Red Hat released updated RHEL 8 container images for gcc-toolset-12-toolchain, gcc-toolset-13-toolchain, and the Camel K RHEL 8 operator, incorporating the kernel security fixes delivered through RHSA-2024:5101. The updates address numerous backported kernel defects across memory management, networking, filesystems, drivers, and architecture-specific code, including CVE-2024-36886, a TIPC message-reassembly use-after-free that may enable remote code execution. Organizations using the affected base images should upgrade them and rebuild downstream images; Camel K users on OpenShift 4.11 and 4.12 should also update image references in Dockerfiles and automation.
Separate RHEL 9.2 Extended Update Support kernel and real-time kernel updates remediate CVE-2023-6240 (the Marvin RSA-decryption side channel), TLS flaws CVE-2024-26582 and CVE-2024-26584, and CVE-2024-26586, a stack-corruption issue in mlxsw Spectrum ACL TCAM handling. Red Hat also issued fixes across supported RHEL 8 and 9 streams for networking defects including CVE-2024-38555 in net/mlx5 command-completion error handling and CVE-2024-26837 in bridge switchdev multicast-database event replay. Administrators must reboot updated RHEL 9.2 systems for the kernel fixes to take effect.

See real exploitation activity before you spend the cycle.
44 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHBA-2024:5386, updating the integration/camel-k-rhel8-operator container image with backported RHSA-2024:5101 security fixes. The update affected RHEL 8-based OpenShift Container Platform 4.11 and 4.12 deployments, and Red Hat advised rebuilding dependent images and updating image references.
Red Hat issued RHBA-2024:5235 for the RHEL 8 rhel8/gcc-toolset-12-toolchain image, incorporating RHSA-2024:5101 backported kernel security fixes, including CVE-2024-36886. Red Hat advised upgrading the base image and rebuilding dependent images.
Red Hat issued RHBA-2024:5233 for the RHEL 8 rhel8/gcc-toolset-13-toolchain image, incorporating backported fixes from RHSA-2024:5101, including CVE-2024-36886. Users were advised to upgrade the image and rebuild dependent container images.
Red Hat released RHSA-2024:5101 and RHSA-2024:5102 to remediate CVE-2023-52471 in RHEL 8 kernel and kernel-rt packages. RHEL 9 kernel and kernel-rt were listed as not affected.
Red Hat addressed CVE-2021-47491, a low-severity Linux kernel memory-management issue in which khugepaged could collapse huge pages for special files, through RHSA-2024:5101 and RHSA-2024:5102. The upstream fix makes khugepaged skip huge-page collapse for special files.
CVE-2024-41005 was reported as a medium-severity Linux kernel netpoll vulnerability caused by a race in netpoll_owner_active() when reading napi->poll_owner. The upstream fix uses an atomic read, and Red Hat later addressed the issue for RHEL 8 and RHEL 9 through RHSA-2024:7000, RHSA-2024:7001, and RHSA-2024:8617.
Patrick Del Bello reported CVE-2024-38608, a low-severity Linux kernel vulnerability involving incorrect network-interface state handling in the net/mlx5e driver. It was fixed upstream in kernel 6.9.3 and 6.10-rc1, and Red Hat issued fixes for RHEL 8, RHEL 9, and RHEL 9.2 EUS.
Patrick Del Bello reported CVE-2024-38555, a medium-severity Linux kernel net/mlx5 vulnerability involving command completions not being discarded during an internal error.
Rohit Keshri reported CVE-2024-36950, a low-severity Linux kernel FireWire OHCI vulnerability involving bus-reset interrupts occurring between the interrupt service routine and bottom-half processing. The upstream fix masks bus-reset interrupts during that interval.
Mauro Matteo Cascella reported CVE-2021-47284, a low-severity Linux kernel flaw in the ISDN mISDN NetJet driver that can crash the nj_probe routine. The upstream fix was released through kernel 5.13, and Red Hat addressed the issue for RHEL 8 in RHSA-2024:5101 and RHSA-2024:5102.
Red Hat tracked CVE-2021-47373, a low-severity Linux kernel GICv3 ITS irqchip issue that can leak a virtual Processing Element resource on an error path. The upstream fix was included in kernels through 5.15, and Red Hat remediated the issue for RHEL 8 through RHSA-2024:5101 and RHSA-2024:5102.
Mauro Matteo Cascella reported CVE-2023-52832, a medium-severity Linux kernel Wi-Fi mac80211 issue in which ieee80211_get_tx_power() could return an unset transmit-power value. The upstream fix prevents returning the unset value, and Red Hat addressed the flaw for RHEL 8 through RHSA-2024:5101 and RHSA-2024:5102.
Mauro Matteo Cascella reported CVE-2023-52845, a low-severity Linux kernel TIPC vulnerability involving bearer-related netlink attribute names. The remediation changes the relevant nla_policy entries to NLA_NUL_STRING; Red Hat later addressed it for RHEL 8 through RHSA-2024:5101 and RHSA-2024:5102.
