Red Hat released Important-rated kernel updates for specialized RHEL 8.8 and RHEL 9.2 support channels, addressing TCP Fast Open (TFO) flaws including CVE-2025-40186. A low-privileged local attacker could close a listener while tcp_conn_request() processes a TFO socket, triggering use-after-free and double-free conditions that may cause a kernel panic or potentially enable privilege escalation. The RHEL 8.8 update also fixes CVE-2025-39955 and the memory-management race condition tracked as CVE-2023-53401; the RHEL 9.2 update additionally remediates qla2xxx driver flaw CVE-2023-53322 and cfg80211 Wi-Fi flaw CVE-2025-39864.
Affected deployments include RHEL 8.8 Extended Life Cycle Long Life, TUS, and SAP update channels on x86_64 and Power LE, and RHEL 9.2 AUS, SAP, four-year update, and Extended Life Cycle offerings across x86_64, ARM64, IBM Z, and Power LE. Red Hat supplied fixed kernel builds 4.18.0-477.123.1.el8_8 for the covered RHEL 8.8 channels and 5.14.0-284.150.1.el9_2 for RHEL 9.2; administrators should install the applicable packages and reboot systems to activate the fixes.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2025:23423 for RHEL 9.2 specialized update offerings. Kernel version 5.14.0-284.150.1.el9_2 fixes CVE-2023-53322, CVE-2025-39864, CVE-2025-39955, and CVE-2025-40186.
Red Hat released RHEL 8 kernel-rt and kernel updates through RHSA-2025:22387 and RHSA-2025:22388 to address CVE-2025-40186, a TCP Fast Open use-after-free and double-free flaw.
An upstream Linux CVE announcement was published for CVE-2023-53401, a race condition in the kernel memory-control-group kmem code that can lead to a NULL-pointer dereference.
Red Hat issued Important-rated RHSA-2025:14418 for selected RHEL 8.8 service variants, updating the kernel to version 4.18.0-477.106.1.el8_8. The update remediates CVE-2025-21919, CVE-2025-22020, CVE-2022-50020, CVE-2025-38086, and CVE-2025-38380; affected systems require a reboot.
An upstream Linux CVE announcement identified CVE-2025-38086 in the CH9200 network driver's MDIO restart path, where ch9200_mdio_read() could use an uninitialized buffer after control_read() failed or returned an unexpected size. The fix validates control_read()'s return value and exits on error.
Red Hat addressed CVE-2023-53401 in RHEL 8 through RHSA-2025:22800 and RHSA-2025:22801, and in RHEL 8.4 and 8.6 specialized support channels through RHSA-2026:0533 and RHSA-2026:0536.
Red Hat issued RHSA-2025:21051 and RHSA-2025:21128 for RHEL 9.2 SAP Solutions streams, and RHSA-2025:21091 and RHSA-2025:21136 for RHEL 9.0 SAP Solutions streams, addressing CVE-2023-53401.
Red Hat addressed CVE-2023-53401 in the RHEL 9.4 Extended Update Support channel through RHSA-2025:19886.
Red Hat issued Important-rated RHSA-2025:23427 for RHEL 8.8 specialized update channels. The kernel 4.18.0-477.123.1.el8_8 update remediates CVE-2023-53401, CVE-2025-39955, and CVE-2025-40186; affected systems require a reboot after installation.
Red Hat released RHSA-2025:23425 to address CVE-2025-40186 in RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and SAP Solutions channels.
Red Hat released RHSA-2025:23463 for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On channels, addressing CVE-2025-40186.
Red Hat released RHSA-2025:23445 to remediate CVE-2025-40186 for the RHEL 8.2 Advanced Update Support stream.
The Linux kernel CVE team assigned CVE-2025-40186 to a TCP Fast Open request-socket lifetime flaw in tcp_conn_request() that can cause reference-count underflow, use-after-free, and double-free conditions. The upstream fix removes reqsk_fastopen_remove() from tcp_conn_request(), with fixed stable releases including 5.4.301, 5.10.246, 5.15.195, 6.1.157, 6.6.113, 6.12.54, 6.17.4, and 6.18-rc1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.