Red Hat released Linux kernel security updates for Red Hat Enterprise Linux (RHEL) 8, RHEL 9, and supported extended-life, update-service, SAP, and Real Time variants. The advisories address Native Branch History Injection (CVE-2024-2201), a Spectre-v2-related speculative-execution flaw on recent Intel CPUs that can bypass FineIBT mitigations and leak kernel memory, alongside vulnerabilities in networking, storage, filesystems, device drivers, wireless code, and CPU handling.
Included fixes cover an AF_UNIX garbage-collector race (CVE-2024-26923), improper LLSEC key-resource release in mac802154 (CVE-2024-26961), an MPTCP uninitialized-state issue (CVE-2024-40931), USB CDC-WDM log-flooding that can trigger CPU soft lockups (CVE-2024-40904), and an out-of-bounds tty imageblit access (CVE-2021-47383). Organizations should install the applicable updated kernel packages—including RHEL 8.6 builds 4.18.0-372.113.1.el8_6, 4.18.0-372.121.1.el8_6, or 4.18.0-372.124.1.el8_6 where relevant—and reboot systems to activate the mitigations.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat addressed CVE-2024-39504 for RHEL 9 through RHSA-2024:8617. The Linux kernel netfilter nft_inner flaw failed to validate mandatory embedded payload and meta netlink attributes, allowing a userspace-triggered NULL-pointer dereference.
Red Hat published Moderate-severity RHSA-2024:8617 for RHEL 9 and associated EUS, AUS, SAP, Extended Life Cycle, and CodeReady offerings. The kernel update remediated 23 CVEs, including CVE-2024-2201, CVE-2024-26923, CVE-2024-26961, CVE-2024-40904, CVE-2024-40931, and CVE-2021-47383; affected systems require a reboot.
Red Hat issued Important-severity RHSA-2024:6994 for RHEL 7 Extended Life Cycle Support, providing kernel 3.10.0-1160.125.1.el7 for x86_64, s390x, ppc64, and ppc64le. The update remediated CVE-2024-2201 (Intel BHI) and CVE-2024-41071, a mac80211 out-of-bounds array-indexing flaw; affected systems require a reboot.
Red Hat published Important-severity RHSA-2024:6995 for RHEL for Real Time 7 x86_64 under Extended Lifecycle Support. Kernel-rt version 3.10.0-1160.125.1.rt56.1277.el7 remediated CVE-2024-2201 (Intel BHI) and CVE-2024-41071, a mac80211 out-of-bounds array-indexing flaw; affected systems require a reboot.
Red Hat issued Important-severity RHSA-2024:6998 for RHEL 8.6 extended-support, AUS, TUS, and SAP Solutions systems. The kernel 4.18.0-372.124.1.el8_6 update fixed six vulnerabilities, including NVMe/TCP use-after-free and mac80211 out-of-bounds indexing flaws.
Red Hat published Moderate-severity RHSA-2024:6297 for supported RHEL 8.6 service variants, providing kernel 4.18.0-372.121.1.el8_6. The update fixed 12 flaws, including vulnerabilities in network drivers, Squashfs, virtual terminals, NVMe/RDMA, BPF, IOMMU, and XFS.
Red Hat released Important-severity RHSA-2024:5365 for RHEL 9.2 kernel-rt deployments under SAP Solutions and Extended Life Cycle offerings. Kernel-rt version 5.14.0-284.79.1.rt14.364.el9_2 addressed 23 Linux kernel CVEs, including CVE-2021-47383.
Red Hat issued Important-severity advisory RHSA-2024:5281 for RHEL 8.6 ELS/Long Life, AUS, TUS, and SAP Solutions channels. Kernel version 4.18.0-372.118.1.el8_6 remediated 18 CVEs, including use-after-free, NULL-pointer dereference, information-disclosure, and denial-of-service flaws; systems require a reboot after installation.
Red Hat issued Moderate-severity advisory RHSA-2024:4902 for supported RHEL 8.6 service variants, shipping kernel 4.18.0-372.113.1.el8_6. The update remediated 13 kernel vulnerabilities, and Red Hat required systems to be rebooted after installation.
CVE-2024-40931 was reported for an MPTCP flaw where snd_una could remain uninitialized during connection setup. A retransmission after MPTCP fallback could occur before the state was initialized.
An upstream Linux kernel advisory was published for CVE-2023-52771, a race condition in the CXL port subsystem between delete_endpoint() and parent-device unregistration. Red Hat later addressed the flaw in RHEL 9.2 EUS via RHSA-2024:5364 and RHSA-2024:5365 and in RHEL 9 via RHSA-2024:5928.
Zack Miele reported CVE-2024-26961, involving incorrect LLSEC key-resource release in the Linux kernel mac802154_llsec_key_del function. The Linux kernel CVE team assigned the identifier.
Zack Miele reported CVE-2024-26923, a race between the AF_UNIX garbage collector and connect() operations. The issue was subsequently assigned by the Linux kernel CVE team.
Red Hat addressed CVE-2021-47566, an improper user-buffer clearing flaw in Linux kernel proc/vmcore fixed upstream with clear_user(), through RHSA-2024:5281 for specified RHEL 8.6 channels and RHSA-2024:6993 for RHEL 8.8 EUS.
Red Hat addressed CVE-2023-52651, an ath10k Wi-Fi driver NULL-pointer dereference in management-frame transmission-completion handling, through RHSA-2024:5363, RHSA-2024:5364, and RHSA-2024:5365 for RHEL 9 and RHEL 9.2 EUS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
19 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.