Red Hat issued fixes for CVE-2022-48754, a use-after-free flaw in the Linux kernel's phylib networking subsystem. The vulnerability occurs in phy_detach() because phy_device_reset() was called after put_device(), which may already have released the PHY device. The upstream correction moves the reset operation before put_device().
The flaw was introduced in Linux 4.16 and corrected in upstream stable releases including 4.19.228, 5.4.176, 5.10.96, 5.15.19, 5.16.5, and 5.17. Red Hat delivered fixes for RHEL 8 kernel, kernel-rt, and RHEL 8.8 Extended Update Support through advisories including RHSA-2024:6206, RHSA-2024:7000, and RHSA-2024:7001; Red Hat listed RHEL 9 kernel and kernel-rt as affected at publication. Red Hat rated the issue Low severity with CVSS 5.6, while the CVE record carried a 7.8 score.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for the RHEL 8 kernel-rt, addressing CVE-2022-48754.
Red Hat released RHSA-2024:6206, fixing the phylib use-after-free vulnerability for the Red Hat Enterprise Linux 8.8 Extended Update Support kernel.
Mauro Matteo Cascella reported CVE-2024-40901, involving test_bit() and set_bit() operations on unallocated memory in the Linux kernel SCSI mpt3sas driver.
A deadlock vulnerability involving extended-attribute inode creation under an external xattr-block buffer lock was reported in Linux ext4. Corrupted filesystems, including a quota file using an xattr block as data, can trigger the flawed lock ordering.
The Linux kernel CVE team assigned CVE-2022-48754 to a phylib use-after-free flaw in phy_detach(), where phy_device_reset() could run after put_device() had released the PHY device. The flaw was introduced in Linux kernel 4.16; the remediation moves the reset call before put_device().
Red Hat addressed CVE-2024-40901 in RHEL 8 through RHSA-2024:7000 and RHSA-2024:7001, RHEL 9 through RHSA-2024:9315, and RHEL 9.4 Extended Update Support through RHSA-2024:9546.
Upstream Linux kernel releases fixed the mpt3sas driver's bit operations on unallocated memory, including versions 4.19.317, 5.4.279, 5.10.221, 5.15.162, 6.1.95, 6.6.35, 6.9.6, and 6.10-rc4.
Red Hat addressed the ext4 vulnerability for RHEL 8 through RHSA-2024:7000 and RHSA-2024:7001, and for RHEL 9 through RHSA-2024:8617.
The ext4 remediation moved EA-inode allocation out of ext4_xattr_set_entry() and into its callers. The issue is listed as fixed in Linux kernel 6.9.7 and 6.10-rc1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.