Red Hat released kernel and live-patch updates for supported Red Hat Enterprise Linux (RHEL) 6, 7, and 8 lifecycle channels to remediate CVE-2021-0920 and CVE-2021-4083. CVE-2021-0920 is a use-after-free flaw in the UNIX-domain socket garbage collector, unix_gc(), that can enable local privilege escalation; CVE-2021-4083 is a related file-descriptor lifetime race in fget() that can leave garbage-collected socket objects reachable and trigger a read-after-free condition.
The fixes were distributed through standard kernel packages and kpatch-patch live-kernel modules for affected Extended Update Support, SAP, telecommunications, virtualization, and Real Time offerings. Several advisories also bundled fixes for other privilege-escalation, use-after-free, information-disclosure, and denial-of-service flaws, including CVE-2021-4028, CVE-2022-0330, CVE-2022-0492, and CVE-2022-22942. Administrators should apply the applicable kernel update and reboot systems where required; deployments using the supplied live-patch modules can receive covered fixes without a conventional reboot.

See real exploitation activity before you spend the cycle.
30 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2022:2189 for RHEL Server Advanced Update Support 7.3 on x86_64, providing kernel 3.10.0-514.101.1.el7. The Important-rated update remediated CVE-2021-4028, CVE-2021-4083, and CVE-2022-0492; affected systems required a reboot.
Red Hat issued RHSA-2022:1418, an Important kpatch-patch live kernel update for RHEL 8.4 EUS, ELL, AUS, TUS, and SAP-related channels. The update remediated CVE-2021-4083, CVE-2022-0492, and CVE-2022-25636 without requiring an immediate reboot.
Red Hat issued RHSA-2022:1417 for RHEL 6 Extended Lifecycle Support, updating the kernel to 2.6.32-754.47.1.el6. The update remediated CVE-2021-0920 alongside CVE-2020-0466, CVE-2021-4155, and CVE-2022-0492.
RHSA-2022:1373 provided a kpatch-patch live update for RHEL 7.7 SAP Solutions and associated AUS/TUS offerings. It fixed CVE-2021-0920, CVE-2021-4083, CVE-2021-4028, and CVE-2022-22942.
RHSA-2022:1324 supplied kernel 3.10.0-1062.66.1.el7 for selected RHEL 7.7 extended-support products. It remediated CVE-2021-0920, CVE-2021-4083, CVE-2021-4028, and CVE-2022-22942.
Red Hat issued RHSA-2022:1199 for RHEL for Real Time 7 and RHEL for Real Time for NFV 7 on x86_64, updating kernel-rt to 3.10.0-1160.62.1.rt56.1203.el7. The Important-rated advisory remediated CVE-2021-4028 and CVE-2021-4083; systems required a reboot after installation.
Red Hat issued RHSA-2022:1198 for supported RHEL 7 Server, Workstation, Desktop, Scientific Computing, ELS, IBM Z, IBM Power, and Red Hat Virtualization Host variants. The Important update supplied kernel 3.10.0-1160.62.1.el7, remediating CVE-2021-4028 and CVE-2021-4083; affected systems required a reboot.
Red Hat issued RHSA-2022:1185 for RHEL 7 Server and Extended Life Cycle Support offerings on x86_64 and ppc64le. The kpatch-patch live update remediated CVE-2021-4083 and the RDMA listen()-path use-after-free CVE-2021-4028 without requiring a kernel reboot.
Red Hat released RHSA-2022:1107 for selected RHEL 7.6 extended-support offerings, including kernel 3.10.0-957.92.1.el7 where applicable. The update fixed CVE-2021-0920, CVE-2021-4083, CVE-2022-0330, and CVE-2022-22942.
Red Hat issued RHSA-2022:1106 for RHEL Server Advanced Update Support 7.3 on x86_64, providing kernel 3.10.0-514.99.1.el7. The Important-rated update remediated CVE-2021-0920 and CVE-2022-0330; affected systems required a reboot.
RHSA-2022:1104 updated the RHEL Server AUS 7.4 kernel to version 3.10.0-693.99.1.el7. It remediated CVE-2021-0920 and CVE-2021-4083 alongside CVE-2020-0466 and CVE-2022-0330.
