Multiple Vulnerabilities in Red Hat Enterprise Linux Components
Multiple vulnerabilities in corosync, libevent, and libsoup within Red Hat Enterprise Linux could allow attackers to execute arbitrary code, bypass security controls, disclose data, or cause denial-of-service.
CVE search metadata
CVE search record: CVE-2024-50602. Severity: medium. CVSS: 5.9. EPSS: 1.03%. KEV: no. Product: Enterprise Linux (RHEL), Enterprise Linux. Brief: Multiple Vulnerabilities in Red Hat Enterprise Linux Components. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rhel-vulnerabilities/
What's new
- 1. added coverage for Enterprise Linux Sep 18, 13:14 via bsi
The German Federal Office for Information Security (BSI) has reported multiple security vulnerabilities affecting specific software components within the Red Hat Enterprise Linux (RHEL) ecosystem. The affected packages include corosync, libevent, and libsoup. These vulnerabilities, tracked under CVE-2024-50602, CVE-2024-50604, and CVE-2024-50605, present varying levels of risk depending on the implementation. Potential impacts of successful exploitation range from arbitrary code execution and security control bypass to unauthorized data manipulation, data disclosure, and the induction of denial-of-service conditions. Organizations utilizing these RHEL components should prioritize patching to mitigate potential exposure, as these libraries are fundamental to various cluster and network-related operations on Linux systems.
Impact
Successful exploitation of these vulnerabilities could result in full system compromise, sensitive data exposure, or significant service disruption within enterprise environments. Given the nature of these core libraries, the impact is applicable across various RHEL-based infrastructures, including those supporting high-availability clusters and network-intensive applications.
Recommendation
Prioritized actions for security operations and IT teams:
- Review the official Red Hat Security Advisories for the specific patch releases corresponding to CVE-2024-50602, CVE-2024-50604, and CVE-2024-50605.
- Apply security patches to all RHEL systems running the affected packages (corosync, libevent, and libsoup) immediately to remediate the vulnerability.
- Implement monitoring for abnormal service behavior or unauthorized process execution associated with cluster services or network-facing applications linked against these libraries.
Immediate actions
Patch affected RHEL systems to latest versions provided by Red Hat for CVE-2024-50602, CVE-2024-50604, and CVE-2024-50605.
Mitigations
Upgrade corosync, libevent, and libsoup packages to versions validated by Red Hat.
CVE-2024-50602, CVE-2024-50604, CVE-2024-50605