Red Hat released kernel security updates across RHEL 7 Extended Life Cycle Support, RHEL 8 and its real-time variants, RHEL 9.2 SAP-related lifecycle channels, and RHEL 10. The advisories remediate multiple memory-safety and denial-of-service issues, including use-after-free flaws in the page-pool subsystem (CVE-2025-38129) and the teql queueing discipline (CVE-2026-23074). The page-pool race can result in a freed page pool being accessed during page recycling and may enable arbitrary code execution; the teql flaw may enable local privilege escalation. Other fixes address buffer overflows, NULL-pointer dereferences, slab out-of-bounds conditions, and flaws in Squashfs, BPF sockmap, SCTP, IPv6, and procfs code paths.
Organizations should apply the relevant Red Hat kernel builds, including 4.18.0-553.107.1.el8_10 for affected RHEL 8 deployments and 5.14.0-284.161.1.el9_2 for applicable RHEL 9.2 SAP systems. Red Hat requires affected systems to be rebooted after installation for the updated kernel and mitigations to take effect; teams should prioritize systems where untrusted local users or workloads can access vulnerable kernel functionality.

See real exploitation activity before you spend the cycle.
50 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2026:5690 for RHEL 9.2 kernel-rt packages in SAP Solutions and Extended Life Cycle channels. Kernel-rt version 5.14.0-284.161.1.rt14.446.el9_2 fixes four vulnerabilities, including BPF sockmap use-after-free CVE-2025-38154, and requires a reboot.
Red Hat issued Moderate-severity advisory RHSA-2026:5813 for RHEL 9.2 Update Services for SAP Solutions and related lifecycle channels. Kernel version 5.14.0-284.161.1.el9_2 fixes four issues, including CVE-2025-38129 and a BPF sockmap use-after-free that can lead to denial of service and privilege escalation.
Red Hat issued Moderate-severity advisory RHSA-2026:4245 for the standard RHEL 9.0 Update Services for SAP Solutions kernel. Kernel version 5.14.0-70.169.1.el9_0 fixes CVE-2025-37882 and CVE-2025-38129 across x86_64, ppc64le, aarch64, and s390x offerings; systems require a reboot after updating.
Red Hat issued Moderate-severity advisory RHSA-2026:4244 for RHEL 9.0 Update Services for SAP Solutions on x86_64. Kernel-rt version 5.14.0-70.169.1.rt21.241.el9_0 fixes CVE-2025-37882 and CVE-2025-38129 use-after-free-related flaws; affected systems require a reboot.
Red Hat issued Important advisory RHSA-2026:3634 for the RHEL 7 x86_64 Real Time Extended Life Cycle Support kernel-rt package. The update fixes nine kernel vulnerabilities, including CVE-2025-40271 and CVE-2026-23074, which may permit privilege escalation, and requires a system reboot.
Red Hat issued Important advisory RHSA-2026:3110 for RHEL 8 Real Time, Real Time for NFV, and x86_64 ELS 8.10. Kernel-rt version 4.18.0-553.107.1.rt7.448.el8_10 fixes the same five vulnerabilities addressed in RHSA-2026:3083, and Red Hat instructed customers to reboot after installation.
Red Hat issued Important advisory RHSA-2026:3083 for RHEL 8, releasing kernel version 4.18.0-553.107.1.el8_10. It fixes five use-after-free vulnerabilities, including CVE-2026-23074 in the teql queueing discipline, which could enable privilege escalation.
Red Hat issued Moderate-severity advisory RHSA-2026:2721 with updated RHEL 10 kernel packages fixing seven vulnerabilities, including use-after-free, buffer-overflow, NULL-pointer dereference, and shift-out-of-bounds flaws. The affected product streams span x86_64, s390x, ppc64le, and aarch64; systems require a reboot after updating.
