Red Hat released Important-security-impact kernel updates for RHEL 9.0 Update Services for SAP Solutions, addressing five kernel vulnerabilities in the qla2xxx SCSI driver, TCP Fast Open (TFO), cfg80211 Wi-Fi handling, and Network Block Device ioctl validation. The updates include CVE-2023-53322, a qla2xxx use-after-free condition in which terminate_rport_io() may return before outstanding FCP-2 I/O completes, potentially causing a system crash, and CVE-2025-40186, a TFO request-path refcount underflow/use-after-free caused by duplicate removal of a request socket while a listening socket is closed.
RHSA-2025:23424 supplies kernel-rt-5.14.0-70.158.1.rt21.230.el9_0 for x86_64 RHEL 9.0 SAP Solutions real-time deployments, while RHSA-2025:23426 provides kernel-5.14.0-70.158.1.el9_0 for affected x86_64, ppc64le, and specified aarch64 and s390x offerings. Organizations should install the applicable kernel packages and reboot affected systems to activate the fixes; no qualifying mitigation was listed for CVE-2023-53322.

See real exploitation activity before you spend the cycle.
27 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:23947 and RHSA-2025:23960 to fix CVE-2023-53322 in the kernel and kernel-rt packages for RHEL 7 Extended Lifecycle Support.
Red Hat issued Important-rated RHSA-2025:23450 for RHEL 9.4 Extended Update Support and associated channels. Kernel version 5.14.0-427.103.1.el9_4 fixes CVE-2025-39864, CVE-2025-39955, and CVE-2025-40186; affected systems require a reboot.
Red Hat issued Important-rated RHSA-2025:23426 for RHEL 9.0 Update Services for SAP Solutions. The update provides kernel 5.14.0-70.158.1.el9_0 packages that remediate CVE-2023-53322 and CVE-2025-40186 and requires a reboot.
Red Hat issued Important-rated RHSA-2025:23424 for RHEL 9.0 Update Services for SAP Solutions. The kernel-rt update fixes CVE-2023-53322 and CVE-2025-40186, among other kernel vulnerabilities, and requires a reboot.
Red Hat issued RHSA-2025:23463 to remediate CVE-2023-53322 for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On.
Red Hat issued RHSA-2025:22072 to fix CVE-2023-53322 in the RHEL 8.8 Telecommunications Update Service kernel.
Red Hat published its CVE record for CVE-2023-53322, documenting the qla2xxx terminate_rport_io() use-after-free vulnerability.
Red Hat issued Important-rated RHSA-2025:10830 for RHEL 9.0 Update Services for SAP Solutions, providing kernel version 5.14.0-70.138.1.el9_0. The update fixes ten kernel vulnerabilities, including flaws in UML, device mapper, IPv6 multicast, Squashfs, ATM LEC, ext4, UDF, and the Atlantic driver; systems must be rebooted after installation.
Red Hat issued RHSA-2024:3138, updating the RHEL 8 kernel to remediate CVE-2023-53322, a use-after-free issue in the qla2xxx SCSI driver.
Red Hat issued Important-rated RHSA-2024:0412 for RHEL 8.6 Extended Update Support and associated channels, providing kernel version 4.18.0-372.87.1.el8_6. The update remediates numerous kernel flaws, including CVE-2023-2513 and CVE-2023-3772, and requires a reboot after installation.
Red Hat issued Important-rated RHSA-2023:7077 for RHEL 8, providing kernel 4.18.0-513.5.1.el8_9. The update remediated CVE-2023-2513 in ext4 extended-attribute handling along with numerous other kernel vulnerabilities; systems require a reboot after installation.
Guilherme de Almeida Suckevicz reported CVE-2023-3772, in which a local user with CAP_NET_ADMIN can trigger a NULL-pointer dereference in xfrm_update_ae_params() and panic the Linux kernel. The flaw stems from use of unallocated XFRM replay-state pointers.
