Red Hat released RHSA-2024:4928 for Red Hat Enterprise Linux 9, delivering a Linux kernel update that fixes 20 security issues across networking, filesystems, SCSI, device drivers, and memory management. Among them, CVE-2024-26852 is a medium-severity use-after-free flaw in the IPv6 ip6_route_mpath_notify() path, while CVE-2024-36924 affects the SCSI lpfc driver and can cause a lock deadlock when its worker wake-up routine is called while hbalock is held. The fixes apply to RHEL 9 and relevant EUS, AUS, SAP, Extended Life Cycle, and CodeReady Linux Builder channels on x86_64, s390x, ppc64le, and aarch64 systems; CVE-2024-26852 was also remediated in supported RHEL 8 and other kernel streams.
Red Hat also refreshed the RHEL 9 el9/flatpak-sdk container image through RHBA-2024:5114 to incorporate the kernel security content. Organizations should apply the updated kernel packages and reboot affected hosts, then update Dockerfiles to reference the revised or latest Flatpak SDK image and rebuild dependent container images.

See real exploitation activity before you spend the cycle.
12 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHBA-2024:5114 to update the RHEL 9 el9/flatpak-sdk container image with the security content from RHSA-2024:4928. Users were advised to update Dockerfiles or scripts and rebuild dependent container images.
Red Hat addressed CVE-2024-27030, a race condition affecting the Linux kernel octeontx2-af component, by changing the component to use separate interrupt handlers. Fixes were provided for RHEL 9 through RHSA-2024:4928 and RHEL 9.2 Extended Update Support through RHSA-2024:5066 and RHSA-2024:5067.
Red Hat addressed CVE-2024-27046, an nfp Flower driver failure to handle acti_netdevs allocation errors, through RHSA-2024:4928 for RHEL 9. The issue was also addressed for RHEL 9.2 Extended Update Support through RHSA-2024:5365 and RHSA-2024:5364.
Red Hat issued Moderate-severity advisory RHSA-2024:4928, providing updated RHEL 9 kernel packages that remediate CVE-2024-26852 and numerous other kernel flaws, including memory-safety, filesystem, networking, and driver issues. Systems must be rebooted after installing the update for the fixes to take effect.
Red Hat addressed CVE-2024-36924, a Moderate-severity deadlock in the Linux kernel SCSI lpfc driver caused by invoking lpfc_worker_wake_up() while holding hbalock. Fixes were issued for RHEL 9.2 Extended Update Support via RHSA-2024:4823 and RHSA-2024:4831, with additional fixes subsequently provided for RHEL 8 and RHEL 9 streams.
An upstream Linux kernel CVE advisory disclosed CVE-2024-38580, an epoll vulnerability involving improper file-object lifetime handling. Red Hat later addressed the issue for RHEL 9 through RHSA-2024:4928.
Robb Gatica reported CVE-2024-26852, a potential use-after-free vulnerability in the Linux kernel IPv6 function ip6_route_mpath_notify(). Red Hat tracked the issue as Bug 2275761.
Red Hat remediated CVE-2024-26737, a Linux kernel BPF timer race between bpf_timer_cancel_and_free and bpf_timer_cancel that may have use-after-free implications. Fixes were issued for RHEL 9 through RHSA-2024:4928 and for RHEL 9.2 Extended Update Support through RHSA-2024:5066 and RHSA-2024:5067.
Red Hat addressed CVE-2024-35885, a Linux kernel mlxbf_gige driver issue resolved by stopping the network interface during system shutdown. Fixes were provided for RHEL 9 through RHSA-2024:4928 and for RHEL 9.2 Extended Update Support through RHSA-2024:5066 and RHSA-2024:5067.
Red Hat addressed CVE-2021-47459, a use-after-free vulnerability in the Linux kernel CAN J1939 subsystem's j1939_netdev_start() function involving j1939_priv rx_kref. Fixes were provided through RHSA-2024:4823 and RHSA-2024:4831 for RHEL 9.2 Extended Update Support and RHSA-2024:4928 for RHEL 9.
Red Hat addressed CVE-2024-26783, an incorrect zone-index call to wakeup_kswapd() in the Linux kernel memory-management vmscan component. Fixes were provided for RHEL 9.2 Extended Update Support through RHSA-2024:4533 and RHSA-2024:4554, and for RHEL 9 through RHSA-2024:4583.
Red Hat addressed CVE-2024-35857, a potential NULL-pointer dereference in the Linux kernel ICMP function icmp_build_probe(), through RHSA-2024:4533 and RHSA-2024:4554 for RHEL 9.2 Extended Update Support and RHSA-2024:4928 for RHEL 9. The upstream fix added protections against the possible NULL dereferences.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.