Red Hat released Important-rated kernel and kernel-rt updates for affected Red Hat Enterprise Linux (RHEL) 8 and 9 deployments, remediating vulnerabilities including CVE-2023-0386, a FUSE flaw that allows a low-privileged local user to escalate privileges, and CVE-2023-0179, a Netfilter/nftables integer overflow that can disclose memory addresses and potentially enable root-level code execution. The advisories also address use-after-free defects in Bluetooth L2CAP (CVE-2022-3564), ALSA PCM handling (CVE-2023-0266), and NFSv4.2 server-side copy handling (CVE-2022-4379), the latter of which can permit remote denial of service, as well as procfs stack-overflow and TC mirred CPU soft-lockup flaws.
The updates span standard kernels, Real Time kernels, and support-channel variants including EUS, AUS, TUS, SAP, NFV, and telecommunications offerings across x86_64, aarch64, s390x, ppc64le, and selected IBM Power systems. Administrators should deploy the applicable updated kernel packages and reboot systems to activate conventional kernel fixes; RHEL 8 customers covered by RHSA-2023:1659 can instead install the updated kpatch-patch module, which loads automatically to live-patch four vulnerabilities without a normal reboot.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2023:1660, an Important kpatch-patch update for RHEL 8.6 EUS and related ELL, AUS, TUS, and SAP update-service offerings. The live-patch module remediated CVE-2023-0266 and the FUSE privilege-escalation flaw CVE-2023-0386 without a conventional kernel reboot.
Red Hat issued RHSA-2023:1659, an Important kpatch-patch update for RHEL 8 x86_64 and ppc64le offerings. The live-patch module remediated CVE-2022-4378, CVE-2023-0266, CVE-2023-0386, and CVE-2023-1476 without requiring a conventional kernel reboot.
Red Hat issued RHSA-2023:1584, an Important kernel-rt security and bug-fix update for affected RHEL 8 Real Time, NFV, telecommunications, and Extended Life Cycle offerings. Version 4.18.0-425.19.2.rt7.230.el8_7 fixed CVE-2022-4269, CVE-2022-4378, CVE-2023-0266, and CVE-2023-0386.
Red Hat issued RHSA-2023:1566, an Important RHEL 8 kernel update providing version 4.18.0-425.19.2.el8_7. It fixed CVE-2022-4269, CVE-2022-4378, CVE-2023-0266, and CVE-2023-0386, the latter allowing low-privileged local users to escalate privileges through FUSE.
Red Hat issued RHSA-2023:1560, an Important kernel-rt update for RHEL Real Time and Real Time for NFV Telecommunications Update Service 8.2 on x86_64. Version 4.18.0-193.105.1.rt13.156.el8_2 fixed CVE-2022-3564 and CVE-2023-0266; affected systems required rebooting.
Red Hat issued RHSA-2023:1559, an Important kernel update for RHEL 8.2 AUS, TUS, and SAP update-service deployments. Kernel version 4.18.0-193.105.1.el8_2 remediated the Bluetooth L2CAP use-after-free CVE-2022-3564 and ALSA use-after-free CVE-2023-0266.
Red Hat issued RHSA-2023:1554, an Important security advisory for RHEL 8.6 EUS and related support-channel offerings. Kernel version 4.18.0-372.51.1.el8_6 fixed the ALSA use-after-free CVE-2023-0266 and the FUSE privilege-escalation flaw CVE-2023-0386; affected systems required rebooting.
Red Hat issued RHSA-2023:1220, an Important kernel-rt update for RHEL 8.4 EUS and specified telecommunications offerings. Version 4.18.0-305.82.1.rt7.154.el8_4 fixed CVE-2022-3564, CVE-2022-4378, and CVE-2022-4269, and required a reboot.
Red Hat issued RHSA-2023:1202, an Important advisory delivering kernel version 5.14.0-70.49.1.el9_0 for RHEL 9.0 EUS and specified SAP update-service variants. It fixed six vulnerabilities, including the NFSv4.2 use-after-free CVE-2022-4379 and Netfilter integer overflow CVE-2023-0179; systems required rebooting.
Red Hat issued RHSA-2023:1008, an Important kpatch-patch update for RHEL 9 x86_64 and ppc64le systems. The live-patch module remediated CVE-2022-3564, CVE-2022-4378, CVE-2022-4379, and CVE-2023-0179.
Red Hat issued RHSA-2023:0979, an Important update for RHEL 9 kernel-rt on x86_64, providing version 5.14.0-162.18.1.rt21.181.el9_1. The update fixed five flaws including CVE-2023-0179 and the CVE-2022-4379 NFS use-after-free that could cause remote denial of service.
Red Hat issued RHSA-2023:0951, an Important security and bug-fix update for the RHEL 9 kernel across x86_64, s390x, ppc64le, and aarch64. It remediated CVE-2022-2873, CVE-2022-3564, CVE-2022-4378, CVE-2022-4379, and CVE-2023-0179; a reboot was required.
Rohit Keshri reported Red Hat Bug 2161713 for CVE-2023-0179, an integer-overflow vulnerability in the Linux kernel Netfilter nft_payload_copy_vlan function. The flaw can leak stack and heap addresses and potentially enable local privilege escalation.
Red Hat's CVE-2023-0386 tracking record detailed how OverlayFS copy-up from a FUSE lower layer can preserve setuid/setgid bits, allowing a low-privileged local user to obtain root privileges under affected configurations. It also identified remediation coverage across RHEL 8, RHEL 9, EUS releases, and Red Hat Virtualization 4.
Red Hat closed Bug 2161713, its high-severity tracking issue for the Linux kernel Netfilter integer-overflow vulnerability CVE-2023-0179.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.