Red Hat released kernel and real-time kernel updates for supported RHEL 8 and RHEL 9 channels, including AUS, EUS, SAP Update Services, Extended Life Cycle, and mission-critical offerings. The advisories address memory-safety vulnerabilities in subsystems including SMC, ATM, bridge multicast, macvlan, BPF sockmap, exFAT, traffic control cls_u32, and nf_tables, affecting x86_64, aarch64, ppc64le, and s390x deployments depending on the release.
The fixes include CVE-2026-23231, a use-after-free in nf_tables_addchain() that could enable local privilege escalation or denial of service, and CVE-2025-38206, an exFAT delayed-free double-free that can cause denial of service. Other remediated flaws include CVE-2025-38180, CVE-2025-38248, CVE-2026-23001, CVE-2025-40064, and CVE-2025-40168; Red Hat advises organizations to install the applicable updated kernel packages and reboot affected systems to activate the fixes.

See real exploitation activity before you spend the cycle.
23 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity RHSA-2026:9643 for RHEL 8.4 AUS and Extended Life Cycle Long Life offerings. Kernel version 4.18.0-305.189.1.el8_4 addresses CVE-2025-40064, CVE-2025-40168, CVE-2026-23204, and CVE-2026-23231.
Red Hat issued Moderate-severity RHSA-2026:9514 for several RHEL 8.6 support variants. Kernel version 4.18.0-372.188.1.el8_6 fixes CVE-2025-40064, CVE-2025-40168, CVE-2026-23204, and CVE-2026-23231; affected systems must be rebooted.
Red Hat issued Moderate-severity RHSA-2026:9513 for RHEL 8.2 AUS on x86_64. Kernel version 4.18.0-193.195.1.el8_2 fixes CVE-2025-40064, CVE-2025-40168, CVE-2026-23204, and CVE-2026-23231, including the nf_tables privilege-escalation or denial-of-service issue.
Red Hat issued Moderate-severity RHSA-2026:7100 for RHEL 9.0 SAP Solutions kernel-rt packages. Version 5.14.0-70.173.1.rt21.245.el9_0 fixes CVE-2025-38154, CVE-2025-38180, CVE-2025-38206, CVE-2025-38248, and CVE-2026-23209.
Red Hat issued Moderate-severity RHSA-2026:6986 for RHEL 9.2 support channels, fixing the ATM use-after-free CVE-2025-38180, exFAT double-free CVE-2025-38206, and macvlan use-after-free CVE-2026-23001. The update supplies kernel build 5.14.0-284.164.1.el9_2 for x86_64, aarch64, ppc64le, and s390x.
Red Hat issued Low-severity RHSA-2026:6948 for the RHEL 9.2 Real Time Linux Kernel. Kernel-rt version 5.14.0-284.164.1.rt14.449.el9_2 fixes CVE-2025-38180, CVE-2025-38206, and CVE-2026-23001; a reboot is required.
Red Hat issued Moderate-severity RHSA-2026:6940 for RHEL 9.6, fixing CVE-2025-38180 in the ATM subsystem and CVE-2026-23231 in nf_tables_addchain(). The latter use-after-free could enable privilege escalation or denial of service; updated packages are version 5.14.0-570.106.1.el9_6.
Red Hat issued RHSA-2026:5197, a Moderate RHEL 9.6 kernel update, fixing CVE-2025-38248 in bridge multicast handling and CVE-2026-23001 in macvlan_forward_source(). The update provides kernel version 5.14.0-570.100.1.el9_6 and requires a reboot.
Red Hat issued Moderate-severity RHSA-2026:3966 for RHEL 9 kernel packages, fixing CVE-2025-38106, an io_uring use-after-free that may permit local privilege escalation, information disclosure, or denial of service, and CVE-2026-23001 in macvlan_forward_source(). The update applies to RHEL 9 architectures and associated support offerings; affected systems require a reboot after installation.
Red Hat issued Moderate-severity RHSA-2025:11570 for selected RHEL 8.6 extended-support and update-service channels. Kernel version 4.18.0-372.153.1.el8_6 fixes CVE-2022-49395, CVE-2022-49058, and the ATM LANE lec_send() use-after-free CVE-2025-22004; affected systems require a reboot.
Red Hat issued Important-rated RHSA-2025:11358 for RHEL 7 Extended Lifecycle Support, supplying kernel version 3.10.0-1160.136.1.el7. The update fixes the ATM LEC send use-after-free CVE-2025-22004 and Atlantic network-driver out-of-range index flaw CVE-2022-50066; affected systems require a reboot.
Red Hat issued Important-rated RHSA-2025:11245 for RHEL 9.4 subscription and lifecycle variants. Kernel version 5.14.0-427.77.1.el9_4 fixes seven flaws, including CVE-2025-22004 in ATM lec_send(), IPv6 multicast, Squashfs, ext4, and MDIO issues; affected systems require a reboot.
An upstream Linux kernel advisory for CVE-2025-38206 was referenced. The flaw is a double-free in the exFAT delayed_free path that can lead to denial of service.
An upstream Linux kernel advisory disclosed CVE-2025-38024, a slab use-after-free read in the RDMA/rxe rxe_queue_cleanup path caused by overlapping cleanup after rxe_cq_from_init fails. The fix centralizes resource cleanup in rxe_cleanup.
An upstream Linux CVE announcement disclosed CVE-2025-22004, a use-after-free in the ATM networking subsystem's lec_send() function. The flaw results when a send operation frees an skb before later code accesses its length; the upstream fix saves the length before invoking send.
Red Hat issued Moderate-severity RHSA-2024:7489 for RHEL 9.2 extended-support and associated service channels. Kernel version 5.14.0-284.86.1.el9_2 fixes four flaws in netfilter bridge multicast processing, bridge MST VLAN handling, Open vSwitch ICMPv6 connection tracking, and netfilter TPROXY; affected systems require a reboot.
Red Hat documented CVE-2024-27415, a Linux kernel netfilter bridge flaw involving confirmation of multicast packets before they are passed up the stack. Red Hat addressed it through RHSA-2024:5928 for RHEL 9 and RHSA-2024:7490 and RHSA-2024:7489 for RHEL 9.2 Extended Update Support.
Red Hat documented CVE-2023-51780, a use-after-free in the Linux kernel's net/atm/ioctl.c do_vcc_ioctl function caused by a race involving vcc_recvmsg. Fedora fixed the issue in Linux 6.6.8 stable updates, while Red Hat addressed it through RHSA-2024:2394 for RHEL 9 and RHSA-2024:2950 and RHSA-2024:3138 for RHEL 8.
Red Hat identified RHSA-2026:7013 as addressing CVE-2025-38206 for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.
Red Hat identified RHSA-2026:4745 as addressing CVE-2025-38206 for Red Hat Enterprise Linux 9.6 Extended Update Support.
Red Hat identified RHSA-2026:4246 as addressing CVE-2025-38206 for Red Hat Enterprise Linux 9.4 Extended Update Support.
Red Hat identified RHSA-2026:3275 as an advisory addressing the exFAT double-free vulnerability CVE-2025-38206 for Red Hat Enterprise Linux 10.
Red Hat identified RHSA-2026:3066 as an advisory addressing the exFAT double-free vulnerability CVE-2025-38206 for Red Hat Enterprise Linux 9.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
21 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.