Red Hat released Important kernel updates for RHEL 7 and RHEL for Real Time 7, delivering 3.10.0-1160.21.1.el7 and 3.10.0-1160.21.1.rt56.1158.el7 respectively. The advisories remediate 11 vulnerabilities, including arbitrary backing-store writes through the LIO SCSI target implementation (CVE-2020-28374), a Netfilter conntrack buffer overflow (CVE-2020-25211), virtual-terminal and pinctrl use-after-free information disclosures (CVE-2020-25656, CVE-2020-0427), and a local memory-exhaustion denial of service (CVE-2021-20265).
The fixes also address an ICMP rate-limiting weakness that can enable off-path UDP-port inference and DNS cache poisoning (CVE-2020-25705), as well as flaws reachable through malicious USB devices, including HID-driver out-of-bounds writes (CVE-2019-19532). Organizations operating affected RHEL 7, extended-support, virtualization-host, and real-time deployments should install the applicable kernel packages and reboot systems; where patching is delayed, restricting exposure to untrusted USB hardware, LIO exports, and unnecessary Netfilter conntrack-netlink access can reduce risk.

See real exploitation activity before you spend the cycle.
37 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2021:2355, an Important Linux kernel update for supported RHEL 7.6 extended-support channels. It fixed CVE-2019-19532, CVE-2020-25211, and CVE-2020-25705, among other kernel defects.
Red Hat issued RHSA-2021:2185 for RHEL 8.2 Extended Update Support and related service channels, providing kernel-4.18.0-193.56.1.el8_2. The update remediated CVE-2020-0466, CVE-2020-12362, CVE-2020-28374, and the mountpoint reference-counter denial-of-service flaw CVE-2020-12114.
Red Hat issued RHSA-2021:2190 for RHEL 8.2 Extended Update Support Real Time and Real Time for NFV Telecommunications Update Service deployments. The kernel-rt update fixed CVE-2020-0466, CVE-2020-12362, CVE-2020-28374, and CVE-2020-12114 in version 4.18.0-193.56.1.rt13.106.el8_2.
Red Hat issued RHSA-2021:2099, an Important kpatch-patch update for RHEL 8.1 EUS and SAP Solutions systems on x86_64 and ppc64le. The live kernel patch remediated CVE-2020-0466, CVE-2020-28374, and CVE-2021-3347.
Red Hat issued RHSA-2021:2106 for RHEL 8.1 Extended Update Support and selected SAP Solutions offerings. The update fixed CVE-2020-0466, CVE-2020-12362, CVE-2020-28374, and CVE-2021-3347 in kernel version 4.18.0-147.48.1.el8_1.
Red Hat closed its tracking bug for the pivot_root mountpoint reference-counter denial-of-service vulnerability CVE-2020-12114 after addressing it for Red Hat Enterprise Linux 8 through RHSA-2021:1578 and RHSA-2021:1739. The flaw can allow a suitably privileged attacker to corrupt a mountpoint reference counter and trigger a kernel panic.
Red Hat issued RHSA-2021:1377 for RHEL 7.6 live-kernel patch deployments, remediating CVE-2021-27364, an out-of-bounds read in libiscsi, and CVE-2021-27365, a heap buffer overflow in the Linux iSCSI subsystem, in addition to CVE-2020-28374.
Red Hat issued RHSA-2021:1288 for the RHEL 6 Extended Lifecycle Support kernel, addressing CVE-2020-29661 and the related local privilege-escalation and denial-of-service risk.
Red Hat remediated CVE-2021-27363 in RHEL 7 kernel-rt through RHSA-2021:1070 and in RHEL 8 kernel-rt through RHSA-2021:1081. The Linux iSCSI driver flaw could allow a low-privileged local attacker to disclose a kernel transport-handle address or terminate arbitrary iSCSI connections.
Red Hat closed its tracking record for CVE-2021-27364 after issuing libiscsi out-of-bounds-read fixes for supported RHEL 6, 7, and 8 releases and extended-support streams. The flaw in drivers/scsi/libiscsi.c can be triggered through send_pdu; Red Hat advised disabling automatic libiscsi loading where iSCSI is unnecessary as a temporary mitigation.
Red Hat closed its tracking bug for CVE-2021-27365, a heap buffer overflow in the Linux iSCSI subsystem caused by oversized iSCSI string attributes. The closure followed remediation through advisories for affected RHEL 6, 7, and 8 releases and extended-support channels.
Red Hat issued RHSA-2021:1070 for RHEL 7 kernel-rt and RHSA-2021:1069 for the RHEL 7 kpatch-patch package, remediating CVE-2021-27364, an out-of-bounds read in the Linux libiscsi module that can expose kernel memory or crash the system.
Red Hat issued RHSA-2021:1093, an Important security advisory providing an updated RHEL 8 kernel. The update remediated eight vulnerabilities, including CVE-2020-0466, CVE-2020-27152, CVE-2020-28374, CVE-2021-3347, CVE-2021-26708, and iSCSI flaws CVE-2021-27363 through CVE-2021-27365.
Red Hat issued RHSA-2021:0940 for the RHEL 7.6 Extended Update Support kpatch-patch stream, remediating the tty_jobctrl use-after-free vulnerability CVE-2020-29661.
Red Hat issued RHSA-2021:0862, an Important kpatch-patch security update for RHEL 7 and ELS deployments on x86_64 and ppc64le. The live kernel patch remediated the SCSI LIO arbitrary backing-store block-write flaw CVE-2020-28374 and the tty_jobctrl use-after-free flaw CVE-2020-29661.
