Red Hat released RHSA-2024:8162, a Moderate-severity update for Red Hat Enterprise Linux 9, remediating 14 Linux-kernel vulnerabilities across standard RHEL 9 and associated EUS, ELS, SAP, and CodeReady Linux Builder offerings. The fixes address issues including local information disclosure on Intel Atom processors, an out-of-bounds write in sch_multiq, a use-after-free condition in the Ionic driver, and several NULL-pointer dereference and networking flaws, including CVE-2023-52658, CVE-2021-47385, and CVE-2024-35989. Affected systems span x86_64, aarch64, ppc64le, and s390x architectures; administrators must reboot after installing the updated kernel.
Red Hat also published refreshed RHEL 9 container images under RHBA-2024:8242, RHBA-2024:8412, RHBA-2024:8441, and RHBA-2024:8578, backporting the RHSA-2024:8162 kernel security fixes into UBI-derived, language-runtime, S2I, support-tools, and Go Toolset images. Organizations should pull the revised images from the Red Hat Container Registry, update base-image references in Dockerfiles and build scripts, and rebuild and redeploy all dependent container images.

See real exploitation activity before you spend the cycle.
12 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHBA-2024:8578, updating RHEL 9 container images with backported security fixes referenced by RHSA-2024:8162. The advisory instructed users to obtain updated images and rebuild dependent container images.
RHBA-2024:8441 updated the RHEL 9 rhel9/support-tools container image with backported RHSA-2024:8162 security fixes. Red Hat advised users to upgrade and rebuild downstream images derived from it.
Red Hat issued RHBA-2024:8412 to provide updated RHEL 9 container images incorporating backported fixes associated with RHSA-2024:8162. Users were advised to update image references and rebuild dependent images.
RHBA-2024:8242 updated the RHEL 9 rhel9/go-toolset container image with backported security fixes from RHSA-2024:8162. Red Hat advised users to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:8165, updating the rhdh/rhdh-hub-rhel9 container image for Red Hat Developer Hub 1.3 on RHEL 9 with backported RHSA-2024:8162 security fixes. Users were advised to upgrade the image and rebuild dependent container images.
Red Hat issued Moderate-severity advisory RHSA-2024:8162 for an updated RHEL 9 kernel. It remediated 14 vulnerabilities, including CVE-2023-52658, CVE-2024-35989, and CVE-2021-47385, and required systems to reboot after installation.
Red Hat reported CVE-2024-42079, a medium-severity GFS2 race condition in which unmounting can leave sd_jdesc NULL and cause gfs2_log_flush to dereference it. The upstream fix adds locking and a NULL check; Red Hat addressed the flaw in RHEL 9 via RHSA-2024:8162 and in RHEL 8 via RHSA-2024:8856 and RHSA-2024:8870.
Red Hat reported CVE-2024-35989, a dmaengine idxd driver flaw that can cause a kernel oops when the module is removed on single-CPU systems.
Red Hat recorded CVE-2024-27403, a Linux kernel netfilter nft_flow_offload vulnerability resolved by resetting the destination field in a route object after flow setup. The issue was later addressed for RHEL 9 through RHSA-2024:8162, as well as certain RHEL EUS and SAP offerings.
Red Hat reported CVE-2023-52658, involving net/mlx5 switchdev mode and namespace inconsistency handling. The remediation reverts the affected net/mlx5 change.
Red Hat documented CVE-2024-38556, a Linux kernel net/mlx5 flaw involving command-queue semaphore acquisition without a timeout. The upstream remediation adds a timeout, and Red Hat addressed the issue through RHSA-2024:8162 and RHEL 9.2 EUS advisories RHSA-2024:5364 and RHSA-2024:5365.
Red Hat documented CVE-2024-39483, a Linux kernel KVM/SVM issue in which an NMI-window request could incorrectly trigger a WARN when virtual NMI support was enabled but NMIs were not genuinely masked. The fix restricts the warning to vCPUs already handling an NMI, and was distributed for RHEL 9 through RHSA-2024:8162.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.