Red Hat released RHEL 8 kernel updates that remediate CVE-2024-26593, a defect in the Linux kernel i2c-i801 driver’s handling of SMBus block process-call transactions. The driver did not reset its block-buffer index before reading returned data, contrary to Intel’s documented transaction sequence, causing it to read from the wrong buffer position. The issue was assessed as having potentially low impact, pending deployment-specific validation.
The fix is included in RHEL 8 kernel version 4.18.0-553.5.1.el8_10 under RHSA-2024:3618 and the Real Time kernel version 4.18.0-553.5.1.rt7.346.el8_10 under RHSA-2024:3627. These advisories also address numerous other kernel flaws across virtualization, cryptography, networking, USB, wireless, filesystems, and memory management; affected RHEL 8 and RHEL for Real Time deployments must reboot after installing the updated packages for mitigations to take effect.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:3627, a Moderate-security kernel-rt update for RHEL 8, which included a fix for CVE-2024-26593. It delivered kernel-rt version 4.18.0-553.5.1.rt7.346.el8_10 for supported Real Time deployments.
Red Hat issued RHSA-2024:3618, a Moderate-severity RHEL 8 kernel update containing a fix for CVE-2024-26593 in I2C i801 block-process-call transactions. The update supplied kernel version 4.18.0-553.5.1.el8_10 and required affected systems to reboot after installation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.