Red Hat released Important and Moderate Linux kernel updates across RHEL 8 and RHEL 9 support channels, including Real Time, SAP Solutions, Extended Life Cycle, and selected update services. The advisories address multiple kernel memory-safety and validation vulnerabilities, notably CVE-2025-38051, a race-driven use-after-free in the CIFS/SMB client directory-reading path; CVE-2025-39933, insufficient SMB response-length validation; and CVE-2025-68301, an Atlantic NIC receive-path fragment overflow that can trigger an out-of-bounds write and kernel panic when processing oversized multi-descriptor packets.
Additional fixes cover CVE-2022-50865, a signed integer overflow in TCP backlog handling, alongside flaws in vsock, Bluetooth L2CAP, DRM scheduling and i915, RDMA, devlink, and other drivers. Affected organizations should install the kernel packages supplied for their specific RHEL release and subscription channel—such as 4.18.0-553.94.1.rt7.435.el8_10, 5.14.0-427.109.1.el9_4, or 5.14.0-284.155.1.el9_2—and reboot systems to activate the mitigations.

See real exploitation activity before you spend the cycle.
44 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:2761 for Red Hat Enterprise Linux 10.0 Extended Update Support, fixing CVE-2025-38051, a use-after-free flaw in the SMB/CIFS client cifs_fill_dirent function.
Red Hat published Important advisory RHSA-2026:1946 for RHEL 9.2 SAP Solutions and Extended Life Cycle, supplying kernel-rt 5.14.0-284.155.1.rt14.440.el9_2. The update fixed the TCP backlog integer overflow and Atlantic RX fragment-overflow flaws, plus Bluetooth and vsock issues.
Red Hat issued Important advisory RHSA-2026:1909 for RHEL 9.2 update and support channels, providing kernel 5.14.0-284.155.1.el9_2. It remediated CVE-2022-50865 and CVE-2025-68301, alongside Bluetooth L2CAP and vsock vulnerabilities.
Red Hat issued Important advisory RHSA-2026:1879 for RHEL 9.4, providing kernel 5.14.0-427.109.1.el9_4. The update fixed CVE-2025-68301 as well as SMB client use-after-free, DRM scheduler, vsock, and devlink flaws.
Red Hat issued Important advisory RHSA-2026:1703 for RHEL 9.6, providing kernel 5.14.0-570.84.1.el9_6. The update remediated CVE-2025-21863 in io_uring, CVE-2025-40248 in vsock, and CVE-2025-68301 in the Atlantic driver RX path; affected systems require a reboot after installation.
Red Hat published Important advisory RHSA-2026:1494 for RHEL 9.0 Update Services for SAP Solutions, providing kernel 5.14.0-70.163.1.el9_0. Among 13 remediated CVEs was CVE-2025-38051 in the SMB client cifs_fill_dirent function.
Red Hat published Important advisory RHSA-2026:1445 for selected RHEL 8.8 services, supplying kernel 4.18.0-477.126.1.el8_8. The update included a fix for CVE-2025-38051 along with network, RDMA, graphics, media, and vsock fixes.
Red Hat issued Important advisory RHSA-2026:0760 for RHEL 8 Real Time, Real Time for NFV, and RHEL 8.10 Extended Life Cycle. The kernel-rt 4.18.0-553.94.1.rt7.435.el8_10 update remediated the same five flaws, including the SMB client and Atlantic-driver vulnerabilities.
Red Hat issued Important advisory RHSA-2026:0759 for RHEL 8, updating the kernel to 4.18.0-553.94.1.el8_10. It fixed CVE-2025-38051, CVE-2025-39933, CVE-2023-53552, CVE-2025-40096, and CVE-2025-68301.
Red Hat issued Important advisory RHSA-2026:0489 for RHEL 9.4 channels, providing kernel 5.14.0-427.106.1.el9_4. The update remediated nine CVEs affecting SCTP, NFS, SMB, e1000e, Bluetooth, TLS, USB DWC3, and Ceph components.
Red Hat issued Moderate advisory RHSA-2026:0173 for RHEL 9.4 entitlement channels, providing kernel 5.14.0-427.104.1.el9_4. The update fixed CVE-2023-52513 in RDMA/siw, CVE-2024-35868 in SMB/CIFS, CVE-2025-39925 in CAN J1939, and CVE-2025-39971 in Intel i40e; affected systems require a reboot.
Red Hat issued Moderate advisory RHSA-2025:22124 for RHEL 9.2 SAP Solutions and Extended Life Cycle subscriptions, providing kernel-rt 5.14.0-284.148.1.rt14.433.el9_2. The update remediated 14 flaws affecting networking, SMB/CIFS, USB audio, IPv6, NFS, Wi-Fi, Bluetooth, efivarfs, NBD, and x86 mitigation code; affected systems require a reboot.
The Linux CVE announcement list published an advisory for CVE-2025-39933, an SMB client flaw addressed by validating data_offset, data_length, and remaining_data_length in recv_done processing.
