Red Hat released Important kernel updates for RHEL 7 and RHEL for Real Time 7 that remediate nine vulnerabilities, including use-after-free, double-free, out-of-bounds-write, information-disclosure, and local privilege-escalation flaws. The fixes include CVE-2021-3752, a Bluetooth lock_sock_nested() use-after-free condition that a local user could potentially trigger to gain partial privilege escalation. Updated packages are kernel-3.10.0-1160.59.1.el7 for RHEL 7 and kernel-rt-3.10.0-1160.59.1.rt56.1200.el7 for the real-time variant, covering supported x86_64, IBM Z, IBM Power, and related RHEL 7 deployments.
Administrators should install the updates published in RHSA-2022:0620 and RHSA-2022:0622 and reboot affected hosts, as the kernel fixes do not take effect until restart. Red Hat also updated the 3scale-amp2/system-rhel7 container image through RHBA-2022:0679 to incorporate the RHEL 7 security fixes; 3scale API Management users should upgrade that image and rebuild dependent container images.

See real exploitation activity before you spend the cycle.
19 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHBA-2022:0740 updating the 3scale-amp2/3scale-rhel7-operator-metadata container image for Red Hat 3scale API Management Platform 2 on RHEL 7. The image incorporated fixes referenced by RHBA-2022:0679, including CVE-2021-3752, and users were advised to upgrade and rebuild dependent images.
Red Hat issued RHBA-2022:0690 updating the devtools/go-toolset-rhel7 container image for Red Hat Developer Tools. The image incorporated backported fixes from RHSA-2022:0620, including CVE-2021-3752, and users were advised to upgrade and rebuild dependent images.
Red Hat issued RHBA-2022:0679, updating the 3scale-amp2/system-rhel7 container image for Red Hat 3scale API Management Platform 2. The image addressed the kernel security issues covered by RHSA-2022:0620, including CVE-2021-3752; users were advised to upgrade and rebuild dependent images.
Red Hat issued Important advisory RHSA-2022:0622 for RHEL for Real Time 7 and its NFV variant, providing kernel-rt 3.10.0-1160.59.1.rt56.1200.el7. The update addressed CVE-2021-3752 and eight other kernel vulnerabilities and required systems to be rebooted.
Red Hat issued Important advisory RHSA-2022:0620 for RHEL 7, supplying kernel version 3.10.0-1160.59.1.el7. The update remediated CVE-2021-3752 alongside eight other kernel vulnerabilities; affected systems require a reboot.
Marian Rehak described CVE-2022-22942, in which a failed usercopy of a fence_rep object can leave a stale file-descriptor-table entry and allow user space to access a dangling file object. The condition can enable use-after-free exploitation scenarios.
Red Hat issued Important advisory RHSA-2021:3987 for RHEL 7.7 AUS, TUS, and SAP Solutions channels, providing kernel version 3.10.0-1062.59.1.el7. The update fixed six vulnerabilities, including CVE-2019-20934, CVE-2020-36385, CVE-2021-22543, CVE-2021-3653, CVE-2021-3656, and CVE-2021-37576; affected systems require a reboot.
Red Hat issued Important advisory RHSA-2021:3812 for RHEL 7.6 AUS, TUS, and SAP Solutions offerings, supplying kernel version 3.10.0-957.84.1.el7. The update fixed CVE-2021-22543, CVE-2021-22555, CVE-2021-3653, CVE-2021-3656, and CVE-2021-37576; affected systems require a reboot.
Red Hat issued Important advisory RHSA-2021:3801 for RHEL 7, providing kernel version 3.10.0-1160.45.1.el7 where applicable. The update fixed four KVM vulnerabilities—CVE-2021-22543, CVE-2021-37576, CVE-2021-3653, and CVE-2021-3656—and required affected systems to reboot.
Guilherme de Almeida Suckevicz reported CVE-2021-37576 in the PowerPC KVM RTAS implementation in arch/powerpc/kvm/book3s_rtas.c. A PowerPC KVM guest user could trigger host memory corruption through guest syscalls, threatening VM isolation; upstream fixed the issue in commit f62f3c20647ebd5fb6ecb8f0b477b9281c44c10a.
Red Hat addressed the Linux fair-scheduler use-after-free CVE-2019-20934 for RHEL 7 through advisories RHSA-2021:2725 and RHSA-2021:2726. The flaw affects NUMA fault-statistics handling in show_numa_stats() and may disclose kernel information to userspace.
Red Hat documented that inadequate validation of an L1 guest-supplied VMCB int_ctl field in AMD SVM nested virtualization can let an L1 guest enable AVIC for an L2 guest. The issue may allow L2 access to host physical memory, host crashes, data disclosure, or guest-to-host escape; it was introduced by commit 3d6368ef580a and fixed upstream in commit 0f923e07124df069ba68d8bb12324398f4b6b709.
Red Hat tracked CVE-2020-0465, an out-of-bounds write in the Linux kernel's hid-multitouch.c component that may lead to local privilege escalation.
A logic error in the Linux kernel's do_epoll_ctl and ep_loop_check_proc eventpoll paths can cause a use-after-free condition tracked as CVE-2020-0466. The flaw may enable local privilege escalation without additional execution privileges or user interaction; upstream fixes were published in commits a9ed4a6560b8562b7e2e2bed9527e88001f7b682 and 52c479697c9b73f628140dcdfcd39ea302d05482.
Red Hat closed its Bugzilla record tracking CVE-2021-3752 after fixes had been made available through the documented kernel advisories.
Red Hat documented that improper validation of an L1 guest-supplied VMCB virt_ext field in AMD SVM nested virtualization could let an L2 guest execute VMLOAD/VMSAVE without required interception. The issue could permit host-memory reads or writes, host crashes, sensitive-data disclosure, or a potential guest-to-host escape; upstream fixed it in commit c7dfa4009965a9b2d7b329ee970eb8da0d32f0bc.
Debian included the Bluetooth use-after-free fix in Linux package 5.10.84-1, and Fedora addressed the issue through its 5.15.3 stable-kernel updates.
Wang ShaoBo's fix, "Bluetooth: fix use-after-free error in lock_sock_nested()," was merged into Linux kernel 5.15 as commit 1bff51ea59a9afb67d2dd78518ab0582a54a472c.
KMSAN reported a use-after-free in the Linux Bluetooth subsystem's lock_sock_nested() path during the l2cap_chan_timeout workqueue handler on a Linux 5.12.0-rc6+ kernel in a QEMU virtual machine. The flaw, tracked as CVE-2021-3752, may allow a local user to partially escalate privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
16 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.