Red Hat released Important Linux kernel security updates for Red Hat Enterprise Linux (RHEL) 8, 9, and 10, remediating vulnerabilities that could cause memory corruption, information disclosure, denial of service, and potentially privilege escalation. The advisories are RHSA-2026:1142 for RHEL 8, RHSA-2026:1143 for RHEL 9, and RHSA-2026:1690 for RHEL 10, covering supported x86_64, ARM64/aarch64, IBM Z/s390x, and Power little-endian deployments, as well as applicable EUS, ELS, SAP, and CodeReady Linux Builder channels.
Notable fixes include CVE-2025-38453, a use-after-free condition in io_uring msg_ring request handling; CVE-2025-40301, which could expose uninitialized memory or cause denial of service through Bluetooth HCI command-complete event processing; and CVE-2025-38731, a double-free flaw in the DRM Xe driver's xe_vm_bind_ioctl path. RHEL 8 updates also address Bluetooth, vsock memory-corruption, Intel ASoC, and VMware SVGA driver flaws. Organizations should deploy the appropriate updated kernel packages and reboot affected systems, as the fixes do not take effect until restart.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued an Important kernel update for RHEL 10 and related EUS, ELS, four-year support, and CodeReady Linux Builder channels. It fixes 19 Linux kernel vulnerabilities, including CVE-2025-38453, CVE-2025-38731, and CVE-2025-40301; affected systems must be rebooted for the fixes to take effect.
Red Hat released an Important Linux kernel update for RHEL 9 that remediates eight flaws, including use-after-free, double-free, race-condition, memory-corruption, and out-of-bounds-write vulnerabilities. The advisory includes fixes for CVE-2025-38141, CVE-2025-38349, CVE-2025-38731, CVE-2025-40248, CVE-2025-40258, CVE-2025-40294, CVE-2025-68301, and CVE-2025-68305.
Red Hat issued an Important kernel security update for Red Hat Enterprise Linux 8, fixing CVE-2023-53673, CVE-2025-40154, CVE-2025-40248, and CVE-2025-40277. The update applies to supported RHEL 8 architectures and designated CodeReady Linux Builder and Extended Life Cycle repositories; systems require a reboot after installation.
Red Hat documented that RHSA-2026:1727 remediates CVE-2025-38453, an io_uring msg_ring use-after-free, and CVE-2025-40301, a Bluetooth HCI event-handling information-disclosure and denial-of-service flaw, for RHEL 10.0 Extended Update Support.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.