Red Hat has documented multiple CWE-772 resource-management flaws that can exhaust memory or device references and cause denial of service. In the Linux kernel, CVE-2022-50269 leaks a configuration object if VKMS initialization fails; CVE-2022-50318 leaks PCI-device references in Intel uncore performance-monitoring code; and CVE-2022-50372 leaks a CIFS/SMB session-setup request when NTLMSSP negotiate-blob construction fails. Each kernel issue is rated CVSS 5.5 and requires local, low-privileged access to trigger resource exhaustion.
Fixes are available for affected RHEL kernel packages, including RHEL 8 for the CIFS issue under RHSA-2024:5101, while some RHEL 9 and real-time kernel fixes remain deferred; unsupported branches are generally unaffected where the vulnerable code is absent. Separately, CVE-2024-2398 affects curl/libcurl HTTP/2 server-push handling: a remote server can repeatedly send oversized pushed headers and cause leaked header memory when libcurl aborts the push. Rated CVSS 7.5, that flaw was fixed for affected JBoss Core Services HTTPD 2.4 components on RHEL 7 and 8 in RHSA-2024:2693.

See real exploitation activity before you spend the cycle.
12 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:13960 and RHSA-2025:13961, fixing affected RHEL 8 kernel and kernel-rt updates for CVE-2022-50269.
Red Hat released RHSA-2024:5101, fixing CVE-2022-50372 in the RHEL 8 kernel. The flaw could leak a session-setup request when NTLMSSP negotiate-blob construction failed during a CIFS mount.
Red Hat issued RHSA-2024:2693 to address CVE-2024-2398 in affected JBoss Core Services HTTPD 2.4 components for RHEL 7 and RHEL 8.
Red Hat published CVE-2024-2398, describing a curl/libcurl HTTP/2 server-push header memory leak that a malicious remote server could repeatedly trigger to consume client memory.
Red Hat released RHSA-2023:7077, fixing affected RHEL 8 kernel packages for CVE-2022-50318 and CVE-2022-50269.
Red Hat released RHSA-2023:2951 to fix CVE-2022-50318 in affected Red Hat Enterprise Linux 8 kernel packages.
Red Hat released RHSA-2023:2458, fixing CVE-2022-50318 in affected Red Hat Enterprise Linux 9 kernel packages.
Red Hat published the CVE-2022-50269 record for a VKMS-module memory leak that can lead to local denial of service through memory exhaustion.
Red Hat released RHSA-2025:15670 to fix CVE-2022-50269 in the RHEL 9.0 Update Services for SAP Solutions kernel package.
Red Hat released RHSA-2025:15658 to fix CVE-2022-50269 in the RHEL 9.0 Update Services for SAP Solutions kernel-rt package.
Red Hat released RHSA-2024:2394, providing an additional fix for CVE-2022-50318 in Red Hat Enterprise Linux 9 kernel packages.
RHSA-2023:4789 fixed CVE-2022-50318 in Red Hat Enterprise Linux 8.6 Extended Update Support kernel packages and Red Hat Virtualization 4 for RHEL 8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.