Red Hat released RHEL 8 kernel security updates through RHSA-2022:1975 for Real Time Linux and RHSA-2022:1988 for related RHEL 8 packages, remediating numerous kernel vulnerabilities affecting memory safety, privilege boundaries, networking, USB, eBPF, denial of service, information disclosure, and speculative execution. Notable fixes include CVE-2021-3612, an out-of-bounds write in joystick ioctl handling; CVE-2021-3759, which could bypass memory-cgroup accounting and crash a host; CVE-2021-3743, an out-of-bounds read in the QRTR protocol handler; and CVE-2021-3773, involving Netfilter behavior that could affect certain OpenVPN NAT deployments.
Affected Real Time, NFV, Telecommunications Update Service, and Extended Life Cycle RHEL 8 x86_64 systems should update to kernel-rt-4.18.0-372.9.1.rt7.166.el8 or a later applicable package and reboot. Red Hat also refreshed Quarkus 2.7, CodeReady Workspaces 2.0, and rhpam-kogito-builder-rhel8 container images that incorporate the kernel fixes; organizations using those images should pull the updated versions, update Dockerfile or build-script references, and rebuild dependent images.

See real exploitation activity before you spend the cycle.
27 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHBA-2022:4969, updating the rhpam-7/rhpam-kogito-builder-rhel8 image with security fixes referenced by RHSA-2022:1988. The advisory directed users to obtain the updated registry image, amend Dockerfile references, and rebuild dependent images.
Red Hat released RHBA-2022:4693 for CodeReady Workspaces 2.0 RHEL Server x86_64 container images, incorporating security fixes referenced in RHBA-2022:4630. Red Hat advised users to upgrade images, update Dockerfiles or scripts, and rebuild dependent images.
Red Hat issued RHBA-2022:2229, updating Red Hat build of Quarkus 2.7 RHEL 8 x86_64 container images with backported security fixes referenced by RHSA-2022:1988. Users were instructed to pull updated images, update image references, and rebuild dependent images.
Red Hat closed Bug 2061721 for CVE-2022-0002, an Intel intra-mode Branch Target Injection vulnerability that can transiently execute disclosure gadgets through aliased indirect-branch predictor entries. RHEL 8 remediation was provided through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat closed Bug 1997467 for CVE-2021-3764, a medium-severity memory-leak denial-of-service flaw in the AMD CCP cryptographic driver's ccp_run_aes_gcm_cmd() error path. RHEL 8 was addressed through RHSA-2022:1975 and RHSA-2022:1988; upstream commit 505d9dcb0f7d contains the fix.
Red Hat closed Bug 2016169 for CVE-2020-13974, an integer-overflow issue in the Linux virtual-terminal keyboard driver's k_ascii() function that can be triggered by repeated calls. RHEL 8 was addressed through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat closed its tracking bug for CVE-2021-0941, an out-of-bounds memory-access flaw in the Linux kernel's __bpf_skb_max_len logic associated with bpf_skb_change_head(). The flaw could allow a specially privileged local attacker to crash the system or disclose kernel information; RHEL 8 fixes were provided through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat closed Bug 2025003 for CVE-2021-43976, a medium-severity denial-of-service flaw in the Marvell mwifiex USB wireless driver's mwifiex_usb_recv() function. Crafted USB devices with an unknown recv_type could trigger the issue; RHEL 8 fixes were provided through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat closed Bug 2000694 for CVE-2021-3772, a medium-severity Linux SCTP flaw that lets a blind attacker using spoofed packets terminate an existing SCTP association. RHEL 8 was addressed through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat closed Bug 2000627 for CVE-2021-3744, a medium-severity memory-resource leak in the Linux kernel CCP crypto driver's ccp_run_aes_gcm_cmd() error paths that can enable denial of service through memory consumption. RHEL 8 was addressed through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat closed its tracking bug for CVE-2021-43389, an array-index-out-of-bounds flaw in the Linux kernel CAPI ISDN detach_capi_ctr() function that can occur when detaching an unattached registered controller. RHEL 8 was addressed through RHSA-2022:1975 and RHSA-2022:1988; the previously assigned CVE-2021-3896 was rejected as a duplicate.
