Red Hat released Moderate-severity kernel updates for RHEL 9.2 servicing streams, including Extended Update Support, Update Services for SAP Solutions, and Extended Life Cycle offerings, to remediate CVE-2024-25744 and CVE-2023-52628. CVE-2024-25744 allows an untrusted virtual-machine monitor to trigger int80 system-call handling at arbitrary points in affected Linux kernels, impacting Intel TDX confidential-computing and AMD memory-encryption-related code; upstream fixed it in Linux 6.6.7.
CVE-2023-52628 is a four-byte out-of-bounds stack write in netfilter/nftables extended-header processing, with potential remote reachability requiring environment-specific validation. RHSA-2024:2845 supplies kernel version 5.14.0-284.66.1.el9_2 for supported RHEL 9.2 architectures, while RHSA-2024:2846 provides the real-time kernel 5.14.0-284.66.1.rt14.351.el9_2 for affected x86_64 deployments; administrators must reboot after installing the updates.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2024:2846 for the RHEL 9.2 Real Time kernel packages. The kernel-rt 5.14.0-284.66.1.rt14.351.el9_2 update fixes CVE-2024-25744 and CVE-2023-52628 on affected x86_64 systems.
Red Hat issued Moderate-severity advisory RHSA-2024:2845 for RHEL 9.2 servicing streams, providing kernel 5.14.0-284.66.1.el9_2. The update remediates both CVE-2024-25744 and CVE-2023-52628, and requires a reboot after installation.
The Linux kernel CVE team assigned CVE-2023-52628 to a netfilter/nftables extended-header flaw involving a four-byte out-of-bounds stack write.
The Linux kernel issue later tracked as CVE-2024-25744 and Red Hat Bugzilla 2263875 was reported. It allows an untrusted VMM to trigger int80 system-call handling at arbitrary points in affected confidential-computing and memory-encryption code paths.
Upstream Linux kernel version 6.6.7 fixed CVE-2024-25744, with the fix associated with commit b82a8dbd3d2f4563156f7150c6f2ecab6e960b30. Fedora also received the remediation through its 6.6.7 stable-kernel updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.