backported Linux kernel security fixes from RHSA-2024:6997. Red Hat advised users to upgrade the image and rebuild dependent container images across supported RHEL 9 architectures and variants.
Red Hat released RHBA-2024:7043 for the integration/camel-k-rhel8-operator image, incorporating RHSA-2024:7000 kernel security content. The update affected OpenShift Container Platform 4.11 and 4.12 on RHEL 8 x86_64, and Red Hat advised rebuilding dependent images.
An upstream Linux kernel CVE advisory disclosed CVE-2024-45018, in which netfilter flowtable flow-offload handling could use an uninitialized extack variable. The upstream fix initializes extack before use; Red Hat delivered fixes for RHEL 8 and RHEL 9 through RHSA-2024:8617, RHSA-2024:8856, RHSA-2024:8870, and RHSA-2024:10939.
Red Hat issued RHBA-2024:6299 to update the RHEL 9 el9/flatpak-sdk container image with backported Linux kernel security fixes from RHSA-2024:5928. The advisory covers 41 kernel CVEs across supported RHEL 9 architectures and instructs users to upgrade the image and rebuild dependent container images.
Red Hat issued RHBA-2024:5464 to update the el9/flatpak-sdk container image for RHEL 9 with backported Linux kernel security fixes from RHSA-2024:5363. Red Hat advised users to upgrade the image and rebuild dependent container images across supported RHEL 9 architectures and variants.
Red Hat issued RHBA-2024:4535 to update the rhel8/support-tools container image with backported Linux kernel security fixes from RHSA-2024:4211. The update covers x86_64, aarch64, ppc64le, and s390x RHEL 8 deployments, and Red Hat advised users to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:4495 to update the rhpam-7/rhpam-kogito-builder-rhel8 container image for RHEL 8-based Middleware Containers with backported Linux kernel security fixes from RHSA-2024:4211. The advisory applied to OpenShift Container Platform 4.10, 4.11, and 4.12 deployments and instructed users to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:4494 to update Red Hat Enterprise Linux 8 container images across x86_64, s390x, ppc64le, and aarch64 with backported kernel security fixes from RHSA-2024:4211. Red Hat instructed users to obtain the updated images, update Dockerfiles or scripts, and rebuild dependent container images.
An upstream Linux kernel CVE announcement disclosed CVE-2024-38562, an nl80211 Wi-Fi subsystem flaw involving unsafe address calculations through out-of-bounds array indexing. The issue was resolved upstream, and Red Hat addressed it for RHEL 9 through RHSA-2024:6997.
Red Hat issued RHBA-2024:3773 to update the rhel8/gcc-toolset-12-toolchain container image with backported Linux kernel security fixes from RHSA-2024:3618. The update covers x86_64, s390x, ppc64le, and aarch64 variants; Red Hat advised users to upgrade the image and rebuild dependent container images.
Red Hat issued RHBA-2024:3622 to refresh RHEL 8 and UBI 8 application container images with backported Linux kernel security fixes from RHSA-2024:3618. The update covers x86_64, s390x, ppc64le, and aarch64 images, and Red Hat advised users to retrieve updated images, update image references, and rebuild dependent containers.
Red Hat reported CVE-2021-47456, a low-severity use-after-free vulnerability in the Linux kernel CAN PEAK PCI driver's peak_pci_remove() removal path. The issue was resolved upstream and Red Hat addressed it for RHEL 8 through RHSA-2024:4211 and RHSA-2024:4352.
Robb Gatica created Red Hat Bug 2281953 for CVE-2024-36004, a low-severity Linux kernel i40e driver issue involving use of the WQ_MEM_RECLAIM flag on an affected workqueue. The upstream remediation removes that flag; Red Hat addressed the issue in RHEL 8 and RHEL 9.4 EUS advisories.
Zack Miele filed Red Hat Bug 2281113 for CVE-2024-27410, a medium-severity Linux kernel Wi-Fi nl80211 issue involving interface-type changes requested alongside mesh ID changes. The upstream fix rejects interface-type changes when the mesh ID is also changed; Red Hat later issued fixes for RHEL 8, RHEL 9, and RHEL 9.4 EUS.
