Red Hat released moderate-severity advisory RHSA-2025:8796 for supported RHEL 9.4 update channels, delivering kernel version 5.14.0-427.72.1.el9_4. The update applies across x86_64, aarch64, ppc64le, and s390x deployments in EUS, AUS, SAP, extended-life-cycle, and CodeReady Linux Builder repositories. Administrators must reboot affected systems after installing the updated kernel.
The advisory remediates kernel issues including CVE-2024-26921, which could release an IPv4 defragmentation socket while still in use; CVE-2024-26645, a tracing-map insertion race condition that can cause local denial of service; CVE-2024-27042, a potential out-of-bounds access in AMDGPU discovery-register initialization; CVE-2024-35930, a possible LPFC SCSI-driver memory leak; and CVE-2024-36933, an NSH GSO packet-header handling flaw. It also addresses a PowerPC vector-operation issue and references CVE-2023-54114; RHEL 9 kernel-rt remains listed as affected by CVE-2024-26645 without a corresponding erratum.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2025:8796 with kernel version 5.14.0-427.72.1.el9_4 for supported RHEL 9.4 update channels. It fixes CVE-2023-52606 and CVE-2024-26645, CVE-2024-26921, CVE-2024-27042, CVE-2024-35930, and CVE-2024-36933; a reboot is required for the new kernel to take effect.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for RHEL 8 kernel-rt, addressing CVE-2024-26645.
An upstream Linux kernel advisory was published for CVE-2024-35930, a possible memory leak in the LPFC SCSI driver's lpfc_rcv_padisc() function.
Zack Miele reported Red Hat bug 2278447 for CVE-2024-27042, a potential out-of-bounds access in amdgpu_discovery_reg_base_init().
The Linux kernel CVE team assigned CVE-2024-26921 to an inet_defrag flaw in which a socket could be released while still in use. The upstream fix prevents the premature socket release.
The Linux kernel CVE team publicly disclosed CVE-2024-26645, a race condition affecting visibility when inserting an element into tracing_map. The upstream resolution ensures visibility during tracing_map insertion.
The Linux kernel CVE team assigned CVE-2024-36933 to an NSH Generic Segmentation Offload issue in nsh_gso_segment(). The resolution restores socket-buffer protocol, data, and MAC-header fields for the outer header.
Upstream Linux kernel releases 6.6.23, 6.7.11, 6.8.2, and 6.9-rc1 incorporated fixes for CVE-2024-27042, the potential out-of-bounds access in amdgpu_discovery_reg_base_init().
Red Hat released RHSA-2024:9315 to fix CVE-2024-26645 in the RHEL 9 kernel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.