Red Hat released Moderate-severity RHEL 8 kernel updates 4.18.0-348.el8 and real-time kernel updates 4.18.0-348.rt7.130.el8 to remediate numerous Linux kernel vulnerabilities across eBPF, networking, Bluetooth, filesystems, device drivers, memory handling, and wireless components. The advisories affect standard RHEL 8 deployments across x86_64, ARM64, IBM Z, and Power little-endian, as well as RHEL for Real Time, Real Time for NFV, related telecommunications editions, and specified x86_64 Extended Life Cycle offerings.
Among the fixed issues is CVE-2020-36158, a buffer overflow in the Marvell mwifiex Wi-Fi driver’s mwifiex_cmd_802_11_ad_hoc_start function. A sufficiently privileged local attacker could trigger the flaw with an overly long SSID while creating an ad-hoc wireless network, potentially achieving arbitrary code execution; affected upstream kernels extend through version 5.10.4. Organizations should apply RHSA-2021:4356 or RHSA-2021:4140 as applicable and reboot systems to activate the patched kernel; blacklisting the mwifiex module is a mitigation where immediate patching is not possible.

See real exploitation activity before you spend the cycle.
42 events from the most recent confirmed update back to the earliest known activity.
Red Hat closed its record for CVE-2021-29155, an eBPF verifier flaw that lets CAP_SYS_ADMIN users bypass speculative out-of-bounds-load protections and potentially infer kernel-memory contents through a side channel. RHEL 8 addressed the flaw through RHSA-2021:4140 and RHSA-2021:4356; unprivileged BPF restrictions mitigate exposure for unprivileged users.
Red Hat closed its tracking record for CVE-2021-31916, a low-severity out-of-bounds write in the Linux device-mapper driver's list_devices function that requires CAP_SYS_ADMIN to exploit. The issue was fixed upstream and addressed for RHEL 8 through RHSA-2021:4140 and RHSA-2021:4356.
Red Hat closed its record for CVE-2021-23133, a Linux SCTP socket use-after-free caused by a race condition in SCTP handling that could permit local privilege escalation. Red Hat advised preventing the SCTP module from loading and noted that RHEL 8 fixes were issued through RHSA-2021:4140 and RHSA-2021:4356.
Red Hat issued RHSA-2021:4356, a Moderate-security update for the RHEL 8 kernel, delivering version 4.18.0-348.el8 across supported architectures and product variants. It fixed numerous Linux-kernel issues spanning eBPF, Wi-Fi, Bluetooth, networking, filesystems, and drivers, including CVE-2020-36158; a reboot was required.
Red Hat issued RHSA-2021:4140, a Moderate-severity security and bug-fix update for RHEL 8 kernel-rt, delivering version 4.18.0-348.rt7.130.el8. The update remediated numerous kernel vulnerabilities, including CVE-2020-36158 in the Marvell mwifiex driver, and required affected systems to reboot.
Guilherme de Almeida Suckevicz reported CVE-2020-36386, a slab out-of-bounds read in the Linux Bluetooth function hci_extended_inquiry_result_evt(). The issue affects kernel versions before 5.8.1 and was fixed upstream in commit 51c19bf3d5cfaa66571e4b88ba2a6f6295311101.
Guilherme de Almeida Suckevicz reported CVE-2021-3573, a use-after-free in the Linux kernel's hci_sock_bound_ioctl() function. The flaw can corrupt kmalloc-8k kernel heap memory and potentially enable further exploitation.
Guilherme de Almeida Suckevicz reported CVE-2021-3564, a medium-severity Linux Bluetooth flaw where failed HCI device initialization can trigger a double-free memory-corruption condition. Fedora fixed the issue in stable Linux kernel version 5.12.10, and Red Hat later addressed it in RHEL security advisories.
Dhananjay Arunesh reported CVE-2020-26141 to Red Hat, involving the Linux Wi-Fi implementation failing to verify the TKIP Message Integrity Check on fragmented frames. An attacker within wireless range could inject an unauthenticated control-packet fragment.