Zack Miele reported CVE-2024-35809, a Linux kernel PCI power-management issue in which runtime-idle callbacks were not drained before driver removal. The upstream fix drains those callbacks during driver teardown; Red Hat addressed the issue in RHEL 8, RHEL 9, and RHEL 9.4 EUS advisories.
The Linux kernel CVE team assigned CVE-2024-26933 to a USB core deadlock affecting the port "disable" sysfs attribute. The issue had been resolved upstream.
The Linux kernel CVE team assigned CVE-2024-26868 for an NFS flaw in which failure of nfs4_ff_layout_prepare_ds() can cause a kernel panic. The issue was resolved upstream, and Red Hat remediated it for RHEL 9 through RHSA-2024:5363.
The Linux kernel CVE team assigned CVE-2024-26828 for an underflow in the CIFS subsystem's parse_server_interfaces() function. The issue was resolved upstream; Red Hat addressed it through RHSA-2024:3460 and RHSA-2024:3461 for RHEL 9.2 EUS and RHSA-2024:5363 for RHEL 9.
The Linux kernel CVE team assigned CVE-2024-26897 for an ath9k Wi-Fi driver race in which ath9k_wmi_event_tasklet() could run before initialization completed. The upstream fix delays tasklet processing until initialization is complete; Red Hat addressed the issue in RHEL 8, RHEL 9, and RHEL 9.2 EUS advisories.
Robb Gatica reported CVE-2024-26744, affecting support for specifying the srpt_service_guid parameter in the Linux kernel RDMA/srpt component. Red Hat tracked the issue as Bug 2273260 with medium severity and listed upstream and RHEL fixes.
Robb Gatica reported Red Hat Bug 2273268 for CVE-2024-26740, affecting mirrored-ingress handling in the Linux kernel net/sched act_mirred traffic-control component. The upstream fix changes mirred ingress processing to use the backlog.
Robb Gatica reported CVE-2024-26717, a NULL-pointer dereference in the Linux kernel HID i2c-hid-of driver that can occur following failed device power-up.
The Linux kernel CVE team assigned CVE-2023-52513 for improper connection-failure handling in the RDMA Software iWARP (siw) component, with an upstream advisory published through linux-cve-announce. Red Hat later addressed the flaw in RHEL 8 through RHSA-2024:3618 and RHSA-2024:3627 and in RHEL 9 through RHSA-2024:9315.
Rohit Keshri reported CVE-2024-0340, a low-severity Linux kernel information-disclosure flaw in vhost_new_msg() caused by uninitialized memory in messages exchanged between virtual guests and the host. A local privileged user could read portions of kernel memory through /dev/vhost-net; the issue was fixed upstream in Linux 6.4-rc6.
The Linux kernel CVE team assigned CVE-2024-38544 for a segmentation fault in the RDMA/rxe component's rxe_comp_queue_pkt() function. The issue was resolved upstream, and Red Hat addressed affected RHEL 9 systems through RHSA-2024:5928.
The Linux kernel CVE team assigned CVE-2021-47606 for an af_netlink flaw involving empty socket buffers. The upstream fix adds a length check to prevent empty skb handling, and Red Hat addressed the issue for RHEL 9 through RHSA-2024:5363.
The Linux kernel CVE team assigned CVE-2024-27022 for a fork-path flaw involving file-backed virtual memory areas. The upstream fix defers linking a file VMA until it is fully initialized; Red Hat addressed the issue for RHEL 9 in RHSA-2024:6997.
CVE-2024-40957 affects Linux kernel SEG6 local-processing End.DX4 and End.DX6 behaviors, which passed an invalid NULL input device to the PREROUTING NF_HOOK() call and could trigger a kernel NULL-pointer dereference in ipt_rpfilter. The upstream fix corrects the NF_HOOK() parameter passing, and Red Hat addressed the issue for RHEL 9 through RHSA-2024:5928.
