Red Hat released fixes across supported RHEL 8 and RHEL 9 streams for a set of Linux kernel flaws affecting networking, device drivers, USB Type-C, x86 machine-check handling, and the block layer. The remediated issues include CVE-2024-36929, where handling SKB_GSO_FRAGLIST packets through skb_copy or skb_copy_expand could yield invalid packets and subsequently crash the kernel; Red Hat rated it Moderate (CVSS 3.1 5.5). Other Moderate-rated issues include an integer overflow in blk_ioctl_discard() (CVE-2024-36917) and a potential uninitialized-value access in IPv6 __ip6_make_skb() (CVE-2024-36903).
Additional fixes address rtnetlink nested VLAN attribute validation (CVE-2024-36017), bonding setup, atl1c DMA receive overflow handling, mlxsw ACL TCAM list handling, and Intel igb firmware-version string truncation, as well as null-pointer, buffer-sizing, and read-limit defects in rtw89 and ath11k Wi-Fi drivers and the UCSI USB Type-C subsystem. Most require local access or concern specialized hardware and were assessed as Low to Moderate impact; the references report no exploitation in the wild. Organizations should apply the applicable Red Hat kernel and kernel-rt advisories, including Extended Update Support and specialized RHEL channels where deployed. CVE-2024-35876, concerning x86 MCE locking, was later rejected by the upstream Linux kernel CVE process despite having been tracked and patched in Red Hat advisories.

See real exploitation activity before you spend the cycle.
19 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:5101 and RHSA-2024:5102 for RHEL 8 kernel and kernel-rt packages, addressing CVE-2024-36017 and CVE-2024-36929.
Red Hat released RHSA-2024:5066 and RHSA-2024:5067 for RHEL 9.2 Extended Update Support, addressing CVE-2024-36017 and CVE-2024-36929 in kernel and kernel-rt packages.
Red Hat released RHSA-2024:4902 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions, fixing CVE-2024-36929.
An upstream Linux kernel CVE advisory was issued for CVE-2023-52784, a bonding-subsystem issue fixed by stopping the device in bond_setup_by_slave().
The Linux kernel CVE team assigned CVE-2024-36006 to an incorrect list API usage issue in the mlxsw Spectrum ACL TCAM component.
An upstream Linux kernel CVE advisory for CVE-2024-35938 was published. The issue in the ath11k Wi-Fi driver was fixed by reducing the MHI channel buffer length to 8 KB.
The upstream Linux kernel CVE process rejected CVE-2024-35876, which had been assigned to an x86 machine-check exception locking issue in set_bank().
Red Hat released RHSA-2024:6993, fixing CVE-2024-36929 for RHEL 8.8 Extended Update Support.
Red Hat released RHSA-2024:6206, fixing CVE-2024-36017 for RHEL 8.8 Extended Update Support.
Red Hat released RHSA-2024:5363 for RHEL 9, addressing CVE-2024-36017 and CVE-2024-36929.
Red Hat released RHSA-2024:5281, fixing CVE-2024-36017 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
The Linux kernel fixed CVE-2024-36929 by making skb_copy and skb_copy_expand reject SKB_GSO_FRAGLIST packets. Processing improperly linearized packets could subsequently crash the kernel and cause denial of service.
The Linux kernel resolved CVE-2024-36917, an integer overflow in the block-layer blk_ioctl_discard() function.
The Linux kernel resolved CVE-2024-36903, a potential uninitialized-value access in the IPv6 __ip6_make_skb() function.
The Linux kernel corrected validation of nested IFLA_VF_VLAN_LIST attributes for CVE-2024-36017. The flaw could allow an undersized attribute to be treated as ifla_vf_vlan_info and later cause an out-of-bounds read.
The Linux kernel resolved CVE-2024-36010 by fixing string-truncation warnings in the igb_set_fw_version function of the Intel igb network driver.
The Linux kernel fixed CVE-2024-35946, a null-pointer access in the rtw89 Wi-Fi driver that can occur when a scan is aborted.
The Linux kernel resolved CVE-2024-35924 in the USB Type-C UCSI component by limiting read size for UCSI version 1.2.
The Linux kernel addressed a DMA receive-overflow issue in the atl1c network driver, tracked as CVE-2023-52834, by adding a workaround for the overflow condition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
14 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.