Red Hat released Moderate-severity kernel security updates for supported Red Hat Enterprise Linux 8 and 9 channels, including RHEL 8.6 and 8.8 Extended Update Support and RHEL 9.2 EUS. The updates address CVE-2024-26735, a flaw in IPv6 Segment Routing that can cause use-after-free and null-pointer-dereference conditions, and CVE-2024-26643, an nf_tables handling issue involving anonymous sets with timeouts during unbinding. RHSA-2024:3461 also remediates additional kernel issues in nft_ct, IP tunneling, CIFS, and sysfs for RHEL 9.2 support variants.
Administrators should install the applicable kernel packages from Red Hat's advisories and reboot affected hosts to activate the fixes. RHEL 9.2 deployments receive kernel version 5.14.0-284.67.1.el9_2; RHEL 8.6 EUS systems receive kernel version 4.18.0-372.105.1.el8_6, which also includes fixes for Spectre-BHB mitigation on AmpereOne, an emac driver use-after-free, and Linux bridge frame-handling data races.

See real exploitation activity before you spend the cycle.
12 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity RHSA-2024:3460 for RHEL 9.2 Extended Update Support kernel-rt packages, providing version 5.14.0-284.67.1.rt14.352.el9_2. The update fixed seven kernel vulnerabilities, including CVE-2024-26642, CVE-2024-26673, CVE-2024-26804, CVE-2024-26828, and CVE-2024-26993, and requires a reboot.
Red Hat issued Moderate-severity RHSA-2024:3462 for RHEL 8.6 Extended Update Support and related channels, providing kernel 4.18.0-372.105.1.el8_6. It added Spectre-BHB mitigation for AmpereOne and fixed CVE-2021-47013, CVE-2023-52578, and an XFS thaw hang; systems must be rebooted.
Red Hat published Moderate-severity advisory RHSA-2024:3461 for RHEL 9.2 support channels, supplying kernel version 5.14.0-284.67.1.el9_2. The update fixed seven vulnerabilities, including CVE-2024-26643 and CVE-2024-26735, and requires a reboot after installation.
Red Hat issued RHSA-2024:1881 for RHEL 9.2 Extended Update Support, addressing CVE-2024-35890, a moderate Linux kernel GRO flaw caused by incorrect socket-reference handling for packets with fragment lists. Triggering the issue can cause kernel bugs or system instability.
The Linux kernel CVE team assigned CVE-2024-26673 to a netfilter nft_ct flaw in which custom expectations insufficiently sanitized layer 3 and layer 4 protocol numbers. The upstream fix sanitizes those protocol values.
Red Hat addressed CVE-2024-26735 in RHEL 8 through RHSA-2024:4211 and RHSA-2024:4352, in specified RHEL 8.6 support channels through RHSA-2024:4447, and in RHEL 8.8 Extended Update Support through RHSA-2024:4740.
Red Hat addressed CVE-2024-26735 for RHEL 9.2 Extended Update Support through RHSA-2024:3460 and for RHEL 9 through RHSA-2024:3619.
Red Hat addressed CVE-2024-26643 for Red Hat Enterprise Linux 8 through RHSA-2024:3618 and RHSA-2024:3627.
Red Hat addressed CVE-2024-26643 for RHEL 9.2 Extended Update Support through RHSA-2024:3460, in addition to the fixes delivered in RHSA-2024:3461.
Red Hat addressed the nf_tables vulnerability CVE-2024-26643 for Red Hat Enterprise Linux 9 through RHSA-2024:3306.
The Linux kernel CVE team assigned CVE-2024-26735 for a flaw in IPv6 Segment Routing that can produce a use-after-free condition and null-pointer dereference.
The Linux kernel CVE team assigned CVE-2024-26643 for an nf_tables issue involving unbinding anonymous sets configured with timeouts; the upstream fix marks the unbound set as dead.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.