Red Hat released Important-rated kernel security updates across Red Hat Enterprise Linux (RHEL) 8, 9, and 10, addressing flaws in USB, graphics, networking, storage, Bluetooth, and virtualization-related components. Among the remediated issues are CVE-2025-68287, a use-after-free race in the DWC3 USB gadget driver that can occur during concurrent request removal, and CVE-2025-40277, in which inadequate validation of VMware SVGA (drm/vmwgfx) command-header sizes can permit integer overflow and out-of-bounds memory access from user-controlled data.
RHEL 9 advisory RHSA-2026:0793 fixes the DWC3 and vmwgfx defects alongside vulnerabilities in DRM/Xe, SMB client handling, and libceph; RHEL 8 updates also address vmwgfx, vsock memory corruption, IPv6 out-of-bounds access, and other subsystem flaws for supported AUS, EUS, real-time, NFV, SAP, and lifecycle variants. RHEL 10 kernel updates remediate DRM/Xe, Bluetooth ISO, TLS, and libceph issues. Organizations should install the applicable updated kernel packages through their supported RHEL repositories and reboot affected systems to activate the fixes.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-security advisory RHSA-2026:0917 for RHEL 9.4 servicing channels, providing kernel version 5.14.0-427.107.1.el9_4. The update fixes CVE-2025-40277 and four additional kernel flaws involving iommufd, KVM arm64, ALSA UMP, and the ASoC bytcr_rt5640 driver.
Red Hat issued an Important kernel update for RHEL 10.0, fixing vulnerabilities in drm/xe, Bluetooth ISO, TLS message handling, and libceph, including the potential libceph use-after-free CVE-2025-68285.
An upstream Linux CVE announcement referenced CVE-2025-40277, involving insufficient validation of userspace-controlled command-header sizes in the drm/vmwgfx VMware SVGA driver.
An upstream Linux CVE announcement referenced CVE-2025-37849, a KVM arm64 flaw where failed vCPU creation could leave vGIC vCPU data initialized, causing a memory leak or potential use-after-free. The upstream fix destroys the vGIC vCPU structures on the failure path.
Red Hat issued an Important kernel update for selected RHEL 8.6 AUS, TUS, Extended Life Cycle Long Life, and SAP support variants. The update remediates CVE-2025-40277 and flaws in mac80211, media remote-control handling, IPv6, and vsock.
Red Hat issued an Important security update for RHEL Server AUS 8.2 on x86_64. It fixes CVE-2025-40277 and five additional kernel vulnerabilities affecting e1000e, media remote-control handling, IPv6 parsing, vsock, and Bluetooth L2CAP.
Red Hat issued an Important kernel-rt update for RHEL 8 Real Time, Real Time for NFV, and Extended Life Cycle 8.10 systems. The update fixes CVE-2025-40277 along with Bluetooth, ASoC, and vsock kernel vulnerabilities.
Red Hat addressed CVE-2025-21724, an iommufd/iova_bitmap shift-out-of-bounds flaw, for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions through RHSA-2026:1441 and RHSA-2026:1443. The upstream fix changes a shifted constant from "1" to "1UL" to prevent undefined shifts at page-shift values above 31.
Red Hat issued an Important kernel security update for RHEL 9 that fixes CVE-2025-40277 in drm/vmwgfx and CVE-2025-68287, a DWC3 USB request-removal race that can cause a use-after-free crash. The advisory also remediates DRM/Xe, SMB client, and libceph flaws.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.