Red Hat released moderate-severity RHEL 8 kernel and real-time kernel updates addressing eight Linux kernel vulnerabilities across networking, IPv6, USB audio, vsock/vmci, ext4, NFSv4/pNFS, and NVMe/TCP components. The updates are delivered through RHSA-2026:2264 for standard RHEL 8 packages and RHSA-2026:2378 for RHEL for Real Time, Real Time for NFV, and applicable Extended Life Cycle streams.
Notable fixes include IPv6 and networking use-after-free risks tracked as CVE-2025-40135, CVE-2025-40158, and CVE-2025-40170, remediated by using RCU-protected access to destination-device data in paths including ip6_xmit(), ip6_output(), and sk_setup_caps(). The updates also address CVE-2025-39757 and CVE-2025-38729, where malformed USB Audio Class 3 descriptors from malicious USB audio firmware could cause out-of-bounds memory accesses. Organizations should apply the appropriate updated kernel packages and reboot affected systems for the fixes to take effect.

See real exploitation activity before you spend the cycle.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:2378, a Moderate-severity kernel-rt update for RHEL 8 Real Time, Real Time for NFV, and x86_64 Extended Life Cycle 8.10. It fixes CVE-2025-40135, CVE-2025-40158, and CVE-2025-40170, and requires a reboot after installation.
Red Hat published RHSA-2026:2264, a Moderate-severity RHEL 8 kernel update that fixes CVE-2025-40135, CVE-2025-40158, and CVE-2025-40170 alongside five other kernel vulnerabilities. The update requires a system reboot for fixes to take effect.
An upstream advisory disclosed CVE-2025-40170, resolved by applying RCU-protected dst->dev access in sk_setup_caps(), sk_dst_gso_max_size(), and other IPv4 and IPv6 networking functions.
An upstream advisory disclosed CVE-2025-40158 in the Linux kernel IPv6 output path. Its fix uses RCU in ip6_output() and dst_dev_rcu(), and removes redundant RCU lock/unlock pairs from ip6_finish_output2().
An upstream advisory disclosed CVE-2025-40135 in the Linux kernel IPv6 networking code. The resolution changes ip6_xmit() to use RCU and dst_dev_rcu() to prevent a possible use-after-free condition.
Red Hat published RHSA-2025:18298, a Moderate-security RHEL 8 kernel-rt update for Real Time, Real Time for NFV, and RHEL 8.10 Extended Life Cycle systems. It fixes CVE-2025-39757 as well as CVE-2025-39751 in the ALSA HDA ca0132 driver and CVE-2023-53373 in crypto seqiv; affected systems require a reboot.
An upstream Linux CVE announcement disclosed CVE-2025-39757, in which insufficient UAC3 cluster-segment descriptor validation could allow malformed USB audio firmware to cause out-of-bounds memory access. The fix verifies descriptor sizes and declared lengths against allocated buffer bounds.
An upstream Linux CVE announcement disclosed CVE-2025-38729, involving insufficient validation of variable-length UAC3 power-domain descriptors that could permit out-of-bounds memory access from malicious USB audio firmware. The kernel fix validates the descriptors and their bLength values before processing.
Red Hat issued Important-rated RHSA-2025:13776 for RHEL 8.6 Extended Life Cycle Long Life, AUS, TUS, and SAP Update Services variants. The 4.18.0-372.157.1.el8_6 kernel update fixes 12 vulnerabilities, including CVE-2022-49788, CVE-2025-21727, CVE-2025-21928, and CVE-2025-38052; affected systems require a reboot.
An upstream Linux CVE announcement disclosed CVE-2024-57980, a double-free flaw in the uvcvideo driver's error path when uvc_status_init() frees dev->status after an int_urb allocation failure without clearing the pointer. The fix sets dev->status to NULL after freeing it, preventing uvc_status_cleanup() from freeing stale memory again.
CVE-2022-49788 affects the Linux VMware VMCI driver's datagram receive path, where uninitialized padding in a vmci_event_qp structure could be copied to userspace. Red Hat issued fixes through 2025 RHSA advisories for affected RHEL 7, 8, and 9 product variants; the upstream fix initializes the structure with memset().
CVE-2024-53197 was resolved in the Linux kernel after it was found that malicious Extigy or Mbox USB devices could report a bNumConfigurations value exceeding the allocation for dev->config, causing later out-of-bounds accesses such as in usb_destroy_configuration. Fedora included the fix in 6.11.11 stable kernel updates, and Red Hat issued fixes for multiple RHEL and OpenShift Container Platform support streams.
Red Hat addressed CVE-2025-39757 through advisories covering RHEL 7, 8, 9, and 10, including Extended Update Support, SAP, telecommunications, and mission-critical product streams.
Red Hat addressed CVE-2025-38729 through advisories for multiple RHEL 7, 8, and 9 support channels, including Extended Update Support, SAP Solutions, telecommunications, and mission-critical variants.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.