Red Hat released RHSA-2025:21931 kernel updates for Red Hat Enterprise Linux 10 that remediate CVE-2025-39955, a TCP Fast Open (TFO) state-management flaw. The vulnerability occurs when a server-side TFO socket is reused as a client before its prior TFO operation completes, potentially leaving tcp_sk(sk)->fastopen_rsk referencing a freed request_sock; a retransmission timer may then access the stale object, causing a kernel warning and potentially enabling use-after-free or information-disclosure conditions.
Red Hat rates the issue Moderate severity with a CVSS v3.1 score of 7.6 and notes that exploitation requires local access and the ability to create and manipulate TFO sockets, typically in privileged or test environments. The advisory updates RHEL 10 kernels for x86_64, s390x, ppc64le, and aarch64, including applicable extended-support variants; it also fixes the NFS filehandle bounds-checking vulnerability CVE-2025-39730. Organizations should apply the updated kernel packages and reboot affected hosts.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:23422, an Important update providing kernel-rt 5.14.0-284.150.1.rt14.435.el9_2 for RHEL 9.2 SAP Solutions and Extended Life Cycle subscriptions. The update fixes CVE-2025-39955 along with CVE-2023-53322, CVE-2025-39864, and CVE-2025-40186; affected systems require a reboot.
Red Hat issued RHSA-2025:21931 for RHEL 10 kernel packages, fixing CVE-2025-39955 and CVE-2025-39730. Systems require a reboot after installation for the kernel fixes to take effect.
The CVE record for CVE-2025-39955, a Linux kernel TCP Fast Open stale-reference flaw, was publicly listed.
An upstream Linux CVE announcement disclosed CVE-2025-39864, a use-after-free vulnerability in the cfg80211 Wi-Fi subsystem's handling of hidden-SSID beacon BSS entries. The upstream fix changes cfg80211_update_known_bss() to avoid freeing beacon-frame elements shared through hidden_beacon_bss.
Red Hat released RHSA-2025:23947 and RHSA-2025:23960 with fixed kernel and kernel-rt packages for Red Hat Enterprise Linux 7 Extended Lifecycle Support.
Red Hat released RHSA-2025:23445, RHSA-2025:23463, and RHSA-2025:23425, supplying fixed kernel packages for RHEL 8.2 Advanced Update Support, RHEL 8.4 mission-critical and extended-support variants, and RHEL 8.6 Advanced Mission Critical Update Support.
Red Hat released RHSA-2025:22571 with fixed kernel packages for Red Hat Enterprise Linux 10.0 Extended Update Support.
Red Hat released RHSA-2025:22388 and RHSA-2025:22387, providing fixed kernel and kernel-rt packages for Red Hat Enterprise Linux 8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.