Red Hat issued Moderate-severity advisory RHSA-2025:22997 for RHEL 9.0 Update Services for SAP Solutions on x86_64. Kernel-rt version 5.14.0-70.157.1.rt21.229.el9_0 fixes CVE-2023-52610, CVE-2025-39841, and CVE-2025-39883; affected systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2025:21128 for RHEL 9.2 Update Services for SAP Solutions and the x86_64 Extended Life Cycle channel. Kernel-rt version 5.14.0-284.146.1.rt14.431.el9_2 fixes 16 kernel vulnerabilities across components including eventpoll, NFS, Wi-Fi, Bluetooth, memory management, networking, and cryptography; affected systems must be rebooted.
Red Hat issued Moderate advisory RHSA-2025:21082 for RHEL 7 Real Time x86_64 under Extended Lifecycle Support. Kernel-rt version 3.10.0-1160.142.1.rt56.1294.el7 fixes six vulnerabilities, including the HFSC use-after-free CVE-2025-37797, CA0132 driver buffer overflow CVE-2025-39751, and seqiv flaw CVE-2023-53373; systems must be rebooted.
An upstream Linux CVE announcement referenced CVE-2023-53373, a use-after-free in the kernel crypto seqiv component caused by failing to handle EBUSY responses for MAY_BACKLOG requests. Red Hat subsequently addressed the flaw across numerous RHEL 7, 8, and 9 releases and support channels through RHSA advisories.
Red Hat issued Important advisory RHSA-2025:14691 for RHEL 9.2 x86_64 Real Time kernel packages in SAP Solutions and Extended Life Cycle channels. Kernel-rt version 5.14.0-284.134.1.rt14.419.el9_2 fixes five flaws including BPF use-after-free CVE-2025-21867 and algif_hash double-free CVE-2025-38079; systems must be rebooted.
Red Hat issued Moderate-severity advisory RHSA-2025:13633 for RHEL 9.2 x86_64 Real Time kernel packages in SAP Solutions and Extended Life Cycle subscriptions. Kernel-rt version 5.14.0-284.130.1.rt14.415.el9_2 fixes nine flaws, including use-after-free issues in padata, Intel ISH HID, memstick, and HFSC handling; affected systems must be rebooted.
Red Hat issued Moderate-severity advisory RHSA-2024:10944 for RHEL 8 Real Time, Real Time for NFV, and RHEL 8.10 x86_64 Extended Life Cycle. Kernel-rt version 4.18.0-553.32.1.rt7.373.el8_10 fixes nine vulnerabilities involving SELinux/Smack, networking, block I/O, arm64 uprobes, XFRM, GIC-v4, IPv6 netfilter, and virtio-vsock; systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2024:10773 for RHEL 9.2 kernel-rt packages in the x86_64 SAP Solutions and Extended Life Cycle channels. Kernel-rt version 5.14.0-284.95.1.rt14.380.el9_2 fixes 16 vulnerabilities across networking, BPF, Bluetooth, XFS, graphics, SCSI, SPI, and memory handling; systems must be rebooted.
Red Hat issued Moderate-severity advisory RHSA-2024:9546 for supported RHEL 9.4 channels. Kernel version 5.14.0-427.44.1.el9_4 fixes numerous flaws, including CVE-2024-26656 in AMDGPU, CVE-2024-26984 in Nouveau, and vulnerabilities affecting ext4, BPF, networking, NFS, storage, and graphics; affected systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2024:9498 for RHEL 9.2 x86_64 Real Time kernel packages in Update Services for SAP Solutions and Extended Life Cycle support. Kernel-rt version 5.14.0-284.92.1.rt14.377.el9_2 fixes 11 flaws, including AMDGPU, TCP, ext4, NFS, MPTCP, networking, and CPU-vector issues; affected systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2024:8614 for RHEL 9.2 x86_64 Real Time kernel packages in Update Services for SAP Solutions and Extended Life Cycle channels. Kernel-rt version 5.14.0-284.90.1.rt14.375.el9_2 fixes 14 flaws, including OverlayFS use-after-free CVE-2023-1252, Intel BHI CVE-2024-2201, and multiple race, NULL-pointer, I/O-hang, and resource-leak issues; systems must be rebooted.
