Red Hat released Important RHEL 8 kernel and kernel-rt updates that remediate CVE-2022-2873, an out-of-bounds memory-access flaw in the Intel iSMT SMBus driver; CVE-2022-41222, a use-after-free race in mm/mremap.c; and CVE-2022-43945, an NFS server buffer overflow triggered by malformed RPC-over-TCP traffic. CVE-2022-2873 can be triggered locally through the I2C_SMBUS ioctl with block-data input and can crash the system, while CVE-2022-41222 can leave stale TLB entries during concurrent memory operations.
RHSA-2023:0832 provides kernel version 4.18.0-425.13.1.el8_7 for supported RHEL 8 architectures, including x86_64, aarch64, ppc64le, and s390x. RHSA-2023:0854 supplies 4.18.0-425.13.1.rt7.223.el8_7 for supported RHEL 8 Real Time, NFV, telecommunications, and Extended Life Cycle deployments. Administrators should install the applicable updated packages and reboot affected systems to activate the fixes.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2023:0839 for RHEL 8, providing kpatch-patch live updates that remediate CVE-2022-41222 and CVE-2022-43945. The package automatically loads a live kernel patch for supported x86_64 and ppc64le RHEL 8 channels without requiring a conventional reboot.
Red Hat issued an Important kernel-rt update for RHEL 8 that fixed CVE-2022-2873, CVE-2022-41222, and CVE-2022-43945. The advisory provided kernel-rt build 4.18.0-425.13.1.rt7.223.el8_7 for supported x86_64 offerings.
Red Hat issued an Important RHEL 8 kernel update containing fixes for CVE-2022-2873, CVE-2022-41222, and CVE-2022-43945. The update supplied kernel version 4.18.0-425.13.1.el8_7 and required a reboot to take effect.
Red Hat released an Important kpatch-patch update for RHEL 9.0 EUS and SAP Update Services. It remediated CVE-2022-1158, CVE-2022-2639, CVE-2022-2959, and CVE-2022-43945.
Red Hat reported tracking bug 2138818 for CVE-2022-41222, a high-severity use-after-free vulnerability involving a race between an rmap walk and mremap operation that can leave stale TLB entries.
Zheyu Ma submitted a patch to fix an out-of-bounds memory-access flaw in the Intel iSMT SMBus driver's ismt_access() block-write path. The patch rejects user-supplied SMBus block lengths below 1 or above I2C_SMBUS_BLOCK_MAX with -EINVAL.
Red Hat closed bug 2138818 for CVE-2022-41222 after addressing the flaw through RHEL 8, RHEL 8.6 EUS, and Red Hat Virtualization 4 advisories.
Red Hat closed its tracking bug for CVE-2022-2873 after issuing fixes for affected RHEL 8, RHEL 9, and RHEL 8.6 Extended Update Support products.
Red Hat issued RHSA-2023:5627 to fix CVE-2022-2873 in the RHEL 8.6 Extended Update Support kernel and the Red Hat Virtualization 4 for RHEL 8 kernel.
Red Hat remediated CVE-2022-2873 in supported RHEL 9 kernel packages through RHSA-2023:0951 and in RHEL 9 kernel-rt packages through RHSA-2023:0979. Both advisories were issued on February 28, 2023.
A subsequent upstream commit to address the i2c-ismt block-length validation issue was applied by the Linux 6.0-rc4 release-candidate cycle.
Fedora fixed CVE-2022-2873, an out-of-bounds memory-access flaw in the Intel iSMT SMBus driver, through its 5.17.13 stable kernel updates.
Fedora fixed the Linux kernel mm/mremap.c use-after-free vulnerability CVE-2022-41222 in its 5.12.18 stable kernel updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.