Upstream Linux wireless patches were published for CVE-2020-26147, in which Wi-Fi implementations reassemble fragmented frames even if some fragments were transmitted in plaintext. The flaw can allow packet injection or exfiltration of selected fragments when WEP, CCMP, or GCMP confidentiality protocols protect fragmented frames.
An upstream Linux wireless patch was published for CVE-2020-26140, in which Linux Wi-Fi implementations can accept plaintext data frames on protected networks. The flaw could let an attacker inject arbitrary data frames regardless of the network configuration; Fedora remediated it through stable Linux kernel 5.12.9 updates.
Guilherme de Almeida Suckevicz documented CVE-2021-31829, in which privileged eBPF programs can bypass speculative-pointer protections to leak kernel-stack data through a side channel. The disclosed data can include kernel addresses that weaken KASLR; RHEL's default disabling of unprivileged eBPF limits exploitation to root or CAP_SYS_ADMIN users until patched.
Guilherme de Almeida Suckevicz reported CVE-2021-29646, an improper validation of data sizes in the Linux kernel TIPC function tipc_nl_retrieve_key(). The medium-severity issue affects kernels before 5.11.11; it was fixed upstream and later addressed for RHEL 8 through RHSA-2021:4140 and RHSA-2021:4356.
Red Hat opened a tracking issue for CVE-2021-3348, a use-after-free read in the Linux Network Block Device driver's nbd_queue_rq() caused by a race in an NBD ioctl operation. The flaw can crash a system and requires a privileged local user with access to an NBD device under the default configuration.
Red Hat issued Important advisory RHSA-2020:1353 for Red Hat Enterprise MRG Realtime 2 kernel-rt packages on x86_64. The update delivered kernel-rt version 3.10.0-693.65.1.rt56.663.el6rt, fixing the Marvell mwifiex heap overflow CVE-2019-14816 and the Realtek rtlwifi buffer overflow CVE-2019-17666; affected systems must reboot after installation.
Red Hat issued Important advisory RHSA-2020:0328 for RHEL 8 kernel-rt packages, including kernel-rt-4.18.0-147.5.1.rt24.98.el8_1 for affected x86_64 systems. The update fixed Marvell mwifiex flaws CVE-2019-14814, CVE-2019-14815, CVE-2019-14816, CVE-2019-14895, and CVE-2019-14901, the Realtek rtlwifi flaw CVE-2019-17666, and incomplete fixes CVE-2019-14898 and CVE-2019-19338; Red Hat instructed customers to reboot.
Red Hat released RHSA-2020:0375 for Red Hat Enterprise Linux 7 kernel-rt packages, remediating the CVE-2019-14816 heap-based buffer overflow in the Marvell mwifiex Wi-Fi driver. The flaw could be exploited by an attacker on the same physical Wi-Fi network to crash a system or potentially execute arbitrary code.
Red Hat issued Important advisory RHSA-2020:0374 for RHEL 7 kernel packages, including kernel-3.10.0-1062.12.1.el7 for applicable variants, and instructed customers to reboot after installation. The update fixed Marvell mwifiex flaws CVE-2019-14816, CVE-2019-14895, and CVE-2019-14901, plus CVE-2019-17133 and the incomplete CVE-2019-11599 race-condition fix tracked as CVE-2019-14898.
Red Hat issued Important advisory RHSA-2020:0204 for the RHEL 8.0 Update Services for SAP Solutions kernel, providing version 4.18.0-80.15.1.el8_0 for x86_64 and ppc64le. The update remediated 12 CVEs, including KNOB, Marvell mwifiex flaws CVE-2019-10126 and CVE-2019-14816, Intel side-channel issues, and KVM and NFS vulnerabilities; systems require a reboot.
