Red Hat released Moderate-severity kernel updates for Red Hat Enterprise Linux 9 and RHEL 9.4 Extended Update Support that remediate CVE-2024-47675, a use-after-free flaw in bpf_uprobe_multi_link_attach(). If bpf_link_prime() fails, an error path can free an array of bpf_uprobe objects without unregistering them, leaving a freed consumer on the uprobe consumer list and leaking the associated uprobe object.
The fix is included in RHSA-2024:10942 for the RHEL 9.4 kernel 5.14.0-427.48.1.el9_4 and RHSA-2024:11486 for RHEL 9. These advisories also address additional kernel flaws affecting components including BPF, Bluetooth, NFS, XFRM, KVM, ARM64 probes, GICv4, and NUMA scheduling across x86_64, ARM64, IBM z, and Power architectures. Organizations should apply the applicable updated kernel packages and reboot systems for remediation to take effect.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:11486, a Moderate-severity RHEL 9 kernel security advisory covering 17 vulnerabilities across Bluetooth, BPF, NFS, ARM64, XFRM, KVM, GICv4, and NUMA scheduler components. The update included a fix for the BPF use-after-free flaw CVE-2024-47675 and required systems to reboot for the updated kernel to take effect.
Red Hat issued RHSA-2024:10942, a Moderate-severity update for the RHEL 9.4 Extended Update Support kernel:5.14.0 module, shipping build 5.14.0-427.48.1.el9_4. It remediated seven kernel vulnerabilities, including CVE-2024-47675, and required affected systems to reboot after installation.
Red Hat documented remediation for CVE-2024-50099, an ARM64 kernel flaw in LDR/LDRSW literal uprobe simulation that could trigger a BUG(), lockup, or kernel panic. The fix rejects uprobes on those instructions and was addressed for RHEL 8, RHEL 9, and RHEL 9.4 EUS through listed RHSA advisories.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.