Red Hat released Important security updates RHSA-2022:7110 and RHSA-2022:7134 for Red Hat Enterprise Linux 8 standard and real-time kernels. The updates deliver kernel-4.18.0-372.32.1.el8_6 and kernel-rt-4.18.0-372.32.1.rt7.189.el8_6, respectively, addressing a cls_route use-after-free that could permit privilege escalation and information-disclosure flaws in scsi_ioctl() and pfkey_register.
The releases also mitigate speculative-execution vulnerabilities affecting AMD and Intel CPUs, including AMD RetBleed (CVE-2022-23816, CVE-2022-29900), Intel RetBleed (CVE-2022-29901), and AMD Branch Type Confusion (CVE-2022-23825), which could expose information through branch-predictor behavior. Affected RHEL 8 deployments—including real-time, NFV, SAP, virtualization, telecommunications, and extended-support channels—should install the applicable kernel packages and reboot systems to activate the fixes.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2022:7337 and RHSA-2022:7338, updating the RHEL 7 kernel and kernel-rt packages to remediate CVE-2022-23816, the AMD RetBleed vulnerability.
Red Hat issued RHBA-2022:7269 updating Red Hat build of Quarkus 2.7 RHEL 8 container images with backported fixes for kernel flaws, including AMD and Intel RetBleed, AMD Branch Type Confusion, CVE-2022-0494, and cls_route privilege escalation. Users were advised to upgrade Quarkus images and rebuild dependent container images.
Red Hat issued RHBA-2022:7198 to update 3SCALE-2.12-RHEL-8 container images with security fixes, including AMD and Intel RetBleed and AMD Branch Type Confusion vulnerabilities. Users were advised to upgrade the images, rebuild dependent images, and update Dockerfiles or scripts to reference the new versions.
Red Hat issued Important advisories RHSA-2022:7110 and RHSA-2022:7134 for RHEL 8 kernel and kernel-rt packages. The updates remediate the AMD and Intel RetBleed issues, AMD Branch Type Confusion, cls_route privilege escalation, and kernel information leaks; systems require a reboot after installation.
Red Hat issued Important-rated RHSA-2022:6872 for RHEL 8.1 Update Services for SAP Solutions on x86_64 and Power LE. Kernel build 4.18.0-147.76.1.el8_1 fixes the CVE-2022-2588 cls_route privilege-escalation flaw and CPU data-cleanup flaws CVE-2022-21123, CVE-2022-21125, and CVE-2022-21166; affected systems require a reboot.
Petr Matousek reported Red Hat Bug 2103148 for CVE-2022-29901, affecting some Intel processors through return-instruction speculative execution and potentially allowing local information disclosure.
Petr Matousek reported Red Hat Bug 2103153 for CVE-2022-23825, an AMD branch-predictor aliasing issue that could cause incorrect branch-type predictions and information disclosure.
Petr Matousek reported Red Hat Bug 2090226 for CVE-2022-23816 and CVE-2022-29900, covering AMD RetBleed speculative code execution through mistrained return-instruction predictions.
Red Hat closed Bug 2114849 for CVE-2022-2588, a Linux kernel cls_route filter use-after-free that could allow local privilege escalation. The vendor directed customers to the CVE page for product-specific remediation status after issuing fixes across affected RHEL and Red Hat Virtualization streams.
Red Hat identified the RHEL 6 kernel as affected by CVE-2022-29901, the Intel RetBleed vulnerability, but stated that it will not provide a fix for that product stream.
Red Hat's Product Security DevOps Team closed Bug 2039448 for CVE-2022-0494, a Linux kernel SCSI ioctl flaw that could expose uninitialized kernel memory to user space. Red Hat had issued fixes for RHEL 9, RHEL 8, and RHEL 8.4 Extended Update Support.
Red Hat closed Bugs 2090226, 2103148, and 2103153 after issuing fixes for affected RHEL product streams, including RHEL 7, 8, 9, and RHEL 9.0 Extended Update Support.
Red Hat marked Bug 2119127 as a duplicate of Bug 2090226, consolidating tracking for the AMD RetBleed CVEs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.