Red Hat addressed CVE-2019-14895, a heap-based buffer overflow in mwifiex_process_country_ie() triggered by country-setting information supplied by a remote Wi-Fi access point during connection negotiation. The flaw could crash affected systems or potentially permit code execution; fixes were issued across RHEL 8, multiple RHEL 7 support channels, and Red Hat Enterprise MRG 2.
Qize Wang publicly disclosed multiple remotely reachable heap-overflow conditions in mwifiex_process_tdls_action_frame() when parsing crafted TDLS setup frames, including unchecked supported-rate and extended-supported-rate lengths. The disclosure credited Wangqize and Huawen of VenusTech ADLab and referenced an upstream Linux kernel patch.
Dhananjay Arunesh reported CVE-2019-14901, a high-severity heap overflow in the Marvell mwifiex driver's mwifiex_process_tdls_action_frame() function. A remote attacker could send a TDLS setup request or response with an EID_SUPP_RATES element longer than 32 to crash a vulnerable system or potentially execute arbitrary code.
Red Hat issued RHSA-2019:3055 for the RHEL 7 kernel and RHSA-2019:3089 for the RHEL 7 Real Time kernel, remediating CVE-2019-10126. The flaw is a heap-based buffer overflow in the Marvell mwifiex wireless implementation that a malicious access point could exploit when a system connects.
Red Hat issued Important advisory RHSA-2019:3076 updating the kpatch-patch live kernel patch module for supported RHEL 7 x86_64 and ppc64le systems. The update provided live fixes for CVE-2018-20856, CVE-2019-3846, CVE-2019-9506 (KNOB), and CVE-2019-10126.
Red Hat issued the Important RHSA-2019:2741 security and bug-fix update for RHEL 8 kernel-rt packages, delivering version 4.18.0-80.11.1.rt9.156.el8_0. The update remediated CVE-2019-3846 and four other kernel flaws affecting KVM, FUSE, and brcmfmac; administrators were instructed to reboot after installation.
Red Hat issued Important security and bug-fix advisory RHSA-2019:2703 for the RHEL 8 Linux kernel. The update fixed seven vulnerabilities, including CVE-2019-3846, CVE-2019-3887, CVE-2019-9500, CVE-2019-11487, CVE-2019-12817, CVE-2018-19824, and CVE-2019-9503; Red Hat instructed administrators to reboot after installation.
An upstream Linux wireless patch fixed CVE-2019-14816, a heap-based buffer overflow in the Marvell Wi-Fi driver's mwifiex_update_vs_ie() processing of vendor-specific information attributes. A nearby attacker on the same Wi-Fi network could crash a vulnerable system and potentially execute arbitrary code.
Huangwen of Venustech ADLab disclosed CVE-2019-14815, a heap-based buffer overflow in mwifiex_set_wmm_params() caused by copying a Microsoft WMM information element into a fixed-size buffer without validating its length. A local user could trigger the flaw through crafted netlink-supplied data to crash a system or potentially execute arbitrary code; a proposed wireless patch series was submitted.
Marian Rehak reported CVE-2019-14814, a heap overflow in the Marvell mwifiex driver's mwifiex_set_uap_rates() function. A local attacker with CAP_NET_ADMIN could corrupt memory and cause denial of service, with possible code execution also noted.
An upstream Linux wireless patch was submitted for CVE-2019-3846, a heap overflow in mwifiex_update_bss_desc_with_ie(). A nearby attacker operating a malicious or impersonated Wi-Fi access point could crash a vulnerable Marvell Wi-Fi device or potentially execute arbitrary code when it attempts to connect.
Red Hat documented CVE-2018-19824, a use-after-free in the Linux ALSA USB-audio driver's usb_audio_probe() function that can be triggered by a malicious USB sound device reporting zero interfaces. Exploitation requires physical access and the ability to execute software on the host, and may allow local privilege escalation; the issue was fixed upstream in commit 5f8cf712582617d523120df67d392059eaf2fc4b and remediated for RHEL 8 through RHSA-2019:2703.
