Red Hat released kernel security update RHSA-2025:9348 for Red Hat Enterprise Linux 10 to remediate multiple Linux kernel flaws, including CVE-2025-21999, a use-after-free bug in proc_get_inode(). The vulnerability stems from a race condition between module removal and /proc inode creation, allowing proc entries to reference module-owned proc_ops after the module has been freed and potentially causing a kernel page fault.
The Linux kernel CVE team said the flaw dates back to kernel 2.6.23 and was corrected in several stable branches, including 6.1.132, 6.6.85, 6.12.21, 6.13.9, and 6.14, while recommending full stable-kernel upgrades instead of cherry-picking fixes. Red Hat’s advisory also addressed CVE-2025-23150 and CVE-2025-37738, two ext4 issues involving an off-by-one error in do_split and improper handling of extended attributes beyond the end of data, and said affected RHEL 10 systems must be rebooted after installing the updated kernel packages.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:9348 for Red Hat Enterprise Linux 10, providing updated kernel packages that address CVE-2025-21999 along with CVE-2025-23150 and CVE-2025-37738. The advisory rates the update Moderate severity and says systems must be rebooted after applying it.
The vulnerability was fixed across multiple kernel branches, including 6.1.132, 6.6.85, 6.12.21, 6.13.9, and 6.14, with branch-specific commits listed in the CVE announcement.
The Linux kernel CVE team assigned CVE-2025-21999 to a race-condition-driven use-after-free vulnerability in proc_get_inode() affecting proc-related code.
The CVE record states the proc_get_inode() use-after-free vulnerability was introduced in Linux kernel 2.6.23 by commit 778f3dd5a13c9e1642e0b2efea4b769387a70afa.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.