The Linux kernel CVE team assigned CVE-2024-26991 for a potential lpage_info overflow while KVM's x86 MMU code checks attributes. Fedora tracked the issue as Bug 2278319, and Red Hat addressed it for RHEL 9 through RHSA-2024:6997.
CVE-2024-44990 affects the Linux kernel bonding subsystem, where bond_ipsec_offload_ok() could dereference a pointer without verifying that an active bonding slave exists. The upstream fix adds an active-slave check; Red Hat addressed the flaw through RHEL 8, RHEL 9, and RHEL 9.4 EUS advisories.
The Linux kernel CVE team assigned CVE-2021-47236 for an skb memory leak in the CDC EEM USB networking driver's transmit-fixup path. The upstream fix releases the skb correctly, and Red Hat addressed the low-severity issue for RHEL 8 through RHSA-2024:4211 and RHSA-2024:4352.
Lion Ackermann reported a race between network-namespace cleanup and garbage collection in netfilter ipset's list:set type that could let the garbage collector access a destroyed set, causing a use-after-free. The fix removes and waits for garbage collectors before set destruction, corrects destruction ordering, and improves RCU locking and list handling; Red Hat shipped fixes for RHEL 8 and 9 through RHSA-2024:8870, RHSA-2024:8856, and RHSA-2024:9315.
The Linux kernel CVE team assigned CVE-2023-52560 for a memory leak in damon_do_test_apply_three_regions() in the DAMON virtual-address test code. The issue was resolved upstream in Linux kernel 6.1.56, 6.5.6, and 6.6; Red Hat tracked it as Bug 2267730 and fixed it for RHEL 8 and RHEL 9 through listed advisories.
The Linux kernel CVE team assigned CVE-2024-35888 for an ERSPAN packet-handling issue resolved by ensuring an erspan_base_hdr is present in skb->head. Red Hat addressed the issue through RHEL 8 advisories RHSA-2024:4211 and RHSA-2024:4352, RHEL 9 advisory RHSA-2024:9315, and RHEL 9.4 EUS advisory RHSA-2025:3510.
CVE-2024-44935 is a Linux kernel SCTP race in reuseport_add_sock() that can cause a null-pointer dereference when SO_REUSEPORT listeners are concurrently created or closed, and can create inactive duplicate reuseport groups. The upstream fix adds hash-bucket locking to SCTP endpoint hash and unhash operations; Red Hat addressed it in RHEL 8 and RHEL 9.4 EUS advisories.
The Linux kernel CVE team assigned CVE-2024-35939 for a dma-direct flaw that can leak pages when dma_set_decrypted() fails. The issue was resolved upstream, and Red Hat addressed it in RHEL 8, RHEL 9, and RHEL 9.4 EUS advisories.
A race condition in the Linux kernel net/bluetooth conn_info_{min,max}_age_set() functions can cause an integer overflow, potentially leading to abnormal Bluetooth connections or denial of service. Red Hat addressed the issue in RHEL 8, RHEL 9, and RHEL 9.4 Extended Update Support advisories.
CVE-2024-46826 affects the Linux kernel ELF loader, which could read kernel.randomize_va_space twice during one exec operation and use inconsistent values if the sysctl changed between reads. The upstream fix reads the value once; Red Hat addressed the issue in RHEL 8, RHEL 9, and RHEL 9.4 EUS through listed RHSA advisories.
CVE-2023-52881 concerns Linux TCP/IP spoofing techniques that use ghost ACKs to infer a server-selected send window and side channels, including TCP SYN cookies, to recover initial sequence numbers. Red Hat issued fixes for multiple RHEL 8 and RHEL 9 update channels, including RHSA-2024:4211, RHSA-2024:4352, RHSA-2024:5281, RHSA-2024:6206, RHSA-2024:10772, and RHSA-2024:10773.