Red Hat issued Moderate-severity advisory RHSA-2024:8158 for RHEL 9.2 x86_64 Real Time kernel packages in Update Services for SAP Solutions and Extended Life Cycle channels. Kernel-rt version 5.14.0-284.88.1.rt14.373.el9_2 fixes nine vulnerabilities affecting Intel Atom processors, the w83792d driver, networking, XFS, firmware DSP handling, IBM virtual NICs, pin control, connection tracking, and TIPC; affected systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2024:7490 for RHEL 9.2 x86_64 Real Time kernel packages in Update Services for SAP Solutions and Extended Life Cycle channels. Kernel-rt version 5.14.0-284.86.1.rt14.371.el9_2 fixes four networking flaws in bridge multicast and MST VLAN handling, Open vSwitch ICMPv6 connection tracking, and netfilter transparent proxying; affected systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2024:6745 for RHEL 9.2 x86_64 Real Time kernel packages in Update Services for SAP Solutions and Extended Life Cycle support. Kernel-rt version 5.14.0-284.84.1.rt14.369.el9_2 fixes 12 vulnerabilities affecting Bluetooth, cryptography, TTY, CPU frequency scaling, SCSI, ACPICA, scheduling, memory management, and SUNRPC; affected systems require a reboot.
CVE-2024-40956 affects the Linux kernel dmaengine idxd driver's irq_process_work_list, where a descriptor could be freed and reused while still being iterated on a work list. The upstream fix uses list_for_each_entry_safe() to allow safe deletion during iteration; Red Hat remediated the flaw through RHEL 9.2 EUS, RHEL 9.4 EUS, and RHEL 9 advisories, including RHSA-2024:6268.
Red Hat issued Moderate-severity advisory RHSA-2024:6268 for RHEL 9.2 x86_64 Real Time kernel packages in Update Services for SAP Solutions and Extended Life Cycle channels. Kernel-rt version 5.14.0-284.82.1.rt14.367.el9_2 fixes 14 vulnerabilities affecting kprobes, netfilter bridging, BPF sockmap, confidential-computing RNG, GFS2, drivers, memory management, DMA, SCSI, TIPC, PPP, and writeback; systems must be rebooted.
Red Hat issued Important security advisory RHSA-2024:5673 for RHEL 9.2 x86_64 Real Time kernel packages in Update Services for SAP Solutions and Extended Life Cycle subscriptions. Kernel-rt version 5.14.0-284.80.1.rt14.365.el9_2 fixes 11 vulnerabilities affecting efivarfs, BPF sockmap, hugetlb, NFSv4, networking, and network drivers; systems must be rebooted.
Red Hat issued Moderate-severity advisory RHSA-2024:5067 for RHEL 9.2 x86_64 Real Time kernel packages in Extended Update Support, SAP Solutions, and Extended Life Cycle channels. Kernel-rt version 5.14.0-284.77.1.rt14.362.el9_2 remediates 22 Linux-kernel vulnerabilities across storage, filesystems, BPF, networking, SCSI, graphics, console handling, and cgroups.
CVE-2024-41056 was reported as a medium-severity Linux kernel cs_dsp firmware flaw in which strlen() could read beyond fixed-size algorithm or coefficient name arrays when parsing malformed Version 1 WMFW files lacking NUL terminators. Upstream replaced strlen() with bounded strnlen() calls in kernels 6.1.100, 6.6.41, 6.9.10, and 6.10, and Red Hat issued fixes for affected RHEL 8 and RHEL 9 variants.
Red Hat issued Moderate-severity advisory RHSA-2024:4349 for RHEL 9 kernel packages across x86_64, s390x, ppc64le, and aarch64 support streams. The update fixes eight CVEs, including Bluetooth, Xen netfront, SMB client, crypto QAT, net/mlx5e, net/mlx5, and hns3 driver flaws, and requires a reboot.
