Red Hat released RHSA-2024:9401 for Red Hat Enterprise Linux 9, updating microcode_ctl to 20240910-1.el9_5 across supported x86_64, EUS, AUS, SAP Solutions, and Extended Life Cycle channels. The advisory supplies Intel and AMD processor microcode and remediates seven Intel CPU flaws, including local privilege-escalation, information-disclosure, denial-of-service, race-condition, and processor-behavior issues.
Among the addressed vulnerabilities is CVE-2023-28746, a moderate-severity flaw affecting certain Intel Atom processors that permits local information disclosure and can compromise data confidentiality. Red Hat rates it CVSS 6.5, requiring local access but low privileges and no user interaction; RHEL 8 and 9 received kernel and microcode updates, while RHEL 7 is not affected. Organizations should deploy the applicable microcode_ctl and kernel updates, and treat unsupported RHEL 6 systems as potentially affected.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:5101, fixing CVE-2023-28746 in the Red Hat Enterprise Linux 8 kernel.
Red Hat issued Moderate-severity advisory RHSA-2024:9401 for RHEL 9, shipping microcode_ctl-20240910-1.el9_5. The update remediates CVE-2023-28746 and six other Intel processor vulnerabilities.
Red Hat released RHSA-2024:8162 for the RHEL 9 kernel and RHSA-2024:8157 and RHSA-2024:8158 for RHEL 9.2 Extended Update Support kernel and kernel-rt packages, fixing CVE-2023-28746.
Red Hat released RHEA-2024:7620, providing a fixed microcode_ctl update for Red Hat Enterprise Linux 9 that addresses CVE-2023-28746.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.