Red Hat released Moderate- and Important-severity Linux kernel security updates across RHEL 8 and RHEL 9 support channels, including Real Time, NFV, SAP Solutions, Extended Life Cycle, Extended Update Support, and Application Update Services offerings. The advisories address vulnerabilities in NFS server processing, SMB/CIFS rename handling, memory-failure recovery, TCP Fast Open, Wi-Fi, Bluetooth, USB audio, EFI variables, SCTP, IPv6 routing, ext4, and network drivers. Updated packages include 4.18.0-553.87.1.el8_10 for RHEL 8.10, 4.18.0-477.120.1.el8_8 for selected RHEL 8.8 channels, 5.14.0-284.148.1.el9_2 for RHEL 9.2 SAP-related channels, and 5.14.0-570.69.1.el9_6 for RHEL 9.6.
The updates include a fix for CVE-2023-53513, an NBD nbd_ioctl validation flaw in which an oversized ioctl argument could cause signed integer overflow during block-write processing and unexpected behavior when narrowed on 64-bit systems. Red Hat also shipped the corresponding real-time kernel build, 4.18.0-553.87.1.rt7.428.el8_10, for affected RHEL 8 real-time deployments. Organizations should apply the appropriate kernel packages for their subscribed architecture and support channel, then reboot systems to activate the fixes; the advisories do not state that the listed issues are under active exploitation.

See real exploitation activity before you spend the cycle.
17 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate advisory RHSA-2025:23000 for RHEL 8.6 Extended Life Cycle, Advanced Update Support, Telecommunications Update Service, and SAP Update Services variants. Kernel version 4.18.0-372.172.1.el8_6 remediates CVE-2025-38724 in NFS server client-confirmation handling and CVE-2023-53226, an mwifiex Wi-Fi driver out-of-bounds and integer-underflow flaw.
Red Hat issued Important advisory RHSA-2025:22392 for RHEL 9.6 servicing channels, supplying kernel 5.14.0-570.69.1.el9_6. It remediated seven CVEs affecting NFS, cfg80211 and mt76 Wi-Fi components, memory unpoisoning, kernfs polling, and TCP Fast Open.
Red Hat issued Moderate advisory RHSA-2025:22388 for RHEL 8 systems across x86_64, s390x, ppc64le, and aarch64, providing kernel 4.18.0-553.87.1.el8_10. The update fixed six described vulnerabilities involving NFS, SMB rename operations, memory-failure recovery, e1000e, NBD ioctl validation, and TCP Fast Open.
Red Hat issued Moderate advisory RHSA-2025:22387 for RHEL 8 Real Time, Real Time for NFV, and applicable RHEL 8.10 Extended Life Cycle deployments. Kernel-rt 4.18.0-553.87.1.rt7.428.el8_10 remediated issues including NFS handling, SMB rename races, e1000e heap overflow, NBD ioctl validation, and TCP Fast Open state handling.
Red Hat issued Moderate advisory RHSA-2025:22095 for RHEL 9.2 SAP, AUS, and Extended Life Cycle offerings, supplying kernel 5.14.0-284.148.1.el9_2. It addressed 14 kernel CVEs, including CVE-2023-53513 in NBD and flaws affecting networking, SMB/CIFS, Bluetooth, NFS, Wi-Fi, and x86 VMSCAPE mitigation.
Red Hat issued Moderate advisory RHSA-2025:22072 for selected RHEL 8.8 service channels, providing kernel 4.18.0-477.120.1.el8_8. The update remediates 13 kernel CVEs across components including USB audio, SCTP, Bluetooth, CIFS, ext4, and memory-failure handling.
Red Hat issued Moderate advisory RHSA-2025:21917 for RHEL 8, providing kernel 4.18.0-553.85.1.el8_10 for supported architectures and relevant Extended Life Cycle offerings. The update remediates CVE-2025-39697, an NFS existing-write race, and CVE-2025-39971, an i40e configuration-queues index-validation flaw.
Red Hat issued Moderate advisory RHSA-2025:17397 for standard RHEL 8 and applicable RHEL 8.10 Extended Life Cycle offerings. Kernel 4.18.0-553.78.1.el8_10 remediates CVE-2025-38527 in the SMB/CIFS client and CVE-2025-39730 in NFS filehandle validation; systems must reboot after installation.
Red Hat issued Moderate advisory RHSA-2025:17398 for RHEL 8 Real Time, Real Time for NFV, and RHEL 8.10 Extended Life Cycle on x86_64. Kernel-rt 4.18.0-553.78.1.rt7.419.el8_10 fixes CVE-2025-38527, an SMB/CIFS oplock-break use-after-free, and CVE-2025-39730, an NFS filehandle bounds-checking flaw.
An upstream Linux CVE announcement disclosed CVE-2023-53513, an NBD ioctl-argument validation flaw that could permit integer overflow or unexpected behavior after narrowing a large value to an int.
An upstream Linux CVE advisory disclosed CVE-2025-39730, in which nfs_fh_to_dentry() could access an embedded NFS filehandle before verifying that the supplied filehandle met the required minimum length. The fix validates the minimum filehandle length before accessing the embedded handle.
An upstream Linux CVE announcement disclosed CVE-2025-39697, an NFS race condition in handling existing write requests. The upstream fix acquires the page-group lock earlier and retains it while the request is removed.
CVE-2025-38724 was published for a race condition in the Linux kernel NFS daemon's client-identifier confirmation handling. An expiring NFS client can trigger a use-after-free, potentially causing denial of service or, in a worst case, kernel-context code execution.
An upstream Linux CVE advisory disclosed CVE-2025-38527, a SMB/CIFS client use-after-free in cifs_oplock_break() that can occur when a CIFS filesystem is unmounted during oplock-break processing. The fix holds an additional superblock reference for the operation so associated inodes cannot be destroyed while the function still accesses them.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for the RHEL 8 kernel-rt, fixing CVE-2023-52683, an ACPI LPIT 32-bit unsigned multiplication-overflow vulnerability.
Red Hat released RHSA-2026:3388 for the RHEL 8.2 Advanced Update Support kernel, remediating CVE-2023-53513, an NBD IOCTL argument-validation flaw that can lead to integer overflow or unsafe integer conversion.
Red Hat released RHSA-2025:23445 for the RHEL 8.2 Advanced Update Support kernel, remediating CVE-2025-39825. The flaw is an SMB client rename race that can permit a concurrent open of the rename target during deferred-close and outstanding-I/O handling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
19 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.