Red Hat released Moderate-severity Linux kernel security updates across RHEL 8, RHEL 9 SAP Solutions, and RHEL 10. The fixes address vulnerabilities in Bluetooth key and L2CAP handling, Wi-Fi cfg80211 connection-result processing, NFS, virtio-vsock, swap management, ALSA, efivarfs, and the lpfc Fibre Channel driver. Bluetooth fixes include CVE-2023-53386, a potential use-after-free triggered while clearing keys after an object has been queued for deferred kfree_rcu() release.
Affected organizations should install the applicable kernel builds, including 4.18.0-553.81.1.el8_10 for RHEL 8.10 variants, 4.18.0-372.168.1.el8_6 for supported RHEL 8.6 service variants, and 5.14.0-70.157.1.el9_0 for RHEL 9.0 SAP Solutions. The RHEL 9 SAP update also fixes an act_ct fragment-handling flaw that can leak sk_buffs and crash systems, an lpfc buffer-lifecycle issue, and a memory-failure assertion bug. Red Hat requires a system reboot after installation for the kernel fixes to take effect.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2025:22661 for RHEL 9.4 support channels, providing kernel version 5.14.0-427.102.1.el9_4. The update fixes CVE-2025-39841 in the SCSI lpfc deferred receive path and CVE-2025-39883 in memory-failure unpoisoning code; affected systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2025:19102 for RHEL 8, providing kernel version 4.18.0-553.81.1.el8_10 and fixing CVE-2023-53386 along with other kernel flaws. Systems must be rebooted after installation.
The upstream Linux kernel resolved CVE-2025-39727, a potential buffer overflow in the swap subsystem's setup_clusters() when a validated badpage is greater than or equal to maxpages. Red Hat addressed the flaw for RHEL 10 through RHSA-2025:19106 and RHSA-2025:21118.
Red Hat issued Moderate-severity RHSA-2025:21084 for supported RHEL 8.6 service variants, including a fix for CVE-2023-53386. The update provides kernel version 4.18.0-372.168.1.el8_6 and requires a reboot to take effect.
The Linux kernel fixed CVE-2023-53386, a potential Bluetooth use-after-free during key-clearing operations caused by accessing a key after it was scheduled for deferred release with kfree_rcu().
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.