Red Hat released Important Linux-kernel updates for RHEL 8, RHEL 9, and RHEL 8.1 Update Services for SAP Solutions to address CVE-2022-32250, a netfilter nf_tables use-after-free write that a local attacker could exploit to gain root privileges. The advisories also remediate CVE-2022-1012, in which predictable TCP source-port generation can allow a network observer to fingerprint hosts, infer traffic patterns, and estimate outbound connections. RHEL 9 updates additionally address CVE-2022-1729, a perf_event_open race condition permitting privilege escalation, and an IPsec ESP buffer-overflow flaw.
Affected administrators should install the applicable updated kernel packages and reboot systems for the fixes to take effect; RHEL 8 version 4.18.0-372.19.1.el8_6 was provided for supported variants and x86_64, aarch64, ppc64le, and s390x architectures. The updates also include stability and performance corrections affecting dm-integrity, SR-IOV, SCTP, asymmetric TCP routing, and virtual-machine booting. Tracking for the netfilter flaw should use CVE-2022-32250: CVE-2022-1966 was rejected as a duplicate. Red Hat notes RHEL 7 is not affected by CVE-2022-1012 because it uses a different TCP port-selection algorithm.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2022:6073 for RHEL 7.7 AUS, TUS, and Update Services for SAP Solutions, remediating the netfilter use-after-free privilege-escalation flaw CVE-2022-32250. The advisory provided kernel version 3.10.0-1062.68.1.el7 and required systems to reboot after installation.
Red Hat issued RHSA-2022:5805 for RHEL Server Advanced Update Support 7.4 on x86_64, remediating the netfilter use-after-free privilege-escalation vulnerability CVE-2022-32250. The update supplied kernel version 3.10.0-693.104.1.el7 and required systems to reboot after installation.
Red Hat issued RHSA-2022:5802 for RHEL 7.6 AUS, TUS, and SAP Solutions offerings, fixing the netfilter use-after-free privilege-escalation flaw CVE-2022-32250. The advisory supplied kernel version 3.10.0-957.95.1.el7 and required affected systems to reboot after installation.
Red Hat released RHSA-2022:5834 to fix CVE-2022-1012 in the RHEL 8 kernel-rt package.
Red Hat issued an Important RHEL 8 kernel update, version 4.18.0-372.19.1.el8_6, addressing CVE-2022-1012 and CVE-2022-32250 across supported architectures and product variants. The update also contained multiple kernel bug fixes and required a reboot.
Red Hat issued RHEL 8.4 Extended Update Support kernel and kernel-rt fixes through RHSA-2022:5626 and RHSA-2022:5633 for the affected kernel vulnerabilities.
RHSA-2022:5636 provided an Important kernel update for RHEL 8.1 Update Services for SAP Solutions on x86_64 and ppc64le. It remediated CVE-2022-1012, CVE-2022-1729, and CVE-2022-32250 and required a reboot after installation.
Red Hat released RHEL 9 kernel-rt and kpatch-patch updates for the affected vulnerabilities, including CVE-2022-1012 and CVE-2022-32250.
Red Hat issued an Important RHEL 9 kernel update addressing CVE-2022-1012, CVE-2022-1729, the netfilter use-after-free issue, and CVE-2022-27666, alongside reliability and performance fixes. Administrators were instructed to reboot after installation.
Red Hat released RHEL 8.2 Extended Update Support kernel and kernel-rt updates that addressed CVE-2022-1012 and the netfilter use-after-free flaw tracked as CVE-2022-32250.
Red Hat issued kernel, kernel-rt, and kpatch-patch fixes for RHEL 7 addressing the netfilter use-after-free vulnerability tracked as CVE-2022-32250 (formerly CVE-2022-1966).
Red Hat designated CVE-2022-1966 as a rejected candidate because it duplicated CVE-2022-32250, the identifier for the Linux netfilter/nf_tables use-after-free vulnerability.
Red Hat released an RHEL 8.2 EUS kpatch-patch update, RHEL 9 kernel update, and Red Hat Virtualization 4 for RHEL 7 update addressing the netfilter use-after-free flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.