Red Hat released multiple Linux kernel security updates for Red Hat Enterprise Linux (RHEL) 8 and 9, addressing use-after-free, double-free, buffer-overflow, integer-overflow, out-of-bounds, and information-disclosure vulnerabilities. The updates cover standard, Real Time, NFV, SAP, Extended Update Support, Extended Life Cycle, and CodeReady Linux Builder offerings across x86_64, aarch64, s390x, and ppc64le systems.
Among the corrected issues is CVE-2025-21999, a race condition in proc_get_inode() that could cause a use-after-free during concurrent /proc inode creation and kernel-module removal. The flaw relies on delete_module, requiring CAP_SYS_MODULE, but Red Hat included the fix in RHEL 9 kernel updates alongside flaws in Bluetooth L2CAP, CIFS/SMB, cfg80211, md, bnxt, UVC, ext4, VMCI, ATM, and other kernel components. Administrators should install the applicable errata and reboot affected systems to load the patched kernel.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important security advisory RHSA-2025:9080 for RHEL 9, including a fix for the proc_get_inode() use-after-free tracked as CVE-2025-21999. Red Hat instructed customers to reboot after applying the kernel update for the fixes to take effect.
Eric Sandeen questioned the vulnerability's privilege-requirement scoring, noting that exploiting the race depends on delete_module, which requires CAP_SYS_MODULE privileges.
An upstream advisory identified a Linux kernel use-after-free vulnerability in proc_get_inode(), caused by a race between module removal and /proc inode instantiation. The flaw could dereference module-owned proc_ops after the module had been freed.
Red Hat issued Moderate-security advisory RHSA-2024:10281 for RHEL 8, updating kernel:4.18.0 to build 4.18.0-553.30.1.el8_10. The update remediates CVE-2024-27043, CVE-2024-27399, CVE-2024-38564, and CVE-2024-46858; affected systems require a reboot after installation.
Red Hat reported and began tracking CVE-2024-27399 as Bugzilla 2280462. The Linux Bluetooth L2CAP flaw is a null-pointer dereference in l2cap_chan_timeout, with an upstream fix included in Linux kernel 6.9.
Red Hat documented CVE-2024-38564 as a missing BPF_PROG_TYPE_CGROUP_SKB attach-type enforcement issue in BPF_LINK_CREATE. Fixes were distributed through additional RHEL 8 and RHEL 9 advisories, including EUS and specialized support channels.
Red Hat addressed CVE-2024-46858, a Linux MPTCP path-manager use-after-free involving concurrent packet processing and Netlink address flushing, through advisories covering multiple RHEL 8 and RHEL 9 support channels. The fix retains the timer reference while holding pm.lock and moves address-list deletion into mptcp_pm_del_add_timer under that lock.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.