Red Hat released RHSA-2024:4107, a Moderate-severity kernel security and bug-fix update for Red Hat Enterprise Linux 8.6 deployments using Advanced Update Support, Telecommunications Update Service, Extended Life Cycle Long Life, and SAP update channels. The advisory delivers kernel version 4.18.0-372.109.1.el8_6 and remediates CVE-2022-1048, an ALSA PCM use-after-free race in snd_pcm_hw_free that a low-privileged local user could potentially use to crash a system or escalate privileges on systems exposing a relevant sound device.
The update also addresses CVE-2024-26993, a reference leak in sysfs_break_active_protection(), and CVE-2024-26642 in netfilter nf_tables. Red Hat assessed CVE-2024-26993 as preliminarily low impact, with no active exploitation or demonstrated impact reported. Administrators should install the updated kernel packages and reboot affected systems to activate the fixes; preventing the snd-pcm module from loading can mitigate CVE-2022-1048 where patching cannot occur immediately.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:3618 for Red Hat Enterprise Linux 8 kernel packages and RHSA-2024:3627 for RHEL 8 kernel-rt packages, remediating the sysfs reference-leak vulnerability CVE-2024-26993.
The Linux kernel CVE team assigned CVE-2024-26993 to a sysfs vulnerability involving a reference leak in sysfs_break_active_protection().
Red Hat issued RHSA-2022:7444 for RHEL 8 kernel-rt and RHSA-2022:7683 for the RHEL 8 kernel, fixing the ALSA PCM use-after-free vulnerability CVE-2022-1048.
Red Hat released Moderate-severity advisory RHSA-2024:4107 for supported RHEL 8.6 update channels. The kernel update fixes CVE-2022-1048, CVE-2024-26642, and CVE-2024-26993; affected systems require a reboot after installation.
Red Hat issued RHSA-2022:8267 for the RHEL 9 kernel and RHSA-2022:7933 for RHEL 9 kernel-rt, addressing CVE-2022-1048.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.