Red Hat released RHSA-2024:8157 for Red Hat Enterprise Linux 9.2 kernel update channels, delivering kernel version 5.14.0-284.88.1.el9_2 and remediating 11 CVEs across x86_64, aarch64, ppc64le, and s390x offerings. The update includes a fix for CVE-2024-36244 in the taprio network scheduler, extending its minimum interval restriction to the entire scheduling cycle, alongside fixes for kernel NULL-pointer dereferences, deadlocks, memory leaks, and other subsystem defects. Systems must be rebooted after installation for the updated kernel to take effect.
The related kernel flaws include CVE-2024-41066, in which inconsistent ibmvnic transmit bookkeeping can overwrite a non-null socket-buffer pointer and leak memory, potentially stopping TCP congestion control and causing ETIMEDOUT denial-of-service conditions. Red Hat rated that issue Low (CVSS 4.4) because exploitation requires high local privileges and affected IBM virtual-network hardware; organizations unable to patch can disable or blacklist the ibmvnic module. Red Hat also documented CVE-2024-42284, a Moderate (CVSS 7.3) TIPC buffer overflow triggered by invalid UDP media-address handling; affected deployments should apply available RHEL 8/9 kernel fixes and review exposure where TIPC is enabled.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:9546 to fix CVE-2024-41066 in the RHEL 9.4 Extended Update Support kernel. The flaw could leak socket buffers when ibmvnic transmit bookkeeping arrays became unsynchronized.
Red Hat issued RHSA-2024:8856 for RHEL 8 kernel packages and RHSA-2024:8870 for RHEL 8 kernel-rt packages. The advisories fixed CVE-2024-41066 in the ibmvnic transmit path and CVE-2024-42284 in TIPC networking code.
Red Hat issued RHSA-2024:8158 for RHEL 9.2 Extended Update Support kernel-rt packages and RHSA-2024:8162 for RHEL 9 kernel packages, addressing CVE-2024-42284.
Red Hat issued the Moderate-severity RHSA-2024:8157 advisory for RHEL 9.2 update channels, delivering kernel version 5.14.0-284.88.1.el9_2. It remediated 11 CVEs, including CVE-2024-36244, CVE-2024-41066, and CVE-2024-42284; affected systems require rebooting after installation.
Red Hat issued RHSA-2024:8107 to provide a kernel fix for CVE-2024-42284 in Red Hat Enterprise Linux 8.8 Extended Update Support.
Red Hat published its record for CVE-2024-42284, a TIPC networking flaw where tipc_udp_addr2str() can return zero for an invalid UDP media address and enable a buffer overflow in tipc_media_addr_printf().
An upstream Linux kernel CVE advisory was published for CVE-2024-36244, involving insufficient enforcement of the minimum interval restriction in the taprio network scheduler across an entire scheduling cycle.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.