Red Hat released Linux kernel security updates across Red Hat Enterprise Linux (RHEL) 8, 9, and 10 channels, addressing vulnerabilities including CVE-2025-37823, a potential use-after-free in the HFSC network scheduler's hfsc_dequeue() path, and CVE-2025-38498, which allowed mount propagation-type changes to be attempted on unmounted mounts or mounts outside the caller's mount namespace. The mount fix restricts these operations to mounts within the caller's namespace. Related updates also remediate flaws in ETS/netem queue-disc handling, ARM SCPI, SMB/CIFS, USB, Intel network drivers, IPv6 multicast, XFRM, and SunRPC TLS-alert handling.
Affected offerings include standard, SAP, real-time, AUS, TUS, Extended Update Support, and extended-lifecycle RHEL deployments. Notable packages include RHEL 9.2 kernel 5.14.0-284.142.1.el9_2, RHEL 9.4 kernel 5.14.0-427.94.1.el9_4, RHEL 8.6 kernel 4.18.0-372.164.1.el8_6, and RHEL 9.0 SAP real-time kernel 5.14.0-70.149.1.rt21.221.el9_0; RHEL 10 updates cover x86_64, aarch64, ppc64le, and s390x systems. Organizations should install the applicable advisory updates and reboot hosts to load the corrected kernel.

See real exploitation activity before you spend the cycle.
20 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2025:17241 for RHEL 9.4 support channels, providing kernel 5.14.0-427.92.1.el9_4. The update fixes CVE-2025-37823 and vulnerabilities including CVE-2025-38200, CVE-2025-38449, CVE-2025-38472, CVE-2025-38500, and CVE-2025-38527; affected systems require a reboot.
Red Hat issued Moderate-severity advisory RHSA-2025:16920 for RHEL 8 Real Time, Real Time for NFV, and RHEL 8.10 Extended Life Cycle deployments. The kernel-rt 4.18.0-553.77.1.rt7.418.el8_10 update fixes four vulnerabilities, including CVE-2025-22026, CVE-2025-37797, CVE-2022-50087, and CVE-2025-38718, and requires a reboot.
Red Hat issued a Moderate-severity RHEL 10 kernel update that fixes CVE-2025-38498 by preventing do_change_type() from operating on unmounted or non-owned mounts. The advisory requires systems to reboot for the updated kernel fixes to take effect.
Red Hat issued Important-rated advisory RHSA-2025:15668 for RHEL 9.4, providing kernel 5.14.0-427.88.1.el9_4 for supported x86_64, aarch64, s390x, and ppc64le channels. The update fixes ten vulnerabilities, including CVE-2024-42094, CVE-2024-50102, CVE-2025-22097, CVE-2025-37914, and CVE-2025-38464, and requires a reboot.
Red Hat issued Important-rated advisory RHSA-2025:15011 for RHEL 9 kernel packages, fixing CVE-2025-37823 and multiple other flaws including CVE-2025-38200, CVE-2025-38211, CVE-2025-38350, CVE-2025-38461, CVE-2025-38464, and CVE-2025-38500. The update affects RHEL 9 streams across x86_64, ARM64, s390x, and ppc64le architectures and requires a reboot.
Red Hat issued Important-rated advisory RHSA-2025:14744 for RHEL 9.0 Update Services for SAP Solutions, providing kernel 5.14.0-70.144.1.el9_0. The update fixes 11 vulnerabilities, including CVE-2025-37890, CVE-2025-38000, CVE-2025-38001, CVE-2025-38177, and CVE-2025-38350, and requires a reboot.
Red Hat issued Important-rated RHSA-2025:14511 for RHEL 8.8 SAP Solutions and Telecommunications Update Service deployments, providing kernel 4.18.0-477.107.1.el8_8. The update fixes eight vulnerabilities, including CVE-2021-47670, CVE-2025-37890, CVE-2025-38000, CVE-2025-38001, CVE-2025-38079, CVE-2025-38177, and CVE-2025-38350, and requires a reboot.
Red Hat issued Moderate-severity advisory RHSA-2025:13946 for RHEL 9.4 offerings, providing kernel 5.14.0-427.83.1.el9_4. The update fixes six vulnerabilities, including CVE-2024-26878, CVE-2024-41035, CVE-2025-22020, CVE-2025-22026, CVE-2025-37797, and CVE-2025-38086, and requires a reboot.
An upstream Linux CVE announcement disclosed CVE-2025-38498, involving mount-propagation changes attempted on unmounted mounts or mounts outside the caller's namespace.
Red Hat issued Moderate-severity advisory RHSA-2025:11855 for RHEL 10 kernel packages across x86_64, s390x, ppc64le, and aarch64. The update fixes CVE-2025-22091, CVE-2025-22121, CVE-2025-37797, CVE-2025-38088, and CVE-2025-38110; affected systems must reboot after updating.
Red Hat reported and began tracking CVE-2025-37823 as Bug 2365024, a medium-severity potential use-after-free issue in the Linux HFSC scheduler's hfsc_dequeue() function.
An upstream Linux kernel advisory referenced CVE-2023-53047, a race condition in amdtee_open_session that can permit a use-after-free when amdtee_close_session frees a session during initialization, potentially causing a kernel panic. The upstream fix delays setting sess->sess_mask until the final initialization step.
Red Hat addressed CVE-2025-22091 in Red Hat Enterprise Linux 9 through RHSA-2025:11861. The RDMA/mlx5 driver flaw could overflow a 4 GB page-size value stored as an unsigned int, triggering a WARN_ON() during memory registration; the fix uses unsigned long storage variables.
Red Hat released RHSA-2026:0755 for the RHEL 7 Extended Lifecycle Support kernel and RHSA-2026:0754 for the corresponding kernel-rt package, remediating CVE-2025-37823.
Red Hat issued a Moderate-severity kernel-rt update for RHEL 9.0 Update Services for SAP Solutions on x86_64. The update fixes both CVE-2025-37823 and CVE-2025-38498, provides kernel-rt 5.14.0-70.149.1.rt21.221.el9_0, and requires a reboot.
Red Hat issued a Moderate-severity RHEL 8.6 kernel update that remediates CVE-2025-38498 alongside nine other kernel vulnerabilities. Affected systems must update to kernel 4.18.0-372.164.1.el8_6 or the corresponding package set and reboot.
Red Hat issued a Moderate-severity kernel update for RHEL 9.4 support channels that fixes CVE-2025-38498 and five other kernel vulnerabilities. The update supplies kernel 5.14.0-427.94.1.el9_4 and requires a reboot.
Red Hat issued an Important-rated RHEL 9.2 Update Services for SAP Solutions kernel update fixing both CVE-2025-37823 and CVE-2025-38498, among other flaws. The update provides kernel 5.14.0-284.142.1.el9_2 and requires a reboot.
Red Hat released RHSA-2025:16372 for Red Hat Enterprise Linux 8, marking CVE-2025-38498 as fixed in the applicable kernel update streams.
The Linux kernel CVE team assigned CVE-2025-37823 to a potential use-after-free in the HFSC scheduler's hfsc_dequeue() function in net/sched/sch_hfsc.c. The advisory states the flaw existed since kernel 2.6.12, has no reliable reproducer, and was fixed in stable releases from 5.4.293 through 6.14.5 as well as 6.15-rc4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
22 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.