Red Hat released RHSA-2024:9942, a Moderate-severity kernel update for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. The update delivers kernel version 5.14.0-70.121.1.el9_0 and addresses four CVEs, including CVE-2022-48796, an IOMMU device-probe race that can trigger a use-after-free when deferred probing accesses a freed dev->iommu structure.
The advisory also fixes CVE-2024-26671, a blk-mq sbitmap wakeup race that can cause I/O hangs and affect availability, as well as an MPTCP path-manager use-after-free (CVE-2024-46858) and CVE-2022-49270. Administrators running affected RHEL 9.0 SAP Solutions Update Services systems should install the updated kernel and reboot hosts to activate the fixes.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2024:9942 and RHSA-2024:9943 for RHEL 9.0 Update Services for SAP Solutions. RHSA-2024:9942 updated kernel packages to 5.14.0-70.121.1.el9_0 and addressed CVE-2024-26671, CVE-2022-48796, and CVE-2024-46858; affected systems require a reboot.
Red Hat released RHSA-2024:2950 for RHEL 8 kernel-rt and RHSA-2024:3138 for RHEL 8 kernel, addressing the blk-mq sbitmap wakeup race.
Red Hat issued RHSA-2024:2394 to fix the blk-mq I/O-hang race in Red Hat Enterprise Linux 9 kernels.
Red Hat published its CVE record for CVE-2024-26671, a moderate Linux kernel blk-mq sbitmap wakeup race that can cause I/O hangs and affect availability.
Red Hat addressed the IOMMU device-probe use-after-free vulnerability through RHSA-2024:6297 for RHEL 8.6 Advanced Mission Critical Update Support, SAP Solutions Update Services, and Telecommunications Update Service.
Red Hat issued RHSA-2024:10262 to fix CVE-2024-26671 in the RHEL 8.8 Extended Update Support kernel.
Red Hat issued RHSA-2024:8613 for the RHEL 9.2 Extended Update Support kernel and RHSA-2024:8614 for kernel-rt, fixing CVE-2024-26671.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.