Red Hat released RHSA-2022:8940 for selected Red Hat Enterprise Linux 8.2 update-service channels, delivering kernel build 4.18.0-193.95.1.el8_2 to remediate CVE-2022-1158 and CVE-2022-2639. Affected offerings include RHEL Server AUS 8.2, Server TUS 8.2, and RHEL 8.2 Update Services for SAP Solutions on x86_64 and Power LE/ppc64le.
CVE-2022-1158 affects KVM's cmpxchg_gpte handling, where user-controlled address values can write page frame numbers outside mapped guest-memory regions and potentially cause use-after-free conditions. CVE-2022-2639 is an Open vSwitch reserve_sfa_size() integer-coercion flaw that lets a low-privileged local attacker supply excessive flow actions, potentially causing an out-of-bounds write, system crash, or privilege escalation. Organizations using affected RHEL 8.2 channels should install the updated kernel and reboot; where patching is not immediately possible, blocklisting the openvswitch kernel module mitigates exposure to CVE-2022-2639.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2022:8809, an Important security and bug-fix update providing kernel 4.18.0-372.36.1.el8_6 for RHEL 8.6 EUS and associated offerings. The reboot-required update remediates the KVM flaw CVE-2022-1158 and the Open vSwitch out-of-bounds-write flaw CVE-2022-2639.
Red Hat issued RHSA-2022:8831, an Important security advisory providing kpatch-patch live updates for RHEL 8.6 update-service channels. The patches remediate the KVM flaw CVE-2022-1158 and the Open vSwitch out-of-bounds-write flaw CVE-2022-2639 without requiring a conventional kernel-replacement reboot.
Red Hat issued RHSA-2022:8686, an Important security advisory providing updated kpatch-patch live-patch modules for RHEL 8.4 offerings. The live patch remediates CVE-2022-1158, the KVM cmpxchg_gpte flaw that can write page frame numbers outside the userspace region.
Red Hat issued RHSA-2022:8685, an Important advisory updating RHEL 8.4 kernel packages to version 4.18.0-305.71.1.el8_4 and remediating the KVM guest-memory flaw CVE-2022-1158. The update covered extended-support and related service channels across x86_64, s390x, ppc64le, and aarch64; affected systems required a reboot.
Red Hat issued RHSA-2022:8673, providing kernel-rt 4.18.0-305.71.1.rt7.143.el8_4 to remediate the KVM guest-memory flaw CVE-2022-1158 in selected RHEL 8.4 ELS and Real Time telecommunications and NFV channels. Systems require a reboot after installing the update.
Red Hat issued RHSA-2022:7683 and RHSA-2022:7444, updating RHEL 8 kernel and kernel-rt packages to address the Open vSwitch integer-coercion out-of-bounds-write flaw CVE-2022-2639.
Red Hat issued RHSA-2023:0058 and RHSA-2023:0059, providing kernel and kpatch-patch fixes for CVE-2022-2639 in RHEL 8.1 Update Services for SAP Solutions.
Red Hat closed Bugzilla 2069793, its tracking issue for CVE-2022-1158.
Red Hat released RHSA-2022:8941 for the RHEL 8.2 Telecommunications Update Service kernel-rt stream and RHSA-2022:8989 for the RHEL 8.2 SAP Solutions kpatch stream to address CVE-2022-2639.
Red Hat published RHSA-2022:8940, supplying kernel 4.18.0-193.95.1.el8_2 for selected RHEL 8.2 AUS, TUS, and SAP update-service channels. The update remediated CVE-2022-1158 in KVM and CVE-2022-2639 in Open vSwitch; affected systems required a reboot.
Red Hat released RHSA-2022:8765 to provide a kernel-rt remediation for CVE-2022-2639 in the RHEL 8.4 Extended Update Support channel.
Fedora remediated CVE-2022-1158 through its stable Linux kernel 5.16.19 updates.
An upstream Linux kernel 5.2 commit introduced CVE-2022-1158, allowing user-controlled guest-memory page-table update values to write beyond mapped userspace memory and potentially trigger use-after-free conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.