Red Hat released fixes for CVE-2023-28466, a moderate-severity race condition in the Linux kernel TLS subsystem's do_tls_getsockopt function. The flaw can trigger a use-after-free condition or NULL-pointer dereference; a local attacker with low privileges could affect system confidentiality, integrity, and availability. Red Hat rates the vulnerability CVSS 7.0.
The remediation includes RHEL 8 kernel packages under RHSA-2023:3847, including kernel-4.18.0-477.15.1.el8_8 for supported x86_64, s390x, ppc64le, and aarch64 variants, with fixes also available for affected RHEL 9 kernels. Organizations should install the applicable updates and reboot systems; where patching cannot occur immediately, Red Hat recommends preventing the TLS kernel module from loading at boot.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2023:3847, a Moderate-severity RHEL 8 kernel security update fixing the TLS do_tls_getsockopt race condition behind CVE-2023-28466. The update supplied kernel version 4.18.0-477.15.1.el8_8 packages and required affected systems to reboot after installation.
Red Hat issued RHSA-2023:3819, providing a fix for CVE-2023-28466 in the Red Hat Enterprise Linux 8 kernel-rt variant.
Red Hat released RHSA-2023:3723 to fix CVE-2023-28466 in the Red Hat Enterprise Linux 9 kernel.
Red Hat released RHSA-2023:3708 to remediate CVE-2023-28466 in the Red Hat Enterprise Linux 9 kernel-rt variant.
Red Hat released RHSA-2023:4814 to remediate CVE-2023-28466 in the Red Hat Enterprise Linux 9.0 Extended Update Support kernel-rt variant.
Red Hat released RHSA-2023:4801 to remediate CVE-2023-28466 in the Red Hat Enterprise Linux 9.0 Extended Update Support kernel.
Red Hat released RHSA-2023:4789, fixing CVE-2023-28466 for the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 for RHEL 8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.