Red Hat released Moderate-severity kernel updates for Red Hat Enterprise Linux 8, including Real Time, Real Time for NFV, and selected Extended Life Cycle deployments, to remediate three Linux wireless-subsystem vulnerabilities. The fixes address CVE-2023-53226, an out-of-bounds access and integer-underflow flaw in the mwifiex Wi-Fi driver's received-packet handling; CVE-2023-53257, involving mac80211 S1G action-frame size handling; and CVE-2025-39864, a use-after-free vulnerability in cfg80211's cmp_bss() function.
The standard RHEL 8 update is provided as kernel version 4.18.0-553.82.1.el8_10 for x86_64, s390x, ppc64le, and aarch64 systems, while the Real Time update is kernel-rt-4.18.0-553.82.1.rt7.423.el8_10. Organizations running affected RHEL 8 variants should install the applicable RHSA updates and reboot systems to load the corrected kernel.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2025:22998 for RHEL 8.8 Extended Life Cycle Long Life, Telecommunications Update Service, and SAP Solutions offerings. The update provides kernel build 4.18.0-477.122.1.el8_8, remediating CVE-2023-53226 alongside CVE-2025-39697 and CVE-2022-50406; affected systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2025:19447 for RHEL 8 kernel packages, remediating CVE-2023-53226 alongside CVE-2023-53257 and CVE-2025-39864. The update supplied kernel version 4.18.0-553.82.1.el8_10 and required affected systems to be rebooted.
Red Hat issued Moderate-severity advisory RHSA-2025:19440 for RHEL 8 kernel-rt packages, fixing CVE-2023-53226 along with CVE-2023-53257 and CVE-2025-39864. The updated kernel-rt release was 4.18.0-553.82.1.rt7.423.el8_10.
An upstream Linux CVE announcement referenced CVE-2023-53226, covering out-of-bounds access and integer-underflow flaws in received-packet processing by the mwifiex Wi-Fi driver.
Red Hat addressed the iomap writeback memory-corruption flaw CVE-2022-50406 through advisories RHSA-2025:21051, 21084, 21091, 21128, 21136, 23445, 23463, and 23960 for affected RHEL 7, 8, and 9 extended-support, SAP, telecommunications, and mission-critical offerings. RHSA-2025:22998 was also listed but is already captured in the timeline.
Red Hat published RHSA-2024:5101 and RHSA-2024:5102 for RHEL 8, remediating the low-severity ath11k Wi-Fi driver locking flaw CVE-2023-52777. The issue concerns GTK offload status-event locking and was fixed upstream as “wifi: ath11k: fix gtk offload status event locking.”
The Linux kernel CVE team announced CVE-2023-52530, a potential key use-after-free vulnerability in the mac80211 Wi-Fi subsystem. The issue was resolved upstream by the fix titled "wifi: mac80211: fix potential key use-after-free."
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.