Red Hat tracked CVE-2021-47257 as Bug 2282553, a low-severity null-pointer dereference in Linux IEEE 802.15.4 device-address parsing. The issue was fixed upstream in kernel versions from 4.9.274 through 5.13 and later addressed for RHEL 8 through RHSA-2024:5101 and RHSA-2024:5102.
Mauro Matteo Cascella reported CVE-2023-52796, a low-severity Linux kernel ipvlan vulnerability. The upstream remediation adds the ipvlan_route_v6_outbound() helper; Red Hat later addressed it for RHEL 8 through RHSA-2024:5101 and RHSA-2024:5102.
Mauro Matteo Cascella reported CVE-2023-52847 to Red Hat's tracker. The low-severity Linux kernel media bttv flaw is a use-after-free caused by the btv->timeout timer.
Robb Gatica reported CVE-2024-35958, a medium-severity Linux kernel vulnerability in the ENA network driver involving incorrect descriptor-free behavior. Upstream fixes were available in kernel versions 5.10.216, 5.15.156, 6.1.87, 6.6.28, 6.8.7, and 6.9, and Red Hat issued fixes across supported RHEL 8 and RHEL 9 streams.
Robb Gatica reported CVE-2024-35969, a medium-severity Linux kernel IPv6 vulnerability caused by a race between ipv6_get_ifaddr() and ipv6_del_addr(). Upstream fixes were released through kernels 4.19.313 to 6.9, and Red Hat issued fixes for supported RHEL 8 and RHEL 9 channels, including RHSA-2024:4447, RHSA-2024:4533, RHSA-2024:4554, RHSA-2024:5363, and RHSA-2024:6993.
Red Hat tracked CVE-2024-35877, a medium-severity Linux kernel vulnerability involving incorrect VM_PAT handling in x86 copy-on-write mappings. The issue was fixed upstream in kernels from 4.19.312 through 6.9 and remediated for RHEL 8, RHEL 9, and RHEL 9.4 EUS through multiple advisories.
Robb Gatica reported CVE-2024-35952, a medium-severity Linux kernel soft-lockup vulnerability in the DRM AST graphics driver. Upstream fixes were released in kernel versions 6.1.87, 6.6.28, 6.8.7, and 6.9; Red Hat later addressed it in RHEL 8 and RHEL 9 advisories.
The Linux kernel CVE team reported CVE-2024-35893, a low-severity information-disclosure issue in net/sched act_skbmod described as “prevent kernel-infoleak.” The issue was fixed in upstream kernel releases from 4.19.312 through 6.9 and later addressed for RHEL 8 in RHSA-2024:5101 and RHSA-2024:5102.
Zack Miele reported CVE-2023-52679, a low-severity Linux kernel double-free vulnerability in the Open Firmware/device-tree function of_parse_phandle_with_args_map. The issue was fixed upstream in kernel versions from 4.19.306 through 6.8 and was later addressed in RHEL 8, RHEL 9, and RHEL 9.4 EUS advisories.
Zack Miele reported CVE-2024-35790, a low-severity Linux kernel issue in the USB Type-C DisplayPort alternate-mode driver's creation of sysfs nodes. The upstream fix creates these nodes as the driver's default device attribute group; Red Hat later remediated it for RHEL 8 and RHEL 9.4 EUS.
Linux published mitigations for Intel's DSA/IAA hardware erratum (CVE-2024-21823), which could allow security-relevant direct access by untrusted applications via affected Sapphire Rapids devices. The changes deny affected SPR_DSA and SPR_IAX devices to VFIO and add an idxd-driver security check.
Zack Miele reported CVE-2024-27388, a medium-severity Linux kernel SUNRPC vulnerability involving memory leaks in gssx_dec_option_array. Upstream fixes were available from kernel 4.19.311 through 6.9-rc1, and Red Hat addressed it for RHEL 8 in RHSA-2024:5101 and RHSA-2024:5102.
Red Hat issued Important-rated RHSA-2024:1882 for the RHEL 9.2 EUS Real Time Linux Kernel. The x86_64 kernel-rt 5.14.0-284.62.1.rt14.347.el9_2 update remediates CVE-2023-6240, CVE-2024-26582, CVE-2024-26584, and CVE-2024-26586.
Red Hat published RHSA-2024:1881, a Moderate kernel update for RHEL 9.2 Extended Update Support and related offerings. Kernel version 5.14.0-284.62.1.el9_2 fixes CVE-2023-6240, CVE-2024-26582, CVE-2024-26584, and CVE-2024-26586; Red Hat instructed users to reboot after installation.
Robb Gatica reported CVE-2024-26837, a medium-severity Linux kernel bridge switchdev issue involving replay of deferred multicast database events during offload handling.
Red Hat tracked CVE-2021-46939, a medium-severity Linux kernel tracing issue remediated by restructuring trace_clock_global() so it never blocks. Fedora fixed it in Linux 5.12.3, and Red Hat later addressed it for RHEL 8 through RHSA-2024:5101 and RHSA-2024:5102.
