Red Hat released multiple Linux kernel security updates for Red Hat Enterprise Linux (RHEL) 8 and 9, addressing use-after-free, double-free, buffer-overflow, integer-overflow, out-of-bounds, and information-disclosure vulnerabilities. The updates cover standard, Real Time, NFV, SAP, Extended Update Support, Extended Life Cycle, and CodeReady Linux Builder offerings across x86_64, aarch64, s390x, and ppc64le systems.
Among the corrected issues is CVE-2025-21999, a race condition in proc_get_inode() that could cause a use-after-free during concurrent /proc inode creation and kernel-module removal. The flaw relies on delete_module, requiring CAP_SYS_MODULE, but Red Hat included the fix in RHEL 9 kernel updates alongside flaws in Bluetooth L2CAP, CIFS/SMB, cfg80211, md, bnxt, UVC, ext4, VMCI, ATM, and other kernel components. Administrators should install the applicable errata and reboot affected systems to load the patched kernel.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important security advisory RHSA-2025:9080 for RHEL 9, including a fix for the proc_get_inode() use-after-free tracked as CVE-2025-21999. Red Hat instructed customers to reboot after applying the kernel update for the fixes to take effect.
Red Hat issued Moderate-severity advisory RHSA-2025:6966 for an updated RHEL 9 kernel, remediating a large set of Linux-kernel vulnerabilities across Bluetooth, networking, filesystems, BPF, drivers, and virtualization. The update includes CVE-2025-1272, involving Secure Boot not automatically enabling kernel lockdown, and requires a reboot after installation.
Eric Sandeen questioned the vulnerability's privilege-requirement scoring, noting that exploiting the race depends on delete_module, which requires CAP_SYS_MODULE privileges.
An upstream advisory identified a Linux kernel use-after-free vulnerability in proc_get_inode(), caused by a race between module removal and /proc inode instantiation. The flaw could dereference module-owned proc_ops after the module had been freed.
Red Hat issued RHBA-2024:11008 to update the integration/camel-k-rhel8-operator-bundle image for RHEL 8-based Middleware Containers, including affected OpenShift Container Platform 4.11 and 4.12 deployments. The update incorporates fixes for multiple Linux kernel vulnerabilities and advises customers to upgrade the image and rebuild dependent images.
Red Hat issued Moderate-security advisory RHSA-2024:10943 for RHEL 8, providing kernel version 4.18.0-553.32.1.el8_10. The update fixes nine vulnerabilities affecting SELinux/SMACK permissions, networking, storage QoS, ARM64 probes, XFRM/IPsec, interrupt virtualization, IPv6 netfilter, and virtio-vsock; systems must be rebooted after installation.
Red Hat issued Moderate-security advisory RHSA-2024:10281 for RHEL 8, updating kernel:4.18.0 to build 4.18.0-553.30.1.el8_10. The update remediates CVE-2024-27043, CVE-2024-27399, CVE-2024-38564, and CVE-2024-46858; affected systems require a reboot after installation.
Red Hat reported CVE-2024-50264 in Linux virtio-vsock, where loopback communication can leave a dangling pointer in vsk->trans and potentially cause a use-after-free. The upstream fix initializes vsk->trans to NULL; Red Hat remediated the issue through RHEL 8, RHEL 9, and RHEL 9.4 EUS advisories.
Red Hat reported and began tracking CVE-2024-27399 as Bugzilla 2280462. The Linux Bluetooth L2CAP flaw is a null-pointer dereference in l2cap_chan_timeout, with an upstream fix included in Linux kernel 6.9.
Red Hat documented CVE-2024-50256, in which nf_send_reset6() can trigger an skb_under_panic kernel crash when a device has a zero hard_header_len and an Ethernet header is pushed. The fix reserves link-layer header space with LL_MAX_HEADER and was distributed through RHEL 8, RHEL 9, and RHEL 9.4 EUS advisories.
Red Hat documented CVE-2024-38564 as a missing BPF_PROG_TYPE_CGROUP_SKB attach-type enforcement issue in BPF_LINK_CREATE. Fixes were distributed through additional RHEL 8 and RHEL 9 advisories, including EUS and specialized support channels.
Red Hat documented CVE-2024-49949, in which malformed userspace-controlled UDP fragmentation offload traffic can cause qdisc_pkt_len_init() to calculate zero GSO segments and trigger a NULL-pointer dereference in FQ-CoDel. The kernel denial-of-service issue was addressed through RHEL 8, RHEL 9, and RHEL 9.4 EUS advisories, including RHSA-2024:10944, RHSA-2024:10939, RHSA-2024:10943, and RHSA-2025:2270.
Red Hat addressed CVE-2024-46858, a Linux MPTCP path-manager use-after-free involving concurrent packet processing and Netlink address flushing, through advisories covering multiple RHEL 8 and RHEL 9 support channels. The fix retains the timer reference while holding pm.lock and moves address-list deletion into mptcp_pm_del_add_timer under that lock.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
16 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.