CVE-2024-36489 affects the Linux kernel TLS subsystem because tls_init() lacked a write memory barrier. On systems permitting store-store reordering, TLS setsockopt or getsockopt operations can observe an uninitialized ctx->sk_proto value and trigger a NULL-pointer dereference, creating an availability risk. Red Hat rates the flaw Low severity, with a product-specific CVSS v3.1 score of 6.1; NVD scores it 5.5.
Upstream fixes are available in Linux kernel versions 5.10.219, 5.15.161, 6.1.93, 6.6.33, 6.9.4, and 6.10-rc1. Red Hat issued errata for affected RHEL 8 and RHEL 9 kernel and kernel-rt streams, including relevant EUS and specialized-support offerings, while RHEL 6 is not affected. Organizations should identify hosts running affected kernel builds and apply the applicable vendor kernel updates.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:5101 and RHSA-2024:5102 to fix affected RHEL 8 kernel and kernel-rt packages.
RHSA-2024:5065 addressed CVE-2024-36489 for RHEL 8.6 Advanced Mission Critical Update Support, SAP Update Services, and Telecommunications Update Service kernel packages.
Red Hat issued RHSA-2024:4823 and RHSA-2024:4831 to fix affected RHEL 9.2 Extended Update Support kernel and kernel-rt packages.
Patrick Del Bello reported the Linux kernel TLS issue, involving a missing write memory barrier in tls_init(). Red Hat published the CVE-2024-36489 record, describing a potential NULL-pointer dereference in TLS setsockopt or getsockopt paths.
Red Hat issued RHSA-2024:6206 to address the vulnerability in the RHEL 8.8 Extended Update Support kernel.
Red Hat released RHSA-2024:5363 to address CVE-2024-36489 in the affected RHEL 9 kernel stream.
Upstream fixes for CVE-2024-36489 were made available in Linux kernel versions 5.10.219, 5.15.161, 6.1.93, 6.6.33, 6.9.4, and 6.10-rc1. The fix uses rcu_assign_pointer() after ctx->sk_proto initialization to provide release-barrier semantics.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.