Red Hat released Moderate-severity kernel updates for Red Hat Enterprise Linux 7 Extended Lifecycle Support and RHEL for Real Time 7, remediating seven Linux kernel vulnerabilities. The updates address flaws in Bluetooth L2CAP, SCTP packet processing, IPv6 multicast routing, the Broadcom FullMAC (brcmfmac) Wi-Fi driver, and the CIFS/SMB client; several of the issues are use-after-free vulnerabilities.
The CIFS fix, tracked as CVE-2022-50341, prevents an arm64 kernel oops triggered when SMB encryption processes vmalloc-backed buffers across a page boundary. Updated packages include kernel-3.10.0-1160.143.1.el7 for RHEL 7 ELS and kernel-rt-3.10.0-1160.143.1.rt56.1295.el7 for Real Time 7 x86_64; Red Hat requires affected systems to be rebooted after installation for the fixes to take effect.

See real exploitation activity before you spend the cycle.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2025:22752 for RHEL 8.4 AUS and Extended Life Cycle Long Life x86_64 systems, supplying kernel 4.18.0-305.179.1.el8_4. The update remediated 41 CVEs, including CVE-2022-50408 in brcmfmac, and required systems to be rebooted after installation.
Red Hat issued Moderate-severity advisory RHSA-2025:21136 for the RHEL 9.0 Update Services for SAP Solutions x86_64 Real Time kernel. The kernel-rt-5.14.0-70.153.1.rt21.225.el9_0 update remediated 23 vulnerabilities, including CVE-2022-50408, and required affected systems to be rebooted after installation.
Red Hat issued Moderate-severity advisory RHSA-2025:18279 for the RHEL 9.2 SAP Solutions and Extended Life Cycle x86_64 Real Time kernel. The kernel-rt-5.14.0-284.143.1.rt14.428.el9_2 update fixed CVE-2023-53125 in the SMSC75xx USB networking driver and CVE-2025-38550 in IPv6 multicast handling; affected systems require a reboot.
An upstream Linux CVE announcement disclosed CVE-2022-50341, a CIFS/SMB client encryption flaw that can cause an arm64 kernel oops through incorrect scatter-gather handling of vmalloc-backed buffers.
Red Hat issued Moderate-severity advisory RHSA-2025:14986 for the RHEL for Real Time 7 x86_64 Extended Life Cycle Support kernel-rt packages. The kernel-rt-3.10.0-1160.138.1.rt56.1290.el7 update remediated CVE-2025-38079, a double-free in crypto algif_hash hash_accept, and requires a reboot.
CVE-2025-38550 was reported as a medium-severity Linux kernel IPv6 multicast flaw in mld_del_delrec(), where pmc->idev could be released before ip6_mc_clear_src() finished using it. Red Hat later addressed the issue through advisories for RHEL 9, RHEL 10, and specified RHEL 9 EUS and SAP update-service variants.
An upstream Linux CVE announcement disclosed CVE-2025-38477, a race involving concurrent access to sch_qfq qfq_aggregate objects that can cause a NULL-pointer dereference in qfq_dump_class or a use-after-free in qfq_delete_class. The fix moves qfq_destroy_class into the critical section and adds sch_tree_lock protection to class dump functions.
An upstream Linux CVE announcement disclosed CVE-2022-50070, an MPTCP race in which retransmission can queue data on a closed subflow socket during socket closure, producing an inet_sock_destruct warning. The kernel fix rechecks subflow status while holding the socket lock and adds a fallback-to-TCP status check.
An upstream Linux kernel CVE advisory disclosed CVE-2022-50211, a slab out-of-bounds read in md-raid10's raid10_remove_disk() caused by using an invalid "number" value during RAID10 disk removal. The fix validates the value before use; Red Hat later shipped fixes across several RHEL 7, 8, and 9 support channels.
Red Hat resolved CVE-2025-21844, a Linux SMB client flaw in receive_encrypted_standard() where unchecked buffer-allocation results could leave next_buffer null and cause a null-pointer dereference. The upstream fix validates cifs_buf_get() and cifs_small_buf_get() return values; Red Hat issued RHSA-2025:20095 for RHEL 10 and RHSA-2025:20518 for RHEL 9.
Red Hat remediated CVE-2022-50408, a use-after-free in the brcmfmac Broadcom FullMAC Wi-Fi driver, through advisories for specified RHEL 7, RHEL 8, and RHEL 9 support offerings. The flaw can occur when an skb is freed after transmission completes before brcmf_netdev_start_xmit() reads skb->len to update transmit statistics.
Red Hat issued Moderate-severity advisory RHSA-2025:22914 for the RHEL for Real Time 7 x86_64 Extended Lifecycle Support kernel-rt package. The update supplied kernel-rt-3.10.0-1160.143.1.rt56.1295.el7 and remediated CVE-2022-50341 with six other kernel flaws; a reboot was required.
Red Hat issued Moderate-severity advisory RHSA-2025:22910 for RHEL 7 Extended Lifecycle Support, providing kernel 3.10.0-1160.143.1.el7 and fixing CVE-2022-50341 along with six other kernel vulnerabilities. The update covered x86_64, s390x, ppc64, and ppc64le systems and required a reboot to take effect.
Red Hat addressed CVE-2022-50341 through RHSA-2025:22006, RHSA-2025:22066, RHSA-2025:22087, RHSA-2025:22072, RHSA-2026:1886, and RHSA-2026:2664 for affected RHEL 8 and RHEL 9 support streams.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.