Red Hat released Important kernel and kernel-rt updates across multiple Red Hat Enterprise Linux streams to fix CVE-2025-68183, a Linux kernel flaw in the Integrity Measurement Architecture (IMA) that can clear the IMA_DIGSIG flag when non-IMA extended attributes are changed. The bug can cause a valid file signature stored in security.ima to be replaced with an IMA hash after changes to attributes such as security.selinux, security.evm, or ACLs, particularly on systems using IMA and EVM in fix mode and workflows such as rpm-plugin-ima. Red Hat rates the issue Moderate with a CVSS v3 score of 7.1 and maps it to CWE-354.
The fix was shipped through multiple advisories covering RHEL 8, RHEL 8 kernel-rt, RHEL 9.2, RHEL 9.4, RHEL 9.6 EUS, RHEL 9.2 kernel-rt, and RHEL 10, alongside other kernel vulnerability remediations. Notable package versions include 5.14.0-284.179.1.el9_2, 5.14.0-427.136.1.el9_4, 5.14.0-570.127.1.el9_6, and 5.14.0-284.179.1.rt14.464.el9_2; Red Hat said affected systems must be rebooted after applying the updates for the fixes to take effect.

See real exploitation activity before you spend the cycle.
12 events from the most recent confirmed update back to the earliest known activity.
Red Hat released Important advisory RHSA-2026:21745 for Red Hat Enterprise Linux 8 kernel-rt packages, fixing CVE-2025-68183 along with other kernel flaws. The advisory covered Real Time and related RHEL 8 offerings and required a reboot.
Red Hat issued Important advisory RHSA-2026:21706 for Red Hat Enterprise Linux 8 kernel packages and included a fix for CVE-2025-68183. The update applied across multiple RHEL 8 architectures and variants and required a reboot.
Red Hat released Important advisory RHSA-2026:21557 for Red Hat Enterprise Linux 10 kernel packages, including a fix for CVE-2025-68183. The update covered multiple RHEL 10 variants and required a reboot after installation.
An upstream advisory for CVE-2025-68183 was published on the linux-cve-announce list. The issue was described as an IMA flaw where non-IMA xattr changes could clear the IMA_DIGSIG flag and lead to a signature being replaced with a hash.
Red Hat's CVE entry states that RHSA-2026:47633 fixed CVE-2025-68183 for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On kernel packages. The same date is also noted as the last modification date of Red Hat's CVE page.
Red Hat's CVE entry states that RHSA-2026:40760 fixed CVE-2025-68183 for Red Hat Enterprise Linux 8.8 Telecommunications Update Service and 8.8 Update Services for SAP Solutions kernel packages. This expanded coverage to additional RHEL 8.8 channels.
Red Hat's CVE entry states that CVE-2025-68183 was fixed for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and 8.6 Extended Update Support Long-Life Add-On in RHSA-2026:40068. This added remediation for additional RHEL 8.6 support streams.
Red Hat's CVE entry states that Red Hat Enterprise Linux 10.0 Extended Update Support kernel packages were fixed for CVE-2025-68183 in RHSA-2026:39371. This extended the remediation to the RHEL 10.0 EUS stream.
Red Hat released Important advisory RHSA-2026:38902 for Red Hat Enterprise Linux 9.6 Extended Update Support and related channels, fixing CVE-2025-68183 among 11 kernel CVEs. Updated kernel packages version 5.14.0-570.127.1.el9_6 were provided and a reboot was required.
Red Hat issued Important advisory RHSA-2026:36767 for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions and related variants. The kernel update fixed CVE-2025-68183 and other vulnerabilities and required a reboot.
Red Hat released Important advisory RHSA-2026:36073 for Red Hat Enterprise Linux 9.2 kernel packages, including a fix for CVE-2025-68183. The advisory covered SAP, AUS, 4-year update, and Extended Life Cycle variants across several architectures.
Red Hat issued Important advisory RHSA-2026:35904 for kernel-rt on Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and Extended Life Cycle. The update fixed CVE-2025-68183 and required systems to be rebooted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.