Red Hat released Important updates for Red Hat Enterprise Linux 7 and RHEL for Real Time 7 to remediate CVE-2022-2588, a CVSS 7.8 use-after-free flaw in the Linux route classifier's route4_change function. A local low-privileged attacker could crash an affected system and potentially gain elevated privileges. The updates also address Linux kernel information-disclosure issues and CPU speculative-execution vulnerabilities, including AMD and Intel RetBleed variants, branch type confusion, and return-stack-buffer prediction issues.
The standard RHEL 7 update supplies kernel version 3.10.0-1160.80.1.el7; the real-time update supplies 3.10.0-1160.80.1.rt56.1225.el7. Red Hat also refreshed OpenShift Dev Spaces 3 container images, including the devspaces/operator-bundle, with backported fixes for CVE-2022-0494, CVE-2022-1353, CVE-2022-2588, CVE-2022-23816, CVE-2022-29900, and CVE-2022-29901. Organizations should install the applicable packages and reboot affected hosts, while Dev Spaces users should upgrade the container images, rebuild dependent images, and update image references in Dockerfiles and automation.

Get the actors, campaigns, and ATT&CK mapping behind it.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHBA-2022:7877 to update Red Hat Software Collections container images for RHEL 7 on x86_64, s390x, and ppc64le. The images incorporate security fixes including CVE-2022-2588 and RetBleed-related vulnerabilities; users were advised to upgrade and rebuild dependent images.
Red Hat issued RHBA-2022:7836, updating the devspaces/operator-bundle container image for OpenShift Dev Spaces 3 on x86_64. The update incorporated the security fixes covered by RHBA-2022:7437, and Red Hat advised rebuilding dependent images.
Red Hat issued RHBA-2022:7437 for OpenShift Dev Spaces 3 container images on x86_64. The images received backported fixes for CVE-2022-2588, kernel information-disclosure flaws, and AMD and Intel RetBleed-related vulnerabilities.
Red Hat released RHSA-2022:7344 to remediate CVE-2022-2588 in the Red Hat Enterprise Linux 7 kpatch-patch stream.
Red Hat issued Important advisory RHSA-2022:7338 for RHEL for Real Time 7 and its NFV variant, releasing kernel-rt-3.10.0-1160.80.1.rt56.1225.el7. The update remediates CVE-2022-2588 and multiple AMD and Intel speculative-execution vulnerabilities.
Red Hat issued Important advisory RHSA-2022:7337 for RHEL 7, releasing kernel-3.10.0-1160.80.1.el7. The update fixes the cls_route use-after-free flaw CVE-2022-2588 and AMD and Intel RetBleed-related speculative-execution issues, among other fixes.
Red Hat released RHSA-2022:7173 to fix CVE-2022-2588 in the RHEL 7.6 Update Services for SAP Solutions kpatch-patch stream.
Red Hat released RHSA-2022:7171, fixing CVE-2022-2588 for RHEL 7.6 Advanced Update Support, Telco Extended Update Support, and Update Services for SAP Solutions kernel streams.
Red Hat released RHSA-2022:7146 to fix CVE-2022-2588 in the Red Hat Enterprise Linux 7.4 Advanced Update Support kernel stream.
Red Hat issued Moderate-severity advisory RHSA-2021:3441, providing kpatch-patch packages for RHEL 7 on x86_64 and ppc64le, including Extended Life Cycle Support variants. The live update remediated the CVE-2021-3715 use-after-free in the Linux kernel's route4_change() function without a conventional reboot.
Red Hat issued Important advisory RHSA-2021:3442, providing a kpatch live-update module for RHEL 8.1 Extended Update Support and SAP Solutions on x86_64 and ppc64le. The update remediated CVE-2021-3609, CVE-2021-3715, and CVE-2021-37576 without requiring a conventional reboot.
Red Hat closed its bug record for CVE-2021-3715, a use-after-free in the Linux Traffic Control routing-decision classifier that could allow local privilege escalation. Red Hat addressed the flaw through advisories for RHEL 7, RHEL 8.1 and 8.2 Extended Update Support, and Red Hat Virtualization 4.
Red Hat released RHSA-2020:4431 and RHSA-2020:4609, fixing the CVE-2021-3715 Linux Traffic Control route4_change() use-after-free vulnerability in RHEL 8 kernel and kernel-rt packages.
Red Hat released RHSA-2023:4022 to fix CVE-2022-2588 for the RHEL 7.7 Advanced Update Support and Telco Extended Update Support kernel streams.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
15 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.