Red Hat addressed CVE-2024-35890, a medium-severity Linux kernel flaw in Generic Receive Offload (GRO) caused by incorrect socket-reference ownership transfer while processing packets with fragment lists. A local, low-privileged attacker could trigger kernel bugs or system instability, producing a high availability impact; Red Hat assigned the issue a CVSS v3.1 score of 5.5. Upstream fixes are included in kernel versions 5.15.154, 6.1.85, 6.6.26, 6.8.5, and 6.9.
Red Hat released patched kernel packages across affected RHEL 8 and RHEL 9 streams, including RHSA-2025:0062 for RHEL 8.8 Extended Update Support and associated service variants. That advisory provides kernel-4.18.0-477.86.1.el8_8 packages for x86_64, s390x, ppc64le, and aarch64 and also remediates CVE-2024-53122. Administrators should install the applicable kernel updates and reboot systems; RHEL 6 is outside support scope and should be treated as affected.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:4352, updating RHEL 8 kernel-rt packages to address CVE-2024-35890.
Red Hat issued RHSA-2024:4211 with Red Hat Enterprise Linux 8 kernel updates addressing CVE-2024-35890.
An automated check reported that the CVE-2024-35890 fix patch had not yet been applied to the source set it examined.
Red Hat issued RHSA-2024:3306, providing RHEL 9 kernel updates that address CVE-2024-35890.
The Linux kernel Generic Receive Offload ownership-transfer issue later tracked as CVE-2024-35890 was reported by ybuenos.
Red Hat issued RHSA-2024:1881 for Red Hat Enterprise Linux 9.2 Extended Update Support, including a fix for CVE-2024-35890.
Red Hat published Important-rated RHSA-2025:0062 for RHEL 8.8 Extended Update Support and related service variants. The advisory shipped kernel version 4.18.0-477.86.1.el8_8, fixing CVE-2024-35890 and CVE-2024-53122; affected systems require a reboot after installation.
RHSA-2024:11485 delivered fixes for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
RHSA-2024:4415 provided RHEL 9.0 Update Services for SAP Solutions kernel updates addressing CVE-2024-35890.
The Linux kernel CVE team assigned CVE-2024-35890 to a GRO ownership-transfer flaw that can retain an skb socket reference and trigger a kernel BUG in skb_orphan. The announcement identified fixes in kernel versions 5.15.154, 6.1.85, 6.6.26, 6.8.5, and 6.9, and recommended upgrading to a current stable release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.