Red Hat released Moderate-severity RHEL 8 kernel and kernel-rt updates addressing three Linux kernel vulnerabilities: CVE-2022-50543, an RDMA RXE mr->map double-free that can cause a KASAN-detected kernel panic; CVE-2023-53539, incomplete state saving in the RDMA RXE requester path; and CVE-2023-53401, a NULL-pointer dereference in obj_stock_flush_required() in the memory-management subsystem. The double-free occurs when rxe_mr_init_user() fails and cleanup frees mr->map more than once; the fix assigns responsibility for freeing the allocation solely to rxe_mr_cleanup().
RHSA-2025:22801 provides kernel version 4.18.0-553.89.1.el8_10 for applicable RHEL 8 systems on x86_64, s390x, ppc64le, and aarch64, including supported Extended Life Cycle and CodeReady Linux Builder repositories. RHSA-2025:22800 supplies kernel-rt-4.18.0-553.89.1.rt7.430.el8_10 for RHEL for Real Time 8, Real Time for NFV 8, and eligible RHEL 8.10 Extended Life Cycle deployments; administrators must reboot systems after applying the updates.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2025:22801 for RHEL 8 kernel packages, fixing CVE-2022-50543 alongside CVE-2023-53401 and CVE-2023-53539. The update provides kernel-4.18.0-553.89.1.el8_10 for supported RHEL 8 architectures and requires a reboot.
Red Hat issued Moderate-severity advisory RHSA-2025:22800 for RHEL 8 kernel-rt packages, including a fix for CVE-2022-50543. The update supplies kernel-rt 4.18.0-553.89.1.rt7.430.el8_10 and requires a reboot.
The remediation made rxe_mr_cleanup() solely responsible for freeing mr->map after successful allocation, preventing the double free that could trigger a KASAN-detected kernel panic.
Commit 1e75550648da reverted “RDMA/rxe: Create duplicate mapping tables for FMRs” and also reverted the earlier double-free correction, reintroducing the issue.
Linux kernel commit 8ff5f5d9d8cf, “RDMA/rxe: Prevent double freeing rxe_map_set(),” corrected the RDMA RXE double-free issue.
Linux kernel commit b18c7da63fcb, “RDMA/rxe: Fix memory leak in error path code,” introduced the error-path condition in which failed user memory-region initialization could lead to a second free of mr->map.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.