Red Hat closed Bug 1919791 for CVE-2020-0404, a medium-severity Linux UVC chain-scanning flaw in which malformed USB descriptors can create cyclic entity chains. RHEL 8 fixes were provided through RHSA-2022:1975 and RHSA-2022:1988; Red Hat advised preventing the uvcvideo module from loading as a mitigation before patching.
Red Hat closed its tracking bug for CVE-2021-4002, a medium-severity Linux kernel flaw caused by a missing TLB flush when unmapping PMD pages that could leak or corrupt huge-page data, including hugetlbfs data. RHEL 8 was addressed through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat closed Bug 2034342 for CVE-2021-4157, a medium-severity Linux kernel decode_nfs_fh() size-check flaw that can overwrite two bytes beyond the destination buffer. RHEL 8 fixes were supplied through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat closed Bug 1901726 for CVE-2020-27820, a low-severity use-after-free flaw in the Linux Nouveau driver's postclose handler that could be triggered by a privileged local user or through physical graphics-device removal. The issue was addressed for RHEL 8 through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat closed Bug 2010463 for CVE-2021-41864, an eBPF stackmap allocation-size integer overflow that can cause an out-of-bounds write. The issue was addressed for RHEL 8 through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat closed its tracking bug for CVE-2020-4788, a speculative-execution side-channel issue affecting IBM POWER9 processors. The issue was addressed for Red Hat Enterprise Linux 8 through RHSA-2022:1988.
Red Hat's Product Security DevOps Team closed the bug associated with CVE-2021-3773 after RHEL 8 fixes were made available through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat closed its tracking bug for CVE-2021-3743 after addressing the QRTR out-of-bounds-read vulnerability for RHEL 8 through RHSA-2022:1975 and RHSA-2022:1988.
Red Hat closed its tracking bug for CVE-2021-3612, a Linux joystick ioctl flaw that could cause an out-of-bounds memory write and kernel panic when malformed JSIOCSBTNMAP input is supplied.
Red Hat released RHEL 8 kernel and kernel-rt fixes for CVE-2021-47556 through RHSA-2022:1988 and RHSA-2022:1975. The ethtool coalesce-settings ioctl flaw can trigger a NULL pointer dereference and local denial-of-service crash.
Red Hat published Important advisory RHSA-2022:1975 for RHEL 8 kernel-rt, providing kernel-rt-4.18.0-372.9.1.rt7.166.el8 and fixes for numerous Linux kernel CVEs, including CVE-2021-3612, CVE-2021-3743, CVE-2021-3759, and CVE-2021-3773. Affected systems were required to reboot after installing the update.
The OpenVPN/Netfilter issue tracked as CVE-2021-3773 was publicly referenced on the Openwall oss-security mailing list. The flaw could enable denial of service, client deanonymization, or redirection to an attacker-controlled server in applicable NAT deployments.
Red Hat closed its tracking bug for CVE-2021-29154, a Linux kernel eBPF JIT branch-displacement flaw that could allow a local user with root or CAP_SYS_ADMIN privileges to escalate privileges. Red Hat noted that RHEL 7 and RHEL 8 fixes were provided through RHSA-2021:3327, RHSA-2021:3328, RHSA-2022:1975, and RHSA-2022:1988.
Dhananjay Arunesh reported CVE-2021-3743, an out-of-bounds read caused by a missing sanity check in the Linux kernel's QRTR qrtr_endpoint_post function. The flaw could allow local kernel-memory disclosure or a system crash.
Red Hat closed its tracking bug for CVE-2021-43056, a PowerPC KVM denial-of-service flaw in which a local user can confuse host offline code and cause a KVM guest to crash. Fedora was tracked as affected, and RHEL 8 was remediated through RHSA-2022:1988; the upstream fix is commit cdeb5d7d890e14f3b70e8087e745c4a6a7d9f337.
Red Hat closed its tracking bug for CVE-2021-4037, an XFS file-creation regression that could let a local user create files with unintended group ownership, group-execute permissions, and SGID bits in writable SGID directories. RHEL 8 fixes were delivered through RHSA-2022:1975 and RHSA-2022:1988.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
32 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.