Red Hat released Important-rated RHEL 8 kernel security updates addressing flaws in the iMON media remote-control driver, Ceph client, SCTP, SMB/CIFS client, EFI variable filesystem, and other kernel components. The primary defects include a use-after-free caused by a disconnect race in imon_disconnect() (CVE-2025-39993), a libceph use-after-free during session initialization (CVE-2025-68285), an SMB-client rename race (CVE-2025-39825), and an out-of-bounds read in efivarfs_d_compare (CVE-2025-39817). The iMON and Ceph issues stem from unsynchronized access to device or map pointers; upstream fixes add disconnected-state validation and locking around protected data.
Advisories RHSA-2026:0443 and RHSA-2026:0444 provide kernel and kernel-rt version 4.18.0-553.92.1 for supported RHEL 8 and RHEL 8.10 Extended Life Cycle streams, remediating CVE-2025-39993, CVE-2025-68285, and SCTP NULL-pointer dereference CVE-2025-40240. RHSA-2026:0533 updates RHEL 8.4 Advanced Update Support and Extended Life Cycle Long Life deployments with 4.18.0-305.183.1.el8_4 or later, addressing 12 kernel issues including SMB, EFI, media, and Ceph vulnerabilities. Organizations should apply the applicable package update and reboot affected systems to activate the patched kernel.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-rated RHSA-2026:2446 for RHEL 8 kpatch live-patch packages, remediating the libceph use-after-free vulnerability CVE-2025-68285. The update provides kpatch modules for multiple 4.18.0-553 kernel builds on x86_64 and ppc64le, including RHEL 8.10 Extended Life Cycle offerings.
Red Hat released RHSA-2026:0786 and RHSA-2026:0747 for RHEL 10 and RHEL 10.0 Extended Update Support, plus RHSA-2026:0755 and RHSA-2026:0754 for RHEL 7 Extended Lifecycle Support kernel and kernel-rt packages. The advisories remediate the libceph use-after-free vulnerability CVE-2025-68285.
Red Hat issued Important-rated RHSA-2026:0643 for RHEL Server 8.2 AUS on x86_64, providing kernel version 4.18.0-193.181.1.el8_2. The update fixes vulnerabilities including CVE-2025-38051 in SMB/CIFS, CVE-2023-53322 in qla2xxx, CVE-2023-53675 in the SES driver, CVE-2025-39971 in Intel i40e, and CVE-2025-68285 in the Ceph client; systems require a reboot after installation.
Red Hat issued Important-rated RHSA-2026:0533 for RHEL 8.4 AUS and Extended Life Cycle Long Life deployments, supplying kernel version 4.18.0-305.183.1.el8_4. It remediates CVE-2025-39817, CVE-2025-39825, CVE-2025-39993, CVE-2025-68285, and eight other kernel vulnerabilities.
Red Hat published RHSA-2026:0443 and RHSA-2026:0444 for RHEL 8, providing kernel-rt and standard kernel packages version 4.18.0-553.92.1.el8_10. The advisories remediate CVE-2025-39993, CVE-2025-40240, and CVE-2025-68285 and require a reboot after installation.
Red Hat issued Important-rated RHSA-2025:23445 for RHEL Server AUS 8.2 on x86_64, providing kernel version 4.18.0-193.178.1.el8_2. The update remediates 31 kernel vulnerabilities, including CVE-2025-39817 and CVE-2025-39825, and requires a reboot after installation.
An upstream Linux CVE announcement disclosed CVE-2025-68285, a potential use-after-free in libceph's have_mon_and_osd_map() during Ceph session initialization. The fix protects monitor-map and OSD-map condition checks with their respective locks.
An upstream Linux CVE announcement disclosed CVE-2025-39971 in the Intel i40e driver's i40e_vc_config_queues_msg() handler. The flaw could iterate over vf->ch[idx] without validating that idx was within the active or initialized traffic-class range; the fix validates the index before iteration.
An upstream Linux CVE announcement disclosed CVE-2025-39825, a race in SMB client rename(2) handling that could allow concurrent opens of the rename target. The kernel fix unhashed the target dentry before rename processing to prevent concurrent opens.
Red Hat issued Important-rated RHSA-2025:15035 for RHEL 8.4 AUS and Extended Life Cycle Long Life on x86_64, providing kernel version 4.18.0-305.170.1.el8_4. The update fixes multiple vulnerabilities, including use-after-free issues in padata, peak_usb, HFSC, and Bluetooth, and requires systems to reboot after installation.
Red Hat issued Important-rated RHSA-2025:13120 for RHEL 8.4 AUS and Extended Life Cycle Long Life on x86_64, providing kernel version 4.18.0-305.166.1.el8_4. The update remediates five vulnerabilities, including flaws in uvcvideo, intel-ish-hid, vmw_vmci, and TIPC, and requires affected systems to reboot.
Red Hat issued Important-rated RHSA-2023:3491 for Red Hat Virtualization 4 and Red Hat Virtualization Host 4 on RHEL 8 x86_64. The update remediated six Linux kernel, Samba, and Open vSwitch vulnerabilities, including multiple use-after-free flaws, a kernel stack overflow, and weak NetLogon Secure Channel configuration.
Fedora fixed the CVE-2022-4378 Linux kernel sysctl stack-overflow vulnerability in stable Linux kernel 6.0.12 updates. The flaw in do_proc_dointvec could let a local user with SYSCTL access crash a system and potentially escalate privileges using malformed sysctl input.
The Linux kernel fixed CVE-2025-39993, a race between active iMON driver writer paths and imon_disconnect() that could dereference a freed USB device. The remediation synchronizes disconnected-state access and returns -ENODEV from affected operations after disconnection.
The Linux kernel fixed CVE-2025-39817 in efivarfs_d_compare, where an invalid filename shorter than EFI_VARIABLE_GUID_LEN could produce a negative guid offset and an out-of-bounds memcmp during parallel lookup. The fix validates guid before comparing the dentry name.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
16 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.