Red Hat issued RHSA-2022:1103, a kpatch-patch update for selected RHEL 7.6 offerings. The live patch fixed CVE-2021-0920 and CVE-2021-4083, as well as CVE-2022-0330 and CVE-2022-22942.
RHSA-2022:0958 updated the kpatch-patch-4_18_0-147_58_1 module for RHEL 8.1 Update Services for SAP Solutions. The advisory remediated CVE-2021-0920 and CVE-2021-4083, plus five other Linux kernel vulnerabilities.
Red Hat issued RHSA-2022:0925, a kpatch-patch update for RHEL 8.2 EUS and associated support channels. The live patch addressed CVE-2021-4083 along with CVE-2022-0330, CVE-2022-0492, and CVE-2022-22942.
RHSA-2022:0851 provided a kpatch-patch update for RHEL 8.1 Update Services for SAP Solutions on x86_64 and ppc64le. It fixed CVE-2021-0920, CVE-2021-4083, and four other kernel vulnerabilities.
Red Hat issued RHSA-2022:0849, a kpatch-patch update for supported RHEL 8 x86_64 and ppc64le offerings. The live patch remediated CVE-2021-0920 and five other kernel vulnerabilities.
RHSA-2022:0825 delivered kernel 4.18.0-348.20.1.el8_5 for supported RHEL 8 offerings and fixed CVE-2021-0920 among eight vulnerabilities. Red Hat required affected systems to reboot after installation.
Red Hat issued RHSA-2022:0823 for RHEL 8.1 Update Services for SAP Solutions, providing kernel 4.18.0-147.64.1.el8_1. The update remediated both CVE-2021-0920 and CVE-2021-4083, among other vulnerabilities.
RHSA-2022:0820 updated RHEL 8.2 EUS and related channels to kernel 4.18.0-193.79.1.el8_2. The Critical-impact update fixed CVE-2021-4083 and four additional kernel vulnerabilities.
RHSA-2022:0777 supplied kernel version 4.18.0-305.40.1.el8_4 for RHEL 8.4 EUS and associated channels, remediating CVE-2021-0920 and other kernel vulnerabilities. A reboot was required for the standard kernel update to take effect.
Red Hat issued RHSA-2022:0772, a kpatch-patch live update for RHEL 8.4 EUS and related channels. It addressed CVE-2021-0920 along with CVE-2021-4028, CVE-2022-0330, CVE-2022-0435, and CVE-2022-22942.
RHSA-2022:0771 updated the Real Time Linux Kernel for selected RHEL 8.4 Extended Update Support offerings to kernel-rt 4.18.0-305.40.1.rt7.112.el8_4, including a fix for CVE-2021-0920.
Red Hat released RHSA-2022:0592, RHSA-2022:0620, and RHSA-2022:0622 for RHEL 7 kernel, kernel-rt, and kpatch-patch packages, remediating CVE-2021-0920.
Red Hat issued RHSA-2022:0636 for RHEL 8.2 update channels, providing kernel-4.18.0-193.75.1.el8_2. The Important-rated update remediated CVE-2021-0920, CVE-2021-4028, and CVE-2021-4155; affected systems required a reboot.
Red Hat issued RHSA-2022:0629 for RHEL 8.2 Extended Update Support real-time deployments, updating kernel-rt to 4.18.0-193.75.1.rt13.125.el8_2. The update fixed CVE-2021-0920, CVE-2021-4028, and CVE-2021-4155.
Red Hat remediated the RDMA CM listener use-after-free vulnerability CVE-2021-4028 in Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 through RHSA-2022:1263.
Red Hat closed its tracking bug for CVE-2021-4083 after issuing updates across affected RHEL lifecycle variants and Red Hat Virtualization products.
Red Hat closed its CVE-2021-0920 tracking bug, noting that future product-specific updates would be reflected on its CVE page.
Upstream Linux addressed CVE-2021-4083 in commit 054aa8d439b9. The AF_UNIX garbage-collection race could cause a read-after-free when a file descriptor was closed before fget() completed its reference acquisition.
Upstream Linux remediated CVE-2021-0920, a use-after-free condition in unix_gc() where MSG_PEEK could violate garbage collection's external-reference assumptions, in commit cbcf01128d0a92e131bd09f1688fe032480b65ca.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
29 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.