Red Hat released kernel updates for multiple Linux vulnerabilities affecting Red Hat Enterprise Linux (RHEL) 8 and 9 product streams. The issues include CVE-2024-26982, a SquashFS invalid-inode handling flaw that can let a low-privileged local attacker trigger an out-of-bounds read and denial of service; CVE-2024-36939, improper NFS error handling during nfs_net_init(); and CVE-2024-40978, a qedi SCSI-driver bug that can crash the kernel when a debugfs attribute is read because a user-space pointer is passed to sprintf().
Red Hat also addressed CVE-2023-52840, a use-after-free in the Synaptics RMI4 input driver’s rmi_unregister_function() path. The bug can free the function object through put_device() before later dereferencing it, with availability impact possible. Organizations should deploy the applicable updated RHEL kernel packages, including relevant extended-update-support releases; RHEL 9 kernel-rt remained affected for the Synaptics issue at the time of the advisory, while no standalone mitigation was identified for the SquashFS flaw.

See real exploitation activity before you spend the cycle.
17 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for RHEL 8 kernel-rt, fixing CVE-2023-52840.
Red Hat released RHSA-2024:4352 to remediate CVE-2024-26982 in the Red Hat Enterprise Linux 8 kernel-rt package.
Red Hat released RHSA-2024:4211 to fix CVE-2024-26982 in the Red Hat Enterprise Linux 8 kernel.
Rohit Keshri reported CVE-2024-36939 in the Linux kernel NFS subsystem. The issue resulted from nfs_net_init() not handling an error returned by rpc_proc_register().
An upstream Linux kernel advisory resolved CVE-2023-52840, a use-after-free in Synaptics RMI4's rmi_unregister_function(). The fix moves put_device() until after the last use of the freed function object.
Zack Miele reported the Linux kernel Squashfs flaw later assigned CVE-2024-26982. The defect failed to reject inode number zero, enabling an out-of-bounds read and potential local denial of service.
Red Hat addressed CVE-2024-36939 for RHEL 8, RHEL 9, and RHEL 9.4 Extended Update Support through security and bug-fix advisories.
CVE-2024-36939 was resolved upstream and fixed in Linux kernel releases 5.4.276, 5.10.217, 5.15.159, 6.1.91, 6.6.31, 6.8.10, and 6.9.
Red Hat addressed CVE-2024-40978 through advisories for RHEL 8, RHEL 9, RHEL 9.0 Update Services for SAP Solutions, and RHEL 9.2 Extended Update Support.
CVE-2024-40978 was identified in the qedi SCSI driver's debugfs read path, where sprintf() directly dereferenced a user-space pointer and could cause a kernel page fault. The remediation uses a local buffer and simple_read_from_buffer() for the copy to user space.
The upstream fix for CVE-2024-26982 was included in Linux kernel versions 6.8.8 and 6.9-rc5.
Red Hat issued RHSA-2025:8248 to remediate CVE-2023-52840 in the Red Hat Enterprise Linux 9.4 Extended Update Support kernel.
Red Hat released RHSA-2024:9315 to fix CVE-2023-52840 in the Red Hat Enterprise Linux 9 kernel.
RHSA-2024:6297 fixed CVE-2024-26982 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
Red Hat issued RHSA-2024:5255 to address CVE-2024-26982 in the Red Hat Enterprise Linux 8.8 Extended Update Support kernel.
Red Hat released RHSA-2024:4928 to fix the Squashfs invalid-inode flaw in the Red Hat Enterprise Linux 9 kernel.
RHSA-2024:4823 and RHSA-2024:4831 remediated CVE-2024-26982 in Red Hat Enterprise Linux 9.2 Extended Update Support kernel and kernel-rt packages, respectively.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.