Red Hat released Important RHEL 8 kernel and kpatch-patch updates addressing CVE-2023-0266, an ALSA PCM control-element use-after-free vulnerability, and CVE-2023-0461, a use-after-free flaw in kernel network ULP handling for listening sockets. The fixes cover RHEL 8.4 EUS, AUS, TUS, Extended Life Cycle Long Life, SAP, and Real Time channels across x86_64, s390x, ppc64le, and aarch64, including kernel version 4.18.0-305.86.2.el8_4 and Real Time version 4.18.0-305.86.2.rt7.160.el8_4 packages.
Red Hat also issued a live-patch update for RHEL 8.1 SAP Solutions systems that remediates CVE-2023-0461 and CVE-2023-1390, a remotely triggerable denial-of-service flaw in the TIPC module. CVE-2023-1390 can allow an attacker to send two small UDP packets to hosts configured with a UDP TIPC bearer, driving CPU use to 100% and making systems unresponsive. Administrators should install the applicable kernel updates and reboot systems where required; kpatch-patch packages apply supported fixes to running kernels without a conventional reboot.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2023:3191 for RHEL 8.1 Update Services for SAP Solutions on x86_64 and ppc64le. Updated kpatch-patch packages remediated CVE-2023-0461 and the remotely triggerable TIPC denial-of-service vulnerability CVE-2023-1390.
Red Hat issued RHSA-2023:3190 for RHEL 8.1 Update Services for SAP Solutions on x86_64 and ppc64le. The kernel update, version 4.18.0-147.83.1.el8_1, remediated CVE-2023-0461 and CVE-2023-1390; affected systems must be rebooted after installation.
Red Hat issued RHSA-2023:1662, supplying updated kpatch-patch packages for supported RHEL 8.4 service streams. The live-patch module remediated CVE-2023-0266 and CVE-2023-0461 without a conventional kernel update process.
Red Hat issued RHSA-2023:1557, delivering kernel version 4.18.0-305.86.2.el8_4 for affected RHEL 8.4 support channels and architectures. It remediated CVE-2023-0266 and CVE-2023-0461, with a reboot required for the updated kernel to take effect.
Red Hat issued RHSA-2023:1556 for RHEL 8.4 Real Time offerings, providing kernel-rt 4.18.0-305.86.2.rt7.160.el8_4. The update fixed the ALSA PCM use-after-free CVE-2023-0266 and the net/ulp listening-socket use-after-free CVE-2023-0461; systems require a reboot after installation.
Red Hat Enterprise Linux 8 kernel-rt packages previously received a fix for CVE-2023-1390 through RHSA-2021:1739.
Red Hat Enterprise Linux 8 kernel packages previously received a fix for the remotely triggerable TIPC denial-of-service vulnerability CVE-2023-1390 through RHSA-2021:1578.
The Linux kernel fixed the TIPC tipc_link_xmit() flaw underlying CVE-2023-1390 in upstream kernel version 5.11, via commit b77413446408fdd256599daf00d5be72b5f3e7c6.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.