The Linux kernel CVE team assigned CVE-2021-47055 for an MTD subsystem flaw that allowed locking and bad-block ioctl operations without write permissions. Fedora fixed the issue in 5.12.4 stable kernel updates, and Red Hat addressed it for RHEL 8 through RHSA-2024:3618 and RHSA-2024:3627.
The Linux kernel CVE team assigned CVE-2024-26739 for a net/sched act_mirred flaw in which the return value could be overridden after the socket buffer had already been lost. The upstream fix prevents that override, and Red Hat addressed the issue in RHEL 9 and RHEL 9.2 Extended Update Support advisories.
CVE-2024-40984 affects ACPICA operation-region mappings crossing page boundaries, where a partial mapping could be accessed using the original full request length and cause a NULL-pointer dereference. The upstream remediation reverts commit d410ee5109a1, and Red Hat addressed the issue in RHEL 8 and multiple RHEL 9 service, support, and EUS variants.
The Linux kernel CVE team assigned CVE-2024-26947 for an ARM memory-flush issue involving no-mapping addresses. The upstream fix checks whether the relevant folio is reserved; Red Hat addressed the issue in RHEL 9.2 EUS through RHSA-2024:5066 and RHSA-2024:5067 and in RHEL 9 through RHSA-2024:6997.
CVE-2019-25162 affects the Linux kernel I2C subsystem, where an adapter structure could be freed before its final use, creating a potential use-after-free. The upstream fix moves the put_device() call later; Fedora shipped the fix in Linux kernel 5.18.18, and Red Hat addressed it in RHEL 8, RHEL 9, and RHEL 9.4 EUS advisories.
The Linux kernel CVE team assigned CVE-2024-35838 for a potential station-link resource leak in the mac80211 Wi-Fi subsystem. The issue was resolved upstream; Red Hat delivered fixes in RHEL 8 advisories RHSA-2024:4211 and RHSA-2024:4352, RHEL 9 advisory RHSA-2024:9315, and RHEL 9.4 EUS advisory RHSA-2025:9584.
CVE-2024-40914 affects Linux kernel huge_zero_folio handling during hardware memory poisoning: unpoison_memory() could incorrectly decrement its reference count and trigger a kernel BUG during memory reclamation. The fix prevents unpoison_memory() from unpoisoning huge_zero_folio; Red Hat addressed it in RHEL 9 and RHEL 9.2 EUS advisories.
The Linux kernel CVE team assigned CVE-2024-26603 for an x86/FPU flaw caused by relying on userspace-provided information when faulting in an XSAVE buffer. The upstream fix stops that reliance; Red Hat addressed the issue in RHEL 8, RHEL 9, and RHEL 9.4 EUS advisories.
The Linux kernel CVE team assigned CVE-2023-52595 for an rt2x00 Wi-Fi subsystem issue resolved by restarting the beacon queue after a hardware reset. Fedora fixed the issue through Linux kernel 6.7.4 stable updates, while Red Hat addressed it in RHEL 8, RHEL 9, and RHEL 9.4 EUS advisories.
The Linux kernel CVE team assigned CVE-2024-27016 for a netfilter flowtable flaw resolved by validating PPPoE headers during flowtable processing. Red Hat addressed the issue in RHEL 9.2 EUS through RHSA-2024:4823 and RHSA-2024:4831, and in RHEL 9 through RHSA-2024:5928.
The Linux kernel CVE team assigned CVE-2024-35789 for mac80211 fast receive handling during non-4-address station VLAN changes. The upstream fix checks and clears fast-RX state in the affected scenario, and Red Hat addressed the issue across supported RHEL 8 and RHEL 9 variants.
The Linux kernel CVE team assigned CVE-2024-26855 for a potential NULL-pointer dereference in the Intel Ethernet ice driver's ice_bridge_setlink() function. The issue was resolved upstream, and Red Hat addressed it in RHEL 8, RHEL 9, and RHEL 9.2 Extended Update Support advisories.
