Red Hat released a series of Moderate-severity kernel and kernel-rt advisories for multiple Red Hat Enterprise Linux 8 and 9 product streams, delivering fixes for a broad set of Linux kernel vulnerabilities across standard, SAP, telecommunications, NFV, mission-critical, and Extended Update Support offerings. The updates cover memory-safety and race-condition bugs in components including RDMA/core, SCTP, fbdev/font glyph handling, Bluetooth, DRM/i915, ASoC, mlx5e, SMB/CIFS, NFS, and USB parsing, with impacts ranging from use-after-free, double free, NULL pointer dereference, and out-of-bounds read/write to information disclosure, denial of service, and possible privilege escalation or arbitrary code execution.
Among the tracked issues, CVE-2025-38022 fixed a race in ib_register_device where ib_device_rename() could update a device name under lock while kobject_uevent() accessed it without equivalent protection, causing a KASAN-reported slab use-after-free read in the RDMA subsystem. Other patched flaws included CVE-2025-40240 in SCTP, CVE-2025-40322 in font glyph handling, CVE-2023-53673 in Bluetooth connection teardown, CVE-2023-53833 in drm/i915, and additional networking and driver bugs. Red Hat published the fixes through advisories including RHSA-2026:1661, RHSA-2026:2352, RHSA-2026:2490, RHSA-2026:2535, RHSA-2026:2766, RHSA-2026:3293, RHSA-2026:3375, RHSA-2026:5691, and RHSA-2026:6961, and instructed customers to reboot systems after applying the updated kernel packages.

See real exploitation activity before you spend the cycle.
44 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:6961 for RHEL 8.6 service variants. The advisory delivered updated kernel packages fixing four vulnerabilities, including CVE-2026-23209, and required a reboot.
Red Hat published RHSA-2026:2821 for RHEL 8 Real Time kernel packages, updating kernel-rt to version 4.18.0-553.105.1.rt7.446.el8_10. The Moderate advisory fixed CVE-2025-40168, CVE-2023-53762, and CVE-2025-40304, and required a reboot after installation.
Red Hat published RHSA-2026:2766 for Red Hat Enterprise Linux 9.4 Extended Update Support. The Moderate kernel advisory fixed multiple vulnerabilities including CVE-2025-40322 and required a reboot.
Red Hat published RHSA-2026:2720, a Moderate RHEL 8 kernel update fixing CVE-2025-40168, CVE-2023-53762, and CVE-2025-40304. The update delivered kernel build 4.18.0-553.105.1.el8_10 for RHEL 8 and RHEL 8.10 Extended Life Cycle offerings and required a reboot.
Red Hat issued Moderate advisory RHSA-2026:2594 for RHEL 9.4 servicing channels, delivering kernel version 5.14.0-427.110.1.el9_4. The update fixed CVE-2025-38022, CVE-2025-38568, CVE-2025-40294, and CVE-2025-40322 and required affected systems to reboot.
Red Hat issued Moderate advisory RHSA-2026:2577 for the x86_64 Real Time kernel in RHEL 9.0 Update Services for SAP Solutions, updating kernel-rt to 5.14.0-70.165.1.rt21.237.el9_0. The update fixed 11 Linux kernel vulnerabilities, including CVE-2023-53192, CVE-2025-40251, CVE-2025-40304, CVE-2025-40322, and CVE-2023-53833, and required a reboot.
Red Hat issued Moderate advisory RHSA-2026:2573 for RHEL 9.0 Update Services for SAP Solutions, updating the kernel to version 5.14.0-70.165.1.el9_0. The update fixed 11 Linux kernel vulnerabilities, including CVE-2025-40304, CVE-2025-40322, CVE-2023-53833, Bluetooth and networking flaws, and required affected systems to reboot.
Red Hat published RHSA-2026:2560 for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and related 9.2 variants. The Moderate advisory updated kernel packages to fix multiple flaws including CVE-2025-38022, CVE-2025-40304, CVE-2025-40322, and CVE-2023-53833, and required a reboot.
Red Hat published RHSA-2026:2490 for RHEL 8.6 mission-critical, SAP, and telecommunications channels. The update fixed CVE-2025-40154, CVE-2023-53581, and CVE-2025-40322, and required a system reboot.
Red Hat published RHSA-2026:2352 for Red Hat Enterprise Linux 9.6 Extended Update Support and related variants. The advisory fixed CVE-2025-38022 and CVE-2025-40322 among other kernel flaws and required a reboot.
Red Hat published RHSA-2026:1661 for Red Hat Enterprise Linux 8 real-time offerings, including a fix for CVE-2025-38022. The Moderate advisory updated kernel-rt packages and required a reboot after installation.
Red Hat issued Moderate advisory RHSA-2026:1443 for the RHEL 9.2 Real Time kernel in SAP Solutions and Extended Life Cycle subscriptions. The update delivered kernel-rt version 5.14.0-284.154.1.rt14.439.el9_2, fixed 14 Linux kernel vulnerabilities including CVE-2025-23142 and CVE-2025-40154, and required a reboot.
