Red Hat released important updates for RHEL 8 Real Time and Red Hat Virtualization Host 4 to remediate seven Linux kernel vulnerabilities, including CVE-2021-4154 and CVE-2022-0435. CVE-2021-4154 is a use-after-free flaw in the cgroup v1 parser’s handling of fsconfig parameters that a local attacker can use for privilege escalation, container escape, or denial of service. The affected Real Time update is kernel-rt 4.18.0-348.20.1.rt7.150.el8_5; Red Hat Virtualization Host 4 received version 4.4.10, along with updated host-release packages.
CVE-2022-0435 affects the kernel’s TIPC networking module and can remotely trigger a stack overflow and kernel panic on systems using TIPC, causing denial of service. In configurations lacking effective stack protections, the issue could potentially lead to remote code execution when an attacker can obtain a stack canary. The virtualization advisory also addresses a Cyrus SASL flaw that could permit arbitrary SQL-command execution. Organizations running affected RHEL 8, Real Time, NFV, extended-support, or Red Hat Virtualization deployments should apply the applicable updates and reboot systems, particularly where containers or TIPC are enabled.

See real exploitation activity before you spend the cycle.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2022:1589 for RHEL 8.1 Update Services for SAP Solutions, providing kernel version 4.18.0-147.65.1.el8_1 for x86_64 and Power LE systems. The update remediated the CVE-2022-0435 TIPC stack-overflow vulnerability and required a reboot.
Red Hat issued Important advisory RHSA-2022:1186, providing a kpatch-patch live kernel module for supported RHEL 8.2 EUS, AUS, TUS, and SAP Solutions channels. The live patch remediated the CVE-2022-0435 TIPC remote stack-overflow vulnerability without a traditional reboot-based kernel update.
Red Hat issued Important advisory RHSA-2022:1213 for RHEL 8.2 Extended Update Support and associated update channels. Kernel version 4.18.0-193.80.1.el8_2 remediated CVE-2022-0435, CVE-2020-8647, and CVE-2020-8649; affected systems required a reboot.
Red Hat issued Important advisory RHSA-2022:1209 for RHEL 8.2 Extended Update Support Real Time Telecommunications and NFV offerings. Kernel-rt version 4.18.0-193.80.1.rt13.130.el8_2 remediated CVE-2022-0435, CVE-2020-8647, and CVE-2020-8649; affected systems required a reboot.
A comment noted that the not-yet-built CentOS Stream 8 kernel-4.18.0-373.el8 appeared to lack the CVE-2022-0435 fix according to its changelog, despite the related tracking bug being closed.
Red Hat closed its bug tracking CVE-2022-0435 after issuing fixes across affected RHEL 8 variants and Red Hat Virtualization 4.
Red Hat issued Important advisory RHSA-2022:0819 for RHEL 8 Real Time kernel packages. The update supplied kernel-rt 4.18.0-348.20.1.rt7.150.el8_5 and remediated seven kernel flaws, including CVE-2021-4154 and CVE-2022-0435.
Red Hat issued RHSA-2022:0771 and RHSA-2022:0772 for RHEL 8.4 Extended Update Support, updating kernel-rt and kpatch-patch packages to remediate the Linux kernel TIPC stack-overflow flaw CVE-2022-0435.
Marian Rehak described CVE-2022-0435, a remote stack-overflow vulnerability in the Linux kernel TIPC networking module that can trigger a kernel panic and denial of service on affected systems.
Red Hat issued Important advisory RHSA-2022:0231, supplying a kpatch-patch live-update module for supported RHEL 8.4 channels. The update remediated CVE-2021-4154, CVE-2021-4155, and CVE-2022-0185 without requiring a conventional reboot.
Red Hat issued Important advisory RHSA-2022:0187 for Real Time Linux Kernel packages on RHEL 8.4 Extended Update Support variants. The kernel-rt 4.18.0-305.34.2.rt7.107.el8_4 update remediated CVE-2021-4154, CVE-2021-4155, and CVE-2022-0185; affected systems required a reboot after installation.
Red Hat closed its bug record for CVE-2022-0185, the Linux kernel Filesystem Context legacy_parse_param heap-overflow vulnerability, after issuing updates for affected RHEL 8, RHEL 8.4 EUS, and Red Hat Virtualization 4 products.
Red Hat Product Security DevOps closed the bug for CVE-2021-4154, a Linux kernel cgroup v1 parser use-after-free issue that could enable local privilege escalation, container escape, or denial of service.
Red Hat issued Important advisory RHSA-2022:0841 for Red Hat Virtualization Host 4 on RHEL 8, delivering version 4.4.10. The update addressed kernel vulnerabilities including CVE-2021-4154 and CVE-2022-0435, as well as the Cyrus SASL SQL-command-execution flaw CVE-2022-24407.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.