Red Hat released RHSA-2025:2270 for RHEL 9.4 Extended Update Support, updating the kernel to 5.14.0-427.57.1.el9_4 and remediating 21 vulnerabilities across EFI, memory management, networking, Open vSwitch, ACPI, ext4, SCTP, I2C, ARM64 probes, and graphics. The update applies across supported x86_64, aarch64, ppc64le, and s390x RHEL 9.4 EUS and associated update channels.
The advisory includes CVE-2024-26843, a medium-severity potential integer overflow in EFI runtime handling of soft-reserved region sizes, and CVE-2024-26846, a low-severity NVMe over Fibre Channel module-exit race that can indefinitely hang module unloading and cause a local availability impact. Upstream fixes for both issues were incorporated in Linux versions 5.10.211, 5.15.150, 6.1.80, 6.6.19, 6.7.7, and 6.8; Red Hat also delivered fixes for standard RHEL 8 and 9 kernels. Systems must be rebooted after installing the updated kernel.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel, remediating the nvme-fc module-unload vulnerability.
Robb Gatica reported Red Hat Bug 2275558 for CVE-2024-26846, a low-severity race condition that can cause an nvme-fc module unload to hang indefinitely.
Robb Gatica reported Red Hat Bug 2275565 for CVE-2024-26843, a medium-severity potential overflow in Linux EFI runtime soft-reserved-region sizing.
Red Hat released Moderate-severity advisory RHSA-2025:2270 for RHEL 9.4 Extended Update Support, supplying kernel version 5.14.0-427.57.1.el9_4 and fixing both CVE-2024-26843 and CVE-2024-26846 among 21 CVEs. Red Hat stated that systems must be rebooted after applying the update.
RHSA-2024:9315 remediated CVE-2024-26843 and CVE-2024-26846 in the standard RHEL 9 kernel.
Red Hat addressed the EFI runtime soft-reserved-region sizing vulnerability in RHEL 8 through RHSA-2024:5101 and RHSA-2024:5102.
The nvme-fc unload fix was included in upstream Linux kernel versions 5.10.211, 5.15.150, 6.1.80, 6.6.19, 6.7.7, and 6.8. The fix removes unnecessary ID destruction and flushes the controller-deletion workqueue before module exit.
The EFI runtime overflow issue was fixed in upstream Linux kernel versions 5.10.211, 5.15.150, 6.1.80, 6.6.19, 6.7.7, and 6.8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.