Rohit Keshri reported CVE-2023-3268, a medium-severity out-of-bounds memory-access vulnerability in the Linux kernel relayfs function relay_file_read_start_pos. A local attacker could crash an affected system or disclose internal kernel information; the issue was fixed upstream in Linux 6.4-rc1.
Mauro Matteo Cascella reported CVE-2023-3161, a medium-severity shift-out-of-bounds flaw in the Linux Framebuffer Console's fbcon_set_font() function. Supplying font width or height values greater than 32 bypassed missing bounds checks, causing undefined behavior that could lead to denial of service.
Red Hat released RHSA-2023:2458 for the RHEL 9 kernel and RHSA-2023:2148 for the RHEL 9 kernel-rt package, remediating CVE-2023-2513, an ext4 extended-attribute use-after-free vulnerability.
Mauro Matteo Cascella reported CVE-2023-2194, a medium-severity out-of-bounds write in the Linux SLIMpro I2C driver's xgene_slimpro_i2c_xfer() path. An insufficiently validated user-controlled data->block[0] value can cause an out-of-bounds memcpy operation in slimpro_i2c_blkwr.
CVE-2023-1074 was reported in the Linux kernel SCTP diagnostic code. An empty SCTP association bound-address list can cause inet_diag_msg_sctpasoc_fill() to invoke list_entry() on an invalid list element, creating a type-confused pointer that may return information to userspace.
CVE-2023-1079, a medium-severity use-after-free flaw in the Linux HID Asus keyboard-backlight handling path, was reported. A malicious USB device impersonating an Asus device could trigger scheduled LED-controller work to access freed memory during connection or disconnection.
A Linux kernel mailing-list reference documented CVE-2023-0590, a use-after-free vulnerability caused by a race condition in qdisc_graft() in net/sched/sch_api.c. The flaw can cause denial of service; a syzkaller-triggered KASAN report showed a use-after-free read in __tcf_qdisc_find during traffic-control filter handling.
Marian Rehak reported CVE-2022-28388, a double-free vulnerability in the Linux kernel's CAN-over-USB usb_8dev_start_xmit function. The issue affected kernel versions through 5.17.1 and was later fixed upstream in commit 3d3925ff6433f98992685a9679613a2cc97f3ce2.
Red Hat documented CVE-2023-4273, a stack overflow in the Linux exFAT driver's filename reconstruction logic that malformed directory entries can trigger. The issue was fixed upstream in commit d42334578eba1390859012ebb91e1e556d51db49 and addressed for RHEL 9 through RHSA-2023:6583.
Red Hat documented CVE-2023-23454, an out-of-bounds read in the Linux CBQ traffic-control classifier's cbq_classify function caused by type confusion in classification-result handling. The flaw can allow a local attacker to cause denial of service; Red Hat addressed it in RHEL 8 advisories RHSA-2023:2736 and RHSA-2023:2951 and in RHEL 8.6 EUS through RHSA-2024:0412.
Red Hat documented CVE-2023-2513, a use-after-free vulnerability in Linux ext4 extended-attribute handling caused by integer underflow or overflow in extra inode-size offset calculations. The upstream fix was included in Linux 6.0-rc1, and Red Hat distributed fixes through kernel and kernel-rt errata for affected RHEL 8 and RHEL 9 streams.
Red Hat documented CVE-2025-22058, an integer-overflow flaw in the Linux kernel's UDP receive-memory accounting that can cause inflated accounting, packet drops, and denial of service. Red Hat issued fixes for affected RHEL 8, RHEL 9, and RHEL 10 product streams.
Red Hat issued RHSA-2026:0643 to remediate CVE-2023-53322 for RHEL 8.2 Advanced Update Support.
Red Hat issued RHSA-2026:0536 to remediate CVE-2023-53322 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
Red Hat closed its tracking bug for CVE-2022-1679, a use-after-free in the Linux ath9k HTC wireless driver's ath9k_htc_probe_device() failure path. A stale driver-private pointer can be dereferenced during USB receive-stream processing, potentially allowing local kernel-memory access, crashes, or information disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
27 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.