Rohit Keshri reported CVE-2023-52471, a low-severity Linux kernel null-pointer dereference issue in the Intel ICE driver's ice_ptp.c component. The flaw stems from missing handling for a possible NULL return from devm_kasprintf() and was fixed upstream in Linux 6.7.2 and 6.8-rc1.
CVE-2021-47408 is a resolved Linux kernel netfilter connection-tracking vulnerability involving serialization of conntrack hash-table resize and cleanup operations. Red Hat addressed the issue for RHEL 8 through RHSA-2024:5101 and RHSA-2024:5102.
CVE-2022-48632 is a potential stack-overflow vulnerability in the Linux MLXBF I2C driver's mlxbf_i2c_smbus_start_transaction() function. An upstream change prevents the overflow, and Red Hat addressed the issue for RHEL 8 through RHSA-2024:5101 and RHSA-2024:5102.
CVE-2024-36940 is a Linux kernel pinctrl-core vulnerability caused by an incorrect free operation in pinctrl_enable(). The issue was resolved upstream, and Red Hat remediated it for RHEL 8, RHEL 9, and RHEL 9.4 EUS through RHSA advisories.
CVE-2022-48747 is a resolved Linux kernel block-subsystem vulnerability caused by an incorrect offset calculation in bio_truncate(). The Linux kernel CVE team assigned the identifier, and Red Hat addressed the issue for RHEL 8 through RHSA-2024:5101 and RHSA-2024:5102.
CVE-2024-35912 is a potential response-information leak in the Linux iwlwifi MVM RFI code path, resolved by the patch “wifi: iwlwifi: mvm: rfi: fix potential response leaks.” Red Hat remediated it for RHEL 8, RHEL 9, and RHEL 9.4 EUS through RHSA-2024:5101, RHSA-2024:5102, RHSA-2024:9315, and RHSA-2025:7526.
CVE-2024-36927 affects the Linux kernel IPv4 implementation through an uninitialized-value access in __ip_make_skb(). Red Hat addressed the issue for RHEL 8, RHEL 9, and RHEL 9.4 EUS through RHSA-2024:5101, RHSA-2024:5102, RHSA-2024:9315, and RHSA-2025:3215.
Red Hat resolved CVE-2024-35896, a Linux kernel netfilter flaw caused by insufficient validation of user-supplied input length that may permit an out-of-bounds kernel read. Red Hat addressed it across RHEL 8, RHEL 9, and RHEL 9.2 EUS through RHSA-2024:5066, RHSA-2024:5067, RHSA-2024:5101, RHSA-2024:5102, and RHSA-2024:5928.
CVE-2024-35823 concerns Unicode-buffer corruption when deleting characters in the Linux kernel virtual terminal subsystem. Red Hat remediated the issue across multiple RHEL 8 and 9 product streams, including through RHSA-2024:5066, RHSA-2024:5067, RHSA-2024:5101, RHSA-2024:5363, RHSA-2024:6297, and RHSA-2024:10262.
CVE-2024-36286 affects the Linux kernel netfilter nfnetlink_queue component, where instance destruction lacked an RCU read lock. The fix acquires rcu_read_lock() in instance_destroy_rcu(), and Red Hat addressed the issue for RHEL 8 in RHSA-2024:5101 and RHSA-2024:5102.
Red Hat resolved CVE-2024-39502, an Ionic driver NAPI use-after-unregistration flaw that can cause a kernel BUG and invalid-opcode crash when NIC queue settings are changed with ethtool. Fixes were issued across RHEL 8 and 9 streams through multiple RHSA advisories, including RHSA-2024:5101, RHSA-2024:5102, RHSA-2024:5256, and RHSA-2024:5257.
CVE-2021-47579 was resolved upstream for a warning condition in the OverlayFS ovl_create_real() function. Red Hat addressed the issue for RHEL 8 through RHSA-2024:5101 and RHSA-2024:5102.
Linux resolved a use-after-free in the AMD power-management driver's kv_parse_power_table function, triggered when allocation of ps fails and later cleanup accesses the freed adev->pm.dpm.ps structure. Fedora fixed the issue in its Linux 6.6.14 stable-kernel update, and Red Hat addressed it for RHEL 8 through RHSA-2024:5101 and RHSA-2024:5102.
Linux resolved CVE-2024-40974 by enforcing compiler-visible minimum result-buffer sizes for plpar_hcall(), plpar_hcall9(), and related PowerPC pSeries hypercall APIs. An undersized caller buffer could otherwise be written past its end and potentially corrupt the stack; RHEL 8 received the fix through RHSA-2024:5101.
Linux resolved CVE-2021-47018, in which the PPC64 fixmap area was defined at an invalid address-space location. The correction places the fixmap at the top of I/O space and adds a build-time check for the reserved area; Fedora fixed it in kernel 5.12.4 and RHEL 8 addressed it through RHSA-2024:5101.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
45 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.