Red Hat released Moderate-severity kernel updates for RHEL 9.2 supported streams and the RHEL 9.2 Real Time kernel, addressing memory-safety flaws in KVM virtualization, Bluetooth socket handling, s390 virtualization, and the mlx5e network driver. The fixes include CVE-2024-26598, a use-after-free in KVM VGIC ITS LPI translation-cache handling caused by a race between cache lookup and invalidation, and CVE-2023-52667, a potential double-free in mlx5e function fs_any_create_groups.
RHSA-2024:3855 covers affected RHEL 9.2 deployments across x86_64, aarch64, ppc64le, and s390x, while RHSA-2024:3854 supplies kernel-rt-5.14.0-284.69.1.rt14.354.el9_2 for eligible RHEL 9.2 real-time systems. Red Hat also included CVE-2024-26598 in a later RHEL 8.6 kernel update, RHSA-2024:8161, alongside CVE-2024-26830, CVE-2024-35884, and CVE-2021-47560. Administrators should install the applicable updated kernel packages and reboot systems to activate the mitigations.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Moderate-security advisory RHSA-2024:8161 for supported RHEL 8.6 offerings, providing kernel 4.18.0-372.126.1.el8_6. The update fixed CVE-2024-26598 along with CVE-2024-26830, CVE-2024-35884, and CVE-2021-47560.
Red Hat published Moderate-security advisory RHSA-2024:3855 for RHEL 9.2 supported update streams, providing kernel-5.14.0-284.69.1.el9_2. It remediated CVE-2023-5090, CVE-2023-51779, CVE-2024-26598, CVE-2023-52639, and CVE-2023-52667.
Red Hat published Moderate-security advisory RHSA-2024:3854 for RHEL 9.2 Extended Update Support kernel-rt packages. The update fixed CVE-2023-5090, CVE-2023-51779, CVE-2024-26598, and CVE-2023-52667 in kernel-rt 5.14.0-284.69.1.rt14.354.el9_2.
Zack Miele reported Red Hat Bug 2281350 to track CVE-2023-52667, a potential double-free in the Linux kernel mlx5e fs_any_create_groups function. Red Hat classified the issue as medium severity and priority.
Fedora fixed CVE-2024-26598, a potential use-after-free in KVM VGIC ITS LPI translation-cache handling, in its 6.6.14 stable kernel update.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.