Red Hat released kernel security updates for Red Hat Enterprise Linux (RHEL) 9 and 10, including a Real Time kernel update for RHEL 9.2 SAP-related lifecycle channels. The advisories remediate memory-safety and stability flaws including out-of-bounds accesses, use-after-free conditions, race conditions, NULL-pointer dereferences, and command-header validation issues. Affected components span the audit subsystem, HID multitouch, SCTP, NFS, SMB, Bluetooth, RDMA, SCSI, TLS, USB DWC3, libceph, and networking memory-management paths.
Notable fixes include CVE-2025-39840, an out-of-bounds read in audit_compare_dname_path() that can occur when an audit watch on / processes a one-character child path, and CVE-2025-39883, which could let a local user with access to the hwpoison debugfs interface trigger a kernel panic through invalid memory unpoisoning. Later RHEL 9.2 SAP update 5.14.0-284.161.1.el9_2 also addresses CVE-2025-38129 and CVE-2025-38154 use-after-free flaws, with the BPF sockmap issue potentially enabling denial of service or privilege escalation. Administrators should deploy the applicable updated kernel packages and reboot systems to activate the fixes.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued a Moderate-severity kernel update, version 5.14.0-284.161.1.el9_2, for RHEL 9.2 SAP and lifecycle channels. The update fixed CVE-2025-38129, CVE-2025-38154, CVE-2025-40240, and CVE-2025-71085, including BPF sockmap use-after-free issues that could enable denial of service or privilege escalation.
Red Hat issued an Important kernel-rt update for RHEL 9.2 Update Services for SAP Solutions and RHEL 9.2 Extended Life Cycle x86_64 systems. It fixed 11 vulnerabilities affecting components including NFS, SMB, Bluetooth, TLS, USB DWC3, and libceph; a reboot is required.
Red Hat issued an Important-severity RHEL 10 kernel update fixing nine vulnerabilities, including CVE-2025-39806, CVE-2025-39840, CVE-2025-39966, CVE-2025-40176, CVE-2025-40240, CVE-2025-40277, and CVE-2025-68287. Affected RHEL 10 systems must be rebooted after applying the update.
Red Hat issued a Moderate-severity RHEL 9 kernel update fixing CVE-2025-39806, CVE-2025-39840, CVE-2025-39883, and CVE-2025-40240. The update applies to multiple RHEL 9 architectures and lifecycle channels, and requires a reboot.
Red Hat issued Moderate-severity advisory RHSA-2025:22996 for RHEL 9.2 SAP, AUS, and Extended Life Cycle channels. Kernel version 5.14.0-284.149.1.el9_2 fixes CVE-2025-39841 in the lpfc SCSI deferred receive path and CVE-2025-39883 in memory-failure handling; affected systems require a reboot.
Red Hat issued a Moderate-severity kernel update for RHEL 9.2 SAP, AUS, extended-life-cycle, and architecture-specific offerings. The 5.14.0-284.146.1.el9_2 update fixes 16 CVEs, including eventpoll recursion, NFS and zswap race conditions, Wi-Fi driver flaws, Bluetooth use-after-free issues, and memory-corruption bugs; affected systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2025:17122 for RHEL 9.2 SAP, AUS, and Extended Life Cycle offerings. Kernel version 5.14.0-284.140.1.el9_2 fixes six flaws in USB DWC3, Intel i40e, vsock, DRM/GEM, netfilter connection tracking, and SMB/CIFS; affected systems require a reboot.
The upstream linux-cve-announce project disclosed CVE-2025-39883, a kernel memory-failure flaw in unpoison_memory() that can lead to a kernel panic when an invalid PFN is supplied through the hwpoison debugfs interface.
The upstream Linux CVE announcement disclosed CVE-2025-39840, an out-of-bounds read in the kernel audit subsystem's audit_compare_dname_path() function. The flaw can be triggered by an audit watch on the root directory combined with a single-character path directly beneath it.
An upstream Linux CVE announcement disclosed CVE-2025-38449, a DRM/GEM reference-counting flaw where a released GEM handle can leave its buffer object attached to a framebuffer. Later mode-setting use can release the dma-buf backing object and trigger a kernel segmentation fault and denial of service.
An upstream Linux kernel advisory disclosed CVE-2025-38200 in the Intel i40e Ethernet driver. Device-supplied input could cause an integer underflow in i40e_clear_hw, leading to an MMIO write to an invalid page; the fix changes affected variable types to prevent the underflow.
An upstream Linux CVE announcement disclosed CVE-2025-37810 in the DWC3 USB gadget driver's event-buffer handling. An unchecked event count from DWC3_GEVNTCOUNT could exceed the allocated buffer length and cause an out-of-bounds memcpy access and kernel paging-request crash; the fix validates the count before copying.
Red Hat documented CVE-2025-38461, a Linux kernel vsock transport-assignment TOCTOU race that can leave a stale transport pointer and cause a kernel page fault during connection handling. Red Hat reported fixes across RHEL 8, 9, and 10, including specialized and extended-support channels.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.