Red Hat released RHSA-2022:5626 for Red Hat Enterprise Linux 8.4 Extended Update Support, delivering kernel 4.18.0-305.57.1.el8_4 for x86_64, s390x, ppc64le, and aarch64. The update remediates six kernel vulnerabilities, including CVE-2022-32250, a netfilter use-after-free write that can enable local root escalation, and CVE-2022-1729, affecting perf_event_open. It also addresses cgroup migration permission handling in CVE-2021-4197, which can let a less-privileged process induce a privileged process to write through an attacker-created file descriptor, and CVE-2021-4203, a socket credential race that can crash the system or disclose kernel information.
Red Hat also issued RHBA-2022:5744 to update Red Hat OpenStack Platform 16.2 container images, incorporating the kernel security fixes for x86_64 and IBM Power ppc64le deployments. Organizations should install the applicable RHEL kernel update and reboot hosts for remediation to take effect; OpenStack Platform users should upgrade the supplied container images and rebuild dependent images.

Get the actors, campaigns, and ATT&CK mapping behind it.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2022:5834 for RHEL 8 Real Time kernel packages, providing kernel-rt 4.18.0-372.19.1.rt7.176.el8_6. The update remediated CVE-2022-32250 and the TCP source-port information-disclosure flaw CVE-2022-1012; affected systems require a reboot.
Red Hat issued RHBA-2022:5744 to update Red Hat OpenStack Platform 16.2 container images for x86_64 and ppc64le with backported fixes for the RHSA-2022:5626 security issues. Users were advised to upgrade the images and rebuild dependent container images.
Red Hat issued Important advisory RHSA-2022:5633 for kernel-rt packages in RHEL 8.4 Extended Update Support Real Time and telecommunications/NFV offerings. Kernel-rt 4.18.0-305.57.1.rt7.129.el8_4 remediated CVE-2021-4197 and CVE-2021-4203 plus four other kernel vulnerabilities; affected systems require a reboot.
Red Hat issued Important advisory RHSA-2022:5626 for RHEL 8.4 Extended Update Support, delivering kernel version 4.18.0-305.57.1.el8_4. The update remediated CVE-2021-4197 and CVE-2021-4203 along with four other kernel vulnerabilities; affected systems require a reboot after installation.
Red Hat issued RHSA-2022:5232 for the RHEL 7 kernel, RHSA-2022:5236 for kernel-rt, and RHSA-2022:5216 for kpatch-patch to remediate the CVE-2022-32250 Netfilter use-after-free vulnerability.
Pablo Neira Ayuso authored and signed off on upstream commit 520778042ccca019f3ffa136dd0ca565c486cedd, which fixes CVE-2022-32250 by validating NFT_STATEFUL_EXPR before expression initialization. The flaw is a netfilter nf_tables use-after-free write that can enable local privilege escalation to root when user and network namespaces can be created.
Red Hat closed its tracking bugs for the cgroup migration permission-check flaw and the socket credential race condition.
Pedro Sampaio reported a Linux kernel sock_getsockopt() use-after-free read caused by races in SO_PEERCRED and SO_PEERGROUPS handling with listen() or connect(). A local user could crash a system or disclose internal kernel information.
A vulnerability in Linux kernel cgroup migration permission checks was reported. The flaw could allow a less-privileged process to induce a more-privileged process to write to a file descriptor it created, potentially enabling local privilege escalation.
Red Hat released RHSA-2021:4356 for RHEL 8 kernel packages and RHSA-2021:4140 for RHEL 8 kernel-rt packages to remediate CVE-2020-29368, a transparent huge page copy-on-write mapcount race condition that can grant unintended write access.
Red Hat issued CVE-2022-32250 fixes for RHEL 7.3, 7.4, and 7.6 Advanced Update Support kernel packages. It also released RHSA-2022:5802 for RHEL 7.6 Telco EUS and SAP Solutions kernels and RHSA-2022:5804 for SAP Solutions kpatch-patch packages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
11 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.