Red Hat released Moderate-severity kernel and Real Time kernel updates for supported RHEL 8.4 Extended Update Support and specialized telecommunications/NFV channels to remediate CVE-2022-0494 and CVE-2022-1353. The standard kernel update, version 4.18.0-305.62.1.el8_4, covers x86_64, s390x, ppc64le, and aarch64 systems; the Real Time update is 4.18.0-305.62.1.rt7.134.el8_4.
CVE-2022-0494 affects SCSI ioctl handling: a SCSI_IOCTL_SEND_COMMAND request can map a buffer that is not zero-initialized, allowing uninitialized kernel memory to be copied to a user-supplied buffer when a disk driver does not populate it. CVE-2022-1353 affects pfkey_register and can also disclose kernel information. Administrators should install the applicable packages and reboot affected systems for the mitigations to take effect.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2022:7110 for RHEL 8 and Red Hat Virtualization 4 kernel packages, and RHSA-2022:7134 for RHEL 8 kernel-rt packages, remediating the CVE-2022-0494 SCSI ioctl information-disclosure flaw.
Red Hat issued RHSA-2022:6460 for RHEL 8 and Red Hat Virtualization 4 kernel packages, addressing CVE-2022-48943. The moderate KVM x86 MMU race condition could cause a guest task to block indefinitely, affecting availability.
Red Hat issued RHSA-2022:6248, a Moderate-security update for the RHEL 8.4 Real Time Linux Kernel in Extended Update Support offerings. Kernel-rt version 4.18.0-305.62.1.rt7.134.el8_4 fixed the CVE-2022-0494 scsi_ioctl() and CVE-2022-1353 pfkey_register information-disclosure flaws.
Red Hat issued RHSA-2022:6243, a Moderate-severity kernel security and bug-fix update for RHEL 8.4 extended and specialized support channels. The 4.18.0-305.62.1.el8_4 update remediated CVE-2022-0494 and CVE-2022-1353; affected systems required a reboot.
Red Hat issued RHSA-2022:5934, a Moderate security and bug-fix update for the RHEL 8.2 Extended Update Support Real Time Linux Kernel. Kernel-rt version 4.18.0-193.90.1.rt13.140.el8_2 remediated the CVE-2022-1353 pfkey_register information-disclosure flaw; affected systems required a reboot.
Red Hat issued RHSA-2022:6003, a Moderate-severity kernel security advisory for RHEL 9. The update remediated CVE-2022-0494 and CVE-2022-1055, included reliability fixes, and required affected systems to reboot after installation.
Red Hat issued RHSA-2022:6002, a Moderate-severity security and bug-fix update for the RHEL 9 x86_64 Real Time Linux Kernel. Kernel-rt version 5.14.0-70.22.1.rt21.94.el9_0 remediated CVE-2022-0494 and CVE-2022-1055; systems required a reboot after installation.
Red Hat issued RHSA-2022:5998, a Moderate-severity kernel security and bug-fix update for RHEL 8.2 Extended Update Support and associated channels. Kernel version 4.18.0-193.90.1.el8_2 fixed CVE-2022-1353 in pfkey_register along with several kernel bugs; affected systems required a reboot.
Haimin Zhang submitted a one-line patch to zero pages allocated by bio_copy_kern, preventing uninitialized bio-buffer contents from being copied to userspace through the SCSI_IOCTL_SEND_COMMAND path. The patch adds __GFP_ZERO to the alloc_page flags in block/blk-map.c.
Red Hat Product Security DevOps marked Bugzilla BZ#2039448, tracking the CVE-2022-0494 Linux kernel SCSI ioctl information-disclosure vulnerability, closed.
Red Hat closed its tracking bug for CVE-2022-1055, a medium-severity Linux kernel use-after-free flaw in tc_new_tfilter() that could enable local privilege escalation when unprivileged user namespaces are available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.