Red Hat updated the rhel8/go-toolset and OpenShift Dev Spaces devspaces/udi-rhel8 container images to incorporate Linux kernel security fixes from RHSA-2024:10943. The updates remediate multiple kernel flaws affecting RHEL 8, including CVE-2024-46695, a permission-check bypass in the SELinux and Smack inode_setsecctx path, alongside information-disclosure, crash, race-condition, dangling-pointer, network-stack, and ARM64 uprobe issues.
CVE-2024-46695 could allow a root user on an NFS client to alter security labels on files in an NFS export despite root squashing, because the vulnerable code bypassed required Linux Security Module permission checks. The kernel fix restores enforcement by replacing __vfs_setxattr_noperm() with __vfs_setxattr_locked(). Red Hat advised customers to upgrade affected container images, update image references in Dockerfiles and automation, and rebuild dependent images; updated Dev Spaces images are available for x86_64, ppc64le, and s390x.

Get the actors, campaigns, and ATT&CK mapping behind it.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.