Red Hat released Linux kernel security updates for RHEL 8 and RHEL 9 that remediate vulnerabilities across networking, filesystems, memory management, and platform components. The fixes include CVE-2024-41040, a use-after-free in the traffic-control connection-tracking path triggered after a conntrack clash; CVE-2024-26826 in Multipath TCP stale-subflow reinjection; and CVE-2024-26870, which can trigger a kernel BUG in NFSv4.2 extended-attribute handling. Other remediated issues include an ext4 corrupted-block-group allocation flaw (CVE-2024-26772), a swap race (CVE-2024-26960), a writeback divide-by-zero (CVE-2024-26720), and CacheFiles memory leakage (CVE-2024-26840).
The updates also address the WMI character-device issue tracked as CVE-2023-52864 and additional kernel defects affecting areas such as TCP, Wi-Fi, VFIO, storage, drivers, IPv6, virtualization, and Netfilter. Red Hat distributed fixes through advisories including RHSA-2024:5065 for selected RHEL 8.6 channels and RHSA-2024:5363 for RHEL 9, covering supported architectures and selected EUS, SAP, telecommunications, mission-critical, and lifecycle support variants. Organizations should deploy the applicable updated kernel packages and reboot affected systems to activate the fixes.

See real exploitation activity before you spend the cycle.
22 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-rated RHSA-2024:9497 for RHEL 9.2 extended-support and selected update-service channels, providing kernel version 5.14.0-284.92.1.el9_2. The update fixes 11 CVEs, including ext4, NFSv4.2, AMDGPU, TCP zero-copy, MPTCP, and IUCV flaws, and requires affected systems to be rebooted.
Red Hat updated its RHSA-2024:5363 RHEL 9 kernel security advisory.
Red Hat issued Important-rated RHSA-2024:5363 for RHEL 9 kernel packages across supported architectures and service channels. The update remediated numerous flaws, including CVE-2023-52864, and requires a reboot to take effect.
Red Hat issued the Moderate-rated RHSA-2024:5065 kernel update for selected RHEL 8.6 support channels. The update included fixes for CVE-2024-26826, CVE-2024-26870, and ten other kernel vulnerabilities; affected systems require a reboot after installation.
The Linux kernel CVE team assigned CVE-2024-26960 for a swap-subsystem race between free_swap_and_cache() and swapoff().
The Linux kernel CVE team assigned CVE-2024-26870 and the NFSv4.2 nfs4_listxattr issue was reported resolved. The flaw could trigger a kernel BUG at mm/usercopy.c:102.
Robb Gatica reported CVE-2024-26840, a CacheFiles memory leak in cachefiles_add_cache().
The Linux kernel CVE team assigned CVE-2024-26804 for an issue in net/ip_tunnel that could cause perpetual headroom growth. The issue was resolved upstream with the fix “net: ip_tunnel: prevent perpetual headroom growth,” and Red Hat later addressed it across RHEL 8 and RHEL 9 product variants.
The Linux kernel upstream advisory reported CVE-2024-26759 resolved with the patch “mm/swap: fix race when skipping swapcache.” The vulnerability is a race condition in swap and swapcache handling; Red Hat later addressed it for RHEL 8, RHEL 9, and RHEL 9.4 Extended Update Support.
The Linux kernel resolved CVE-2024-26907 with the fix “RDMA/mlx5: Fix fortify source warning while accessing Eth segment.” Red Hat addressed the low-impact RDMA/mlx5 issue through advisories for RHEL 8, RHEL 9, and RHEL 9.4 Extended Update Support.
The Linux kernel resolved CVE-2024-26906 by disallowing copy_from_kernel_nofault() from reading the x86 vsyscall page. Red Hat addressed the issue for RHEL 8, RHEL 9, and specified RHEL 9 Extended Update Support releases through multiple 2024 advisories.
The Linux kernel resolved CVE-2024-41012 by reliably removing locks when a race between fcntl and close operations is detected. Red Hat addressed the flaw in RHEL 8 via RHSA-2024:7000 and RHSA-2024:7001, and in RHEL 9 via RHSA-2024:9315.
The Linux kernel fixed CVE-2024-40958 by making get_net_ns() use maybe_get_net(), preventing references to network namespaces whose reference count has reached zero. Red Hat addressed the issue in RHEL 9 through RHSA-2024:5363 and in RHEL 8 through RHSA-2024:7000 and RHSA-2024:7001.
The Linux kernel resolved CVE-2024-26973 with the fix “fat: fix uninitialized field in nostale filehandles.” Red Hat listed fixes for RHEL 8, RHEL 9, and RHEL 9.4 Extended Update Support.
Red Hat listed security advisories addressing CVE-2024-26960 for RHEL 8, RHEL 9, and RHEL 9.4 Extended Update Support. The issue is the race between free_swap_and_cache() and swapoff().
The upstream remediation for CVE-2024-41040 retrieves the conntrack entry from the socket buffer again after conntrack confirmation, preventing a freed entry from reaching tcf_ct_flow_table_process_conn. Red Hat listed fixes for RHEL 8, RHEL 9, and selected Extended Update Support releases.
The Linux kernel resolved CVE-2024-26720 with a fix for a possible divide-by-zero condition in wb_dirty_limits(). Red Hat listed remediation for RHEL 8, RHEL 9, and relevant Extended Update Support releases.
The Linux kernel fixed CVE-2024-26840, a memory leak in cachefiles_add_cache(), in kernel versions from 4.19.309 through 6.8. Red Hat also listed security and bug-fix advisories for affected RHEL releases.
The Linux kernel resolved CVE-2024-26826 with the fix “mptcp: fix data re-injection from stale subflow.” Red Hat listed fixes for RHEL 8 and RHEL 9 product variants.
CVE-2023-52864 in the kernel platform/x86 WMI component was resolved by correcting character-device opening behavior. Red Hat listed remediation across RHEL 8, RHEL 9, and several extended-support offerings.
The upstream remediation for CVE-2024-26772 changed ext4_mb_find_by_goal() to avoid allocating blocks from corrupted block groups. Red Hat subsequently listed fixes for RHEL 8, RHEL 9, and specialized support variants.
The Linux kernel resolved CVE-2024-40928 in ethtool_get_phy_stats_ethtool() by returning -EOPNOTSUPP when ops->get_ethtool_phy_stats is unavailable, preventing a null-pointer function call. Red Hat addressed the flaw in RHEL 9 through RHSA-2024:5363.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
19 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.