Red Hat released Important-rated kernel and kernel-rt updates for Red Hat Enterprise Linux 7 Extended Lifecycle Support, addressing memory-safety flaws in the Intel i40e and e1000e network drivers and a vsock vulnerability. The i40e_vc_config_queues_msg() flaw, tracked as CVE-2025-39971, inadequately validates traffic-class indexes and can enable a low-privileged attacker to trigger out-of-bounds memory access, potentially causing memory corruption, denial of service, or code execution; Red Hat rates it CVSS 7.6.
The updates also remediate CVE-2025-39898, a heap-overflow condition in e1000_set_eeprom() caused by insufficient EEPROM-change length validation, and CVE-2025-40248, which can cause vsock memory corruption. RHSA-2026:1581 covers RHEL 7 ELS systems on x86_64, IBM Z, and IBM Power, while RHSA-2026:1623 supplies kernel-rt version 3.10.0-1160.146.1.rt56.1298.el7 for RHEL for Real Time 7 x86_64 ELS. Red Hat says no qualifying mitigations are available and requires a reboot after installation for the fixes to take effect.

See real exploitation activity before you spend the cycle.
17 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2026:3848, supplying RHEL 8 kpatch live-patch modules for CVE-2025-40248, the Linux kernel vsock memory-corruption vulnerability. The modules target kernel-4.18.0-553.30.1.el8_10 and support x86_64 and ppc64le deployments, including RHEL 8.10 Extended Life Cycle systems.
Red Hat published CVE-2025-40248, an Important-severity Linux kernel vsock flaw where an interrupted connect() on an established socket can cause incorrect state handling and a race condition. A low-privileged local attacker could potentially cause denial of service or escalate privileges through memory-corruption conditions, including use-after-free or null-pointer dereference.
Red Hat released RHSA-2025:22395 for the RHEL 10 kernel, fixing CVE-2025-39898 and CVE-2025-39971. It also released RHSA-2025:22388 and RHSA-2025:22387 for the RHEL 8 kernel and kernel-rt, respectively, to fix CVE-2025-39898.
Red Hat issued Moderate-severity RHSA-2025:21933 for RHEL 9.6 kernel packages, updating them to version 5.14.0-570.66.1.el9_6. The advisory fixes CVE-2025-39898 and CVE-2025-39971 as well as CVE-2025-40047, and requires affected systems to be rebooted.
Red Hat issued RHSA-2025:21920 for RHEL 8 kernel-rt packages, remediating CVE-2025-39697, a race condition when updating an existing NFS write. The update applies to Real Time 8, Real Time for NFV 8, and RHEL 8.10 Extended Life Cycle systems and requires a reboot.
Red Hat released RHSA-2025:21917 and RHSA-2025:21920, updating the RHEL 8 kernel and kernel-rt packages to fix CVE-2025-39971.
Red Hat published CVE-2025-39971, an out-of-bounds write issue caused by inadequate traffic-class index validation in the Linux kernel Intel i40e driver.
Red Hat published the CVE-2025-39898 record for a reported heap overflow in the Linux e1000e driver's e1000_set_eeprom() function. The assigning CNA marked the CVE as Rejected.
Red Hat documented CVE-2025-40047, in which io_waitid_wait() could leave a wait-queue entry in place during cancellation and race with another callback invocation. Red Hat linked fixes for RHEL 9, RHEL 9.6 EUS, RHEL 10, and RHEL 10.0 EUS to RHSA-2025:21469, RHSA-2025:21933, RHSA-2025:22854, and RHSA-2026:1727, respectively.
Red Hat released RHSA-2026:1886, updating RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On kernel packages to fix CVE-2025-39971.
Red Hat issued Important-rated RHSA-2026:1623 for RHEL for Real Time 7 x86_64 under Extended Lifecycle Support. Kernel-rt version 3.10.0-1160.146.1.rt56.1298.el7 fixed CVE-2025-39898, CVE-2025-39971, and CVE-2025-40248, and requires a reboot to take effect.
Red Hat issued Important-rated RHSA-2026:1581 for RHEL 7 Extended Lifecycle Support, supplying kernel version 3.10.0-1160.146.1.el7. The update fixed CVE-2025-39898, CVE-2025-39971, and CVE-2025-40248; Red Hat said affected systems must be rebooted after installation.
Red Hat released RHSA-2026:1512 for the RHEL 8.2 Advanced Update Support kernel, fixing CVE-2025-39898.
Red Hat released RHSA-2026:0643, updating the RHEL 8.2 Advanced Update Support kernel to fix CVE-2025-39971.
Red Hat released RHSA-2026:0533 for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On, and RHSA-2026:0536 for RHEL 8.6 Advanced Mission Critical Update Support. These kernel updates fixed CVE-2025-39898; RHSA-2026:0536 also fixed CVE-2025-39971.
Red Hat released RHSA-2025:22571 for the RHEL 10.0 Extended Update Support kernel, addressing CVE-2025-39898 and CVE-2025-39971.
The Linux kernel CVE team disclosed that CVE-2025-40248 affects net/vmw_vsock/af_vsock.c and fixed it in stable releases 5.4.302, 6.6.118, 6.12.60, 6.17.10, and 6.18. The fix prevents connect() from disconnecting a socket that has already become established after a signal or timeout.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcelore.kernel.org
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.