Red Hat released Moderate-severity Linux kernel updates for supported RHEL 8 and RHEL 9 channels, including SAP, telecommunications, EUS, AUS, ELC, and mission-critical offerings. The advisories address multiple flaws across NFS, network scheduling, USB, KVM, vsock, HID, Bluetooth, cryptography, storage, and firmware components; affected systems span x86_64, s390x, ppc64le, and aarch64 platforms depending on the advisory.
Key fixes include CVE-2025-39751, a buffer overflow in the ALSA HDA CA0132 driver's add_tuning_control() function caused by unbounded sprintf; CVE-2025-39849, which could corrupt memory when cfg80211 processed a Wi-Fi connection-result SSID longer than 32 bytes; and CVE-2022-50087, an ARM SCPI driver use-after-free condition following a failed probe. Organizations should install the applicable updated kernel packages—including RHEL 8.10 build 4.18.0-553.80.1.el8_10, RHEL 8.8 SAP/TUS build 4.18.0-477.116.1.el8_8, or RHEL 8.6 build 4.18.0-372.166.1.el8_6 where relevant—and reboot systems to activate the mitigations.

See real exploitation activity before you spend the cycle.
16 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:21667, a Moderate-severity update for RHEL Server AUS 8.2 on x86_64, updating the kernel to 4.18.0-193.173.1.el8_2. It fixes 20 vulnerabilities, including CVE-2025-39751 and CVE-2022-50087, and requires affected systems to reboot after installation.
Red Hat issued Moderate-severity advisory RHSA-2025:21063 for RHEL 7 Extended Life Cycle Support, providing kernel version 3.10.0-1160.142.1.el7 for x86_64, s390x, ppc64, and ppc64le. The update fixes CVE-2025-39751 and five other kernel vulnerabilities, and requires a reboot after installation.
Red Hat issued RHSA-2025:19223 for RHEL 9.2 x86_64 SAP Solutions and Extended Life Cycle offerings using the Real Time Linux Kernel. The Moderate-severity update provides kernel-rt 5.14.0-284.144.1.rt14.429.el9_2 and fixes CVE-2025-39751 alongside three other Linux kernel vulnerabilities.
Red Hat published RHSA-2025:19222 for selected RHEL 8.6 support channels, supplying kernel version 4.18.0-372.166.1.el8_6. The update remediates CVE-2025-39751 and nine additional kernel CVEs.
Red Hat issued Moderate-severity advisory RHSA-2025:19104 for RHEL 9.4 EUS, AUS, SAP Update Services, Extended Life Cycle, and related channels. Kernel build 5.14.0-427.96.1.el9_4 fixes CVE-2025-39751 along with six other kernel CVEs and requires a reboot.
Red Hat issued RHSA-2025:18932 for RHEL 8.8 Update Services for SAP Solutions and Telecommunications Update Service. The kernel update fixes CVE-2025-39751 alongside eight other Linux kernel CVEs.
Red Hat published RHSA-2025:18297, a Moderate-severity RHEL 8 kernel update that fixes CVE-2025-39751 in ALSA HDA CA0132 add_tuning_control. The update replaces the vulnerable behavior that permitted a buffer overflow and also fixes two other kernel vulnerabilities.
Red Hat published RHSA-2025:18281, a Moderate-severity RHEL 9 kernel update that fixes CVE-2025-39849 by capping SSID length in __cfg80211_connect_result(). The update also remediates six other kernel CVEs, including CVE-2022-50087.
Red Hat issued Moderate-severity advisory RHSA-2025:17570 for RHEL 8.8 Update Services for SAP Solutions and Telecommunications Update Service. The kernel 4.18.0-477.114.1.el8_8 update fixes eight vulnerabilities, including CVE-2022-50087 in ARM SCPI firmware, and requires a reboot.
Red Hat issued Moderate-severity advisory RHSA-2025:16919 for RHEL 8, delivering kernel version 4.18.0-553.77.1.el8_10. The update fixes CVE-2022-50087 in ARM SCPI probing, plus NFS server, HFSC traffic-scheduling, and SCTP vulnerabilities; affected systems require a reboot.
Red Hat received Bug 2396928 for CVE-2025-39849 through OSIDB Bzimport. The cfg80211 SME connection-result handling could corrupt memory when supplied an SSID longer than 32 bytes.
An upstream Linux CVE advisory for CVE-2022-50087 was referenced. The flaw could leave the exported scpi_info pointer referring to freed memory after a failed ARM SCPI driver probe.
An upstream CVE advisory was published for CVE-2025-22026, an NFS server flaw in which nfsd_proc_stat_init() ignored svc_proc_register() failures. The fix propagates the registration result and prevents nfsd_net construction when procfile registration fails.
Red Hat addressed CVE-2021-47609, a string-overflow vulnerability in the Linux kernel ARM SCPI generic power-domain driver, for Red Hat Enterprise Linux 8. The issue was resolved upstream and remediated through advisories RHSA-2024:7000 and RHSA-2024:7001.
Red Hat documented CVE-2025-37797, a Linux kernel HFSC queueing-discipline use-after-free caused by a time-of-check/time-of-use condition in hfsc_change_class(). The upstream fix adds a second queue-length check after qdisc_peek_len(), and Red Hat remediated the flaw across affected RHEL 7, 8, 9, and 10 streams.
Red Hat documented CVE-2022-49985, an eBPF vulnerability in which tnum_range() could overapproximate BPF poke-descriptor array indices and permit an out-of-range value, causing a KASAN slab-out-of-bounds read in bpf_int_jit_compile. The issue was addressed across multiple RHEL 8 and RHEL 9 update-service variants, including advisories RHSA-2025:15471, RHSA-2025:15472, RHSA-2025:18043, RHSA-2025:22752, RHSA-2026:5693, and RHSA-2026:5732.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
21 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.