Red Hat released a Moderate-severity kernel update, RHSA-2024:8616, for specified Red Hat Enterprise Linux 8.6 deployments on x86_64 and Power LE (ppc64le). The update delivers kernel version 4.18.0-372.127.1.el8_6 and remediates CVE-2024-40998, an ext4 race in __ext4_fill_super() where sysfs registration could expose a rate-limit setting before ratelimit_state->lock had been initialized. A local low-privileged user could alter the interval during that window and trigger unsafe locking behavior or an availability impact; Red Hat scored the issue 5.5 CVSS v3.1.
The advisory also fixes CVE-2022-48773 in the kernel's xprtrdma RPC-over-RDMA component. Error paths in rpcrdma_ep_create could leave pointers containing error values rather than NULL, allowing rpcrdma_ep_destroy to free invalid pointers and cause a kernel Oops. Organizations using affected RHEL 8.6 kernel packages should install the update and reboot systems to activate the fixes; Red Hat also issued fixes for the ext4 issue across supported RHEL 8 and 9 streams.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:10265 for RHEL 8.4 ELL, AUS, TUS, and SAP update-service offerings, providing kernel version 4.18.0-305.145.1.el8_4. The update fixes CVE-2022-48773 and the MPTCP path-manager use-after-free vulnerability CVE-2024-46858.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for RHEL 8 kernel-rt, fixing the ext4 initialization-order flaw in CVE-2024-40998.
Red Hat released RHSA-2024:8617 for RHEL 9 and RHSA-2024:8613 and RHSA-2024:8614 for RHEL 9.2 Extended Update Support kernel and kernel-rt packages, addressing CVE-2024-40998.
Red Hat issued RHSA-2024:8616 for specified RHEL 8.6 update-service offerings. The kernel update fixed both CVE-2024-40998 and the xprtrdma invalid-pointer error-handling flaw tracked as CVE-2022-48773.
Red Hat released RHSA-2024:8107 to fix CVE-2024-40998 in the RHEL 8.8 Extended Update Support kernel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.