CVE-2024-27393 affects the Linux kernel Xen netfront driver because it omits a skb_mark_for_recycle call, with an automated assessment indicating a likely low-impact skb leak. Red Hat remediated the upstream-resolved flaw in RHEL 9, including 9.2 EUS and 9.0 SAP Solutions, through RHSA-2024:4106, RHSA-2024:4108, RHSA-2024:4349, and RHSA-2024:5257.
Red Hat issued Important security advisory RHSA-2024:4106 for RHEL 9.2 x86_64 Real Time kernel packages in SAP Solutions and Extended Life Cycle support. Kernel-rt version 5.14.0-284.71.1.rt14.356.el9_2 fixes eight flaws in netfilter/nftables, Xen netfront, SMB reconnect handling, network drivers, and OcteonTX2 AF; affected systems require a reboot.
Patrick Del Bello reported CVE-2024-36270, a medium-severity Linux kernel netfilter transparent-proxy vulnerability in which tproxy did not bail out when IP was disabled on a device. Upstream fixes were released in kernel versions 5.4.278, 5.10.219, 5.15.161, 6.1.93, 6.6.33, 6.9.4, and 6.10-rc2, and Red Hat remediated the issue across RHEL 8, RHEL 9, and specialized support channels.
Patrick Del Bello reported CVE-2024-38615, a low-severity Linux kernel cpufreq vulnerability involving an optional exit() callback. Upstream fixes were released from kernel 5.4.278 through 6.10-rc1, and Red Hat remediated the issue across RHEL 8, RHEL 8.8 EUS, RHEL 9, and RHEL 9.2 EUS advisories.
Patrick Del Bello reported CVE-2024-38573, a low-severity Linux kernel cppc_cpufreq flaw that could cause a null-pointer dereference. Upstream resolved it in kernel versions 5.15.161, 6.1.93, 6.6.33, 6.8.12, 6.9.3, and 6.10-rc1, and Red Hat issued fixes for affected RHEL 8 and RHEL 9 support variants.
Patrick Del Bello reported CVE-2024-38558, a medium-severity Linux kernel Open vSwitch flaw that incorrectly overwrites the connection-tracking original tuple for ICMPv6 traffic. Upstream fixed it in kernel versions from 4.19.316 through 6.10-rc1, and Red Hat remediated affected RHEL 8, RHEL 9, and EUS releases through multiple advisories.
Avinash Hanwate reported CVE-2024-36979, a medium-severity use-after-free in VLAN handling within the Linux bridge Multiple Spanning Tree code. Upstream fixes were identified in kernel versions 6.1.93, 6.6.33, 6.8.12, 6.9.3, and 6.10-rc1, and Red Hat remediated the flaw through RHEL 8 and RHEL 9 advisories.
Patrick Del Bello reported CVE-2024-38570, a medium-severity Linux kernel GFS2 vulnerability involving a potential glock use-after-free during filesystem unmount. Upstream fixed the issue in kernel versions 6.6.33, 6.8.12, 6.9.3, and 6.10-rc1, and Red Hat remediated it across multiple RHEL 8 and RHEL 9 lifecycle variants.
Robb Gatica reported CVE-2024-35960, a medium-severity Linux kernel net/mlx5 flaw involving improperly linking new filesystem rules into the tree. Upstream fixed it in kernels 4.19.313 through 6.9, and Red Hat remediated it across multiple RHEL 8 and RHEL 9 support streams.
Robb Gatica reported CVE-2024-35962, a medium-severity Linux kernel netfilter vulnerability caused by incomplete validation of user input. Upstream fixes were included in kernels 5.10.216, 5.15.156, 6.1.87, 6.6.28, and 6.8.7; Red Hat later addressed it through RHEL 9 and RHEL 9.2 EUS advisories.
Zack Miele reported CVE-2024-26984, a medium-severity Linux kernel nouveau-driver vulnerability involving an instmem race condition around pointer stores. The issue was resolved upstream in kernel versions 5.15.157, 6.1.88, 6.6.29, 6.8.8, and 6.9-rc5, and Red Hat later tracked fixes through RHEL advisories.