Red Hat issued Moderate advisory RHSA-2026:1441 for RHEL 9.2 Update Services for SAP Solutions, AUS, and Extended Life Cycle offerings, updating the kernel to version 5.14.0-284.154.1.el9_2. The update fixed 14 Linux kernel CVEs, including CVE-2025-23142, CVE-2025-40154, and flaws in IOMMU, Open vSwitch, Bluetooth, IPv6, graphics, networking drivers, and virtualization; customers were instructed to reboot.
Red Hat published Important advisory RHSA-2026:0576 for the standard kernel in RHEL 9.0 Update Services for SAP Solutions, updating packages to version 5.14.0-70.161.1.el9_0. The update fixed 13 Linux kernel vulnerabilities, including CVE-2025-23142, CVE-2025-68287, and flaws in CAN J1939, SMB/CIFS, NFSD, Bluetooth, IPv6, SCSI SES, and libceph; Red Hat required a reboot.
Red Hat published Important advisory RHSA-2026:0537 for the kernel-rt package in RHEL 9.0 Update Services for SAP Solutions. The update fixed CVE-2025-23142 and multiple other Linux kernel flaws, including issues in CAN J1939, SMB/CIFS, NFSD, Bluetooth, USB DWC3, and libceph, and required a reboot.
Red Hat published Important advisory RHSA-2026:0457 for RHEL 9.6 Extended Update Support and related offerings, updating kernel packages to version 5.14.0-570.77.1.el9_6. The update fixed CVE-2025-23142, CVE-2025-39806, CVE-2025-39981, CVE-2025-39983, CVE-2025-40176, and CVE-2025-68287; Red Hat instructed customers to reboot after installation.
An upstream Linux kernel advisory was published for CVE-2023-53833 in drm/i915. The fix added a NULL check for new_crtc_state to prevent a NULL pointer dereference.
An upstream Linux kernel CVE announcement disclosed CVE-2023-53751, a CIFS use-after-free risk involving TCP_Server_Info::hostname during reconnect operations. The fix protects hostname access outside the reconnect path, where updates could otherwise race with unprotected access.
An upstream Linux kernel advisory was published for CVE-2025-40240, an SCTP NULL dereference caused by dereferencing chunk->skb when a chunk data buffer is missing. The fix changed the logic to check frag_list just before replacing chunk->skb.
Red Hat issued Moderate advisory RHSA-2025:22087 for the RHEL 9.0 x86_64 Real Time kernel in Update Services for SAP Solutions. The update delivered kernel-rt 5.14.0-70.155.1.rt21.227.el9_0, fixed nine kernel CVEs including USB-audio, Bluetooth, CIFS, RDMA, and ext4 flaws, and required a reboot.
An upstream Linux kernel advisory disclosed CVE-2025-40168 in the SMC subsystem. The flaw could cause a use-after-free because smc_clc_prfx_match() accessed sk_dst_get(sk)->dev from smc_listen_work() without RCU or RTNL protection; the fix uses __sk_dst_get() and dst_dev_rcu().
Red Hat issued Moderate advisory RHSA-2025:21091 for the RHEL 9.0 Update Services for SAP Solutions kernel, delivering build 5.14.0-70.153.1.el9_0 for x86_64, ppc64le, aarch64, and s390x. The update fixed 23 kernel CVEs, including CVE-2025-38718 and flaws affecting USB audio, IPv6, SCTP, NFS, Wi-Fi, Bluetooth, memory management, filesystems, networking, and cryptography; systems require a reboot.
An upstream Linux kernel advisory was published for CVE-2025-40154 in the ASoC Intel bytcr_rt5640 driver. The fix changed invalid quirk input handling to map bad values to a safe default instead of leaving them unchanged.
An upstream Linux kernel advisory disclosed CVE-2023-53552 in the Intel i915 DRM driver, where GuC virtual-engine request handling could lead to a use-after-free during fence release. The fix marks virtual-engine requests with an additional rq->execution_mask bit so release logic does not rely on an invalid engine pointer.
Red Hat issued Moderate advisory RHSA-2025:17159 for the RHEL 9.0 Update Services for SAP Solutions kernel, delivering build 5.14.0-70.148.1.el9_0. The update fixed six vulnerabilities affecting AMD display handling, MD RAID10, RDMA iWCM, LPFC SCSI, vsock, and DRM GEM framebuffer handling, and required a reboot.
An upstream Linux kernel CVE announcement disclosed CVE-2023-53297 in Bluetooth L2CAP's l2cap_disconnect_rsp path. The flaw could trigger a bad unlock balance when l2cap_get_chan_by_scid() returned NULL because conn->chan_lock had not been acquired; upstream fixed the locking defect.
An upstream Linux kernel CVE announcement disclosed CVE-2025-39757 in ALSA USB-audio handling of UAC3 cluster segment descriptors. Insufficient validation of descriptor sizes and declared lengths could let malicious USB audio firmware trigger out-of-bounds memory accesses; the fix verifies descriptor lengths and allocated-buffer bounds.
