Red Hat released moderate-severity Linux kernel security updates for RHEL 10 and RHEL 8 Real Time deployments, addressing flaws in ublk, NFS server handling, memory-failure processing, Intel e1000e and i40e drivers, and the mt76 Wi-Fi driver. The affected RHEL 10 offerings include standard, Extended Update Support, extended-life-cycle, four-year-support, and CodeReady Linux Builder repositories across x86_64, ARM64, IBM Z/s390x, and Power little-endian platforms.
The updates remediate CVE-2025-39918, a linked-list corruption issue in the mt76 driver caused by scheduled WCID entries remaining on a temporary stack list; Red Hat also issued fixes for RHEL 9 and RHEL 9.6 EUS. RHEL 8 kernel-rt packages fix CVE-2025-39697, an NFS race condition during updates to an existing write, and CVE-2025-39971, insufficient index validation in an i40e configuration-queues message. Organizations should install the applicable updated kernel or kernel-rt packages and reboot affected systems to activate the fixes.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:22395, a Moderate-severity RHEL 10 kernel update addressing CVE-2025-22068, CVE-2025-38724, CVE-2025-39883, CVE-2025-39898, CVE-2025-39918, and CVE-2025-39971. The update affects RHEL 10 and related support offerings across x86_64, ARM64, IBM Z/s390x, and Power little-endian architectures, and requires a reboot.
Red Hat issued RHSA-2025:21920, a Moderate-severity kernel-rt update for RHEL 8 that fixes CVE-2025-39697, an NFS write-update race condition, and CVE-2025-39971, insufficient index validation in i40e configuration-queues handling. The update covers Real Time, Real Time for NFV, and RHEL 8.10 Extended Life Cycle offerings; affected systems require a reboot after installation.
Red Hat issued Moderate-severity advisory RHSA-2025:19103 for RHEL 8 kernel-rt packages, updating them to version 4.18.0-553.81.1.rt7.422.el8_10. The update fixes six vulnerabilities, including CVE-2025-39841 in lpfc and flaws in Bluetooth L2CAP/key handling, efivarfs, and cfg80211; systems must be rebooted after installation.
Red Hat issued Moderate-severity advisory RHSA-2025:19102 for RHEL 8 kernel packages, updating them to version 4.18.0-553.81.1.el8_10. The update fixes CVE-2025-39841 and five other described vulnerabilities affecting Bluetooth L2CAP/key handling, efivarfs, and cfg80211; affected systems require a reboot.
An upstream Linux kernel CVE announcement referenced CVE-2025-39918, a linked-list-corruption flaw in the mt76 Wi-Fi driver caused by scheduled WCID entries remaining on a temporary on-stack list.
An upstream Linux CVE announcement disclosed CVE-2025-39841, a race in the SCSI lpfc driver's deferred receive path that could cause double-free or use-after-free conditions. The fix clears and detaches the RQ-buffer context pointer while locked before freeing the buffer after releasing the lock.
Red Hat released RHSA-2025:15782 for the RHEL 10 kernel, fixing CVE-2025-22068, a Linux ublk driver use-after-free issue involving queue freezing and uring_cmd processing.
An upstream Linux CVE announcement documented CVE-2025-22068, a ublk driver flaw in which queue freezing could leave ubq->canceling unset and permit a use-after-free involving uring_cmd operations. The upstream fix sets the canceling flag when the queue is frozen so pending commands are cancelled and completed safely.
Red Hat published security advisory RHSA-2025:21083. The provided reference does not specify the affected products, vulnerabilities addressed, or a date on which the advisory was issued.
Red Hat’s CVE record lists the RHEL 9 kernel-rt package as affected by CVE-2025-39918 and provides no corresponding erratum. It states that RHEL 6, 7, 8 and their listed real-time kernels are unaffected because the vulnerable code is absent.
Red Hat issued RHSA-2025:22571 to remediate CVE-2025-39918 in Red Hat Enterprise Linux 10.0 Extended Update Support.
Red Hat issued RHSA-2025:22392 to remediate CVE-2025-39918 in Red Hat Enterprise Linux 9.6 Extended Update Support.
Red Hat issued RHSA-2025:22405 to address CVE-2025-39918, the mt76 Wi-Fi driver linked-list-corruption vulnerability, in Red Hat Enterprise Linux 9.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
15 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourcecwe.mitre.org
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.