Red Hat issued RHSA-2021:0857, an Important kernel-rt update for RHEL for Real Time 7 and Real Time for NFV 7. The update addressed the same set of kernel flaws, including CVE-2020-25656, CVE-2020-28374, CVE-2020-29661, and CVE-2021-20265.
Red Hat issued RHSA-2021:0856, an Important RHEL 7 kernel update containing fixes for 11 vulnerabilities, including CVE-2019-19532, CVE-2020-25211, CVE-2020-25656, CVE-2020-25705, CVE-2020-28374, CVE-2020-29661, and CVE-2021-20265.
Red Hat published the CVE-2021-27365 record for an Important-severity heap-based buffer overflow in the Linux iSCSI subsystem, reported by Adam Nichols of GRIMM. A low-privileged local attacker could trigger the flaw by writing an iSCSI string attribute exceeding one page and then reading it.
Red Hat issued RHSA-2021:0537 for RHEL 8 kernel-rt, addressing CVE-2020-25705, whose global ICMP rate-limit counter can provide an off-path DNS-poisoning side channel.
Red Hat issued RHSA-2021:0558 for the RHEL 8 kernel, fixing CVE-2020-14351, a perf-subsystem use-after-free flaw that a local user permitted to monitor perf events could potentially exploit to corrupt memory and elevate privileges.
Dhananjay Arunesh reported CVE-2021-26708, a high-severity race-condition vulnerability caused by incorrect locking in the Linux kernel's VMware VSOCK implementation (net/vmw_vsock/af_vsock.c). An upstream fix was published in commit c518adafa39f37858697ac9309c6cf1805581446.
Pedro Sampaio reported CVE-2021-3347, a use-after-free flaw in Linux kernel priority-inheritance futex handling that may permit code execution. An upstream fix was published in kernel commit c64396cc36c6e60704ab06c1fb1c4a46179c9120.
Dhananjay Arunesh reported CVE-2021-20265, in which improper memory freeing in unix_stream_recvmsg when a signal is pending can let an unprivileged local user exhaust memory and crash a Linux system.
Fedora pushed advisories FEDORA-2020-98ccae320c and FEDORA-2020-e211716d08 to the Fedora 33 and Fedora 32 stable repositories, respectively, to address CVE-2020-25656.
A proposed Linux kernel mailing-list patch addressed CVE-2020-25656, a virtual-terminal race between KDGKBSENT and KDSKBSENT ioctl operations that causes a use-after-free read.
Prasad Pandit reported CVE-2020-27152, in which erroneous KVM IRQ-state handling can cause an infinite loop and host-kernel stack overflow; a guest user could crash the host. Disabling APICv mitigates the issue, and an upstream patch was subsequently provided in commit 77377064c3a94911339f13ce113b3abf265e06da.
Fedora released advisories FEDORA-2020-5920a7a0b2 and FEDORA-2020-3c6fedeb83 for Fedora 31 and 32, addressing the Netfilter conntrack-netlink buffer-overflow vulnerability CVE-2020-25211.
Red Hat issued errata addressing the Intel GuC firmware integer-overflow flaw CVE-2020-12362 for RHEL 8, RHEL 8 EUS, RHEL 7 and its support channels, and RHEL 6 Extended Lifecycle Support. Remediation required both updated linux-firmware and kernel packages; exposure generally required explicitly enabling Intel GuC firmware loading.
Red Hat issued RHSA-2024:3138 for the RHEL 8 kernel and RHSA-2024:2950 for the RHEL 8 kernel-rt packages, fixing the virtual-terminal use-after-free vulnerability CVE-2020-25656.
Red Hat issued RHSA-2021:4356 for the RHEL 8 kernel and RHSA-2021:4140 for RHEL 8 kernel-rt, addressing CVE-2020-0427, a local pinctrl use-after-free/out-of-bounds-read flaw.
Red Hat issued RHSA-2021:2732 to address CVE-2020-28374 in RHEL 7.4 Advanced Update Support, Telco Extended Update Support, and SAP Update Services kernel packages.
Red Hat issued RHSA-2021:2164 for RHEL 7.4 Advanced Update Support, Telco Extended Update Support, and SAP Update Services streams, addressing CVE-2020-25705 and CVE-2020-29661.
Red Hat issued RHSA-2021:1531 for RHEL 7.7 update-service channels, fixing CVE-2019-19532, CVE-2020-25211, CVE-2020-25705, and CVE-2020-28374, along with three iSCSI vulnerabilities.
Red Hat issued RHSA-2021:1376 and RHSA-2021:1377 for RHEL 7.6 Extended Update Support kernel and kpatch-patch packages, addressing the SCSI LIO arbitrary backing-store block-write vulnerability CVE-2020-28374.
Red Hat issued additional advisories for CVE-2020-14351 across RHEL 8.1 and 8.2 Extended Update Support and RHEL 7.3, 7.4, 7.6, and 7.7 support streams, including RHSA-2021:0686, :0765, :0774, :0848, :0878, :1028, and :1267. The perf-subsystem use-after-free flaw could permit memory corruption and possible local privilege escalation when an attacker has access to perf events.
Red Hat released RHSA-2021:0354 for Red Hat Enterprise Linux 7 to remediate CVE-2020-29661, a tty_jobctrl locking flaw that could allow a local attacker to corrupt kernel memory or escalate privileges.
Andrey Konovalov disclosed 15 syzkaller-found Linux kernel USB-subsystem vulnerabilities, including use-after-free flaws, out-of-bounds writes, information leaks, and a race condition. The issues could be triggered by a malicious physically connected USB device and had already been fixed upstream.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceseclists.org
Open sourceopenwall.com
Open sourceopenwall.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.