Red Hat released Moderate-severity Linux kernel security updates for RHEL 8, RHEL 9, and RHEL 10, addressing vulnerabilities that include use-after-free conditions, an x86 VMSCAPE issue, and an IPv6 Segment Routing MAC-comparison timing flaw. RHEL 10 advisory RHSA-2025:19469 fixes CVE-2025-39702 and the kernfs polling use-after-free CVE-2025-39881; RHEL 9 advisory RHSA-2025:19409 fixes CVE-2025-39702, the NILFS use-after-free CVE-2022-50367, and XTS crypto request handling flaw CVE-2023-53494.
RHEL 8 advisories RHSA-2025:19931 and RHSA-2025:19932 update standard and real-time kernels to address CVE-2025-40300 through conditional IBPB mitigation, the zswap writeback race CVE-2023-53178, and CVE-2022-50367. The updates span x86_64, IBM Z, Power, and ARM64 offerings where applicable, including selected CodeReady Builder, EUS, ELC, SAP, NFV, and Real Time repositories. Red Hat requires systems to be rebooted after installing the updated kernel packages for mitigations and fixes to take effect.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:19932, a Moderate-severity update for RHEL 8 kernel-rt packages, including Real Time and Real Time for NFV offerings. Kernel-rt build 4.18.0-553.83.1.rt7.424.el8_10 fixes CVE-2025-40300, CVE-2023-53178, and CVE-2022-50367, with a reboot required.
Red Hat issued RHSA-2025:19931, a Moderate-severity RHEL 8 kernel update providing build 4.18.0-553.83.1.el8_10. It fixes CVE-2025-40300, CVE-2023-53178, and CVE-2022-50367; affected systems must be rebooted.
Red Hat issued RHSA-2025:19469, a Moderate-severity RHEL 10 kernel update addressing CVE-2025-39702, a non-constant-time IPv6 Segment Routing MAC comparison, and CVE-2025-39881, a kernfs polling use-after-free. A reboot is required for the update to take effect.
Red Hat published RHSA-2025:19409, a Moderate-severity RHEL 9 kernel update fixing CVE-2023-53494, CVE-2025-39702, and CVE-2022-50367. The advisory covers multiple RHEL 9 architectures and update-service variants and requires a reboot after installation.
An upstream CVE announcement for CVE-2023-53494 was referenced. The Linux kernel XTS cryptography flaw could cause a use-after-free when an EBUSY result for a backlogged request was not handled like EINPROGRESS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.