Red Hat released Moderate-severity Linux kernel security updates for RHEL 9 and RHEL 10, addressing a broad set of memory-safety, denial-of-service, information-disclosure, and privilege-escalation risks across subsystems including BPF, KVM, netfilter, MPTCP, SMB, RDMA, NFS, and device drivers. The fixes are delivered through RHSA-2025:20518 for RHEL 9 and RHSA-2026:18134 for RHEL 10, covering supported x86_64, aarch64, s390x, and ppc64le variants, including applicable extended-support offerings.
Among the remediated flaws, CVE-2025-21839 affects KVM/x86 handling of the guest DR6 debug register: under certain fast-path VM-exit conditions, particularly in nested VMX deployments, KVM could restore a stale DR6 value and overwrite the guest's current value. CVE-2024-53216 affects the NFS server (nfsd), where cache objects could be released while RCU readers still accessed them, creating a slab use-after-free condition; the fix defers object release until after an RCU grace period. Red Hat requires affected systems to be rebooted after installing the updated kernel for protections to take effect.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Moderate-severity advisory RHSA-2026:18134, making updated RHEL 10 kernel packages available for multiple architectures and product variants. The update fixed numerous flaws, including CVE-2025-21839, CVE-2025-40257, CVE-2026-23111, CVE-2026-23210, and CVE-2026-23243; Red Hat instructed administrators to reboot after applying it.
Red Hat documented CVE-2024-57981, a moderate Linux kernel xHCI USB driver NULL pointer dereference that can allow a local low-privileged user to crash the kernel. Kernel fixes were released for RHEL 9 in RHSA-2025:20518 and RHEL 10 in RHSA-2025:20095; RHEL 9 kernel-rt was marked will not fix.
Red Hat issued Moderate-severity advisory RHSA-2025:20518 for RHEL 9, providing an updated kernel that remediates numerous vulnerabilities across kernel subsystems. The update addressed CVE-2025-21839 and CVE-2024-53216, among other flaws, and required systems to be rebooted after installation.
Red Hat issued RHSA-2025:6966 for Red Hat Enterprise Linux 9, fixing the moderate nfsd export-cache use-after-free vulnerability CVE-2024-53216.
CVE-2024-58014, a moderate Linux kernel brcmsmac Wi-Fi driver out-of-bounds read in wlc_phy_iqcal_gainparams_nphy(), was publicly listed. The missing gain-range check could permit local disclosure of sensitive memory or cause a system crash.
Red Hat addressed CVE-2024-53216 for Red Hat Enterprise Linux 9.6 Extended Update Support through advisory RHSA-2026:14339.
Red Hat addressed the nfsd RCU-related use-after-free vulnerability CVE-2024-53216 in RHEL 10 through advisory RHSA-2025:20095.
Red Hat resolved CVE-2025-21851, an eBPF arena_map_free() flaw that can cause segmentation faults and soft lockups on AArch64 systems using 64 KB pages. The issue was addressed for RHEL 9 in RHSA-2025:20518 and for RHEL 10 in RHSA-2025:20095.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.