Syzbot identified a NULL-pointer dereference in the Linux kernel's IPv6 XFRM xfrm6_get_saddr() function when ip6_dst_idev() returns NULL. The upstream fix adds a NULL-return check; Red Hat addressed the issue in RHEL 8 via RHSA-2024:7000 and RHSA-2024:7001 and in RHEL 9 via RHSA-2024:8162.
syzbot identified that the Linux Aiptek input-tablet driver could submit a URB using an endpoint of the wrong type because it validated only the endpoint count. The upstream fix uses usb_find_common_endpoints() to select suitable endpoints; Red Hat addressed the issue for RHEL 8 in RHSA-2024:7000 and RHSA-2024:7001.
Syzbot reported a slab out-of-bounds read in thrustmaster_probe() because the HID hid-thrustmaster driver did not validate the USB interface endpoint count before accessing the endpoint array. The fix validates the endpoint count and logs an error on mismatch; Red Hat addressed the issue for RHEL 8 through RHSA-2024:7000 and RHSA-2024:7001.
CVE-2024-40954 affects Linux kernel socket creation failure handling: a dangling struct socket pointer can remain attached to an sk object and lead to a slab use-after-free. The upstream fix clears the socket reference in sk_common_release(); Red Hat addressed the issue in RHEL 9 via RHSA-2024:5363 and in RHEL 8 via RHSA-2024:7000 and RHSA-2024:7001.
The Linux kernel community rejected CVE-2024-39501, which had described a race between really_probe() and dev_uevent() that could dereference a cleared dev->driver pointer and crash the kernel. Red Hat had previously included fixes for the issue in RHEL 8 advisories RHSA-2024:7000 and RHSA-2024:7001 and RHEL 9 advisory RHSA-2024:9315.
The Linux kernel CVE team assigned CVE-2023-52683 for an unchecked u32 multiplication overflow in the ACPI LPIT code. Red Hat addressed the resolved issue through RHEL 8 advisories RHSA-2024:7000 and RHSA-2024:7001, RHEL 9 advisory RHSA-2024:9315, and RHEL 9.4 EUS advisory RHSA-2025:2270.
Linux Verification Center identified CVE-2024-39506 using SVACE: the LiquidIO driver's lio_vf_rep_copy_packet() could pass a NULL pg_info->page to skb_add_rx_frag(). The fix moves the call within the pg_info->page conditional, and Red Hat addressed the issue for RHEL 8 in RHSA-2024:7000 and RHSA-2024:7001.
The Linux kernel CVE team assigned CVE-2024-36905 for a Linux kernel TCP issue resolved by deferring shutdown(SEND_SHUTDOWN) for sockets in the TCP_SYN_RECV state. Red Hat addressed the issue in RHEL 8 advisories RHSA-2024:5101 and RHSA-2024:5102, RHEL 9 advisory RHSA-2024:9315, and RHEL 9.4 EUS advisory RHSA-2025:2270.
The Linux kernel CVE team assigned CVE-2023-52528 for an uninitialized-value access in __smsc75xx_read_reg in the USB smsc75xx network driver. The issue was resolved upstream, and Red Hat addressed it through RHEL 8 advisories RHSA-2024:3618 and RHSA-2024:3627, RHEL 9 advisory RHSA-2024:9315, and RHEL 9.4 EUS advisory RHSA-2025:4342.
Red Hat addressed CVE-2024-26665, an out-of-bounds access in the Linux kernel IPv6 PMTU ICMPv6 error-building path, through RHSA-2024:7001 and RHSA-2024:7000 for RHEL 8 and RHSA-2024:6993 for RHEL 8.8 Extended Update Support. The upstream fix replaces an unsafe direct checksum calculation in iptunnel_pmtud_build_icmpv6() with skb_checksum().
The Linux kernel CVE project rejected CVE-2024-26908, which had been assigned for added null-pointer checks in the x86/Xen SMP implementation's smp.c. Red Hat had previously tracked and addressed the issue through advisories affecting several RHEL 8 and RHEL 9 product streams.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.