Red Hat released Important Linux kernel and real-time kernel updates across RHEL 7, 8, and 9, including Extended Update Support, AUS, Telecommunications Update Service, NFV, SAP, and virtualization-related variants. The updates address CVE-2022-1729, a perf_event_open() race condition through which an unprivileged local user can gain kernel exploit primitives and potentially escalate to root; netfilter use-after-free flaws including CVE-2022-32250/CVE-2022-1966 that can enable root escalation; and CVE-2022-1012, which weakens TCP source-port randomization and can expose connection-pattern information and enable persistent fingerprinting. RHEL 9 updates also remediate CVE-2022-27666, a buffer overflow in IPsec ESP transformation handling.
Affected organizations should deploy the applicable Red Hat kernel packages, including kernel-rt-5.14.0-70.17.1.rt21.89.el9_0 for RHEL 9 Real Time, kernel-rt-4.18.0-193.87.1.rt13.137.el8_2 for RHEL 8.2 Real Time EUS, and 3.10.0-514.104.1.el7 for RHEL 7.3 AUS. Red Hat also issued an RHEL 8.4 real-time EUS update covering earlier DNS cache-poisoning and security-regression issues alongside the IPsec vulnerability. Administrators must reboot systems after installation for the patched kernels to take effect.

See real exploitation activity before you spend the cycle.
25 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2022:6432, an Important Linux kernel security and bug-fix update for selected RHEL 7.6 AUS, TUS, and SAP support offerings. Kernel version 3.10.0-957.97.1.el7 remediated CVE-2022-1729 and a POSIX ACL object leak; affected systems require a reboot.
Red Hat issued an Important kernel update for RHEL Server Advanced Update Support 7.3 on x86_64. The update fixed CVE-2022-1729 and the netfilter use-after-free privilege-escalation flaw CVE-2022-32250.
Red Hat issued Important advisory RHSA-2022:5476 for RHEL 8.2 EUS, AUS, TUS, and Update Services for SAP Solutions. The kpatch-patch live update remediated CVE-2022-1966 and CVE-2022-27666 on x86_64 and ppc64le without a conventional reboot.
Red Hat issued RHSA-2022:5316, an Important Linux kernel security and bug-fix update for supported RHEL 8 deployments. Kernel version 4.18.0-372.13.1.el8_6 remediated CVE-2022-27666 and CVE-2020-28915; affected systems require a reboot.
Red Hat issued Important advisory RHSA-2022:5344 for RHEL 8 Real Time and Real Time for NFV, providing kernel-rt 4.18.0-372.13.1.rt7.170.el8_6. The update fixed the IPsec ESP buffer overflow CVE-2022-27666 and fbcon_get_font out-of-bounds read CVE-2020-28915; affected systems require a reboot.
Red Hat issued Important security advisory RHSA-2022:5219, providing a kpatch-patch live kernel module for supported RHEL 8 x86_64 and ppc64le product channels. The update remediated the Linux kernel IPsec ESP buffer-overflow vulnerability CVE-2022-27666 without requiring a conventional reboot.
Red Hat issued Important security advisory RHSA-2022:5214, providing a kpatch-patch live-kernel update for RHEL 9 on x86_64 and ppc64le. The live patch remediated CVE-2022-1012, CVE-2022-1966, and CVE-2022-27666 without requiring a conventional reboot.
Red Hat issued Important security advisory RHSA-2022:5232 for Red Hat Enterprise Linux 7, providing kernel version 3.10.0-1160.71.1.el7 where applicable. The update remediated CVE-2022-1729 and CVE-2022-1966, along with CVE-2022-32250 and several kernel bug fixes.
Red Hat issued an Important kernel-rt update for RHEL 9 x86_64, including extended-support and SAP product streams. The release fixed CVE-2022-1012, CVE-2022-1729, CVE-2022-1966, and CVE-2022-27666.
Red Hat released an Important Linux kernel update for RHEL 9 and CodeReady Linux Builder 9. It remediated CVE-2022-1012, CVE-2022-1729, CVE-2022-1966, and CVE-2022-27666.
Red Hat issued an Important kernel-rt update for RHEL 7 Real Time and Real Time for NFV on x86_64. The update fixed CVE-2022-1729 and CVE-2022-1966.
Red Hat released an Important kernel-rt update for RHEL 8.2 Extended Update Support Real Time product streams. It addressed CVE-2022-1012, CVE-2022-1729, CVE-2022-1966, CVE-2022-27666, and CVE-2020-29368.
Red Hat issued an Important Linux kernel security and bug-fix update for RHEL 8.2 extended-support, update-service, SAP, and CodeReady Linux Builder channels. The kernel-4.18.0-193.87.1.el8_2 update addressed CVE-2022-1012, CVE-2022-1729, CVE-2022-1966, CVE-2022-27666, CVE-2020-29368, CVE-2021-47435, and CVE-2022-32250.
Red Hat issued Important advisory RHSA-2022:5157 for RHEL Server Advanced Update Support 7.4 on x86_64. Kernel version 3.10.0-693.103.1.el7 remediated local privilege-escalation flaws CVE-2022-0492 and CVE-2022-1729; affected systems require a reboot.
Red Hat issued Important security advisory RHSA-2022:4942 for RHEL 8.1 Update Services for SAP Solutions on x86_64 and ppc64le. The kpatch live-patch update remediated the Linux kernel IPsec ESP buffer-overflow vulnerability CVE-2022-27666 without requiring a conventional reboot.
Red Hat issued Important security advisory RHSA-2022:4924 for RHEL 8.1 Update Services for SAP Solutions on x86_64 and ppc64le. Kernel version 4.18.0-147.67.1.el8_1 remediated the IPsec ESP buffer-overflow vulnerability CVE-2022-27666 and required a reboot to activate.
Red Hat issued RHSA-2022:4809 for the RHEL 8.4 Extended Update Support kpatch-patch package, remediating the Linux kernel IPsec ESP heap-based buffer overflow CVE-2022-27666.
Red Hat issued an Important kernel-rt update for RHEL 8.4 Extended Update Support, fixing CVE-2021-20322, CVE-2021-4037, and the IPsec ESP buffer overflow CVE-2022-27666.
Red Hat created tracking bugs 2089288 and 2089289 for CVE-2022-1729 in Fedora 34 and Fedora 35, respectively.
Marian Rehak described CVE-2022-1729, a race condition in the Linux kernel perf_event_open() interface that can allow an unprivileged local user to escalate privileges to root.
Guilherme de Almeida Suckevicz reported CVE-2020-29368, a race condition in the Transparent Huge Pages mapcount check in __split_huge_pmd that could grant unintended write access through the Linux kernel copy-on-write implementation. The issue affected kernels before 5.7.5 and was fixed upstream in commit c444eb564fb16645c172d550359cb3d75fe8a040.
Red Hat closed bug 1899177 for CVE-2020-28915, the Linux framebuffer-console fbcon_get_font() out-of-bounds read vulnerability. The flaw could allow a specially privileged local attacker to crash a system or disclose internal kernel information.
Red Hat issued RHSA-2022:6741 to fix CVE-2022-1729 in RHEL 7.7 Advanced Update Support, Telco Extended Update Support, and Update Services for SAP Solutions.
Red Hat closed its bug record for the Linux kernel IPsec ESP heap buffer overflow CVE-2022-27666, directing further product-specific update information to the CVE record page.
Red Hat closed its tracking bugs for CVE-2022-1012 and CVE-2022-1729, directing subsequent product-specific information to the relevant CVE records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
27 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.