Red Hat released kernel updates for RHEL 9 and RHEL 10 addressing several locally exploitable Linux kernel flaws, including CVE-2025-21647 in the sch_cake traffic-control scheduler. An underflow in per-host bulk-flow fairness counters could lead to an out-of-bounds read, potentially exposing kernel memory or crashing the system; Red Hat assigned it a CVSS 3.1 score of 7.1. The upstream correction adds centralized bounds checking for counter access.
The updates also remediate denial-of-service issues in the mt76 mt7925 Wi-Fi driver (CVE-2024-57989), HID core (CVE-2024-57986), IDPF driver (CVE-2024-58057), and Realtek Bluetooth setup path (CVE-2024-57987). These flaws can trigger NULL-pointer dereferences, CPU-workqueue starvation, or system crashes under local attack conditions. RHEL 9 kernel-rt remains affected or will not fix for several listed issues; organizations should apply the applicable kernel errata and reboot systems to activate the patched kernel.

See real exploitation activity before you spend the cycle.
17 events from the most recent confirmed update back to the earliest known activity.
Red Hat addressed CVE-2025-21738 through RHSA-2025:20518 for RHEL 9 and RHSA-2025:20095 for RHEL 10. The libata-sff flaw allowed ata_pio_sector() to write beyond its allocated buffer via a crafted SCSI_IOCTL_SEND_COMMAND request; the fix adds a bounds check.
Red Hat addressed CVE-2025-21726, a use-after-free race in the Linux kernel padata reorder_work path, through RHSA-2025:20095 for RHEL 10 and RHSA-2025:20518 for RHEL 9. The fix retains a reference to the padata instance while reorder_work is queued and processed, preventing access after it is freed.
Red Hat remediated CVE-2024-56662, an ACPI NFIT out-of-bounds read in acpi_nfit_ctl(), through RHSA-2025:20095 for RHEL 10 and RHSA-2025:20518 for RHEL 9. The fix validates that the ioctl buffer is non-NULL and large enough for struct nd_cmd_pkg before accessing its members.
Red Hat addressed CVE-2024-58072 in the Linux rtlwifi driver through RHSA-2025:20095 for RHEL 10 and RHSA-2025:20518 for RHEL 9. The fix removes unused private-data list-management code that could leave freed data on a global list after a failed probe, allowing a subsequent probe to access stale memory.
Red Hat released kernel errata RHSA-2025:20095 for RHEL 10 and RHSA-2025:20518 for RHEL 9, addressing CVE-2024-57986, CVE-2024-57987, CVE-2024-57989, CVE-2024-58057, and CVE-2025-21647. The CVE-2025-21647 fix adds bounds-checking helpers for sch_cake per-host bulk-flow counters, preventing counter underflow from producing out-of-bounds memory access.
An upstream Linux kernel advisory announced CVE-2025-37994, a NULL-pointer access vulnerability in the USB Type-C UCSI DisplayPort driver during USB Type-C partner removal. The fix waits for pending ucsi_displayport_work tasks to finish before removing the partner.
The Linux kernel community rejected CVE-2025-21837 for an io_uring uring_cmd issue in which reuse of a submission queue entry before request completion could cause stale SQE data to be read and lead to data corruption. The proposed mitigation was to unconditionally copy SQEs during request preparation.
An upstream Linux kernel advisory announced CVE-2025-21846, a NULL-pointer dereference in acct(2) final accounting-file writes after the initiating task has exited and released current->fs. The upstream fix moves the final write to a workqueue while retaining the original caller's credentials.
The CVE record for CVE-2024-58057 was published for CPU-bound workqueues in the Linux IDPF driver that can be starved when a process monopolizes their assigned CPU. Delayed completion processing can cause timeouts and system crashes, resulting in local denial of service.
The CVE record for CVE-2024-57987 was published for a missing NULL check in the Linux Bluetooth Realtek driver's btrtl_setup_realtek() function. Local low-privileged exploitation can cause an availability failure such as a system crash or restart.
The CVE record for CVE-2024-57989 was published for an unchecked devm_kzalloc() return value in the Linux mt76 mt7925 Wi-Fi driver. The flaw can allow a local authenticated attacker to trigger a NULL-pointer dereference and denial of service.
An upstream Linux kernel advisory disclosed CVE-2025-21796, a use-after-free flaw in NFS server ACL handling when acl_default acquisition fails. The fix clears acl_access and acl_default after releasing POSIX ACLs, preventing stale-pointer reuse that could trigger a kernel panic and denial of service on systems using panic_on_warn.
A 2019 syzbot fuzzing report identified two errors involving HID-core Resolution Multiplier handling. A prior Linux commit, ea427a222d8b, fixed one of those errors, while the other remained unresolved and was later tracked as CVE-2024-57986.
Red Hat released RHSA-2026:2352 to remediate CVE-2025-21647 in the RHEL 9.6 Extended Update Support kernel. The vulnerability affects sch_cake bulk-flow fairness counters and can enable out-of-bounds memory access after counter underflow.
Red Hat addressed CVE-2025-21847 through RHSA-2025:20095 for RHEL 10 and RHSA-2025:20518 for RHEL 9. The ASoC SOF stream IPC flaw could cause a NULL-pointer dereference because sof_ipc_msg_data() did not validate that sps->cstream was non-NULL.
Red Hat remediated CVE-2024-49570 in RHEL 10 via RHSA-2025:20095 and in RHEL 9 via RHSA-2025:20518. The fix prevents the DRM Xe xe_bo_move trace event from dereferencing xe_mem_type_to_name[] at TP_printk trace-print time, eliminating a potential use-after-free.
The Linux kernel CVE team announced CVE-2025-21647, an underflow in sch_cake per-host bulk-flow fairness counters that can cause out-of-bounds memory access. The upstream fix centralizes counter access in bounds-checking helpers and is available in kernel versions 6.1.125, 6.6.72, 6.12.10, and 6.13-rc7.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
22 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.