Red Hat issued fixes for two Linux kernel vulnerabilities affecting supported Red Hat Enterprise Linux update streams. CVE-2023-52638 affects the CAN J1939 networking subsystem, where contention involving j1939_socks_lock can trigger a deadlock; the upstream remediation replaces the lock with a read-write lock. Red Hat delivered advisories for RHEL 9, RHEL 9.2 Extended Update Support, and RHEL 9.0 Update Services for SAP Solutions.
CVE-2023-53705 affects IPv6 packet-option parsing in ipv6_find_tlv(). The function can read an option-length value without first verifying that at least two bytes remain, creating an out-of-bounds memory-access condition. The flaw, identified by InfoTeCS on behalf of the Linux Verification Center using SVACE, was addressed through RHSA updates for supported RHEL 7, 8, and 9 update-service variants.

See real exploitation activity before you spend the cycle.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important-rated RHSA-2026:0536 for selected RHEL 8.6 support channels, providing kernel 4.18.0-372.175.1.el8_6. The update fixes CVE-2023-53675 and CVE-2023-53680 along with additional vulnerabilities affecting SMB/CIFS, SCSI, memory management, NBD, RDMA/rxe, network drivers, and Ceph; affected systems require a reboot after installation.
Red Hat issued advisories addressing CVE-2023-53705 for supported RHEL 7, 8, and 9 update-service variants, including RHEL 9.0 SAP Solutions, RHEL 8.4 mission-critical and EUS offerings, RHEL 8.8 SAP and telecommunications services, and RHEL 7 Extended Lifecycle Support.
Red Hat issued January 2026 advisories addressing CVE-2023-53675, a possible desc_ptr out-of-bounds access in the Linux kernel SCSI SES ses_enclosure_data_process() function. The advisories cover specialized RHEL 7, 8, and 9 update-service offerings, including RHSA-2026:0532 through RHSA-2026:0537, RHSA-2026:0643, RHSA-2026:0754, and RHSA-2026:0755.
Red Hat issued Moderate-severity RHSA-2025:22006 for supported RHEL 8.6 service variants, providing kernel 4.18.0-372.170.1.el8_6 for x86_64 and certain SAP Solutions deployments on ppc64le. The update fixes 18 CVEs, including CVE-2023-53365, and requires systems to reboot after installation.
Red Hat issued Moderate-severity RHSA-2025:22087 for the Real Time Linux Kernel on RHEL 9.0 Update Services for SAP Solutions x86_64 systems. The update provides kernel-rt 5.14.0-70.155.1.rt21.227.el9_0, remediates nine kernel CVEs including CVE-2023-53365, and requires a reboot after installation.
Red Hat issued Moderate-severity RHSA-2025:22066 for RHEL 9.0 Update Services for SAP Solutions, providing kernel 5.14.0-70.155.1.el9_0 for x86_64, ppc64le, aarch64, and s390x. The update fixes nine CVEs, including CVE-2023-53365, and requires affected systems to reboot after installation.
An upstream Linux CVE announcement was published for CVE-2023-53705, covering the IPv6 ipv6_find_tlv() out-of-bounds access issue.
An upstream Linux CVE announcement referenced CVE-2023-53680, an NFSD flaw in which nfsd4_decode_compound() could pass OP_ILLEGAL (10044) to OPDESC(), causing an out-of-bounds access to the nfsd4_ops[] array.
An upstream Linux CVE announcement referenced CVE-2023-53365, an IPv6 multicast-routing flaw in ip6mr_cache_report() that can pass a negative network offset to skb_push(), causing unsigned underflow, skb_under_panic, and a kernel crash under an affected VLAN-on-pim6reg configuration.
Red Hat issued Important-rated RHSA-2025:14692 for selected RHEL 8.6 extended-support and update-service offerings, providing kernel 4.18.0-372.158.1.el8_6. The update fixes nine vulnerabilities, including CAN, HFSC networking, cryptographic, ftrace, and Bluetooth flaws, and requires a reboot after installation.
Red Hat Bugzilla records CVE-2025-39898, a Linux kernel e1000e issue described as a heap overflow in the e1000_set_eeprom function.
InfoTeCS, acting for the Linux Verification Center, identified an out-of-bounds access vulnerability in the Linux kernel ipv6_find_tlv() function using the SVACE analysis tool. The flaw results from reading optlen without ensuring that more than one byte remains to parse.
Red Hat addressed CVE-2023-52638 in advisories for RHEL 9, RHEL 9.2 Extended Update Support, and RHEL 9.0 Update Services for SAP Solutions, including RHSA-2024:4533, RHSA-2024:4554, RHSA-2024:4583, RHSA-2026:0537, and RHSA-2026:0576.
The Linux kernel CVE team assigned CVE-2023-52638 for a CAN J1939 subsystem flaw that could deadlock on j1939_socks_lock. The upstream fix replaced the lock with a read-write lock to prevent the deadlock.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.