Red Hat released RHSA-2024:11313 for Red Hat Enterprise Linux 9.4 support channels, updating the kernel to 5.14.0-427.49.1.el9_4. The update remediates four vulnerabilities: CVE-2021-47384, a w83793 hardware-monitoring driver NULL-pointer dereference that can cause system instability; CVE-2024-38627, a double-free in STM device registration; CVE-2024-39499, a VMCI event-delivery speculative information-leak risk; and CVE-2024-40989, an ARM64 KVM teardown flaw that can leave vCPUs with dangling redistributor-region pointers.
The advisory applies across supported RHEL 9.4 x86_64, ARM64, IBM Z/s390x, and Power little-endian deployments, including EUS, AUS, SAP Update Services, and Extended Life Cycle channels. Red Hat rates the advisory Moderate; the w83793 flaw has a CVSS 3.1 score of 5.5 and requires local, low-privileged access, while the other fixes address memory-safety, speculative-execution, and virtualization risks. Organizations should deploy the updated kernel packages and reboot affected systems for the fixes to take effect.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 and RHSA-2024:7001 for RHEL 8 kernel and kernel-rt packages, and RHSA-2024:6993 for RHEL 8.8 EUS, addressing the w83793 NULL-pointer dereference.
CVE-2024-40989 was reported in ARM64 KVM teardown logic, where vCPUs could retain dangling pointers to a removed GIC redistributor region.
CVE-2024-39499 was reported in the Linux kernel VMCI event_deliver() path, where a user-controlled event value could be used as an unsanitized index and potentially enable speculative information leakage.
Patrick Del Bello reported CVE-2024-38627, a double-free condition in the Linux kernel STM class function stm_register_device().
The upstream Linux kernel advisory for CVE-2021-47384 was published. The w83793 hwmon-driver flaw could trigger a NULL-pointer dereference, and its fix removes an unnecessary structure field.
Red Hat published RHSA-2024:11313, delivering kernel version 5.14.0-427.49.1.el9_4 for RHEL 9.4 support channels. The update fixes CVE-2021-47384, CVE-2024-38627, CVE-2024-39499, and CVE-2024-40989; affected systems require a reboot after installation.
Red Hat released RHSA-2024:9315 for the RHEL 9 kernel package, addressing CVE-2021-47384.
Red Hat released RHSA-2024:8613 and RHSA-2024:8614 for RHEL 9.2 Extended Update Support kernel and kernel-rt packages to address CVE-2021-47384.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.