Red Hat issued Important security advisories for supported RHEL 8 and RHEL 9 extended-support, SAP-focused, and Advanced Update Support offerings, delivering kernel and live-patch updates for vulnerabilities in performance-event cgroups, networking, virtualization, NFS, Wi-Fi, and Xen/x86 code. The fixes include CVE-2022-48799, in which unsafe iteration during perf_cgroup_switch() could corrupt the performance-event cgroup list when a nested scheduling path removes an entry; the upstream correction uses safe list iteration.
The advisories also address CVE-2024-36971, a use-after-free in network route management, plus CVE-2024-41090 and CVE-2024-41091, denial-of-service issues involving short frames in virtio-net tap/tun and mlx5_core paths. RHSA-2024:6992 supplies kernel version 4.18.0-193.141.1.el8_2 for RHEL 8.2 AUS x86_64 and requires a reboot after installation, while RHSA-2024:5582 provides kpatch modules for specified RHEL 8.6 SAP kernels to remediate affected systems without restarting the running kernel.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2024:6992 for RHEL Server Advanced Update Support 8.2 on x86_64, releasing kernel version 4.18.0-193.141.1.el8_2. The update fixes multiple kernel issues, including CVE-2022-48799 perf cgroup list corruption, Xen/x86, NFSD, virtio-net, and mac80211 flaws; affected systems must be rebooted after installation.
Red Hat issued Important advisory RHSA-2024:5582, providing kpatch live kernel modules for specified RHEL 8.6 SAP Solutions kernels. The patches remediate CVE-2024-36971 and the virtio-net/mlx5_core short-frame denial-of-service flaws CVE-2024-41090 and CVE-2024-41091 without requiring a kernel restart.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.