Red Hat issued Moderate advisory RHSA-2025:16880 for RHEL 9 kernel packages, remediating five flaws in netfilter connection tracking, SMB/CIFS, SCTP, kernel TLS, and io_uring/futex. The update affects multiple RHEL 9 architectures and subscription variants; systems require a reboot after installation.
Red Hat issued Important advisory RHSA-2025:15016 for RHEL 9.4, providing kernel build 5.14.0-427.85.1.el9_4 for supported architectures and subscription channels. The update remediated 10 CVEs across BPF, cryptography, networking, USB, MMC/SDIO, pin control, PowerPC, and s390 ptrace code; affected systems require a reboot.
Red Hat issued Important advisory RHSA-2025:13135 for RHEL 9.4 support channels, providing kernel version 5.14.0-427.81.1.el9_4. The update remediated 21 CVEs affecting USB, PowerPC, networking, memory management, media, cryptography, and other kernel components; affected systems require a reboot.
Red Hat issued Important advisory RHSA-2025:11810 for RHEL 9.4 supported update channels, providing kernel version 5.14.0-427.79.1.el9_4. The update remediated 17 CVEs across components including OverlayFS, traffic control, AMD display, UDMABUF, firmware DSP handling, ext4, networking, and USB; affected systems require a reboot.
Red Hat issued Important advisory RHSA-2025:10701 for RHEL 9.4 supported update channels, providing kernel version 5.14.0-427.76.1.el9_4. The update remediated 19 CVEs affecting USB, Wi-Fi, networking, ext4, graphics, pin control, MD, UDF, and other kernel components; systems require a reboot after installation.
An upstream Linux kernel advisory announced the resolution of CVE-2025-38051, a cifs_fill_dirent use-after-free caused by concurrent readdir operations accessing a released SMB response buffer. The advisory included a proof of concept for triggering the race.
Red Hat issued Important advisory RHSA-2025:8248 for RHEL 9.4 EUS and associated channels, providing kernel 5.14.0-427.70.1.el9_4. The update remediated 12 CVEs affecting filesystem, RDMA, networking, USB, input, Wi-Fi, graphics, vsock, and PPP components; affected systems require a reboot.
Red Hat issued Important advisory RHSA-2025:7526 for RHEL 9.4 Extended Update Support and associated offerings, providing kernel build 5.14.0-427.68.1.el9_4. The update remediated 11 CVEs affecting vhost, Wi-Fi, DMA, cachefiles, memory management, cryptography, generic radix trees, and netfilter ipset; systems require a reboot.
Red Hat issued Important advisory RHSA-2025:4509 for RHEL 9.4 Extended Update Support and related offerings, providing kernel version 5.14.0-427.67.1.el9_4. The update remediated nine CVEs affecting UBIFS, iwlwifi, mlxsw, hardware monitoring, SUNRPC, IPVS, driver APIs, LSM hooks, and NVMe/TCP; systems require a reboot.
Red Hat issued Moderate advisory RHSA-2025:3510 for RHEL 9.4 support channels, providing kernel version 5.14.0-427.62.1.el9_4. The update remediated nine described kernel vulnerabilities affecting CEC, traffic control, KVM, SUNRPC, Wi-Fi, DRM, ERSPAN, block statistics, and virtio-vsock; systems require a reboot.
Red Hat issued Important advisory RHSA-2025:2490 for RHEL 9.4 update channels, providing kernel version 5.14.0-427.59.1.el9_4. The update remediated ten CVEs affecting x86 FPU handling, Think-LMI, hwrng, RDMA/srpt, nvmem, LEDs, HID, CAN BCM, and ALSA USB audio; systems require a reboot.
Mauro Matteo Cascella reported CVE-2023-52803, a medium-severity SUNRPC flaw in which an RPC client could clean up already-freed pipefs dentries, with automated analysis identifying a potential KASAN use-after-free. Upstream fixes were incorporated in Linux 5.10.202, 5.15.140, 6.1.64, 6.5.13, and 6.6.3; Red Hat later addressed it in RHEL 8 and RHEL 9.4 EUS advisories.
Zack Miele reported CVE-2024-35801, a low-severity Linux kernel x86 FPU issue in which xfd_state was not kept synchronized with the MSR_IA32_XFD register. Upstream resolved it with “x86/fpu: Keep xfd_state in sync with MSR_IA32_XFD”; Red Hat later addressed it for RHEL 8, RHEL 9, and RHEL 9.4 EUS.
The Linux kernel CVE team documented CVE-2024-27013, in which a TUN device could print messages excessively when receiving illegal packets. The upstream fix rate-limits those log messages; Red Hat later shipped fixes for RHEL 8, RHEL 9, and RHEL 9.4 EUS.
Zack Miele reported CVE-2023-52653 to Red Hat as Bug 2278515, covering a low-severity memory leak in the Linux SUNRPC function gss_import_v2_context. Upstream fixes were included in Linux kernel 6.6.23, 6.7.11, 6.8.2, and 6.9-rc1, and Red Hat later addressed the issue for RHEL 8 and RHEL 9.4 EUS.
