Red Hat released Important kernel security updates for RHEL 8.4 extended-support channels and RHEL 9.0 Extended Update Support to remediate CVE-2022-4139 and CVE-2022-2964. CVE-2022-4139 affects Intel Gen12 i915 GPUs: an incorrect GPU TLB flush can leave stale mappings that enable random memory access, potentially resulting in data exposure or memory corruption. CVE-2022-2964 is a memory-corruption vulnerability in handling AX88179_178A USB Ethernet devices.
Affected organizations should install kernel 4.18.0-305.76.1.el8_4 on applicable RHEL 8.4 deployments and 5.14.0-70.43.1.el9_0 on applicable RHEL 9.0 EUS systems, then reboot to activate the fixes. Red Hat also delivered the fixes through its RHEL 9 live-kernel-patching package, alongside remediation for a watch-queue privilege-escalation race condition and an nfsd TCP/RPC buffer-overflow flaw; the live patch is available for x86_64 and little-endian Power RHEL 9 systems.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2023:1130 for RHEL 8.6 servicing channels, supplying kernel 4.18.0-372.46.1.el8_6. The reboot-required update remediated CVE-2022-2964, CVE-2022-41222, and CVE-2022-4269 across supported architectures.
Red Hat issued Important advisory RHSA-2023:0536, updating the kpatch-patch live kernel module for RHEL 9.0 Extended Update Support and SAP Solutions channels on x86_64 and ppc64le. The live patch remediated CVE-2022-2964 and CVE-2022-4139 without a conventional kernel reboot.
Red Hat issued Important advisory RHSA-2023:0499 for RHEL 8.4 supported update channels. The kpatch-patch live kernel module remediated CVE-2022-2964 and CVE-2022-4139 on affected x86_64 and ppc64le systems without requiring a conventional reboot.
Red Hat issued Important advisory RHSA-2023:0512 for RHEL 9.0 Extended Update Support, delivering kernel version 5.14.0-70.43.1.el9_0. The update remediated CVE-2022-4139 and CVE-2022-2964 across supported architectures and required a reboot for fixes to take effect.
Red Hat issued Important advisory RHSA-2023:0496 for RHEL 8.4 extended-support channels, providing kernel version 4.18.0-305.76.1.el8_4. The update fixed CVE-2022-4139 and the AX88179_178A USB Ethernet memory-corruption flaw CVE-2022-2964; affected systems required a reboot.
Red Hat issued Important advisory RHSA-2023:0531 for RHEL 8.4 Extended Update Support and telecommunications Real Time channels, providing kernel-rt 4.18.0-305.76.1.rt7.148.el8_4 for x86_64. The reboot-required update remediated CVE-2022-2964 and CVE-2022-4139.
Red Hat issued RHSA-2023:0399, RHSA-2023:0400, and RHSA-2023:0404 to fix CVE-2022-2964 in RHEL 7 kernel, kernel-rt, and kpatch packages. It also released RHSA-2023:0395 and RHSA-2023:0392 for affected RHEL 8.2 Advanced Update Support and Telecommunications Update Service channels.
Red Hat issued Important advisory RHSA-2023:0348, updating the kpatch-patch live kernel module for RHEL 9. The live patch remediated CVE-2022-2959, CVE-2022-2964, CVE-2022-4139, and CVE-2022-43945 on x86_64 and ppc64le systems.
Red Hat issued Important advisory RHSA-2023:0123, providing kpatch-patch-4_18_0-425_3_1-1-2.el8 for affected RHEL 8 x86_64 and ppc64le channels. The live kernel patch remediated the AX88179_178A USB Ethernet memory-corruption flaw CVE-2022-2964 and the Intel i915 GPU TLB-flush flaw CVE-2022-4139.
Red Hat issued Important advisory RHSA-2023:0114, providing kernel-rt 4.18.0-425.10.1.rt7.220.el8_7 for affected RHEL 8 Real Time and related x86_64 offerings. The reboot-required update fixed CVE-2022-2964 and CVE-2022-4139 and addressed an RT-kernel boot issue affecting systems with PERC12 controllers.
Red Hat issued Important advisory RHSA-2023:0101 for RHEL 8, providing kernel version 4.18.0-425.10.1.el8_7 across x86_64, s390x, ppc64le, and aarch64 platforms. The reboot-required update remediated the AX88179_178A USB Ethernet memory-corruption flaw CVE-2022-2964 and the Intel i915 GPU TLB-flush issue CVE-2022-4139.
Red Hat closed its medium-severity tracking bug for CVE-2021-26401, an AMD LFENCE/JMP speculative-execution mitigation weakness related to Spectre Variant 2. The issue affected AMD Zen through Zen 3 processors under a specific SMT-sibling workload and had been addressed for RHEL 8 through RHSA-2022:1975 and RHSA-2022:1988.
Marian Rehak described CVE-2022-0330, a random-memory-access flaw in the Linux Intel i915 GPU driver. A local user able to run malicious GPU code could crash an affected system or potentially escalate privileges.
Red Hat documented that an incorrect TLB flush in the Linux i915 GPU driver can enable random memory access, memory corruption or disclosure, system crashes, and possible local privilege escalation. It stated that RHEL 7 is not affected because it lacks Intel Gen12 GPU support and that no mitigation meeting its deployment and stability criteria is available.
Red Hat closed its tracking bug for the Intel i915 GPU TLB-flush vulnerability CVE-2022-4139 after issuing fixes across affected RHEL releases and Red Hat Virtualization 4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
21 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.