Red Hat logged CVE-2025-38568 as Bug 2389507 after it was reported as a medium-severity Linux kernel flaw in mqprio traffic-control entry parsing. The vulnerable policy allowed index 16 for the 16-element fp[] stack array, causing a 4-byte out-of-bounds write; the fix limits the maximum index to TC_QOPT_MAX_QUEUE - 1.
An upstream Linux kernel advisory for CVE-2025-38022 was published, documenting a race in RDMA/core that could trigger a KASAN slab-use-after-free read in ib_register_device. The fix added locking around device-name access in kobject_uevent().
Red Hat recorded CVE-2022-49969, a medium-severity flaw in drm/amd/display where an OPTC underflow bit could persist after the ODM clock was disabled. The upstream remediation clears any existing OPTC underflow condition before turning off the ODM clock.
An upstream Linux kernel advisory identified CVE-2023-53034 in the ntb_hw_switchtec driver. The shift-out-of-bounds flaw could occur when ntb_mw_clear_trans() passed zero address and size values, making xlate_pos negative; the fix ensures xlate_pos is nonnegative before applying BIT.
Red Hat documented CVE-2026-52924, an SCTP use-after-free in stale COOKIE-ECHO handling where rebuilt stream state can leave scheduler and queued-data references to freed stream entries, potentially crashing the kernel. The upstream fix purges the association outqueue during Stale Cookie processing; Red Hat addressed the issue in RHEL 8 and 9 through RHSA-2026:59737, RHSA-2026:59821, and RHSA-2026:59723.
Red Hat documented CVE-2025-38718, in which SCTP processing of cloned GSO packets could unsafely access fragment-list socket buffers shared with the original skb, producing KMSAN use-of-uninitialized-memory reports. The upstream fix linearizes cloned GSO packets in sctp_rcv(), and Red Hat issued fixes across affected RHEL 7, 8, 9, and 10 streams.
Red Hat documented CVE-2025-40300 (VMSCAPE), in which a malicious guest VM could poison branch-predictor state later consumed by a userspace hypervisor after VM exit. The upstream mitigation conditionally issues an IBPB before returning to userspace; Red Hat addressed the issue through advisories for RHEL 8, 9, and 10 support streams.
An upstream advisory identified CVE-2025-40251 in Linux devlink rate handling: devl_rate_nodes_destroy() failed to clear devlink_rate->parent after destroying rate objects, leaving a dangling pointer and causing refcount errors in netdevsim and mlx5 reproductions. The fix explicitly sets the parent pointer to NULL after notifying the driver; Red Hat later addressed the issue across multiple RHEL 9 and 10 streams.
Red Hat documented CVE-2023-53192, in which VXLAN passed a 32-bit skb_get_hash() value to nexthop code expecting a 31-bit hash. A hash with its high bit set could become negative and cause an out-of-bounds nh_buckets[] access in resilient nexthop groups, potentially triggering a kernel panic; fixes were shipped in multiple RHEL 9 SAP advisories.
Red Hat documented CVE-2025-23142, an SCTP use-after-free read in sctp_outq_select_transport() that can occur when a transport is removed during a sendmsg race. The upstream fix restores a transport dead flag, detects deletion after the socket lock is reacquired, and returns -EAGAIN for userspace to retry; Red Hat addressed the issue in multiple RHEL 9 EUS and SAP update streams.
An upstream advisory identified CVE-2023-53762 as a Linux Bluetooth use-after-free in hci_disconnect_all_sync that could crash hci_set_powered_sync during concurrent connection deletion. The fix iterates the connection list backwards, cleans child links before parent objects, and relies on hci_abort_conn_sync deleting the last connection; Red Hat said the issue was addressed in RHEL 8 and RHEL 9.2 SAP offerings through multiple RHSA advisories.
An upstream Linux kernel advisory identified CVE-2025-40304, an fbdev bit_putcs out-of-bounds-write vulnerability caused by clipped framebuffer rendering retaining an oversized character count. The fix added bounds checks and synchronized the character count with clipped image width to prevent writes beyond framebuffer boundaries.
A follow-up Bugzilla comment said the initial fix for CVE-2025-40322 was faulty because it assumed vc->vc_font.charcount was always set. The regression reportedly caused garbage text or white blocks on fbcon virtual consoles, including at least RHEL 8.10.
Red Hat published RHSA-2026:5691 for RHEL 8.6 support channels, fixing CVE-2025-40240 along with three other kernel vulnerabilities. Updated kernel packages were released as version 4.18.0-372.185.1.el8_6.
Red Hat published RHSA-2026:3375 for the kernel-rt package in Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. The Moderate advisory fixed CVE-2025-38022 and other kernel flaws and instructed customers to reboot.
Red Hat published RHSA-2026:3293 for Red Hat Enterprise Linux 9.0 offerings, including Update Services for SAP Solutions. The advisory fixed CVE-2025-38022 and several other kernel vulnerabilities and required a reboot.
Red Hat published RHSA-2026:2535 for RHEL 8.8 SAP Solutions and Telecommunications Update Service. The advisory fixed CVE-2025-38022, CVE-2025-40240, CVE-2025-40322, CVE-2023-53833, CVE-2025-40154, and CVE-2025-40096 among other kernel issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.