Red Hat documented CVE-2019-17666, a kernel-memory-corruption flaw in the Realtek rtlwifi driver's Wi-Fi Direct Notice of Absence frame handling, where an unchecked attacker-controlled length can cause a buffer overflow. A nearby attacker could crash or potentially compromise a device with Wi-Fi Direct enabled; Red Hat remediated the issue across RHEL 6, 7, and 8 channels and Red Hat Enterprise MRG 2.
Red Hat closed its record for CVE-2021-28971, in which mishandling of PEBS status in intel_pmu_drain_pebs_nhm can let a userspace application using performance counters crash affected Haswell systems. The issue was fixed upstream in commit d88d05a9e0b6d9356e97129d4ff9942d765f46ea and addressed for RHEL 8 through RHSA-2021:4140 and RHSA-2021:4356.
Red Hat closed its tracking record for CVE-2020-24503, an insufficient-access-control flaw in certain Intel Ethernet E810 proprietary Linux drivers before version 1.0.4. An authenticated local user could potentially disclose information; RHEL 8 addressed the issue through RHSA-2021:4140 and RHSA-2021:4356.
Red Hat tracked CVE-2020-24504, an uncontrolled resource-consumption vulnerability in Intel Ethernet E810 Adapter drivers before version 1.0.4 that could allow an authenticated local user to cause a denial of service. Red Hat stated that the issue appears to affect Intel's proprietary driver rather than the upstream Linux ice driver and addressed it for RHEL 8 through RHSA-2021:4140 and RHSA-2021:4356.
Red Hat documented CVE-2021-3679, in which a stale value used by rb_per_cpu_empty() can trap tracing_read_pipe() in an unkillable infinite event-polling loop. Exploitation requires control of tracefs, such as root or CAP_SYS_ADMIN; the issue was fixed upstream in commit 67f0d6d9883c13174669f88adac4f0ee656cc16a and addressed in RHEL 8 through RHSA-2021:4140 and RHSA-2021:4356.
Red Hat documented CVE-2021-3659, a denial-of-service flaw in the Linux IEEE 802.15.4 LR-WPAN link-layer security code where failed AEAD cipher-handle allocation can cause a NULL-pointer dereference. The issue was fixed upstream in commit 1165affd484889d4986cf3b724318935a0b120d8 and was addressed for RHEL 8 in RHSA-2021:4140 and RHSA-2021:4356.
Red Hat documented CVE-2021-20194, a heap overflow in __cgroup_bpf_run_filter_getsockopt() affecting certain Linux BPF and cgroup configurations. The flaw could enable denial of service or possible local privilege escalation; Red Hat recommended disabling unprivileged BPF and noted RHEL 8 disables it by default.
Red Hat issued RHSA-2020:1493 to remediate CVE-2019-14901 in the RHEL 7 kernel-alt variant. The Marvell mwifiex TDLS heap overflow can be exploited by an adjacent-network attacker to crash a vulnerable system or potentially execute code as root.
Red Hat released RHSA-2020:1016 for Red Hat Enterprise Linux 7 kernel packages, remediating CVE-2019-14814. The Marvell mwifiex_set_uap_rates() heap-based buffer overflow could allow a local attacker with CAP_NET_ADMIN or administrative privileges to corrupt memory, cause denial of service, or potentially execute code.
Red Hat addressed CVE-2019-17133, a kernel-stack buffer overflow in cfg80211_mgd_wext_giwessid triggered when a system joins a Wi-Fi network advertising an overlong ESSID. Beyond RHSA-2020:0374, fixes were issued for RHEL 6, RHEL 7 EUS/AUS/SAP/Telco variants, and Red Hat Enterprise MRG 2; Fedora had fixed the issue in stable kernel 5.3.8 updates.
Red Hat released RHSA-2020:0174, remediating the CVE-2019-3846 Marvell mwifiex Wi-Fi heap-based buffer overflow in the RHEL 7 kernel-alt variant.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
49 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcelore.kernel.org
Open sourceopenwall.com
Open sourceseclists.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.