Red Hat released Moderate-severity Linux kernel security updates for RHEL 9.0 SAP Solutions, RHEL 9.2 SAP and associated offerings, and RHEL 10/10.2 variants. The advisories remediate vulnerabilities in networking, HID, SCTP, ALSA audio, RDMA, KVM, event polling, TLS, cryptographic, and Wi-Fi code, including buffer overflows, use-after-free conditions, and recursion that could exhaust kernel resources. Key fixes include CVE-2025-38614 in eventpoll, CVE-2025-39864 in cfg80211, CVE-2025-39903 affecting NUMA memory-node handling, and CVE-2025-39946 in TLS stream handling.
Affected organizations should deploy the applicable kernel packages—5.14.0-70.151.1.el9_0 for RHEL 9.0 SAP, 5.14.0-70.151.1.rt21.223.el9_0 for its real-time kernel, and 5.14.0-284.144.1.el9_2 for RHEL 9.2 SAP—across x86_64, aarch64, ppc64le, and s390x systems as applicable. Red Hat requires a reboot after installation for mitigations to take effect; its kernel maintenance also includes a resolved Intel SOF HDA issue, CVE-2022-50050, where unsafe handling of snprintf() output could lead to a buffer overflow.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Moderate-severity RHSA-2025:21463 for RHEL 10 kernel packages across x86_64, s390x, ppc64le, and aarch64. The update fixes eventpoll recursion, cfg80211 use-after-free, NUMA memory-node kernel panic, and TLS bogus-header handling vulnerabilities; systems must be rebooted after installation.
Red Hat issued Moderate-severity RHSA-2025:19492 for the RHEL 9.0 Update Services for SAP Solutions kernel across x86_64, ppc64le, aarch64, and s390x. Kernel version 5.14.0-70.151.1.el9_0 fixes ten CVEs, including CVE-2022-50050, and requires a reboot after installation.
Red Hat issued Moderate-severity RHSA-2025:19268 for the RHEL 9.0 SAP Solutions x86_64 kernel-rt packages. Version 5.14.0-70.151.1.rt21.223.el9_0 remediates ten kernel CVEs, including CVE-2022-50050 in the Intel HDA component; a reboot is required for the update to take effect.
Red Hat issued Moderate-severity advisory RHSA-2025:19224 for RHEL 9.2 Update Services for SAP Solutions and associated offerings. Kernel version 5.14.0-284.144.1.el9_2 fixes four vulnerabilities affecting HID, SCTP, TLS, and ALSA CA0132 components.
Red Hat issued Moderate-severity advisory RHSA-2025:17776 for RHEL 10 kernel packages across x86_64, ARM64, IBM Z, and Power architectures. The update fixes CVE-2025-38556 in HID core, CVE-2025-39761 in the ath12k Wi-Fi driver, and CVE-2025-39757 in ALSA USB-audio; affected systems require a reboot after installation.
Red Hat issued Important-rated RHSA-2025:14696 for RHEL 9.2 Update Services for SAP Solutions and related support channels. Kernel version 5.14.0-284.134.1.el9_2 fixes five vulnerabilities in BPF, crypto algif_hash, ftrace, and network scheduling components; affected systems require a reboot.
Red Hat issued Moderate-severity RHSA-2025:13781 for RHEL 9.2 Update Services for SAP Solutions. Kernel version 5.14.0-284.130.1.el9_2 remediates nine vulnerabilities, including flaws in uvcvideo, padata, intel-ish-hid, AMD microcode handling, SELinux, and network drivers; a reboot is required.
An upstream advisory was published for CVE-2022-50050, a potential buffer overflow in the Linux kernel ASoC SOF Intel HDA component caused by use of snprintf() truncation return values. The upstream fix replaced snprintf() with scnprintf().
Red Hat addressed the Linux kernel HID-core zero-bit conversion vulnerability CVE-2025-38556 through RHSA-2025:16372 for RHEL 8 and RHSA-2025:17760 for RHEL 9, with additional affected RHEL support-channel variants also covered. The flaw could trigger a shift-out-of-bounds crash when HID report fields have a size of zero.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.