Robb Gatica reported CVE-2024-26901, a low-severity Linux kernel information-disclosure flaw in do_sys_name_to_handle() that could expose uninitialized kernel memory. The issue was fixed by using kzalloc() to zero-initialize the allocation and was later addressed in RHEL 8, RHEL 9, and RHEL 9.4 EUS advisories.
The Linux kernel CVE team assigned CVE-2023-52565 for an out-of-bounds read in the uvcvideo media driver. The issue was resolved upstream by the “media: uvcvideo: Fix OOB read” change and was referenced in an upstream advisory.
ybuenos reported CVE-2024-25739, a medium-severity Linux kernel denial-of-service flaw in the UBI subsystem's create_empty_lvol() function. A missing ubi->leb_size validation could trigger a zero-byte allocation and kernel crash; upstream fixed the issue in Linux 6.9-rc1, and Red Hat later remediated it for RHEL 8, RHEL 9, and RHEL 9.4 EUS.
Rohit Keshri reported CVE-2024-23848, a medium-severity use-after-free in the Linux kernel CEC subsystem's cec_queue_msg_fh function affecting kernels through 6.7.1. The issue was tracked by Red Hat as Bug 2260038 and later remediated for RHEL 8, RHEL 9, and RHEL 9.4 EUS.
The Linux kernel CVE team assigned CVE-2024-27056 for an iwlwifi MVM Wi-Fi driver vulnerability resolved by ensuring that an offloading TID queue exists. Red Hat addressed the flaw for RHEL 8 in RHSA-2024:3618 and RHSA-2024:3627, and for RHEL 9.4 EUS in RHSA-2025:4509.
The Linux kernel CVE team assigned CVE-2021-47386 for a NULL-pointer dereference in the hwmon w83791d driver. The upstream fix removes an unnecessary structure field, and Red Hat addressed the flaw for RHEL 8, RHEL 9, and RHEL 9.4 EUS.
The Linux kernel CVE team assigned CVE-2023-52622 for an ext4 issue in which an oversized flex block group could cause online filesystem resizing failures. Fedora fixed the issue in Linux 6.7.4 stable updates, and Red Hat later addressed it for RHEL 8, RHEL 9, and RHEL 9.4 EUS.
The Linux kernel CVE team assigned CVE-2023-52594 for a potential array-index-out-of-bounds read in the ath9k_htc_txstatus() Wi-Fi driver function. Fedora fixed it in Linux 6.7.4 stable updates, and Red Hat later remediated it for RHEL 8, RHEL 9, and RHEL 9.4 EUS through listed RHSA advisories.
The Linux kernel resolved CVE-2024-35868, a potential use-after-free vulnerability in the SMB/CIFS client function cifs_stats_proc_write(). Red Hat addressed the issue in multiple RHEL 9 offerings, including through RHSA-2025:22095, RHSA-2025:22124, RHSA-2026:0173, RHSA-2026:0537, and RHSA-2026:0576.
The Linux kernel addressed CVE-2025-38724 in nfsd4_setclientid_confirm(), where an NFSv4 SETCLIENTID_CONFIRM race with confirmed-client expiration could leave get_client_locked() unchecked and lead to a use-after-free. The fix acquires a confirmed-client reference earlier and handles failed reference acquisition and expiring unconfirmed clients safely.
The Linux kernel resolved CVE-2025-39982, a Bluetooth use-after-free in hci_acl_create_conn_sync that could occur when a BT_OPEN connection was freed concurrently during command submission. The fix also covered similar connection-creation behavior in hci_le_create_conn_sync.
Red Hat issued Moderate advisory RHSA-2026:2583 for RHEL 9.2 kernel-rt packages, releasing version 5.14.0-284.156.1.rt14.441.el9_2. The update included a fix for CVE-2025-38051 and eight other Linux kernel vulnerabilities across RDMA, Bluetooth, DRM, MPTCP, devlink, fbdev, and font handling.
The Linux kernel CVE team assigned CVE-2023-52520 for a reference leak in the platform/x86 Think-LMI component. Upstream resolved it with the “platform/x86: think-lmi: Fix reference leak” patch, and Red Hat later addressed it in RHEL 8, RHEL 9, and RHEL 9.4 EUS advisories.
Red Hat addressed CVE-2024-27010, a Linux net/sched mirred action flaw that could deadlock during recursive device handling, through RHSA-2024:5101 and RHSA-2024:5102 for RHEL 8 and RHSA-2024:9315 for RHEL 9. The issue was also included in the existing RHEL 9.4 EUS advisory RHSA-2025:3510.
The Linux kernel fixed CVE-2025-68301 in the Atlantic driver RX path, where large multi-descriptor packets could exceed MAX_SKB_FRAGS and cause an out-of-bounds write in skb_add_rx_frag_netmem(). The fix accounts for an extra fragment for oversized buffers and uses an earlier bounds check.
The Linux kernel fixed CVE-2022-50865, a signed integer overflow in tcp_add_backlog() caused by calculating a limit from integer receive and send buffer values plus 64 KB. The patch reduces the limit budget and halves the send-buffer contribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
45 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.