Zack Miele reported CVE-2024-26640, a medium-severity Linux kernel TCP receive-side zero-copy vulnerability, on March 18, 2024. Upstream added sanity checks and fixed the flaw in kernel versions 5.10.210, 5.15.149, 6.1.77, 6.6.16, 6.7.4, and 6.8; Fedora and Red Hat later shipped fixes across affected RHEL 8 and RHEL 9 support variants.
CVE-2024-50082 is a Linux kernel blk-rq-qos race between rq_qos_wait() and rq_qos_wake_function() that can cause wake_up_process() to dereference a stale task pointer and crash the kernel. The fix wakes the waiter before removing its waitqueue entry and uses list_del_init_careful(); Red Hat addressed the issue for RHEL 8, RHEL 9, and RHEL 9.4 EUS.
CVE-2024-26601 affects ext4 fast-commit replay, where buddy metadata must be regenerated after block freeing fails. The flawed change was introduced in kernel 5.11 and fixed upstream in 6.8; Fedora shipped a fix in 6.7.5, and Red Hat remediated affected RHEL 9, RHEL 9.2 EUS, and RHEL 9.4 EUS releases.
CVE-2024-26930 is a resolved Linux kernel SCSI qla2xxx driver double-free involving the ha->vp_map pointer, potentially causing memory corruption or kernel instability. Red Hat addressed it for RHEL 9 and RHEL 9.2 Extended Update Support through RHSA-2024:5066, RHSA-2024:5067, and RHSA-2024:6997.
CVE-2023-52489 is a Linux kernel sparse-memory-management race condition when accessing memory_section->usage. Fedora fixed the issue in Linux kernel 6.7.3 stable updates, while Red Hat addressed it through RHSA advisories for RHEL 8, RHEL 9, SAP Solutions, Extended Update Support, and EUS variants.
Red Hat documented CVE-2025-21867, a Linux kernel BPF test-run use-after-free in eth_skb_pkt_type() caused by insufficient validation of user_data passed through bpf_prog_test_run_xdp(). The kernel fix rejects user_data smaller than ETH_HLEN; Red Hat listed remediation for RHEL 9, RHEL 10, and specified RHEL 9.2 and 9.4 lifecycle channels.
Red Hat addressed Linux kernel HID-core vulnerability CVE-2022-48978 for Red Hat Enterprise Linux 7 Extended Lifecycle Support through RHSA-2025:21063. The flaw could trigger a shift-out-of-bounds condition when snto32() processes a HID field bit length greater than 32; the kernel fix bounds the value to 32.
CVE-2024-50110 is a Linux kernel XFRM information-disclosure flaw in which uninitialized structure padding can be copied to user space during algorithm dumping through XFRM netlink interfaces. Red Hat addressed the issue for RHEL 8, RHEL 9, and RHEL 9.4 Extended Update Support; the fix zeroes relevant padding before returning algorithm data.
CVE-2023-52619 affects the Linux kernel pstore/ram component and can crash systems configured with an odd number of CPUs. Fedora fixed it in stable kernel 6.7.4 updates, and Red Hat remediated it across RHEL 8, RHEL 8.8 EUS, RHEL 9, RHEL 9.2 EUS, and RHEL 9.4 EUS through multiple RHSA advisories.
Red Hat documented CVE-2023-0597, in which predictable x86 CPU-entry-area and exception-stack virtual addresses weakened KASLR. The upstream v6.2-rc6 change 97e3d26b5e5f introduced randomization, and Red Hat remediated the issue through RHEL 8, RHEL 9, and Extended Update Support advisories.
CVE-2023-52610 was assigned to a Linux kernel net/sched act_ct flaw that can leak socket buffers and crash when processing out-of-order fragmented packets. Fedora fixed the issue in its 6.6.14 stable kernel updates.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.